api.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508
  1. <?php
  2. require_once('php/include.php');
  3. // TODO - Add API handling.
  4. $method = $_SERVER['REQUEST_METHOD'];
  5. $ret = array();
  6. if(isset($_GET['type'])){
  7. if(isset($_GET['id'])){
  8. $id = $_GET['id'];
  9. switch($_GET['type']){
  10. case 'test':
  11. echo time()+get('expire');
  12. break;
  13. case 'user':
  14. back(true);
  15. $ret['template'] = array(
  16. 'type'=>'pages',
  17. 'name'=>'user'
  18. );
  19. $ret['topbar'] = 'back';
  20. if($user = userObj($id)){
  21. $context = array(
  22. 'name'=>$user['name'],
  23. 'email'=>$user['email']
  24. );
  25. if($LOGGEDIN){
  26. $context['key'] = true;
  27. $context['user'] = userObj($_SESSION['username']);
  28. };
  29. $ret['context'] = $context;
  30. }else{
  31. $ret['state'] = array(
  32. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  33. );
  34. }
  35. retj($ret,'User - '.$context['name']);
  36. break;
  37. case 'group':
  38. back(true);
  39. // TODO - handle group requests
  40. if(false){
  41. // TODO
  42. }else{
  43. $ret['state'] = array(
  44. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  45. );
  46. }
  47. retj($ret);
  48. break;
  49. case 'issue':
  50. back(true);
  51. $ret['template'] = array(
  52. 'type'=>'pages',
  53. 'name'=>'issue'
  54. );
  55. $ret['topbar'] = 'back';
  56. if($context = issueObj($id)){
  57. $context['user'] = userObj($context['user']);
  58. if($LOGGEDIN){
  59. $context['key'] = true;
  60. $context['user'] = userObj($_SESSION['username']);
  61. };
  62. $ret['context'] = $context;
  63. }else{
  64. $ret['state'] = array(
  65. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  66. );
  67. }
  68. retj($ret,'Issue #'.$id. ' - '.$context['title']);
  69. break;
  70. case 'scrum':
  71. back(true);
  72. $ret['template'] = array(
  73. 'type'=>'pages',
  74. 'name'=>'scrum'
  75. );
  76. $ret['topbar'] = 'back';
  77. if($context = scrumObj($id)){
  78. $context['user'] = userObj($context['user']);
  79. if($LOGGEDIN){
  80. $context['key'] = true;
  81. $context['user'] = userObj($_SESSION['username']);
  82. };
  83. $ret['context'] = $context;
  84. }else{
  85. $ret['state'] = array(
  86. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  87. );
  88. }
  89. retj($ret,'Scrum - '.$context['title']);
  90. break;
  91. case 'project':
  92. back(true);
  93. $ret['template'] = array(
  94. 'type'=>'pages',
  95. 'name'=>'project'
  96. );
  97. $ret['topbar'] = 'project';
  98. if($context = projectObj($id)){
  99. $context['user'] = userObj($context['user']);
  100. if($LOGGEDIN){
  101. $context['key'] = true;
  102. $context['user'] = userObj($_SESSION['username']);
  103. };
  104. $ret['context'] = $context;
  105. }else{
  106. $ret['state'] = array(
  107. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  108. );
  109. }
  110. retj($ret,'Project - '.$context['title']);
  111. break;
  112. case 'message':
  113. // TODO - handle message requests
  114. $context = array();
  115. if(false){
  116. // TODO
  117. }else{
  118. $ret['state'] = array(
  119. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  120. );
  121. }
  122. retj($ret,'Project - '.$context['title']);
  123. break;
  124. case 'admin':
  125. back(true);
  126. // TODO - handle admin requests
  127. if(false){
  128. // TODO
  129. }else{
  130. $ret['state'] = array(
  131. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  132. );
  133. }
  134. retj($ret);
  135. break;
  136. case 'page':
  137. $title = $id;
  138. if(file_exists(PATH_DATA.'pages/'.$id.'.template')){
  139. $context = array();
  140. $ret['template'] = array(
  141. 'type'=>'pages',
  142. 'name'=>$id
  143. );
  144. if($LOGGEDIN){
