index.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391
  1. <?php
  2. header('Content-type: application/json');
  3. header('Access-Control-Allow-Origin: *');
  4. require_once("../../header.php");
  5. if(!isset($_GET['action'])){
  6. $opts = getopt('a:',array('action:'));
  7. $_GET['action'] = isset($opts['action'])?$opts['action']:(isset($opts['a'])?$opts['a']:'');
  8. }
  9. $u = is_logged_in();
  10. switch($_GET['action']){
  11. case 'test':
  12. //$u or die();
  13. //print_r(atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'topic','#omnimaga'));
  14. //echo mkpasswd('root');
  15. break;
  16. case 'lang':
  17. echo file_get_contents(DIR.'/lang/'.LOCALE.'/C/LC_MESSAGES/omninet.po');
  18. die();
  19. break;
  20. case 'login':
  21. isset($_GET['username']) && isset($_GET['password']) or die('{"code":2,"message":"'.__('Missing username and/or password').'"}');
  22. isset($_GET['type']) or die('{"code":2,"message":"'.__('Missing user type').'"}');
  23. $r = login($_GET['username'],$_GET['password'],$_GET['type']);
  24. if($r !== true){
  25. die('{"code":2,"message":"'.$r.'"}');
  26. }else{
  27. die('{"code":0}');
  28. }
  29. break;
  30. case 'verify':
  31. isset($_GET['token']) or die('{"code":1,"message":"'.__('No token set').'"}');
  32. $r = verify($_GET['token']);
  33. if($r !== true){
  34. die('{"code":2,"message":"'.$r.'"}');
  35. }
  36. die('{"code":0,"message":"'.$r.'"}');
  37. break;
  38. case 'logout':
  39. logout();
  40. die('{"code":0}');
  41. break;
  42. case 'get-memos':
  43. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  44. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  45. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','list');
  46. if($res[0]){
  47. $res = explode('&#10;',$res[1]);
  48. $memos = array();
  49. foreach($res as $k => $row){
  50. if($k != 0 && $k != 1){
  51. $row = preg_split('/^-\s/',$row);
  52. if(isset($row[1])){
  53. $row = explode(' ',$row[1]);
  54. $memo = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','read',array($row[0]));
  55. $memo = explode('&#10;',$memo[1]);
  56. array_push($memos,array(
  57. 'id'=>$row[0],
  58. 'from'=>$row[2],
  59. 'date'=>array(
  60. 'month'=>$row[4],
  61. 'day'=>$row[5],
  62. 'time'=>$row[6],
  63. 'year'=>$row[7]
  64. ),
  65. 'body'=>$memo[2]
  66. ));
  67. }
  68. }
  69. }
  70. die('{"code":0,"memos":'.json_encode($memos).'}');
  71. }else{
  72. die('{"code":1,"message":"'.__('Cannot fetch memos').'"}');
  73. }
  74. break;
  75. case 'get-news':
  76. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  77. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  78. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'InfoServ','list');
  79. if($res[0]){
  80. $res = explode('&#10;',$res[1]);
  81. $news = array();
  82. foreach($res as $k => $row){
  83. if($k != count($res)-1){
  84. array_push($news,array(
  85. 'id'=>preg_replace('/^(\d)+:.+$/i','\1',$row),
  86. 'title'=>preg_replace('/^\d+: \[(.+)\] .+/i','\1',$row),
  87. 'from'=>preg_replace('/^\d+: \[.+\] by (.+) at \d\d?:\d\d? on (\d\d)\/\d\d\/\d\d\d\d: .+/i','\1',$row),
  88. 'date'=>array(
  89. 'time'=>preg_replace('/^\d+: \[.+\] by .+ at (\d\d?:\d\d?) on .+/','\1',$row),
  90. 'day'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on (\d\d)\/\d\d\/\d\d\d\d: .+/i','\1',$row),
  91. 'month'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/(\d\d)\/\d\d\d\d: .+/i','\1',$row),
  92. 'year'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/\d\d\/(\d\d\d\d): .+/i','\1',$row)
  93. ),
  94. 'body'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/\d\d\/\d\d\d\d: (.+)/i','\1',$row)
  95. ));
