api.php 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341
  1. <?php
  2. require_once('php/include.php');
  3. // TODO - Add API handling.
  4. $method = $_SERVER['REQUEST_METHOD'];
  5. $ret = array();
  6. if(isset($_GET['type'])){
  7. if(isset($_GET['id'])){
  8. $id = $_GET['id'];
  9. switch($_GET['type']){
  10. case 'user':
  11. back(true);
  12. if(!isset($_GET['template'])){
  13. $ret['template'] = file_get_contents(PATH_DATA.'pages/user.template');
  14. }
  15. if($user = userObj($id)){
  16. $context = array(
  17. 'name'=>$user['name'],
  18. 'email'=>$user['email']
  19. );
  20. if($LOGGEDIN){
  21. $context['key'] = true;
  22. $context['user'] = userObj($_SESSION['username']);
  23. };
  24. $ret['context'] = $context;
  25. }else{
  26. $ret['state'] = array(
  27. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  28. );
  29. }
  30. retj($ret,'User - '.$context['name']);
  31. break;
  32. case 'group':
  33. back(true);
  34. // TODO - handle group requests
  35. if(false){
  36. // TODO
  37. }else{
  38. $ret['state'] = array(
  39. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  40. );
  41. }
  42. retj($ret,'Project - '.$context['title']);
  43. break;
  44. case 'issue':
  45. back(true);
  46. // TODO - handle issue requests
  47. if(false){
  48. // TODO
  49. }else{
  50. $ret['state'] = array(
  51. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  52. );
  53. }
  54. retj($ret,'Project - '.$context['title']);
  55. break;
  56. case 'scrum':
  57. back(true);
  58. // TODO - handle scrum requests
  59. if(false){
  60. // TODO
  61. }else{
  62. $ret['state'] = array(
  63. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  64. );
  65. }
  66. retj($ret,'Project - '.$context['title']);
  67. break;
  68. case 'project':
  69. back(true);
  70. if(!isset($_GET['template'])){
  71. $ret['template'] = file_get_contents(PATH_DATA.'pages/project.template');
  72. }
  73. if($context = projectObj($id)){
  74. $context['user'] = userObj($context['user']);
  75. if($LOGGEDIN){
  76. $context['key'] = true;
  77. $context['user'] = userObj($_SESSION['username']);
  78. };
  79. $ret['context'] = $context;
  80. }else{
  81. $ret['state'] = array(
  82. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  83. );
  84. }
  85. retj($ret,'Project - '.$context['title']);
  86. break;
  87. case 'message':
  88. // TODO - handle message requests
  89. if(false){
  90. // TODO
  91. }else{
  92. $ret['state'] = array(
  93. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  94. );
  95. }
  96. retj($ret,'Project - '.$context['title']);
  97. break;
  98. case 'admin':
  99. back(true);
  100. // TODO - handle admin requests
  101. if(false){
  102. // TODO
  103. }else{
  104. $ret['state'] = array(
  105. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  106. );
  107. }
  108. retj($ret,'Project - '.$context['title']);
  109. break;
  110. case 'page':
  111. $title = $id;
  112. if(file_exists(PATH_DATA.'pages/'.$id.'.template')){
  113. $context = array();
  114. if($LOGGEDIN){
  115. $context['key'] = true;
  116. $context['user'] = userObj($_SESSION['username']);
  117. };
  118. if(file_exists(PATH_DATA.'pages/'.$id.'.options')){
  119. $options = objectToarray(json_decode(file_get_contents(PATH_DATA.'pages/'.$id.'.options'),true));
  120. if(isset($options['secure'])&&$options['secure']&&!$LOGGEDIN){
  121. back(true);
  122. }
  123. if(isset($options['title'])){
  124. $title = $options['title'];
  125. }
  126. if(isset($options['context'])){
  127. foreach($options['context'] as $key){
  128. switch($key){
  129. case 'users':
  130. if($res = query("SELECT name FROM `users`;")){
  131. $context['users'] = fetch_all($res,MYSQLI_ASSOC);
  132. }
  133. break;
  134. case 'projects':
  135. if($res = query("SELECT p.title,p.id,p.description,u.name as user FROM `projects` p JOIN `users` u ON u.id = p.u_id")){
  136. $context['projects'] = fetch_all($res,MYSQLI_ASSOC);
  137. foreach($context['projects'] as $key => $project){
  138. $context['projects'][$key]['user'] = userObj($project['user']);
  139. }
  140. }
  141. break;
  142. case 'messages':
  143. if($LOGGEDIN){
  144. $context['messages'] = messages($context['user']['id'],'user');
  145. }else{
  146. $context['messages'] = array();
  147. }
  148. break;
  149. }
  150. }
  151. }
  152. if(isset($options['actions'])){
  153. foreach($options['actions'] as $key){
  154. switch($key){
  155. case 'pm_mark_read':
  156. query("UPDATE `users` SET last_pm_check=CURRENT_TIMESTAMP WHERE id='%d'; ",array(userId($_SESSION['username'])));
  157. break;
  158. }
  159. }
  160. }
  161. }
  162. $ret['context'] = $context;
  163. }else{
  164. $ret['error'] = 'That page does not exist';
  165. }
  166. retj($ret,$title);
  167. break;
  168. case 'manifest':
  169. case 'pages':
  170. if(isset($_GET['id'])){
  171. $manifest = array();
