api.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453
  1. <?php
  2. require_once('php/include.php');
  3. // TODO - Add API handling.
  4. $method = $_SERVER['REQUEST_METHOD'];
  5. $ret = array();
  6. if(isset($_GET['type'])){
  7. if(isset($_GET['id'])){
  8. $id = $_GET['id'];
  9. switch($_GET['type']){
  10. case 'user':
  11. back(true);
  12. $ret['template'] = array(
  13. 'type'=>'pages',
  14. 'name'=>'user'
  15. );
  16. $ret['topbar'] = 'back';
  17. if($user = userObj($id)){
  18. $context = array(
  19. 'name'=>$user['name'],
  20. 'email'=>$user['email']
  21. );
  22. if($LOGGEDIN){
  23. $context['key'] = true;
  24. $context['user'] = userObj($_SESSION['username']);
  25. };
  26. $ret['context'] = $context;
  27. }else{
  28. $ret['state'] = array(
  29. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  30. );
  31. }
  32. retj($ret,'User - '.$context['name']);
  33. break;
  34. case 'group':
  35. back(true);
  36. // TODO - handle group requests
  37. if(false){
  38. // TODO
  39. }else{
  40. $ret['state'] = array(
  41. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  42. );
  43. }
  44. retj($ret);
  45. break;
  46. case 'issue':
  47. back(true);
  48. $ret['template'] = array(
  49. 'type'=>'pages',
  50. 'name'=>'issue'
  51. );
  52. $ret['topbar'] = 'back';
  53. if($context = issueObj($id)){
  54. $context['user'] = userObj($context['user']);
  55. if($LOGGEDIN){
  56. $context['key'] = true;
  57. $context['user'] = userObj($_SESSION['username']);
  58. };
  59. $ret['context'] = $context;
  60. }else{
  61. $ret['state'] = array(
  62. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  63. );
  64. }
  65. retj($ret,'Issue #'.$id. ' - '.$context['title']);
  66. break;
  67. case 'scrum':
  68. back(true);
  69. $ret['template'] = array(
  70. 'type'=>'pages',
  71. 'name'=>'scrum'
  72. );
  73. $ret['topbar'] = 'back';
  74. if($context = scrumObj($id)){
  75. $context['user'] = userObj($context['user']);
  76. if($LOGGEDIN){
  77. $context['key'] = true;
  78. $context['user'] = userObj($_SESSION['username']);
  79. };
  80. $ret['context'] = $context;
  81. }else{
  82. $ret['state'] = array(
  83. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  84. );
  85. }
  86. retj($ret,'Scrum - '.$context['title']);
  87. break;
  88. case 'project':
  89. back(true);
  90. $ret['template'] = array(
  91. 'type'=>'pages',
  92. 'name'=>'project'
  93. );
  94. $ret['topbar'] = 'back';
  95. if($context = projectObj($id)){
  96. $context['user'] = userObj($context['user']);
  97. if($LOGGEDIN){
  98. $context['key'] = true;
  99. $context['user'] = userObj($_SESSION['username']);
  100. };
  101. $ret['context'] = $context;
  102. }else{
  103. $ret['state'] = array(
  104. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  105. );
  106. }
  107. retj($ret,'Project - '.$context['title']);
  108. break;
  109. case 'message':
  110. // TODO - handle message requests
  111. $context = array();
  112. if(false){
  113. // TODO
  114. }else{
  115. $ret['state'] = array(
  116. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  117. );
  118. }
  119. retj($ret,'Project - '.$context['title']);
  120. break;
  121. case 'admin':
  122. back(true);
  123. // TODO - handle admin requests
  124. if(false){
  125. // TODO
  126. }else{
  127. $ret['state'] = array(