  96. }
  97. }
  98. die('{"code":0,"news":'.json_encode($news).'}');
  99. }else{
  100. die('{"code":1,"message":"'.__('Cannot fetch news').'"}');
  101. }
  102. break;
  103. case 'get-channels':
  104. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  105. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  106. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'NickServ','listchans');
  107. if($res[0]){
  108. $res = explode('&#10;',$res[1]);
  109. $channels = array();
  110. foreach($res as $k => $row){
  111. if($k != count($res)-1){
  112. $flags_list = str_split(preg_replace('/^Access flag\(s\) \+(.+) in .+$/i','\1',$row));
  113. $name = preg_replace('/^Access flag\(s\) \+.+ in (.+)$/i','\1',$row);
  114. $chan = array(
  115. 'name'=>$name
  116. );
  117. if(in_array('F',$flags_list)){
  118. $chan['candrop'] = true;
  119. $chan['canaccess'] = true;
  120. }
  121. if(in_array('f',$flags_list)){
  122. $chan['canaccess'] = true;
  123. }
  124. $res2 = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','flags',array($name));
  125. if($res2[0]){
  126. $res2 = explode('&#10;',$res2[1]);
  127. $users = array();
  128. foreach($res2 as $kk => $row2){
  129. if($kk > 1 && $kk < count($res2)-2){
  130. $user = array(
  131. 'id'=>preg_replace('/^(\d+)\b.+$/','\1',$row2),
  132. 'name'=>trim(preg_replace('/^\d+\s+(.+)\s+\+.+/','\1',$row2)),
  133. 'flags'=>array()
  134. );
  135. $flags_list = str_split(preg_replace('/^\d+\s+.+\s+\+(.+)\s+\[.+/i','\1',$row2));
  136. foreach($flags_list as $kk => $flag){
  137. $name = channel_flag_name($flag);
  138. array_push($user['flags'],array(
  139. 'flag'=>$flag,
  140. 'name'=>$name
  141. ));
  142. }
  143. array_push($users,$user);
  144. }
  145. }
  146. }
  147. $chan['users'] = $users;
  148. array_push($channels,$chan);
  149. }
  150. }
  151. die('{"code":0,"channels":'.json_encode($channels).'}');
  152. }else{
  153. die('{"code":1,"message":"'.__('Cannot fetch channels').'"}');
  154. }
  155. break;
  156. case 'send-memo':
  157. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  158. isset($_GET['to']) && isset($_GET['message']) or die('{"code":1,"message":"'.__('No message or user entered').'"}');
  159. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','send',array($_GET['to'],$_GET['message']));
  160. if($res[0]){
  161. if(substr($res[1],-19) == ' is not registered.'){
  162. die('{"code":1,"message":"'.__('User').' '.$_GET['to'].' '.__('does not exist').'"}');
  163. }else{
  164. die('{"code":0,"message":"'.__('Memo Sent').'"}');
  165. }
  166. }else{
  167. die('{"code":1,"message":"'.__('Cannot send memo').': '.$res[1].'"}');
  168. }
  169. break;
  170. case 'delete-memo':
  171. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  172. isset($_GET['id']) or die('{"code":1,"message":"'.__('No id given').'"}');
  173. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','delete',array($_GET['id']));
  174. if(!$res[0]){
  175. die('{"code":1,"message":"'.__('Cannot delete memo').': '.$res[1].'"}');
  176. }
  177. die('{"code":0}');
  178. break;
  179. case 'delete-channel':
  180. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  181. isset($_GET['channel']) or die('{"code":1,"message":"'.__('No channel given').'"}');
  182. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','drop',array($_GET['channel']));
  183. if(!$res[0]){
  184. die('{"code":1,"message":"'.__('Cannot drop channel').': '.$res[1].'"}');
  185. }
  186. die('{"code":0}');
  187. break;
  188. case 'channel-flags':
  189. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  190. isset($_GET['channel']) or die('{"code":1,"message":"'.__('No channel given').'"}');