  172. $files = array_diff(scandir(PATH_DATA.'/'.$_GET['id']),array('..', '.','.htaccess','version'));
  173. foreach($files as $k => $file){
  174. if(pathinfo(PATH_DATA.'/'.$_GET['id'].'/'.$file,PATHINFO_EXTENSION) == 'template'){
  175. array_push($manifest,basename($file,'.template'));
  176. }
  177. }
  178. retj(array(
  179. 'manifest'=>$manifest
  180. ));
  181. }else{
  182. retj(array(
  183. 'error'=>'Manifest ID not defined'
  184. ));
  185. }
  186. break;
  187. break;
  188. case 'template':
  189. if(isset($_GET['name'])){
  190. retj(array(
  191. 'template'=>file_get_conetents(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'])
  192. ));
  193. }else{
  194. retj(array(
  195. 'error'=>'Template name missing'
  196. ));
  197. }
  198. break;
  199. case 'action':
  200. switch($id){
  201. case 'login':
  202. $ret['state'] = array(
  203. 'data'=>array(
  204. 'type'=>'page',
  205. 'id'=>'login',
  206. )
  207. );
  208. if(isset($_GET['username'])&&isset($_GET['password'])){
  209. $key = login($_GET['username'],$_GET['password']);
  210. if($key){
  211. $_SESSION['username'] = $_GET['username'];
  212. }else{
  213. $ret['error'] = "Login failed. Username or Password didn't match.";
  214. }
  215. }else{
  216. $ret['error'] = "Please provide a valid username and password.";
  217. }
  218. retj($ret,$id);
  219. break;
  220. case 'register':
  221. $ret['state'] = array(
  222. 'data'=>array(
  223. 'type'=>'page',
  224. 'id'=>'register'
  225. )
  226. );
  227. if(is_valid('username')&&is_valid('password')&&is_valid('password1')&&is_valid('email')&&is_valid('captcha')){
  228. if($_GET['password']==$_GET['password1']){
  229. if(compare_captcha($_GET['captcha'])){
  230. if(addUser($_GET['username'],$_GET['password'],$_GET['email'])){
  231. $key = login($_GET['username'],$_GET['password']);
  232. $_SESSION['username'] = $_GET['username'];
  233. sendMail('welcome','Welcome!',$_GET['email'],get('email'),array($_GET['username'],$_GET['password'],get('email')));
  234. }else{
  235. $ret['error'] = "Could not add user. ".$mysqli->error;
  236. }
  237. }else{
  238. $ret['error'] = "Captcha did not match.";
  239. }
  240. }else{
  241. $ret['error'] = "Passwords didn't match.";
  242. }
  243. }else{
  244. $ret['error'] = "Please fill in all the fields.";
  245. }
  246. retj($ret,$id);
  247. break;
  248. case 'project':
  249. back(true);
  250. $ret['state'] = array(
  251. 'data'=>array(
  252. 'type'=>'page',
  253. 'id'=>$id,
  254. )
  255. );
  256. if(isset($_GET['pid'])){
  257. $ret['error'] = 'Invalid Action';
  258. }elseif(is_valid('title')&&is_valid('description')){
  259. if(!newProject($_GET['title'],$_GET['description'])){
  260. $ret['error'] = 'Unable to create project.';
  261. }
  262. }else{
  263. $ret['error'] = 'Fill in all the details.';
  264. }
  265. retj($ret,$id);
  266. break;
  267. case 'message':
  268. back(true);
  269. if(isset($_GET['to'])&&isset($_GET['message'])){
  270. if($uid = userId($_GET['to'])){
  271. if(!personal_message($uid,$_GET['message'])){
  272. $ret['error'] = 'Could not send message';
  273. }
  274. }else{
  275. $ret['error'] = "That user doesn't exist";
  276. }
  277. }else{
  278. $ret['error'] = 'Empty details';
  279. }
  280. retj($ret,$id);
  281. break;
  282. case 'notifications':
  283. if($LOGGEDIN){
  284. if($res = query("SELECT count(m.id) as notifications,UNIX_TIMESTAMP(max(m.timestamp)) as timestamp FROM `messages` m JOIN `users` u ON u.id = m.to_id WHERE u.id = %d AND u.last_pm_check < m.timestamp;",array(userId($_SESSION['username'])))){
  285. $res = $res->fetch_assoc();
  286. $ret['count'] = $res['notifications'];
  287. $ret['timestamp'] = $res['timestamp'];
  288. }
  289. }
  290. retj($ret,$_GET['title']);
  291. break;
  292. case 'comment':
  293. if(isset($_GET['comment_type'])&&isset($_GET['comment_id'])&&isset($_GET['message'])){
  294. $cid = $_GET['comment_id'];
  295. $ret = array(
  296. 'state'=>stateObj($_GET['comment_type'],$cid)
  297. );
  298. switch($_GET['comment_type']){
  299. case 'project':
  300. if(!function_exists('project_comment')){
  301. $ret['error'] = "fn doesn't exist!";
  302. }
  303. if(!project_comment($cid,$_GET['message'])){
  304. $ret = array(
  305. 'error'=>'Could not comment on project'
  306. );
  307. }
  308. break;
  309. default:
  310. $ret['error'] = 'Comment type not implemented';
  311. }
  312. }else{
  313. $ret['error'] = 'Missing comment paremeters';
  314. $ret['state'] = array(
  315. 'title'=>'error'
  316. );
  317. }
  318. retj($ret,$ret['state']['title']);
  319. break;
  320. default:
  321. retj(array(
  322. 'error'=>'Invalid action.'
  323. ));
  324. }
  325. break;
  326. default:
  327. retj(array(
  328. 'error'=>'Invalid type.'
  329. ));
  330. }
  331. }else{
  332. retj(array(
  333. 'error'=>'ID missing.'
  334. ));
  335. }
  336. }else{
  337. retj(array(
  338. 'error'=>'Type missing.'
  339. ));
  340. }
  341. ?>