  145. $context['key'] = true;
  146. $context['user'] = userObj($_SESSION['username']);
  147. };
  148. if(file_exists(PATH_DATA.'pages/'.$id.'.options')){
  149. $options = objectToarray(json_decode(file_get_contents(PATH_DATA.'pages/'.$id.'.options'),true));
  150. if(isset($options['secure'])&&$options['secure']&&!$LOGGEDIN){
  151. back(true);
  152. }
  153. if(isset($options['title'])){
  154. $title = $options['title'];
  155. }
  156. if(isset($options['topbar'])){
  157. $ret['topbar'] = $options['topbar'];
  158. }
  159. if(isset($options['context'])){
  160. foreach($options['context'] as $key){
  161. switch($key){
  162. case 'users':
  163. if($res = query("SELECT name FROM `users`;")){
  164. $context['users'] = fetch_all($res,MYSQLI_ASSOC);
  165. }
  166. break;
  167. case 'projects':
  168. if($res = query("SELECT p.title,p.id,p.description,u.name as user FROM `projects` p JOIN `users` u ON u.id = p.u_id")){
  169. $context['projects'] = fetch_all($res,MYSQLI_ASSOC);
  170. foreach($context['projects'] as $key => $project){
  171. $context['projects'][$key]['user'] = userObj($project['user']);
  172. }
  173. }
  174. break;
  175. case 'messages':
  176. if($LOGGEDIN){
  177. $context['messages'] = messages($context['user']['id'],'user');
  178. }else{
  179. $context['messages'] = array();
  180. }
  181. break;
  182. case 'issues':
  183. if($res = query("SELECT i.id,i.title,i.description,u.name as user,s.name as status,p.name as priority,p.color,s.isopen FROM `issues` i JOIN `users` u ON u.id = i.u_id LEFT JOIN `statuses` s ON s.id = i.st_id LEFT JOIN `priorities` p ON p.id = i.pr_id")){
  184. $context['issues'] = fetch_all($res,MYSQLI_ASSOC);
  185. foreach($context['issues'] as $key => $issue){
  186. $context['issues'][$key]['user'] = userObj($issue['user']);
  187. }
  188. }
  189. break;
  190. case 'latest':
  191. if($res = query("SELECT a.date, a.id FROM `activity` AS a ORDER BY a.date DESC LIMIT 10")){
  192. $context['activity'] = fetch_all($res,MYSQLI_ASSOC);
  193. foreach($context['activity'] as $key => $activity){
  194. $context['activity'][$key] = activityObj($activity['id']);
  195. }
  196. }
  197. break;
  198. }
  199. }
  200. }
  201. if(isset($options['actions'])){
  202. foreach($options['actions'] as $key){
  203. switch($key){
  204. case 'pm_mark_read':
  205. query("UPDATE `users` SET last_pm_check=CURRENT_TIMESTAMP WHERE id='%d'; ",array(userId($_SESSION['username'])));
  206. break;
  207. }
  208. }
  209. }
  210. }
  211. $ret['context'] = $context;
  212. }else{
  213. $ret['error'] = 'That page does not exist';
  214. $ret['state'] = array(
  215. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  216. );
  217. }
  218. retj($ret,$title);
  219. break;
  220. case 'manifest':
  221. case 'pages':
  222. if(isset($_GET['id'])){
  223. if($_GET['id'] != 'emails'){
  224. $manifest = array();
  225. $files = array_diff(scandir(PATH_DATA.'/'.$_GET['id']),array('..', '.','.htaccess','version'));
  226. foreach($files as $k => $file){
  227. if(pathinfo(PATH_DATA.'/'.$_GET['id'].'/'.$file,PATHINFO_EXTENSION) == 'template'){
  228. array_push($manifest,array(
  229. 'name'=>basename($file,'.template'),
  230. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$file)
  231. ));
  232. }
  233. }
  234. retj(array(
  235. 'manifest'=>$manifest,
  236. 'type'=>$_GET['id']
  237. ));
  238. }else{
  239. retj(array(
  240. 'error'=>'Cannot return that manifest'
  241. ));
  242. }
  243. }else{
  244. retj(array(
  245. 'error'=>'Manifest ID not defined'
  246. ));
  247. }
  248. break;
  249. break;
  250. case 'template':
  251. if(isset($_GET['name'])){
  252. if($_GET['id'] != 'emails'){
  253. retj(array(
  254. 'template'=>file_get_contents(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template'),
