api.php 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124
  1. <?php
  2. require_once('php/include.php');
  3. // TODO - Add API handling.
  4. $method = $_SERVER['REQUEST_METHOD'];
  5. $ret = Array();
  6. if(isset($_GET['type'])){
  7. if(isset($_GET['id'])){
  8. $id = $_GET['id'];
  9. switch($_GET['type']){
  10. case 'user':
  11. $ret['template'] = file_get_contents(PATH_DATA.'pages/user.template');
  12. $user = userObj($id);
  13. $context = Array(
  14. 'name'=>$user['name'],
  15. 'email'=>$user['email']
  16. );
  17. if($LOGGEDIN){
  18. $context['key'] = true;
  19. $context['user'] = userObj($_SESSION['username']);
  20. };
  21. $ret['context'] = $context;
  22. retj($ret,$id);
  23. break;
  24. case 'group':
  25. // TODO - handle group requests
  26. break;
  27. case 'issue':
  28. // TODO - handle issue requests
  29. break;
  30. case 'scrum':
  31. // TODO - handle scrum requests
  32. break;
  33. case 'admin':
  34. // TODO - handle admin requests
  35. break;
  36. case 'page':
  37. if(file_exists(PATH_DATA.'pages/'.$id.'.template')){
  38. $ret['template'] = file_get_contents(PATH_DATA.'pages/'.$id.'.template');
  39. $context = Array();
  40. if($LOGGEDIN){
  41. $context['key'] = true;
  42. $context['user'] = userObj($_SESSION['username']);
  43. };
  44. if(file_exists(PATH_DATA.'pages/'.$id.'.options')){
  45. $options = objectToArray(json_decode(file_get_contents(PATH_DATA.'pages/'.$id.'.options'),true));
  46. foreach($options as $key){
  47. switch($key){
  48. case 'users':
  49. $res = query("SELECT name FROM `users`;");
  50. $users = $res->fetch_all(MYSQLI_ASSOC);
  51. $context['users'] = $users;
  52. break;
  53. }
  54. }
  55. }
  56. $ret['context'] = $context;
  57. }else{
  58. $ret['error'] = 'That page does not exist';
  59. }
  60. retj($ret,$id);
  61. break;
  62. case 'action':
  63. switch($id){
  64. case 'login':
  65. $ret['state'] = Array(
  66. 'data'=>Array(
  67. 'type'=>'page',
  68. 'id'=>'login',
  69. )
  70. );
  71. if(isset($_GET['username'])&&isset($_GET['password'])){
  72. $key = login($_GET['username'],$_GET['password']);
  73. if($key){
  74. $_SESSION['username'] = $_GET['username'];
  75. }else{
  76. $ret['error'] = "Login failed. Username or Password didn't match.";
  77. }
  78. }else{
  79. $ret['error'] = "Please provide a valid username and password.";
  80. }
  81. retj($ret,$id);
  82. break;
  83. case 'register':
  84. $ret['state'] = Array(
  85. 'data'=>Array(
  86. 'type'=>'page',
  87. 'id'=>'register'
  88. )
  89. );
  90. if(isvalid('username')&&isvalid('password')&&isvalid('password1')&&isvalid('email')&&isvalid('captcha')){
  91. if($_GET['password']==$_GET['password1']){
  92. if(compare_captcha($_GET['captcha'])){
  93. if(addUser($_GET['username'],$_GET['password'],$_GET['email'])){
  94. $key = login($_GET['username'],$_GET['password']);
  95. $_SESSION['username'] = $_GET['username'];
  96. sendMail('welcome','Welcome!',$_GET['email'],get('email'),Array($_GET['username'],$_GET['password'],get('email')));
  97. }else{
  98. $ret['error'] = "Could not add user. ".$mysqli->error;
  99. }
  100. }else{
  101. $ret['error'] = "Captcha did not match.";
  102. }
  103. }else{
  104. $ret['error'] = "Passwords didn't match.";
  105. }
  106. }else{
  107. $ret['error'] = "Please fill in all the fields.";
  108. }
  109. retj($ret,$id);
  110. break;
  111. default:
  112. die('invalid action');
  113. }
  114. break;
  115. default:
  116. die("invalid type");
  117. }
  118. }else{
  119. die("id missing");
  120. }
  121. }else{
  122. die("type missing");
  123. }
  124. ?>