api-functions.php 35 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126
  1. <?php /** @noinspection SqlResolve */
  2. /** @noinspection SqlResolve */
  3. /** @noinspection SqlResolve */
  4. /** @noinspection SqlResolve */
  5. /** @noinspection SyntaxError */
  6. function login($array)
  7. {
  8. // Grab username and Password from login form
  9. $username = $password = $oAuth = $oAuthType = '';
  10. foreach ($array['data'] as $items) {
  11. foreach ($items as $key => $value) {
  12. if ($key == 'name') {
  13. $newKey = $value;
  14. }
  15. if ($key == 'value') {
  16. $newValue = $value;
  17. }
  18. if (isset($newKey) && isset($newValue)) {
  19. $$newKey = $newValue;
  20. }
  21. }
  22. }
  23. $username = strtolower($username);
  24. $days = (isset($remember)) ? 7 : 1;
  25. $oAuth = (isset($oAuth)) ? $oAuth : false;
  26. try {
  27. $database = new Dibi\Connection([
  28. 'driver' => 'sqlite3',
  29. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  30. ]);
  31. $authSuccess = false;
  32. $function = 'plugin_auth_' . $GLOBALS['authBackend'];
  33. if (!$oAuth) {
  34. $result = $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $username);
  35. switch ($GLOBALS['authType']) {
  36. case 'external':
  37. if (function_exists($function)) {
  38. $authSuccess = $function($username, $password);
  39. }
  40. break;
  41. /** @noinspection PhpMissingBreakStatementInspection */
  42. case 'both':
  43. if (function_exists($function)) {
  44. $authSuccess = $function($username, $password);
  45. }
  46. // no break
  47. default: // Internal
  48. if (!$authSuccess) {
  49. // perform the internal authentication step
  50. if (password_verify($password, $result['password'])) {
  51. $authSuccess = true;
  52. }
  53. }
  54. }
  55. } else {
  56. // Has oAuth Token!
  57. switch ($oAuthType) {
  58. case 'plex':
  59. if ($GLOBALS['plexoAuth']) {
  60. $tokenInfo = checkPlexToken($oAuth);
  61. if ($tokenInfo) {
  62. $authSuccess = array(
  63. 'username' => $tokenInfo['user']['username'],
  64. 'email' => $tokenInfo['user']['email'],
  65. 'image' => $tokenInfo['user']['thumb'],
  66. 'token' => $tokenInfo['user']['authToken']
  67. );
  68. $authSuccess = ((!empty($GLOBALS['plexAdmin']) && strtolower($GLOBALS['plexAdmin']) == strtolower($tokenInfo['user']['username'])) || checkPlexUser($tokenInfo['user']['username'])) ? $authSuccess : false;
  69. }
  70. }
  71. break;
  72. default:
  73. return 'error';
  74. break;
  75. }
  76. $result = ($authSuccess) ? $database->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $authSuccess['username'], $authSuccess['email']) : '';
  77. }
  78. if ($authSuccess) {
  79. // Make sure user exists in database
  80. $userExists = false;
  81. $passwordMatches = ($oAuth) ? true : false;
  82. $token = (is_array($authSuccess) && isset($authSuccess['token']) ? $authSuccess['token'] : '');
  83. if ($result['username']) {
  84. $userExists = true;
  85. $username = $result['username'];
  86. $passwordMatches = (password_verify($password, $result['password'])) ? true : false;
  87. }
  88. if ($userExists) {
  89. //does org password need to be updated
  90. if (!$passwordMatches) {
  91. $database->query('
  92. UPDATE users SET', [
  93. 'password' => password_hash($password, PASSWORD_BCRYPT)
  94. ], '
  95. WHERE id=?', $result['id']);
  96. writeLog('success', 'Login Function - User Password updated from backend', $username);
  97. }
  98. if ($token !== '') {
  99. if ($token !== $result['plex_token']) {
  100. $database->query('
  101. UPDATE users SET', [
  102. 'plex_token' => $token
  103. ], '
  104. WHERE id=?', $result['id']);
  105. writeLog('success', 'Login Function - User Plex Token updated from backend', $username);
  106. }
  107. }
  108. // 2FA might go here
  109. if ($result['auth_service'] !== 'internal' && strpos($result['auth_service'], '::') !== false) {
  110. $TFA = explode('::', $result['auth_service']);
  111. // Is code with login info?
