api.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441
  1. <?php
  2. require_once('php/include.php');
  3. // TODO - Add API handling.
  4. $method = $_SERVER['REQUEST_METHOD'];
  5. $ret = array();
  6. if(isset($_GET['type'])){
  7. if(isset($_GET['id'])){
  8. $id = $_GET['id'];
  9. switch($_GET['type']){
  10. case 'user':
  11. back(true);
  12. $ret['template'] = array(
  13. 'type'=>'pages',
  14. 'name'=>'user'
  15. );
  16. if($user = userObj($id)){
  17. $context = array(
  18. 'name'=>$user['name'],
  19. 'email'=>$user['email']
  20. );
  21. if($LOGGEDIN){
  22. $context['key'] = true;
  23. $context['user'] = userObj($_SESSION['username']);
  24. };
  25. $ret['context'] = $context;
  26. }else{
  27. $ret['state'] = array(
  28. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  29. );
  30. }
  31. retj($ret,'User - '.$context['name']);
  32. break;
  33. case 'group':
  34. back(true);
  35. // TODO - handle group requests
  36. if(false){
  37. // TODO
  38. }else{
  39. $ret['state'] = array(
  40. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  41. );
  42. }
  43. retj($ret);
  44. break;
  45. case 'issue':
  46. back(true);
  47. $ret['template'] = array(
  48. 'type'=>'pages',
  49. 'name'=>'issue'
  50. );
  51. if($context = issueObj($id)){
  52. $context['user'] = userObj($context['user']);
  53. if($LOGGEDIN){
  54. $context['key'] = true;
  55. $context['user'] = userObj($_SESSION['username']);
  56. };
  57. $ret['context'] = $context;
  58. }else{
  59. $ret['state'] = array(
  60. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  61. );
  62. }
  63. retj($ret,'Issue #'.$id. ' - '.$context['title']);
  64. break;
  65. case 'scrum':
  66. back(true);
  67. $ret['template'] = array(
  68. 'type'=>'pages',
  69. 'name'=>'scrum'
  70. );
  71. if($context = scrumObj($id)){
  72. $context['user'] = userObj($context['user']);
  73. if($LOGGEDIN){
  74. $context['key'] = true;
  75. $context['user'] = userObj($_SESSION['username']);
  76. };
  77. $ret['context'] = $context;
  78. }else{
  79. $ret['state'] = array(
  80. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  81. );
  82. }
  83. retj($ret,'Scrum - '.$context['title']);
  84. break;
  85. case 'project':
  86. back(true);
  87. $ret['template'] = array(
  88. 'type'=>'pages',
  89. 'name'=>'project'
  90. );
  91. if($context = projectObj($id)){
  92. $context['user'] = userObj($context['user']);
  93. if($LOGGEDIN){
  94. $context['key'] = true;
  95. $context['user'] = userObj($_SESSION['username']);
  96. };
  97. $ret['context'] = $context;
  98. }else{
  99. $ret['state'] = array(
  100. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  101. );
  102. }
  103. retj($ret,'Project - '.$context['title']);
  104. break;
  105. case 'message':
  106. // TODO - handle message requests
  107. $context = array();
  108. if(false){
  109. // TODO
  110. }else{
  111. $ret['state'] = array(
  112. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  113. );
  114. }
  115. retj($ret,'Project - '.$context['title']);
  116. break;
  117. case 'admin':
  118. back(true);
  119. // TODO - handle admin requests
  120. if(false){
  121. // TODO
  122. }else{
  123. $ret['state'] = array(
  124. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  125. );
  126. }
  127. retj($ret);
  128. break;
  129. case 'page':
  130. $title = $id;
  131. if(file_exists(PATH_DATA.'pages/'.$id.'.template')){
  132. $context = array();
  133. $ret['template'] = array(
  134. 'type'=>'pages',
  135. 'name'=>$id
  136. );
  137. if($LOGGEDIN){
  138. $context['key'] = true;
  139. $context['user'] = userObj($_SESSION['username']);
  140. };
  141. if(file_exists(PATH_DATA.'pages/'.$id.'.options')){
  142. $options = objectToarray(json_decode(file_get_contents(PATH_DATA.'pages/'.$id.'.options'),true));
  143. if(isset($options['secure'])&&$options['secure']&&!$LOGGEDIN){
  144. back(true);
  145. }
  146. if(isset($options['title'])){
  147. $title = $options['title'];
  148. }
  149. if(isset($options['topbar'])){
  150. $ret['topbar'] = $options['topbar'];
  151. }
  152. if(isset($options['context'])){
  153. foreach($options['context'] as $key){
  154. switch($key){
  155. case 'users':
  156. if($res = query("SELECT name FROM `users`;")){
  157. $context['users'] = fetch_all($res,MYSQLI_ASSOC);