  191. isset($_GET['user']) or die('{"code":1,"message":"'.__('No user given').'"}');
  192. if(isset($_GET['flags'])){
  193. $flags = $_GET['flags'];
  194. }else{
  195. $flags = array();
  196. }
  197. $flags_on = '';
  198. $flags_off = '';
  199. $flags = sanitize_channel_flags($flags);
  200. foreach($flags as $flag => $val){
  201. if($val){
  202. $flags_on .= ' '.$flag;
  203. }else{
  204. $flags_off .= ' '.$flag;
  205. }
  206. }
  207. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','flags',array($_GET['channel'],$_GET['user'],'+'.$flags_on));
  208. if(!$res[0] && $res[2] != 12){
  209. die('{"code":1,"message":"'.__('Cannot change flag').': '.$res[1].'"}');
  210. }
  211. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','flags',array($_GET['channel'],$_GET['user'],'-'.$flags_off));
  212. if(!$res[0] && $res[2] != 12){
  213. die('{"code":1,"message":"'.__('Cannot change flag').': '.$res[1].'"}');
  214. }
  215. die('{"code":0,"flags":'.json_encode($flags).'}');
  216. break;
  217. case 'register-channel':
  218. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  219. isset($_GET['channel']) or die('{"code":1,"message":"'.__('No channel given').'"}');
  220. $ret = irccommands(array(
  221. 'join '.$_GET['channel'],
  222. 'samode '.$_GET['channel'].' +o RehashServ',
  223. 'cs register '.$_GET['channel'],
  224. 'cs set '.$_GET['channel'].' keeptopic on',
  225. 'cs set '.$_GET['channel'].' founder '.$_COOKIE['user']
  226. ));
  227. if($ret['code'] !== 0){
  228. die(json_encode($ret));
  229. }
  230. $ret2 = irccommands(array(
  231. 'join '.$_GET['channel'],
  232. 'cs set '.$_GET['channel'].' founder '.$_COOKIE['user'],
  233. 'cs flags '.$_GET['channel'].' RehashServ -AORafhioqrstv'
  234. ),$_COOKIE['user']);
  235. if($ret2['code'] !== 0){
  236. $ret2['message'] = 'Failed to register channel. See log for information.';
  237. }
  238. $ret2['log'] = $ret['log']."\r\n".$ret2['log'];
  239. die(json_encode($ret));
  240. break;
  241. case 'persona-login':
  242. if($u){
  243. $register = true;
  244. }else{
  245. $register = false;
  246. }
  247. $url = get_conf('persona-endpoint');
  248. $assert = filter_input(
  249. INPUT_POST,
  250. 'assertion',
  251. FILTER_UNSAFE_RAW,
  252. FILTER_FLAG_STRIP_LOW|FILTER_FLAG_STRIP_HIGH
  253. );
  254. $params = 'assertion='.urlencode($assert).'&audience='.urlencode(get_conf('persona-audience'));
  255. $ch = curl_init();
  256. $options = array(
  257. CURLOPT_URL => $url,
  258. CURLOPT_RETURNTRANSFER => TRUE,
  259. CURLOPT_POST => 2,
  260. CURLOPT_SSL_VERIFYPEER => 0,
  261. CURLOPT_SSL_VERIFYHOST => 2,
  262. CURLOPT_POSTFIELDS => $params
  263. );
  264. curl_setopt_array($ch, $options);
  265. $result = curl_exec($ch);
  266. curl_close($ch);
  267. $result = json_decode($result);
  268. if($result->status == 'okay'){
  269. if($register && !add_email($u['id'],$result->email)){
  270. die('{"code":1,"message":"'.__('Failed to add email').' '.$result->email.' '.__('to user').' '.$u['nick'].'"}');
  271. }elseif(!$register && !$u = get_user_for_email($result->email)){
  272. die('{"code":1,"message":"'.__('Email does not match any users').'"}');
  273. }
  274. setcookie('personaUser',$result->email,null,'/');
  275. $pass = null;
  276. if(isset($_SESSION['password']) && !is_null($_SESSION['password']) && $_SESSION['password'] != ''){
  277. $pass = $_SESSION['password'];
  278. }
  279. $types = get_user_types($u['id']);
  280. $r = login($u['nick'],$pass,'persona',$types[0]);
  281. if($r !== true){
  282. if($r){
  283. die('{"code":2,"message":"'.$r.'"}');
  284. }else{
  285. die('{"code":2}');
  286. }