  128. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  129. );
  130. }
  131. retj($ret);
  132. break;
  133. case 'page':
  134. $title = $id;
  135. if(file_exists(PATH_DATA.'pages/'.$id.'.template')){
  136. $context = array();
  137. $ret['template'] = array(
  138. 'type'=>'pages',
  139. 'name'=>$id
  140. );
  141. if($LOGGEDIN){
  142. $context['key'] = true;
  143. $context['user'] = userObj($_SESSION['username']);
  144. };
  145. if(file_exists(PATH_DATA.'pages/'.$id.'.options')){
  146. $options = objectToarray(json_decode(file_get_contents(PATH_DATA.'pages/'.$id.'.options'),true));
  147. if(isset($options['secure'])&&$options['secure']&&!$LOGGEDIN){
  148. back(true);
  149. }
  150. if(isset($options['title'])){
  151. $title = $options['title'];
  152. }
  153. if(isset($options['topbar'])){
  154. $ret['topbar'] = $options['topbar'];
  155. }
  156. if(isset($options['context'])){
  157. foreach($options['context'] as $key){
  158. switch($key){
  159. case 'users':
  160. if($res = query("SELECT name FROM `users`;")){
  161. $context['users'] = fetch_all($res,MYSQLI_ASSOC);
  162. }
  163. break;
  164. case 'projects':
  165. if($res = query("SELECT p.title,p.id,p.description,u.name as user FROM `projects` p JOIN `users` u ON u.id = p.u_id")){
  166. $context['projects'] = fetch_all($res,MYSQLI_ASSOC);
  167. foreach($context['projects'] as $key => $project){
  168. $context['projects'][$key]['user'] = userObj($project['user']);
  169. }
  170. }
  171. break;
  172. case 'messages':
  173. if($LOGGEDIN){
  174. $context['messages'] = messages($context['user']['id'],'user');
  175. }else{
  176. $context['messages'] = array();
  177. }
  178. break;
  179. case 'issues':
  180. if($res = query("SELECT i.id,i.title,i.description,u.name as user,s.name as status,p.name as priority,p.color FROM `issues` i JOIN `users` u ON u.id = i.u_id LEFT JOIN `statuses` s ON s.id = i.st_id LEFT JOIN `priorities` p ON p.id = i.pr_id")){
  181. $context['issues'] = fetch_all($res,MYSQLI_ASSOC);
  182. foreach($context['issues'] as $key => $issue){
  183. $context['issues'][$key]['user'] = userObj($issue['user']);
  184. }
  185. }
  186. break;
  187. case 'latest':
  188. if($res = query("SELECT i.id,i.title,i.description,u.name as user,s.name as status,p.name as priority,p.color FROM `issues` i JOIN `users` u ON u.id = i.u_id LEFT JOIN `statuses` s ON s.id = i.st_id LEFT JOIN `priorities` p ON p.id = i.pr_id LIMIT 10")){
  189. $context['issues'] = fetch_all($res,MYSQLI_ASSOC);
  190. foreach($context['issues'] as $key => $issue){
  191. $context['issues'][$key]['user'] = userObj($issue['user']);
  192. }
  193. }
  194. break;
  195. }
  196. }
  197. }
  198. if(isset($options['actions'])){
  199. foreach($options['actions'] as $key){
  200. switch($key){
  201. case 'pm_mark_read':
  202. query("UPDATE `users` SET last_pm_check=CURRENT_TIMESTAMP WHERE id='%d'; ",array(userId($_SESSION['username'])));
  203. break;
  204. }
  205. }
  206. }
  207. }
  208. $ret['context'] = $context;
  209. }else{
  210. $ret['error'] = 'That page does not exist';
  211. $ret['state'] = array(
  212. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  213. );
  214. }
  215. retj($ret,$title);
  216. break;
  217. case 'manifest':
  218. case 'pages':
  219. if(isset($_GET['id'])){
  220. if($_GET['id'] != 'emails'){
  221. $manifest = array();