  112. if ($tfaCode == '') {
  113. return '2FA';
  114. } else {
  115. if (!verify2FA($TFA[1], $tfaCode, $TFA[0])) {
  116. return '2FA-incorrect';
  117. }
  118. }
  119. }
  120. // End 2FA
  121. // authentication passed - 1) mark active and update token
  122. if (createToken($result['username'], $result['email'], $result['image'], $result['group'], $result['group_id'], $GLOBALS['organizrHash'], $days)) {
  123. writeLoginLog($username, 'success');
  124. writeLog('success', 'Login Function - A User has logged in', $username);
  125. ssoCheck($username, $password, $token); //need to work on this
  126. return true;
  127. } else {
  128. return 'error';
  129. }
  130. } else {
  131. // Create User
  132. //ssoCheck($username, $password, $token);
  133. return authRegister((is_array($authSuccess) && isset($authSuccess['username']) ? $authSuccess['username'] : $username), $password, defaultUserGroup(), (is_array($authSuccess) && isset($authSuccess['email']) ? $authSuccess['email'] : ''), $token);
  134. }
  135. } else {
  136. // authentication failed
  137. writeLoginLog($username, 'error');
  138. writeLog('error', 'Login Function - Wrong Password', $username);
  139. return 'mismatch';
  140. }
  141. } catch (Dibi\Exception $e) {
  142. return $e;
  143. }
  144. }
  145. function createDB($path, $filename)
  146. {
  147. try {
  148. if (!file_exists($path)) {
  149. mkdir($path, 0777, true);
  150. }
  151. $createDB = new Dibi\Connection([
  152. 'driver' => 'sqlite3',
  153. 'database' => $path . $filename,
  154. ]);
  155. // Create Users
  156. $createDB->query('CREATE TABLE `users` (
  157. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  158. `username` TEXT UNIQUE,
  159. `password` TEXT,
  160. `email` TEXT,
  161. `plex_token` TEXT,
  162. `group` TEXT,
  163. `group_id` INTEGER,
  164. `locked` INTEGER,
  165. `image` TEXT,
  166. `register_date` DATE,
  167. `auth_service` TEXT DEFAULT \'internal\'
  168. );');
  169. // Create Tokens
  170. $createDB->query('CREATE TABLE `chatroom` (
  171. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  172. `username` TEXT,
  173. `gravatar` TEXT,
  174. `uid` TEXT,
  175. `date` DATE,
  176. `ip` TEXT,
  177. `message` TEXT
  178. );');
  179. $createDB->query('CREATE TABLE `tokens` (
  180. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  181. `token` TEXT UNIQUE,
  182. `user_id` INTEGER,
  183. `created` DATE,
  184. `expires` DATE
  185. );');
  186. $createDB->query('CREATE TABLE `groups` (
  187. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  188. `group` TEXT UNIQUE,
  189. `group_id` INTEGER,
  190. `image` TEXT,
  191. `default` INTEGER
  192. );');
  193. $createDB->query('CREATE TABLE `categories` (
  194. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  195. `order` INTEGER,
  196. `category` TEXT UNIQUE,
  197. `category_id` INTEGER,
  198. `image` TEXT,
  199. `default` INTEGER
  200. );');
  201. // Create Tabs
  202. $createDB->query('CREATE TABLE `tabs` (
  203. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  204. `order` INTEGER,
  205. `category_id` INTEGER,
  206. `name` TEXT,
  207. `url` TEXT,
  208. `url_local` TEXT,
  209. `default` INTEGER,
  210. `enabled` INTEGER,
  211. `group_id` INTEGER,
  212. `image` TEXT,
  213. `type` INTEGER,
  214. `splash` INTEGER,
  215. `ping` INTEGER,
  216. `ping_url` TEXT
  217. );');
  218. // Create Options
  219. $createDB->query('CREATE TABLE `options` (
  220. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  221. `name` TEXT UNIQUE,
  222. `value` TEXT
  223. );');
  224. // Create Invites
  225. $createDB->query('CREATE TABLE `invites` (
  226. `id` INTEGER PRIMARY KEY AUTOINCREMENT UNIQUE,
  227. `code` TEXT UNIQUE,
  228. `date` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  229. `email` TEXT,
  230. `username` TEXT,
  231. `dateused` TIMESTAMP,
  232. `usedby` TEXT,
  233. `ip` TEXT,
  234. `valid` TEXT,
  235. `type` TEXT
  236. );');
  237. return true;
  238. } catch (Dibi\Exception $e) {
  239. return false;
  240. }
  241. }
  242. // Upgrade Database
  243. function updateDB($oldVerNum = false)
  244. {
  245. $tempLock = $GLOBALS['dbLocation'] . 'DBLOCK.txt';
  246. if (!file_exists($tempLock)) {
  247. touch($tempLock);
  248. // Create Temp DB First
  249. $migrationDB = 'tempMigration.db';
  250. $pathDigest = pathinfo($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  251. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  252. unlink($GLOBALS['dbLocation'] . $migrationDB);
  253. }
  254. $backupDB = $pathDigest['dirname'] . '/' . $pathDigest['filename'] . '[' . date('Y-m-d_H-i-s') . ']' . ($oldVerNum ? '[' . $oldVerNum . ']' : '') . '.bak.db';
  255. copy($GLOBALS['dbLocation'] . $GLOBALS['dbName'], $backupDB);
  256. $success = createDB($GLOBALS['dbLocation'], $migrationDB);
  257. if ($success) {
  258. try {
