api.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363
  1. <?php
  2. require_once('php/include.php');
  3. // TODO - Add API handling.
  4. $method = $_SERVER['REQUEST_METHOD'];
  5. $ret = array();
  6. if(isset($_GET['type'])){
  7. if(isset($_GET['id'])){
  8. $id = $_GET['id'];
  9. switch($_GET['type']){
  10. case 'user':
  11. back(true);
  12. $ret['template'] = array(
  13. 'type'=>'pages',
  14. 'name'=>'user'
  15. );
  16. if($user = userObj($id)){
  17. $context = array(
  18. 'name'=>$user['name'],
  19. 'email'=>$user['email']
  20. );
  21. if($LOGGEDIN){
  22. $context['key'] = true;
  23. $context['user'] = userObj($_SESSION['username']);
  24. };
  25. $ret['context'] = $context;
  26. }else{
  27. $ret['state'] = array(
  28. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  29. );
  30. }
  31. retj($ret,'User - '.$context['name']);
  32. break;
  33. case 'group':
  34. back(true);
  35. // TODO - handle group requests
  36. if(false){
  37. // TODO
  38. }else{
  39. $ret['state'] = array(
  40. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  41. );
  42. }
  43. retj($ret,'Project - '.$context['title']);
  44. break;
  45. case 'issue':
  46. back(true);
  47. // TODO - handle issue requests
  48. if(false){
  49. // TODO
  50. }else{
  51. $ret['state'] = array(
  52. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  53. );
  54. }
  55. retj($ret,'Project - '.$context['title']);
  56. break;
  57. case 'scrum':
  58. back(true);
  59. // TODO - handle scrum requests
  60. if(false){
  61. // TODO
  62. }else{
  63. $ret['state'] = array(
  64. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  65. );
  66. }
  67. retj($ret,'Project - '.$context['title']);
  68. break;
  69. case 'project':
  70. back(true);
  71. $ret['template'] = array(
  72. 'type'=>'pages',
  73. 'name'=>'project'
  74. );
  75. if($context = projectObj($id)){
  76. $context['user'] = userObj($context['user']);
  77. if($LOGGEDIN){
  78. $context['key'] = true;
  79. $context['user'] = userObj($_SESSION['username']);
  80. };
  81. $ret['context'] = $context;
  82. }else{
  83. $ret['state'] = array(
  84. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  85. );
  86. }
  87. retj($ret,'Project - '.$context['title']);
  88. break;
  89. case 'message':
  90. // TODO - handle message requests
  91. if(false){
  92. // TODO
  93. }else{
  94. $ret['state'] = array(
  95. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  96. );
  97. }
  98. retj($ret,'Project - '.$context['title']);
  99. break;
  100. case 'admin':
  101. back(true);
  102. // TODO - handle admin requests
  103. if(false){
  104. // TODO
  105. }else{
  106. $ret['state'] = array(
  107. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  108. );
  109. }
  110. retj($ret,'Project - '.$context['title']);
  111. break;
  112. case 'page':
  113. $title = $id;
  114. if(file_exists(PATH_DATA.'pages/'.$id.'.template')){
  115. $context = array();
  116. $ret['template'] = array(
  117. 'type'=>'pages',
  118. 'name'=>$id
  119. );
  120. if($LOGGEDIN){
  121. $context['key'] = true;
  122. $context['user'] = userObj($_SESSION['username']);
  123. };
  124. if(file_exists(PATH_DATA.'pages/'.$id.'.options')){
  125. $options = objectToarray(json_decode(file_get_contents(PATH_DATA.'pages/'.$id.'.options'),true));
  126. if(isset($options['secure'])&&$options['secure']&&!$LOGGEDIN){
  127. back(true);