  222. $files = array_diff(scandir(PATH_DATA.'/'.$_GET['id']),array('..', '.','.htaccess','version'));
  223. foreach($files as $k => $file){
  224. if(pathinfo(PATH_DATA.'/'.$_GET['id'].'/'.$file,PATHINFO_EXTENSION) == 'template'){
  225. array_push($manifest,array(
  226. 'name'=>basename($file,'.template'),
  227. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$file)
  228. ));
  229. }
  230. }
  231. retj(array(
  232. 'manifest'=>$manifest,
  233. 'type'=>$_GET['id']
  234. ));
  235. }else{
  236. retj(array(
  237. 'error'=>'Cannot return that manifest'
  238. ));
  239. }
  240. }else{
  241. retj(array(
  242. 'error'=>'Manifest ID not defined'
  243. ));
  244. }
  245. break;
  246. break;
  247. case 'template':
  248. if(isset($_GET['name'])){
  249. if($_GET['id'] != 'emails'){
  250. retj(array(
  251. 'template'=>file_get_contents(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template'),
  252. 'name'=>$_GET['name'],
  253. 'type'=>$_GET['id'],
  254. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template')
  255. ));
  256. }else{
  257. retj(array(
  258. 'error'=>'Cannot return that type of template'
  259. ));
  260. }
  261. }else{
  262. retj(array(
  263. 'error'=>'Template name missing'
  264. ));
  265. }
  266. break;
  267. case 'action':
  268. switch($id){
  269. case 'login':
  270. $ret['state'] = array(
  271. 'data'=>array(
  272. 'type'=>'page',
  273. 'id'=>'login',
  274. )
  275. );
  276. if(isset($_GET['username'])&&isset($_GET['password'])){
  277. $key = login($_GET['username'],$_GET['password']);
  278. if($key){
  279. $_SESSION['username'] = $_GET['username'];
  280. }else{
  281. $ret['error'] = "Login failed. Username or Password didn't match.";
  282. }
  283. }else{
  284. $ret['error'] = "Please provide a valid username and password.";
  285. }
  286. retj($ret,$id);
  287. break;
  288. case 'register':
  289. $ret['state'] = array(
  290. 'data'=>array(
  291. 'type'=>'page',
  292. 'id'=>'register'
  293. )
  294. );
  295. if(is_valid('username')&& strpos($_GET['username'],' ') === false&&is_valid('password')&&is_valid('password1')&&is_valid('email')&&is_valid('captcha')){
  296. if($_GET['password']==$_GET['password1']){
  297. if(compare_captcha($_GET['captcha'])){
  298. if(addUser($_GET['username'],$_GET['password'],$_GET['email'])){
  299. $key = login($_GET['username'],$_GET['password']);
  300. $_SESSION['username'] = $_GET['username'];
  301. sendMail('welcome','Welcome!',$_GET['email'],get('email'),array($_GET['username'],$_GET['password'],get('email')));
  302. }else{
  303. $ret['error'] = "Could not add user. ".$mysqli->error;
  304. }
  305. }else{
  306. $ret['error'] = "Captcha did not match.";
  307. }
  308. }else{
  309. $ret['error'] = "Passwords didn't match.";
  310. }
  311. }else{
  312. $ret['error'] = "Please fill in all the fields.";
  313. }
  314. retj($ret,$id);
  315. break;
  316. case 'project':
  317. back(true);
  318. $ret['state'] = array(
  319. 'data'=>array(
  320. 'type'=>'page',
  321. 'id'=>$id,
  322. )
  323. );
  324. if(isset($_GET['pid'])){
  325. $ret['error'] = 'Invalid Action';
  326. }elseif(is_valid('title')&&is_valid('description')){
  327. if(!newProject($_GET['title'],$_GET['description'])){
  328. $ret['error'] = 'Unable to create project.';
  329. }
  330. }else{
  331. $ret['error'] = 'Fill in all the details.';
  332. }
  333. retj($ret,$id);
  334. break;