  259. $connectOldDB = new Dibi\Connection([
  260. 'driver' => 'sqlite3',
  261. 'database' => $backupDB,
  262. ]);
  263. $connectNewDB = new Dibi\Connection([
  264. 'driver' => 'sqlite3',
  265. 'database' => $GLOBALS['dbLocation'] . $migrationDB,
  266. ]);
  267. $tables = $connectOldDB->fetchAll('SELECT name FROM sqlite_master WHERE type="table"');
  268. foreach ($tables as $table) {
  269. $data = $connectOldDB->fetchAll('SELECT * FROM ' . $table['name']);
  270. foreach ($data as $row) {
  271. $connectNewDB->query('INSERT into ' . $table['name'], $row);
  272. }
  273. }
  274. $connectOldDB->disconnect();
  275. $connectNewDB->disconnect();
  276. // Remove Current Database
  277. if (file_exists($GLOBALS['dbLocation'] . $migrationDB)) {
  278. $oldFileSize = filesize($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  279. $newFileSize = filesize($GLOBALS['dbLocation'] . $migrationDB);
  280. if ($newFileSize >= $oldFileSize) {
  281. @unlink($GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  282. copy($GLOBALS['dbLocation'] . $migrationDB, $GLOBALS['dbLocation'] . $GLOBALS['dbName']);
  283. @unlink($GLOBALS['dbLocation'] . $migrationDB);
  284. writeLog('success', 'Update Function - Migrated Old Info to new Database', 'Database');
  285. unlink($tempLock);
  286. return true;
  287. }
  288. }
  289. unlink($tempLock);
  290. return false;
  291. } catch (Dibi\Exception $e) {
  292. writeLog('error', 'Update Function - Error [' . $e . ']', 'Database');
  293. unlink($tempLock);
  294. return false;
  295. }
  296. }
  297. unlink($tempLock);
  298. return false;
  299. }
  300. return false;
  301. }
  302. function createFirstAdmin($path, $filename, $username, $password, $email)
  303. {
  304. try {
  305. $createDB = new Dibi\Connection([
  306. 'driver' => 'sqlite3',
  307. 'database' => $path . $filename,
  308. ]);
  309. $userInfo = [
  310. 'username' => $username,
  311. 'password' => password_hash($password, PASSWORD_BCRYPT),
  312. 'email' => $email,
  313. 'group' => 'Admin',
  314. 'group_id' => 0,
  315. 'image' => gravatar($email),
  316. 'register_date' => $GLOBALS['currentTime'],
  317. ];
  318. $groupInfo0 = [
  319. 'group' => 'Admin',
  320. 'group_id' => 0,
  321. 'default' => false,
  322. 'image' => 'plugins/images/groups/admin.png',
  323. ];
  324. $groupInfo1 = [
  325. 'group' => 'Co-Admin',
  326. 'group_id' => 1,
  327. 'default' => false,
  328. 'image' => 'plugins/images/groups/coadmin.png',
  329. ];
  330. $groupInfo2 = [
  331. 'group' => 'Super User',
  332. 'group_id' => 2,
  333. 'default' => false,
  334. 'image' => 'plugins/images/groups/superuser.png',
  335. ];
  336. $groupInfo3 = [
  337. 'group' => 'Power User',
  338. 'group_id' => 3,
  339. 'default' => false,
  340. 'image' => 'plugins/images/groups/poweruser.png',
  341. ];
  342. $groupInfo4 = [
  343. 'group' => 'User',
  344. 'group_id' => 4,
  345. 'default' => true,
  346. 'image' => 'plugins/images/groups/user.png',
  347. ];
  348. $groupInfoGuest = [
  349. 'group' => 'Guest',
  350. 'group_id' => 999,
  351. 'default' => false,
  352. 'image' => 'plugins/images/groups/guest.png',
  353. ];
  354. $settingsInfo = [
  355. 'order' => 1,
  356. 'category_id' => 0,
  357. 'name' => 'Settings',
  358. 'url' => 'api/?v1/settings/page',
  359. 'default' => false,
  360. 'enabled' => true,
  361. 'group_id' => 1,
  362. 'image' => 'fontawesome::cog',
  363. 'type' => 0
  364. ];
  365. $homepageInfo = [
  366. 'order' => 2,
  367. 'category_id' => 0,
  368. 'name' => 'Homepage',
  369. 'url' => 'api/?v1/homepage/page',
  370. 'default' => false,
  371. 'enabled' => false,
  372. 'group_id' => 4,
  373. 'image' => 'fontawesome::home',
  374. 'type' => 0
  375. ];
  376. $unsortedInfo = [
  377. 'order' => 1,
  378. 'category' => 'Unsorted',
  379. 'category_id' => 0,
  380. 'image' => 'plugins/images/categories/unsorted.png',
  381. 'default' => true
  382. ];
  383. $createDB->query('INSERT INTO [users]', $userInfo);
  384. $createDB->query('INSERT INTO [groups]', $groupInfo0);
  385. $createDB->query('INSERT INTO [groups]', $groupInfo1);
  386. $createDB->query('INSERT INTO [groups]', $groupInfo2);
  387. $createDB->query('INSERT INTO [groups]', $groupInfo3);
  388. $createDB->query('INSERT INTO [groups]', $groupInfo4);
  389. $createDB->query('INSERT INTO [groups]', $groupInfoGuest);
  390. $createDB->query('INSERT INTO [tabs]', $settingsInfo);
  391. $createDB->query('INSERT INTO [tabs]', $homepageInfo);
  392. $createDB->query('INSERT INTO [categories]', $unsortedInfo);
  393. return true;
  394. } catch (Dibi\Exception $e) {
  395. writeLog('error', 'Wizard Function - Error [' . $e . ']', 'Wizard');
  396. return false;
  397. }
  398. }
  399. function defaultUserGroup()
  400. {
  401. try {
  402. $connect = new Dibi\Connection([
  403. 'driver' => 'sqlite3',