  255. 'name'=>$_GET['name'],
  256. 'type'=>$_GET['id'],
  257. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template')
  258. ));
  259. }else{
  260. retj(array(
  261. 'error'=>'Cannot return that type of template'
  262. ));
  263. }
  264. }else{
  265. retj(array(
  266. 'error'=>'Template name missing'
  267. ));
  268. }
  269. break;
  270. case 'action':
  271. switch($id){
  272. case 'login':
  273. $ret['state'] = array(
  274. 'data'=>array(
  275. 'type'=>'page',
  276. 'id'=>'login',
  277. )
  278. );
  279. if(isset($_GET['username'])&&isset($_GET['password'])){
  280. $key = login($_GET['username'],$_GET['password']);
  281. if($key){
  282. $_SESSION['username'] = $_GET['username'];
  283. $ret['key'] = $key;
  284. }else{
  285. $ret['error'] = "Login failed. Username or Password didn't match.";
  286. }
  287. }else{
  288. $ret['error'] = "Please provide a valid username and password.";
  289. }
  290. retj($ret,$id);
  291. break;
  292. case 'register':
  293. $ret['state'] = array(
  294. 'data'=>array(
  295. 'type'=>'page',
  296. 'id'=>'register'
  297. )
  298. );
  299. if(is_valid('username')&& strpos($_GET['username'],' ') === false&&is_valid('password')&&is_valid('password1')&&is_valid('email')&&is_valid('captcha')){
  300. if($_GET['password']==$_GET['password1']){
  301. if(compare_captcha($_GET['captcha'])){
  302. if(addUser($_GET['username'],$_GET['password'],$_GET['email'])){
  303. $key = login($_GET['username'],$_GET['password']);
  304. $_SESSION['username'] = $_GET['username'];
  305. sendMail('welcome','Welcome!',$_GET['email'],get('email'),array(
  306. 'username'=>$_GET['username'],
  307. 'password'=>$_GET['password'],
  308. 'email'=>get('email')));
  309. }else{
  310. $ret['error'] = "Could not add user. ".get_sql()->error;
  311. }
  312. }else{
  313. $ret['error'] = "Captcha did not match.";
  314. }
  315. }else{
  316. $ret['error'] = "Passwords didn't match.";
  317. }
  318. }else{
  319. $ret['error'] = "Please fill in all the fields.";
  320. }
  321. retj($ret,$id);
  322. break;
  323. case 'project':
  324. back(true);
  325. $ret['state'] = array(
  326. 'data'=>array(
  327. 'type'=>'page',
  328. 'id'=>$id,
  329. )
  330. );
  331. if(isset($_GET['pid'])){
  332. $ret['error'] = 'Invalid Action';
  333. }elseif(is_valid('title')&&is_valid('description')){
  334. if($pid = newProject($_GET['title'],$_GET['description'])){
  335. sendMailAll('newproject','New Project - '.$_GET['title'],array(
  336. 'title'=>$_GET['title'],
  337. 'url'=>'http://'.$_SERVER['HTTP_HOST'],
  338. 'id'=>$pid
  339. ));
  340. }else{
  341. $ret['error'] = 'Unable to create project. '.get_sql()->error;
  342. }
  343. }else{
  344. $ret['error'] = 'Fill in all the details.';
  345. }
  346. retj($ret,$id);
  347. break;
  348. case 'issue':
  349. back(true);
  350. switch($_GET['action']){
  351. case 'status':
  352. if(!setStatus($_GET['issue'],$_GET['status'])){
  353. $ret['error'] = 'Could not update status.';
  354. }else{
  355. alog('i',$_GET['issue'],'Status changed to '.statusName($_GET['status']));
  356. }
  357. retj($ret);
  358. break;
  359. case 'priority':
  360. if(!setPriority($_GET['issue'],$_GET['priority'])){
  361. $ret['error'] = 'Could not update priority.';
  362. }else{
  363. alog('i',$_GET['issue'],'Priority changed to '.priorityName($_GET['priority']));
  364. }
  365. retj($ret);
  366. break;
  367. default:
  368. $ret['state'] = array(
  369. 'data'=>array(
  370. 'type'=>'page',
  371. 'id'=>$id,
  372. )
  373. );
  374. if(isset($_GET['pid'])){
  375. $ret['error'] = 'Invalid Action';
  376. }elseif(is_valid('title')&&is_valid('description')){
  377. if($id = newIssue($_GET['title'],$_GET['description'])){