  158. }
  159. break;
  160. case 'projects':
  161. if($res = query("SELECT p.title,p.id,p.description,u.name as user FROM `projects` p JOIN `users` u ON u.id = p.u_id")){
  162. $context['projects'] = fetch_all($res,MYSQLI_ASSOC);
  163. foreach($context['projects'] as $key => $project){
  164. $context['projects'][$key]['user'] = userObj($project['user']);
  165. }
  166. }
  167. break;
  168. case 'messages':
  169. if($LOGGEDIN){
  170. $context['messages'] = messages($context['user']['id'],'user');
  171. }else{
  172. $context['messages'] = array();
  173. }
  174. break;
  175. case 'issues':
  176. if($res = query("SELECT i.id,i.title,i.description,u.name as user,s.name as status,p.name as priority,p.color FROM `issues` i JOIN `users` u ON u.id = i.u_id LEFT JOIN `statuses` s ON s.id = i.st_id LEFT JOIN `priorities` p ON p.id = i.pr_id")){
  177. $context['issues'] = fetch_all($res,MYSQLI_ASSOC);
  178. foreach($context['issues'] as $key => $issue){
  179. $context['issues'][$key]['user'] = userObj($issue['user']);
  180. }
  181. }
  182. break;
  183. }
  184. }
  185. }
  186. if(isset($options['actions'])){
  187. foreach($options['actions'] as $key){
  188. switch($key){
  189. case 'pm_mark_read':
  190. query("UPDATE `users` SET last_pm_check=CURRENT_TIMESTAMP WHERE id='%d'; ",array(userId($_SESSION['username'])));
  191. break;
  192. }
  193. }
  194. }
  195. }
  196. $ret['context'] = $context;
  197. }else{
  198. $ret['error'] = 'That page does not exist';
  199. $ret['state'] = array(
  200. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  201. );
  202. }
  203. retj($ret,$title);
  204. break;
  205. case 'manifest':
  206. case 'pages':
  207. if(isset($_GET['id'])){
  208. if($_GET['id'] != 'emails'){
  209. $manifest = array();
  210. $files = array_diff(scandir(PATH_DATA.'/'.$_GET['id']),array('..', '.','.htaccess','version'));
  211. foreach($files as $k => $file){
  212. if(pathinfo(PATH_DATA.'/'.$_GET['id'].'/'.$file,PATHINFO_EXTENSION) == 'template'){
  213. array_push($manifest,array(
  214. 'name'=>basename($file,'.template'),
  215. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$file)
  216. ));
  217. }
  218. }
  219. retj(array(
  220. 'manifest'=>$manifest,
  221. 'type'=>$_GET['id']
  222. ));
  223. }else{
  224. retj(array(
  225. 'error'=>'Cannot return that manifest'
  226. ));
  227. }
  228. }else{
  229. retj(array(
  230. 'error'=>'Manifest ID not defined'
  231. ));
  232. }
  233. break;
  234. break;
  235. case 'template':
  236. if(isset($_GET['name'])){
  237. if($_GET['id'] != 'emails'){
  238. retj(array(
  239. 'template'=>file_get_contents(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template'),
  240. 'name'=>$_GET['name'],
  241. 'type'=>$_GET['id'],
  242. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template')
  243. ));
  244. }else{
  245. retj(array(
  246. 'error'=>'Cannot return that type of template'
  247. ));
  248. }
  249. }else{
  250. retj(array(
  251. 'error'=>'Template name missing'
  252. ));
  253. }
  254. break;
  255. case 'action':
  256. switch($id){
  257. case 'login':
  258. $ret['state'] = array(
  259. 'data'=>array(
  260. 'type'=>'page',
  261. 'id'=>'login',
  262. )
  263. );
  264. if(isset($_GET['username'])&&isset($_GET['password'])){
  265. $key = login($_GET['username'],$_GET['password']);
  266. if($key){
  267. $_SESSION['username'] = $_GET['username'];
  268. }else{
  269. $ret['error'] = "Login failed. Username or Password didn't match.";
  270. }
  271. }else{
  272. $ret['error'] = "Please provide a valid username and password.";
  273. }
  274. retj($ret,$id);
  275. break;
  276. case 'register':
  277. $ret['state'] = array(
  278. 'data'=>array(
  279. 'type'=>'page',
  280. 'id'=>'register'
  281. )
  282. );
  283. if(is_valid('username')&& strpos($_GET['username'],' ') !== false&&is_valid('password')&&is_valid('password1')&&is_valid('email')&&is_valid('captcha')){
  284. if($_GET['password']==$_GET['password1']){
  285. if(compare_captcha($_GET['captcha'])){
  286. if(addUser($_GET['username'],$_GET['password'],$_GET['email'])){
  287. $key = login($_GET['username'],$_GET['password']);
  288. $_SESSION['username'] = $_GET['username'];
  289. sendMail('welcome','Welcome!',$_GET['email'],get('email'),array($_GET['username'],$_GET['password'],get('email')));