  404. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  405. ]);
  406. $all = $connect->fetch('SELECT * FROM groups WHERE `default` = 1');
  407. return $all;
  408. } catch (Dibi\Exception $e) {
  409. return false;
  410. }
  411. }
  412. function defaultTabCategory()
  413. {
  414. try {
  415. $connect = new Dibi\Connection([
  416. 'driver' => 'sqlite3',
  417. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  418. ]);
  419. $all = $connect->fetch('SELECT * FROM categories WHERE `default` = 1');
  420. return $all;
  421. } catch (Dibi\Exception $e) {
  422. return false;
  423. }
  424. }
  425. function getGuest()
  426. {
  427. if (isset($GLOBALS['dbLocation'])) {
  428. try {
  429. $connect = new Dibi\Connection([
  430. 'driver' => 'sqlite3',
  431. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  432. ]);
  433. $all = $connect->fetch('SELECT * FROM groups WHERE `group_id` = 999');
  434. return $all;
  435. } catch (Dibi\Exception $e) {
  436. return false;
  437. }
  438. } else {
  439. return array(
  440. 'group' => 'Guest',
  441. 'group_id' => 999,
  442. 'image' => 'plugins/images/groups/guest.png'
  443. );
  444. }
  445. }
  446. function adminEditGroup($array)
  447. {
  448. switch ($array['data']['action']) {
  449. case 'changeDefaultGroup':
  450. try {
  451. $connect = new Dibi\Connection([
  452. 'driver' => 'sqlite3',
  453. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  454. ]);
  455. $connect->query('UPDATE groups SET `default` = 0');
  456. $connect->query('
  457. UPDATE groups SET', [
  458. 'default' => 1
  459. ], '
  460. WHERE id=?', $array['data']['id']);
  461. writeLog('success', 'Group Management Function - Changed Default Group from [' . $array['data']['oldGroupName'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  462. return true;
  463. } catch (Dibi\Exception $e) {
  464. return false;
  465. }
  466. break;
  467. case 'deleteUserGroup':
  468. try {
  469. $connect = new Dibi\Connection([
  470. 'driver' => 'sqlite3',
  471. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  472. ]);
  473. $connect->query('DELETE FROM groups WHERE id = ?', $array['data']['id']);
  474. writeLog('success', 'Group Management Function - Deleted Group [' . $array['data']['groupName'] . ']', $GLOBALS['organizrUser']['username']);
  475. return true;
  476. } catch (Dibi\Exception $e) {
  477. return false;
  478. }
  479. break;
  480. case 'addUserGroup':
  481. try {
  482. $connect = new Dibi\Connection([
  483. 'driver' => 'sqlite3',
  484. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  485. ]);
  486. $newGroup = [
  487. 'group' => $array['data']['newGroupName'],
  488. 'group_id' => $array['data']['newGroupID'],
  489. 'default' => false,
  490. 'image' => $array['data']['newGroupImage'],
  491. ];
  492. $connect->query('INSERT INTO [groups]', $newGroup);
  493. writeLog('success', 'Group Management Function - Added Group [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  494. return true;
  495. } catch (Dibi\Exception $e) {
  496. return false;
  497. }
  498. break;
  499. case 'editUserGroup':
  500. try {
  501. $connect = new Dibi\Connection([
  502. 'driver' => 'sqlite3',
  503. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  504. ]);
  505. $connect->query('
  506. UPDATE groups SET', [
  507. 'group' => $array['data']['groupName'],
  508. 'image' => $array['data']['groupImage'],
  509. ], '
  510. WHERE id=?', $array['data']['id']);
  511. writeLog('success', 'Group Management Function - Edited Group Info for [' . $array['data']['oldGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  512. return true;
  513. } catch (Dibi\Exception $e) {
  514. return false;
  515. }
  516. break;
  517. default:
  518. return false;
  519. break;
  520. }
  521. }
  522. function adminEditUser($array)
  523. {
  524. switch ($array['data']['action']) {
  525. case 'changeGroup':
  526. try {
  527. $connect = new Dibi\Connection([
  528. 'driver' => 'sqlite3',
  529. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  530. ]);
  531. $connect->query('
  532. UPDATE users SET', [
  533. 'group' => $array['data']['newGroupName'],
  534. 'group_id' => $array['data']['newGroupID'],
  535. ], '
  536. WHERE id=?', $array['data']['id']);
  537. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  538. return true;
  539. } catch (Dibi\Exception $e) {
  540. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  541. return false;
  542. }
  543. break;
  544. case 'editUser':
  545. try {
  546. $connect = new Dibi\Connection([
  547. 'driver' => 'sqlite3',
  548. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  549. ]);
  550. if (!usernameTakenExcept($array['data']['username'], $array['data']['email'], $array['data']['id'])) {
  551. $connect->query('
  552. UPDATE users SET', [
  553. 'username' => $array['data']['username'],
  554. 'email' => $array['data']['email'],