  335. case 'issue':
  336. back(true);
  337. $ret['state'] = array(
  338. 'data'=>array(
  339. 'type'=>'page',
  340. 'id'=>$id,
  341. )
  342. );
  343. if(isset($_GET['pid'])){
  344. $ret['error'] = 'Invalid Action';
  345. }elseif(is_valid('title')&&is_valid('description')){
  346. if(!newIssue($_GET['title'],$_GET['description'])){
  347. $ret['error'] = 'Unable to create issue. ';
  348. }
  349. }else{
  350. $ret['error'] = 'Fill in all the details.';
  351. }
  352. retj($ret,$id);
  353. break;
  354. case 'message':
  355. back(true);
  356. if(isset($_GET['to'])&&isset($_GET['message'])){
  357. if($uid = userId($_GET['to'])){
  358. if(!personal_message($uid,$_GET['message'])){
  359. $ret['error'] = 'Could not send message';
  360. }
  361. }else{
  362. $ret['error'] = "That user doesn't exist";
  363. }
  364. }else{
  365. $ret['error'] = 'Empty details';
  366. }
  367. retj($ret,$id);
  368. break;
  369. case 'notifications':
  370. if($LOGGEDIN){
  371. if($res = query("SELECT count(m.id) as notifications,UNIX_TIMESTAMP(max(m.timestamp)) as timestamp FROM `messages` m JOIN `users` u ON u.id = m.to_id WHERE u.id = %d AND u.last_pm_check < m.timestamp;",array(userId($_SESSION['username'])))){
  372. $res = $res->fetch_assoc();
  373. $ret['count'] = $res['notifications'];
  374. $ret['timestamp'] = $res['timestamp'];
  375. }
  376. }
  377. retj($ret,$_GET['title']);
  378. break;
  379. case 'comment':
  380. if(isset($_GET['comment_type'])&&isset($_GET['comment_id'])&&isset($_GET['message'])){
  381. $cid = $_GET['comment_id'];
  382. $ret = array(
  383. 'state'=>stateObj($_GET['comment_type'],$cid)
  384. );
  385. switch($_GET['comment_type']){
  386. case 'project':
  387. if(!function_exists('project_comment')){
  388. $ret['error'] = "fn doesn't exist!";
  389. }
  390. if(!project_comment($cid,$_GET['message'])){
  391. $ret = array(
  392. 'error'=>'Could not comment on project'
  393. );
  394. }
  395. break;
  396. case 'issue':
  397. if(!function_exists('issue_comment')){
  398. $ret['error'] = "fn doesn't exist!";
  399. }
  400. if(!issue_comment($cid,$_GET['message'])){
  401. $ret = array(
  402. 'error'=>'Could not comment on project'
  403. );
  404. }
  405. break;
  406. default:
  407. $ret['error'] = 'Comment type not implemented';
  408. }
  409. }else{
  410. $ret['error'] = 'Missing comment paremeters';
  411. $ret['state'] = array(
  412. 'title'=>'error'
  413. );
  414. }
  415. retj($ret,$ret['state']['title']);
  416. break;
  417. case 'more':
  418. if(isset($_GET['of']) && isset($_GET['pid'])){
  419. $ret = array();
  420. $limit = array(
  421. isset($_GET['at'])?$_GET['at']:0,
  422. isset($_GET['amount'])?$_GET['amount']:10
  423. );
  424. $ret['messages'] = messages($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  425. $ret['params'] = array($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  426. }else{
  427. $ret['error'] = 'Missing comment parameters';
  428. }
  429. retj($ret);
  430. break;
  431. default:
  432. retj(array(
  433. 'error'=>'Invalid action.'
  434. ));
  435. }
  436. break;
  437. default:
  438. retj(array(
  439. 'error'=>'Invalid type.'
  440. ));
  441. }
  442. }else{
  443. retj(array(
  444. 'error'=>'ID missing.'
  445. ));
  446. }
  447. }else{
  448. $_GET['type'] = '';
  449. retj(array(
  450. 'error'=>'Type missing.'
  451. ));
  452. }
  453. ?>