  128. }
  129. if(isset($options['title'])){
  130. $title = $options['title'];
  131. }
  132. if(isset($options['context'])){
  133. foreach($options['context'] as $key){
  134. switch($key){
  135. case 'users':
  136. if($res = query("SELECT name FROM `users`;")){
  137. $context['users'] = fetch_all($res,MYSQLI_ASSOC);
  138. }
  139. break;
  140. case 'projects':
  141. if($res = query("SELECT p.title,p.id,p.description,u.name as user FROM `projects` p JOIN `users` u ON u.id = p.u_id")){
  142. $context['projects'] = fetch_all($res,MYSQLI_ASSOC);
  143. foreach($context['projects'] as $key => $project){
  144. $context['projects'][$key]['user'] = userObj($project['user']);
  145. }
  146. }
  147. break;
  148. case 'messages':
  149. if($LOGGEDIN){
  150. $context['messages'] = messages($context['user']['id'],'user');
  151. }else{
  152. $context['messages'] = array();
  153. }
  154. break;
  155. }
  156. }
  157. }
  158. if(isset($options['actions'])){
  159. foreach($options['actions'] as $key){
  160. switch($key){
  161. case 'pm_mark_read':
  162. query("UPDATE `users` SET last_pm_check=CURRENT_TIMESTAMP WHERE id='%d'; ",array(userId($_SESSION['username'])));
  163. break;
  164. }
  165. }
  166. }
  167. }
  168. $ret['context'] = $context;
  169. }else{
  170. $ret['error'] = 'That page does not exist';
  171. }
  172. retj($ret,$title);
  173. break;
  174. case 'manifest':
  175. case 'pages':
  176. if(isset($_GET['id'])){
  177. if($_GET['id'] != 'emails'){
  178. $manifest = array();
  179. $files = array_diff(scandir(PATH_DATA.'/'.$_GET['id']),array('..', '.','.htaccess','version'));
  180. foreach($files as $k => $file){
  181. if(pathinfo(PATH_DATA.'/'.$_GET['id'].'/'.$file,PATHINFO_EXTENSION) == 'template'){
  182. array_push($manifest,basename($file,'.template'));
  183. }
  184. }
  185. retj(array(
  186. 'manifest'=>$manifest,
  187. 'type'=>$_GET['id']
  188. ));
  189. }else{
  190. retj(array(
  191. 'error'=>'Cannot return that manifest'
  192. ));
  193. }
  194. }else{
  195. retj(array(
  196. 'error'=>'Manifest ID not defined'
  197. ));
  198. }
  199. break;
  200. break;
  201. case 'template':
  202. if(isset($_GET['name'])){
  203. if($_GET['id'] != 'emails'){
  204. retj(array(
  205. 'template'=>file_get_contents(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template'),
  206. 'name'=>$_GET['name'],
  207. 'type'=>$_GET['id']
  208. ));
  209. }else{
  210. retj(array(
  211. 'error'=>'Cannot return that type of template'
  212. ));
  213. }
  214. }else{
  215. retj(array(
  216. 'error'=>'Template name missing'
  217. ));
  218. }
  219. break;
  220. case 'action':
  221. switch($id){
  222. case 'login':
  223. $ret['state'] = array(
  224. 'data'=>array(
  225. 'type'=>'page',
  226. 'id'=>'login',
  227. )
  228. );
  229. if(isset($_GET['username'])&&isset($_GET['password'])){
  230. $key = login($_GET['username'],$_GET['password']);
  231. if($key){
  232. $_SESSION['username'] = $_GET['username'];
  233. }else{
  234. $ret['error'] = "Login failed. Username or Password didn't match.";
  235. }
  236. }else{
  237. $ret['error'] = "Please provide a valid username and password.";
  238. }
  239. retj($ret,$id);
  240. break;
  241. case 'register':
  242. $ret['state'] = array(
  243. 'data'=>array(
  244. 'type'=>'page',
  245. 'id'=>'register'
  246. )
  247. );
  248. if(is_valid('username')&&is_valid('password')&&is_valid('password1')&&is_valid('email')&&is_valid('captcha')){