  555. 'image' => gravatar($array['data']['email']),
  556. ], '
  557. WHERE id=?', $array['data']['id']);
  558. if (!empty($array['data']['password'])) {
  559. $connect->query('
  560. UPDATE users SET', [
  561. 'password' => password_hash($array['data']['password'], PASSWORD_BCRYPT)
  562. ], '
  563. WHERE id=?', $array['data']['id']);
  564. }
  565. writeLog('success', 'User Management Function - User: ' . $array['data']['username'] . '\'s info was changed', $GLOBALS['organizrUser']['username']);
  566. return true;
  567. } else {
  568. return false;
  569. }
  570. } catch (Dibi\Exception $e) {
  571. writeLog('error', 'User Management Function - Error - User: ' . $array['data']['username'] . '\'s group was changed from [' . $array['data']['oldGroup'] . '] to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  572. return false;
  573. }
  574. break;
  575. case 'addNewUser':
  576. $defaults = defaultUserGroup();
  577. if (createUser($array['data']['username'], $array['data']['password'], $defaults, $array['data']['email'])) {
  578. writeLog('success', 'Create User Function - Account created for [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  579. return true;
  580. } else {
  581. writeLog('error', 'Registration Function - An error occurred', $GLOBALS['organizrUser']['username']);
  582. return 'username taken';
  583. }
  584. break;
  585. case 'deleteUser':
  586. try {
  587. $connect = new Dibi\Connection([
  588. 'driver' => 'sqlite3',
  589. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  590. ]);
  591. $connect->query('DELETE FROM users WHERE id = ?', $array['data']['id']);
  592. writeLog('success', 'User Management Function - Deleted User [' . $array['data']['username'] . ']', $GLOBALS['organizrUser']['username']);
  593. return true;
  594. } catch (Dibi\Exception $e) {
  595. return false;
  596. }
  597. break;
  598. default:
  599. return false;
  600. break;
  601. }
  602. }
  603. function editTabs($array)
  604. {
  605. switch ($array['data']['action']) {
  606. case 'changeGroup':
  607. try {
  608. $connect = new Dibi\Connection([
  609. 'driver' => 'sqlite3',
  610. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  611. ]);
  612. $connect->query('
  613. UPDATE tabs SET', [
  614. 'group_id' => $array['data']['newGroupID'],
  615. ], '
  616. WHERE id=?', $array['data']['id']);
  617. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s group was changed to [' . $array['data']['newGroupName'] . ']', $GLOBALS['organizrUser']['username']);
  618. return true;
  619. } catch (Dibi\Exception $e) {
  620. return false;
  621. }
  622. break;
  623. case 'changeCategory':
  624. try {
  625. $connect = new Dibi\Connection([
  626. 'driver' => 'sqlite3',
  627. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  628. ]);
  629. $connect->query('
  630. UPDATE tabs SET', [
  631. 'category_id' => $array['data']['newCategoryID'],
  632. ], '
  633. WHERE id=?', $array['data']['id']);
  634. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s category was changed to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  635. return true;
  636. } catch (Dibi\Exception $e) {
  637. return false;
  638. }
  639. break;
  640. case 'changeType':
  641. try {
  642. $connect = new Dibi\Connection([
  643. 'driver' => 'sqlite3',
  644. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  645. ]);
  646. $connect->query('
  647. UPDATE tabs SET', [
  648. 'type' => $array['data']['newTypeID'],
  649. ], '
  650. WHERE id=?', $array['data']['id']);
  651. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s type was changed to [' . $array['data']['newTypeName'] . ']', $GLOBALS['organizrUser']['username']);
  652. return true;
  653. } catch (Dibi\Exception $e) {
  654. return false;
  655. }
  656. break;
  657. case 'changeEnabled':
  658. try {
  659. $connect = new Dibi\Connection([
  660. 'driver' => 'sqlite3',
  661. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  662. ]);
  663. $connect->query('
  664. UPDATE tabs SET', [
  665. 'enabled' => $array['data']['tabEnabled'],
  666. ], '
  667. WHERE id=?', $array['data']['id']);
  668. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s enable status was changed to [' . $array['data']['tabEnabledWord'] . ']', $GLOBALS['organizrUser']['username']);
  669. return true;
  670. } catch (Dibi\Exception $e) {
  671. return false;
  672. }
  673. break;
  674. case 'changeSplash':
  675. try {
  676. $connect = new Dibi\Connection([
  677. 'driver' => 'sqlite3',
  678. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  679. ]);
  680. $connect->query('
  681. UPDATE tabs SET', [
  682. 'splash' => $array['data']['tabSplash'],
  683. ], '
  684. WHERE id=?', $array['data']['id']);
  685. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s splash status was changed to [' . $array['data']['tabSplashWord'] . ']', $GLOBALS['organizrUser']['username']);