  290. }else{
  291. $ret['error'] = "Could not add user. ".$mysqli->error;
  292. }
  293. }else{
  294. $ret['error'] = "Captcha did not match.";
  295. }
  296. }else{
  297. $ret['error'] = "Passwords didn't match.";
  298. }
  299. }else{
  300. $ret['error'] = "Please fill in all the fields.";
  301. }
  302. retj($ret,$id);
  303. break;
  304. case 'project':
  305. back(true);
  306. $ret['state'] = array(
  307. 'data'=>array(
  308. 'type'=>'page',
  309. 'id'=>$id,
  310. )
  311. );
  312. if(isset($_GET['pid'])){
  313. $ret['error'] = 'Invalid Action';
  314. }elseif(is_valid('title')&&is_valid('description')){
  315. if(!newProject($_GET['title'],$_GET['description'])){
  316. $ret['error'] = 'Unable to create project.';
  317. }
  318. }else{
  319. $ret['error'] = 'Fill in all the details.';
  320. }
  321. retj($ret,$id);
  322. break;
  323. case 'issue':
  324. back(true);
  325. $ret['state'] = array(
  326. 'data'=>array(
  327. 'type'=>'page',
  328. 'id'=>$id,
  329. )
  330. );
  331. if(isset($_GET['pid'])){
  332. $ret['error'] = 'Invalid Action';
  333. }elseif(is_valid('title')&&is_valid('description')){
  334. if(!newIssue($_GET['title'],$_GET['description'])){
  335. $ret['error'] = 'Unable to create issue. ';
  336. }
  337. }else{
  338. $ret['error'] = 'Fill in all the details.';
  339. }
  340. retj($ret,$id);
  341. break;
  342. case 'message':
  343. back(true);
  344. if(isset($_GET['to'])&&isset($_GET['message'])){
  345. if($uid = userId($_GET['to'])){
  346. if(!personal_message($uid,$_GET['message'])){
  347. $ret['error'] = 'Could not send message';
  348. }
  349. }else{
  350. $ret['error'] = "That user doesn't exist";
  351. }
  352. }else{
  353. $ret['error'] = 'Empty details';
  354. }
  355. retj($ret,$id);
  356. break;
  357. case 'notifications':
  358. if($LOGGEDIN){
  359. if($res = query("SELECT count(m.id) as notifications,UNIX_TIMESTAMP(max(m.timestamp)) as timestamp FROM `messages` m JOIN `users` u ON u.id = m.to_id WHERE u.id = %d AND u.last_pm_check < m.timestamp;",array(userId($_SESSION['username'])))){
  360. $res = $res->fetch_assoc();
  361. $ret['count'] = $res['notifications'];
  362. $ret['timestamp'] = $res['timestamp'];
  363. }
  364. }
  365. retj($ret,$_GET['title']);
  366. break;
  367. case 'comment':
  368. if(isset($_GET['comment_type'])&&isset($_GET['comment_id'])&&isset($_GET['message'])){
  369. $cid = $_GET['comment_id'];
  370. $ret = array(
  371. 'state'=>stateObj($_GET['comment_type'],$cid)
  372. );
  373. switch($_GET['comment_type']){
  374. case 'project':
  375. if(!function_exists('project_comment')){
  376. $ret['error'] = "fn doesn't exist!";
  377. }
  378. if(!project_comment($cid,$_GET['message'])){
  379. $ret = array(
  380. 'error'=>'Could not comment on project'
  381. );
  382. }
  383. break;
  384. case 'issue':
  385. if(!function_exists('issue_comment')){
  386. $ret['error'] = "fn doesn't exist!";
  387. }
  388. if(!issue_comment($cid,$_GET['message'])){
  389. $ret = array(
  390. 'error'=>'Could not comment on project'
  391. );
  392. }
  393. break;
  394. default:
  395. $ret['error'] = 'Comment type not implemented';
  396. }
  397. }else{
  398. $ret['error'] = 'Missing comment paremeters';
  399. $ret['state'] = array(
  400. 'title'=>'error'
  401. );
  402. }
  403. retj($ret,$ret['state']['title']);
  404. break;
  405. case 'more':
  406. if(isset($_GET['of']) && isset($_GET['pid'])){
  407. $ret = array();
  408. $limit = array(
  409. isset($_GET['at'])?$_GET['at']:0,
  410. isset($_GET['amount'])?$_GET['amount']:10
  411. );
  412. $ret['messages'] = messages($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  413. $ret['params'] = array($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  414. }else{
  415. $ret['error'] = 'Missing comment parameters';
  416. }
  417. retj($ret);
  418. break;
  419. default:
  420. retj(array(
  421. 'error'=>'Invalid action.'
  422. ));
  423. }
  424. break;
  425. default:
  426. retj(array(
  427. 'error'=>'Invalid type.'
  428. ));
  429. }
  430. }else{
  431. retj(array(
  432. 'error'=>'ID missing.'
  433. ));
  434. }
  435. }else{
  436. $_GET['type'] = '';
  437. retj(array(
  438. 'error'=>'Type missing.'
  439. ));
  440. }
  441. ?>