  249. if($_GET['password']==$_GET['password1']){
  250. if(compare_captcha($_GET['captcha'])){
  251. if(addUser($_GET['username'],$_GET['password'],$_GET['email'])){
  252. $key = login($_GET['username'],$_GET['password']);
  253. $_SESSION['username'] = $_GET['username'];
  254. sendMail('welcome','Welcome!',$_GET['email'],get('email'),array($_GET['username'],$_GET['password'],get('email')));
  255. }else{
  256. $ret['error'] = "Could not add user. ".$mysqli->error;
  257. }
  258. }else{
  259. $ret['error'] = "Captcha did not match.";
  260. }
  261. }else{
  262. $ret['error'] = "Passwords didn't match.";
  263. }
  264. }else{
  265. $ret['error'] = "Please fill in all the fields.";
  266. }
  267. retj($ret,$id);
  268. break;
  269. case 'project':
  270. back(true);
  271. $ret['state'] = array(
  272. 'data'=>array(
  273. 'type'=>'page',
  274. 'id'=>$id,
  275. )
  276. );
  277. if(isset($_GET['pid'])){
  278. $ret['error'] = 'Invalid Action';
  279. }elseif(is_valid('title')&&is_valid('description')){
  280. if(!newProject($_GET['title'],$_GET['description'])){
  281. $ret['error'] = 'Unable to create project.';
  282. }
  283. }else{
  284. $ret['error'] = 'Fill in all the details.';
  285. }
  286. retj($ret,$id);
  287. break;
  288. case 'message':
  289. back(true);
  290. if(isset($_GET['to'])&&isset($_GET['message'])){
  291. if($uid = userId($_GET['to'])){
  292. if(!personal_message($uid,$_GET['message'])){
  293. $ret['error'] = 'Could not send message';
  294. }
  295. }else{
  296. $ret['error'] = "That user doesn't exist";
  297. }
  298. }else{
  299. $ret['error'] = 'Empty details';
  300. }
  301. retj($ret,$id);
  302. break;
  303. case 'notifications':
  304. if($LOGGEDIN){
  305. if($res = query("SELECT count(m.id) as notifications,UNIX_TIMESTAMP(max(m.timestamp)) as timestamp FROM `messages` m JOIN `users` u ON u.id = m.to_id WHERE u.id = %d AND u.last_pm_check < m.timestamp;",array(userId($_SESSION['username'])))){
  306. $res = $res->fetch_assoc();
  307. $ret['count'] = $res['notifications'];
  308. $ret['timestamp'] = $res['timestamp'];
  309. }
  310. }
  311. retj($ret,$_GET['title']);
  312. break;
  313. case 'comment':
  314. if(isset($_GET['comment_type'])&&isset($_GET['comment_id'])&&isset($_GET['message'])){
  315. $cid = $_GET['comment_id'];
  316. $ret = array(
  317. 'state'=>stateObj($_GET['comment_type'],$cid)
  318. );
  319. switch($_GET['comment_type']){
  320. case 'project':
  321. if(!function_exists('project_comment')){
  322. $ret['error'] = "fn doesn't exist!";
  323. }
  324. if(!project_comment($cid,$_GET['message'])){
  325. $ret = array(
  326. 'error'=>'Could not comment on project'
  327. );
  328. }
  329. break;
  330. default:
  331. $ret['error'] = 'Comment type not implemented';
  332. }
  333. }else{
  334. $ret['error'] = 'Missing comment paremeters';
  335. $ret['state'] = array(
  336. 'title'=>'error'
  337. );
  338. }
  339. retj($ret,$ret['state']['title']);
  340. break;
  341. default:
  342. retj(array(
  343. 'error'=>'Invalid action.'
  344. ));
  345. }
  346. break;
  347. default:
  348. retj(array(
  349. 'error'=>'Invalid type.'
  350. ));
  351. }
  352. }else{
  353. retj(array(
  354. 'error'=>'ID missing.'
  355. ));
  356. }
  357. }else{
  358. $_GET['type'] = '';
  359. retj(array(
  360. 'error'=>'Type missing.'
  361. ));
  362. }
  363. ?>