  686. return true;
  687. } catch (Dibi\Exception $e) {
  688. return false;
  689. }
  690. break;
  691. case 'changePing':
  692. try {
  693. $connect = new Dibi\Connection([
  694. 'driver' => 'sqlite3',
  695. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  696. ]);
  697. $connect->query('
  698. UPDATE tabs SET', [
  699. 'ping' => $array['data']['tabPing'],
  700. ], '
  701. WHERE id=?', $array['data']['id']);
  702. writeLog('success', 'Tab Editor Function - Tab: ' . $array['data']['tab'] . '\'s ping status was changed to [' . $array['data']['tabPingWord'] . ']', $GLOBALS['organizrUser']['username']);
  703. return true;
  704. } catch (Dibi\Exception $e) {
  705. return false;
  706. }
  707. break;
  708. case 'changeDefault':
  709. try {
  710. $connect = new Dibi\Connection([
  711. 'driver' => 'sqlite3',
  712. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  713. ]);
  714. $connect->query('UPDATE tabs SET `default` = 0');
  715. $connect->query('
  716. UPDATE tabs SET', [
  717. 'default' => 1
  718. ], '
  719. WHERE id=?', $array['data']['id']);
  720. writeLog('success', 'Tab Editor Function - Changed Default Tab to [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  721. return true;
  722. } catch (Dibi\Exception $e) {
  723. return false;
  724. }
  725. break;
  726. case 'deleteTab':
  727. try {
  728. $connect = new Dibi\Connection([
  729. 'driver' => 'sqlite3',
  730. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  731. ]);
  732. $connect->query('DELETE FROM tabs WHERE id = ?', $array['data']['id']);
  733. writeLog('success', 'Tab Editor Function - Deleted Tab [' . $array['data']['tab'] . ']', $GLOBALS['organizrUser']['username']);
  734. return true;
  735. } catch (Dibi\Exception $e) {
  736. return false;
  737. }
  738. break;
  739. case 'editTab':
  740. try {
  741. $connect = new Dibi\Connection([
  742. 'driver' => 'sqlite3',
  743. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  744. ]);
  745. $connect->query('
  746. UPDATE tabs SET', [
  747. 'name' => $array['data']['tabName'],
  748. 'url' => $array['data']['tabURL'],
  749. 'ping_url' => $array['data']['pingURL'],
  750. 'image' => $array['data']['tabImage'],
  751. ], '
  752. WHERE id=?', $array['data']['id']);
  753. writeLog('success', 'Tab Editor Function - Edited Tab Info for [' . $array['data']['tabName'] . ']', $GLOBALS['organizrUser']['username']);
  754. return true;
  755. } catch (Dibi\Exception $e) {
  756. return false;
  757. }
  758. case 'changeOrder':
  759. try {
  760. $connect = new Dibi\Connection([
  761. 'driver' => 'sqlite3',
  762. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  763. ]);
  764. foreach ($array['data']['tabs']['tab'] as $key => $value) {
  765. if ($value['order'] != $value['originalOrder']) {
  766. $connect->query('
  767. UPDATE tabs SET', [
  768. 'order' => $value['order'],
  769. ], '
  770. WHERE id=?', $value['id']);
  771. writeLog('success', 'Tab Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  772. }
  773. }
  774. writeLog('success', 'Tab Editor Function - Tab Order Changed', $GLOBALS['organizrUser']['username']);
  775. return true;
  776. } catch (Dibi\Exception $e) {
  777. return false;
  778. }
  779. break;
  780. case 'addNewTab':
  781. try {
  782. $default = defaultTabCategory()['category_id'];
  783. $connect = new Dibi\Connection([
  784. 'driver' => 'sqlite3',
  785. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  786. ]);
  787. $newTab = [
  788. 'order' => $array['data']['tabOrder'],
  789. 'category_id' => $default,
  790. 'name' => $array['data']['tabName'],
  791. 'url' => $array['data']['tabURL'],
  792. 'ping_url' => $array['data']['pingURL'],
  793. 'default' => $array['data']['tabDefault'],
  794. 'enabled' => 1,
  795. 'group_id' => $array['data']['tabGroupID'],
  796. 'image' => $array['data']['tabImage'],
  797. 'type' => $array['data']['tabType']
  798. ];
  799. $connect->query('INSERT INTO [tabs]', $newTab);
  800. writeLog('success', 'Tab Editor Function - Created Tab for: ' . $array['data']['tabName'], $GLOBALS['organizrUser']['username']);
  801. return true;
  802. } catch (Dibi\Exception $e) {
  803. return false;
  804. }
  805. break;
  806. default:
  807. return false;
  808. break;
  809. }
  810. }
  811. function editCategories($array)
  812. {
  813. switch ($array['data']['action']) {
  814. case 'changeDefault':
  815. try {
  816. $connect = new Dibi\Connection([
  817. 'driver' => 'sqlite3',
  818. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  819. ]);
  820. $connect->query('UPDATE categories SET `default` = 0');
  821. $connect->query('
  822. UPDATE categories SET', [
  823. 'default' => 1
  824. ], '
  825. WHERE id=?', $array['data']['id']);