  378. sendMailAll('newissue','New Issue - '.$_GET['title'],array(
  379. 'title'=>$_GET['title'],
  380. 'url'=>'http://'.$_SERVER['HTTP_HOST'],
  381. 'id'=>$id
  382. ));
  383. }else{
  384. $ret['error'] = 'Unable to create issue. '.get_sql()->error;
  385. }
  386. }else{
  387. $ret['error'] = 'Fill in all the details.';
  388. }
  389. retj($ret,$id);
  390. break;
  391. case 'message':
  392. back(true);
  393. if(isset($_GET['to'])&&isset($_GET['message'])){
  394. if($uid = userId($_GET['to'])){
  395. if(!personal_message($uid,$_GET['message'])){
  396. $ret['error'] = 'Could not send message';
  397. }
  398. }else{
  399. $ret['error'] = "That user doesn't exist";
  400. }
  401. }else{
  402. $ret['error'] = 'Empty details';
  403. }
  404. retj($ret,$id);
  405. }
  406. break;
  407. case 'notifications':
  408. if($LOGGEDIN){
  409. if($res = query("SELECT count(m.id) as notifications,UNIX_TIMESTAMP(max(m.timestamp)) as timestamp FROM `messages` m JOIN `users` u ON u.id = m.to_id WHERE u.id = %d AND u.last_pm_check < m.timestamp;",array(userId($_SESSION['username'])))){
  410. $res = $res->fetch_assoc();
  411. $ret['count'] = $res['notifications'];
  412. $ret['timestamp'] = $res['timestamp'];
  413. }
  414. }
  415. retj($ret,$_GET['title']);
  416. break;
  417. case 'comment':
  418. if(isset($_GET['comment_type'])&&isset($_GET['comment_id'])&&isset($_GET['message'])){
  419. $cid = $_GET['comment_id'];
  420. $ret = array(
  421. 'state'=>stateObj($_GET['comment_type'],$cid)
  422. );
  423. switch($_GET['comment_type']){
  424. case 'project':
  425. if(!function_exists('project_comment')){
  426. $ret['error'] = "fn doesn't exist!";
  427. }
  428. if(!project_comment($cid,$_GET['message'])){
  429. $ret = array(
  430. 'error'=>'Could not comment on project'
  431. );
  432. }
  433. break;
  434. case 'issue':
  435. if(!function_exists('issue_comment')){
  436. $ret['error'] = "fn doesn't exist!";
  437. }
  438. if(!issue_comment($cid,$_GET['message'])){
  439. $ret = array(
  440. 'error'=>'Could not comment on project'
  441. );
  442. }
  443. break;
  444. default:
  445. $ret['error'] = 'Comment type not implemented';
  446. }
  447. }else{
  448. $ret['error'] = 'Missing comment paremeters';
  449. $ret['state'] = array(
  450. 'title'=>'error'
  451. );
  452. }
  453. retj($ret,$ret['state']['title']);
  454. break;
  455. case 'more':
  456. if(isset($_GET['of']) && isset($_GET['pid'])){
  457. $ret = array();
  458. $limit = array(
  459. isset($_GET['at'])?$_GET['at']:0,
  460. isset($_GET['amount'])?$_GET['amount']:10
  461. );
  462. switch($_GET['of']){
  463. case 'latest':
  464. $ret['template'] = 'activity';
  465. if($res = query("SELECT a.date, a.id FROM `activity` AS a ORDER BY a.date DESC LIMIT %d,%d",array($limit[0],$limit[1]))){
  466. $ret['messages'] = fetch_all($res,MYSQLI_ASSOC);
  467. foreach($ret['messages'] as $key => $activity){
  468. $ret['messages'][$key] = activityObj($activity['id']);
  469. }
  470. }else{
  471. $ret['messages'] = array();
  472. }
  473. break;
  474. default:
  475. $ret['messages'] = messages($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  476. $ret['params'] = array($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  477. }
  478. }else{
  479. $ret['error'] = 'Missing comment parameters';
  480. }
  481. retj($ret);
  482. break;
  483. case 'mailqueue':
  484. die();
  485. break;
  486. default:
  487. retj(array(
  488. 'error'=>'Invalid action.'
  489. ));
  490. }
  491. break;
  492. default:
  493. retj(array(
  494. 'error'=>'Invalid type.'
  495. ));
  496. }
  497. }else{
  498. retj(array(
  499. 'error'=>'ID missing.'
  500. ));
  501. }
  502. }else{
  503. $_GET['type'] = '';
  504. retj(array(
  505. 'error'=>'Type missing.'
  506. ));
  507. }
  508. ?>