  826. writeLog('success', 'Category Editor Function - Changed Default Category from [' . $array['data']['oldCategoryName'] . '] to [' . $array['data']['newCategoryName'] . ']', $GLOBALS['organizrUser']['username']);
  827. return true;
  828. } catch (Dibi\Exception $e) {
  829. return false;
  830. }
  831. break;
  832. case 'deleteCategory':
  833. try {
  834. $connect = new Dibi\Connection([
  835. 'driver' => 'sqlite3',
  836. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  837. ]);
  838. $connect->query('DELETE FROM categories WHERE id = ?', $array['data']['id']);
  839. writeLog('success', 'Category Editor Function - Deleted Category [' . $array['data']['category'] . ']', $GLOBALS['organizrUser']['username']);
  840. return true;
  841. } catch (Dibi\Exception $e) {
  842. return false;
  843. }
  844. break;
  845. case 'addNewCategory':
  846. try {
  847. $connect = new Dibi\Connection([
  848. 'driver' => 'sqlite3',
  849. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  850. ]);
  851. $newCategory = [
  852. 'category' => $array['data']['categoryName'],
  853. 'order' => $array['data']['categoryOrder'],
  854. 'category_id' => $array['data']['categoryID'],
  855. 'default' => false,
  856. 'image' => $array['data']['categoryImage'],
  857. ];
  858. $connect->query('INSERT INTO [categories]', $newCategory);
  859. writeLog('success', 'Category Editor Function - Added Category [' . $array['data']['categoryName'] . ']', $GLOBALS['organizrUser']['username']);
  860. return true;
  861. } catch (Dibi\Exception $e) {
  862. return $e;
  863. }
  864. break;
  865. case 'editCategory':
  866. try {
  867. $connect = new Dibi\Connection([
  868. 'driver' => 'sqlite3',
  869. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  870. ]);
  871. $connect->query('
  872. UPDATE categories SET', [
  873. 'category' => $array['data']['name'],
  874. 'image' => $array['data']['image'],
  875. ], '
  876. WHERE id=?', $array['data']['id']);
  877. writeLog('success', 'Category Editor Function - Edited Category Info for [' . $array['data']['name'] . ']', $GLOBALS['organizrUser']['username']);
  878. return true;
  879. } catch (Dibi\Exception $e) {
  880. return false;
  881. }
  882. break;
  883. case 'changeOrder':
  884. try {
  885. $connect = new Dibi\Connection([
  886. 'driver' => 'sqlite3',
  887. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  888. ]);
  889. foreach ($array['data']['categories']['category'] as $key => $value) {
  890. if ($value['order'] != $value['originalOrder']) {
  891. $connect->query('
  892. UPDATE categories SET', [
  893. 'order' => $value['order'],
  894. ], '
  895. WHERE id=?', $value['id']);
  896. writeLog('success', 'Category Editor Function - ' . $value['name'] . ' Order Changed From ' . $value['order'] . ' to ' . $value['originalOrder'], $GLOBALS['organizrUser']['username']);
  897. }
  898. }
  899. writeLog('success', 'Category Editor Function - Category Order Changed', $GLOBALS['organizrUser']['username']);
  900. return true;
  901. } catch (Dibi\Exception $e) {
  902. return false;
  903. }
  904. break;
  905. default:
  906. return false;
  907. break;
  908. }
  909. }
  910. function allUsers()
  911. {
  912. try {
  913. $connect = new Dibi\Connection([
  914. 'driver' => 'sqlite3',
  915. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  916. ]);
  917. $users = $connect->fetchAll('SELECT * FROM users');
  918. $groups = $connect->fetchAll('SELECT * FROM groups ORDER BY group_id ASC');
  919. foreach ($users as $k => $v) {
  920. // clear password from array
  921. unset($users[$k]['password']);
  922. }
  923. $all['users'] = $users;
  924. $all['groups'] = $groups;
  925. return $all;
  926. } catch (Dibi\Exception $e) {
  927. return false;
  928. }
  929. }
  930. function usernameTaken($username, $email)
  931. {
  932. try {
  933. $connect = new Dibi\Connection([
  934. 'driver' => 'sqlite3',
  935. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  936. ]);
  937. $all = $connect->fetch('SELECT * FROM users WHERE username = ? COLLATE NOCASE OR email = ? COLLATE NOCASE', $username, $email);
  938. return ($all) ? true : false;
  939. } catch (Dibi\Exception $e) {
  940. return false;
  941. }
  942. }
  943. function usernameTakenExcept($username, $email, $id)
  944. {
  945. try {
  946. $connect = new Dibi\Connection([
  947. 'driver' => 'sqlite3',
  948. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  949. ]);
  950. $all = $connect->fetch('SELECT * FROM users WHERE id IS NOT ? AND username = ? COLLATE NOCASE OR id IS NOT ? AND email = ? COLLATE NOCASE', $id, $username, $id, $email);
  951. return ($all) ? true : false;
  952. } catch (Dibi\Exception $e) {
  953. return false;
  954. }
  955. }
  956. function createUser($username, $password, $defaults, $email = null)
  957. {
  958. $email = ($email) ? $email : random_ascii_string(10) . '@placeholder.eml';
  959. try {
  960. if (!usernameTaken($username, $email)) {
  961. $createDB = new Dibi\Connection([
  962. 'driver' => 'sqlite3',
  963. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  964. ]);
  965. $userInfo = [
  966. 'username' => $username,
  967. 'password' => password_hash($password, PASSWORD_BCRYPT),
  968. 'email' => $email,
  969. 'group' => $defaults['group'],
  970. 'group_id' => $defaults['group_id'],
  971. 'image' => gravatar($email),
  972. 'register_date' => $GLOBALS['currentTime'],
  973. ];
  974. $createDB->query('INSERT INTO [users]', $userInfo);
  975. return true;
  976. } else {
  977. return false;
  978. }
  979. } catch (Dibi\Exception $e) {
  980. return false;
  981. }
  982. }
  983. function importUsers($array)
  984. {
  985. $imported = 0;
  986. $defaults = defaultUserGroup();
  987. foreach ($array as $user) {
  988. $password = random_ascii_string(30);
  989. if ($user['username'] !== '' && $user['email'] !== '' && $password !== '' && $defaults !== '') {
  990. $newUser = createUser($user['username'], $password, $defaults, $user['email']);
  991. if (!$newUser) {
  992. writeLog('error', 'Import Function - Error', $user['username']);
  993. } else {
  994. $imported++;
  995. }
  996. }
  997. }
  998. return $imported;
  999. }
  1000. function importUsersType($array)
  1001. {
  1002. $type = $array['data']['type'];
  1003. if ($type !== '') {
  1004. switch ($type) {
  1005. case 'plex':
  1006. return importUsers(allPlexUsers(true));
  1007. break;
  1008. default:
  1009. return false;
  1010. }
  1011. }
  1012. return false;
  1013. }
  1014. function allTabs()
  1015. {
  1016. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1017. try {
  1018. $connect = new Dibi\Connection([
  1019. 'driver' => 'sqlite3',
  1020. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1021. ]);
  1022. $all['tabs'] = $connect->fetchAll('SELECT * FROM tabs ORDER BY `order` ASC');
  1023. $all['categories'] = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1024. $all['groups'] = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1025. return $all;
  1026. } catch (Dibi\Exception $e) {
  1027. return false;
  1028. }
  1029. }
  1030. return false;
  1031. }
  1032. function allGroups()
  1033. {
  1034. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1035. try {
  1036. $connect = new Dibi\Connection([
  1037. 'driver' => 'sqlite3',
  1038. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1039. ]);
  1040. $all = $connect->fetchAll('SELECT * FROM groups ORDER BY `group_id` ASC');
  1041. return $all;
  1042. } catch (Dibi\Exception $e) {
  1043. return false;
  1044. }
  1045. }
  1046. return false;
  1047. }
  1048. function loadTabs()
  1049. {
  1050. if (file_exists('config' . DIRECTORY_SEPARATOR . 'config.php')) {
  1051. try {
  1052. $connect = new Dibi\Connection([
  1053. 'driver' => 'sqlite3',
  1054. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1055. ]);
  1056. $sort = ($GLOBALS['unsortedTabs'] == 'top') ? 'DESC' : 'ASC';
  1057. $tabs = $connect->fetchAll('SELECT * FROM tabs WHERE `group_id` >= ? AND `enabled` = 1 ORDER BY `order` ' . $sort, $GLOBALS['organizrUser']['groupID']);
  1058. $categories = $connect->fetchAll('SELECT * FROM categories ORDER BY `order` ASC');
  1059. $all['tabs'] = $tabs;
  1060. foreach ($tabs as $k => $v) {
  1061. $v['access_url'] = isset($v['url_local']) && getenv('SERVER_ADDR') == userIP() ? $v['url_local'] : $v['url'];
  1062. }
  1063. $count = array_map(function ($element) {
  1064. return $element['category_id'];
  1065. }, $tabs);
  1066. $count = (array_count_values($count));
  1067. foreach ($categories as $k => $v) {
  1068. $v['count'] = isset($count[$v['category_id']]) ? $count[$v['category_id']] : 0;
  1069. }
  1070. $all['categories'] = $categories;
  1071. return $all;
  1072. } catch (Dibi\Exception $e) {
  1073. return false;
  1074. }
  1075. }
  1076. return false;
  1077. }
  1078. function getActiveTokens()
  1079. {
  1080. try {
  1081. $connect = new Dibi\Connection([
  1082. 'driver' => 'sqlite3',
  1083. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1084. ]);
  1085. $all = $connect->fetchAll('SELECT * FROM `tokens` WHERE `user_id` = ? AND `expires` > ?', $GLOBALS['organizrUser']['userID'], $GLOBALS['currentTime']);
  1086. return $all;
  1087. } catch (Dibi\Exception $e) {
  1088. return false;
  1089. }
  1090. }
  1091. function revokeToken($array)
  1092. {
  1093. if ($array['data']['token']) {
  1094. try {
  1095. $connect = new Dibi\Connection([
  1096. 'driver' => 'sqlite3',
  1097. 'database' => $GLOBALS['dbLocation'] . $GLOBALS['dbName'],
  1098. ]);
  1099. $connect->query('DELETE FROM tokens WHERE user_id = ? AND token = ?', $GLOBALS['organizrUser']['userID'], $array['data']['token']);
  1100. return true;
  1101. } catch (Dibi\Exception $e) {
  1102. return false;
  1103. }
  1104. }
  1105. }