  287. }else{
  288. die('{"code":0,"assertion":'.json_encode($result).'}');
  289. }
  290. }else{
  291. die('{"code":1,"message":"'.$result->reason.'"}');
  292. }
  293. break;
  294. case 'persona-remove':
  295. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  296. isset($_GET['id']) or die('{"code":1,"message":"'.__('No ID set').'"}');
  297. if(!remove_email($u['id'],$_GET['id'],true)){
  298. die('{"code":1,"message":"'.__('Could not remove email address').'"}');
  299. }
  300. die('{"code":0}');
  301. break;
  302. case '2-factor-register':
  303. $r = register_token();
  304. if($r !== true){
  305. die('{"code":1,"message":"'.$r.'"}');
  306. }
  307. die('{"code":0}');
  308. break;
  309. case '2-factor-delete':
  310. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  311. $r = delete_token($u['id']);
  312. if($r !== true){
  313. die('{"code":1,"message":"'.$r.'"}');
  314. }
  315. die('{"code":0,"message":"'.__('2-factor disabled.').'"}');
  316. break;
  317. case 'ping':
  318. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  319. die('{"code":0}');
  320. break;
  321. case 'newpass':
  322. $u && isset($_GET['password']) && isset($_GET['newpass']) or die('{"code":2,"message":"'.__('Make sure that everything is filled in. Try reloading if it is.').'"}');
  323. $u['password'] == mkpasswd($_GET['password'],$u['salt']) or die('{"code":2,"message":"'.__('Invalid password').'"}');
  324. $u['api_key'] == $_COOKIE['key'] or die('{"code":3,"message":"Not Logged in to use '.$u['nick'].' with key '.$u['api_key'].' != '.$_COOKIE['key'].'."}');
  325. if($_COOKIE['type'] == 'user'){
  326. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$u['nick'],$_GET['password'],'NickServ','set',array('password',trim($_GET['newpass'])));
  327. if($res[0] === false){
  328. die('{"code":2,"message":"'.__('Could not update password with nickserv').': '.$res[1].'"}');
  329. }else{
  330. $_SESSION['password'] = $_GET['newpass'];
  331. }
  332. }
  333. query("UPDATE users u SET u.password='%s' WHERE u.id=%d",array(mkpasswd($_GET['newpass']),$u['id']));
  334. die('{"code":0}');
  335. break;
  336. case 'sync-pass':
  337. $u && isset($_SESSION['password'])or die('{"code":2,"message":"'.__('Make sure that everything is filled in. Try reloading if it is.').'"}');
  338. $u['api_key'] == $_COOKIE['key'] or die('{"code":3,"message":"'.__('Not Logged in to use').' '.$u['nick'].' '.__('with key').' '.$u['api_key'].' != '.$_COOKIE['key'].'."}');
  339. $_COOKIE['type'] == 'user' or die('{"code":3,"message":"'.__('Must be logged in with type user to sync pass').'"}');
  340. $res = atheme_login(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),$u['nick'],$_SESSION['password']);
  341. if($res[0] === false){
  342. die('{"code":2,"message":"'.__('Could not verify with nickserv').': '.$res[1].'"}');
  343. }
  344. query("UPDATE users u SET u.password='%s' WHERE u.id=%d",array(mkpasswd($_SESSION['password']),$u['id']));
  345. die('{"code":0,"message":"'.__('Nickserv password synchronized with main account').'"}');
  346. break;
  347. case 'role':
  348. $u && isset($_GET['type']) or die('{"code":2,"message":"'.__('Make sure that everything is filled in. Try reloading if it is.').'"}');
  349. setcookie('type',$_GET['type'],null,'/');
  350. die('{"code":0}');
  351. break;
  352. case 'user':
  353. $u or die('{"code":10,"message":"'.__('Not logged in').'"}');
  354. isset($_GET['id']) or die('{"code":2,"message":"'.__('No user set.').'"}');
  355. isset($_GET['email']) or die('{"code":2,"message":"'.__('No email set.').'"}');
  356. isset($_GET['real_name']) or die('{"code":2,"message":"'.__('No real name set.').'"}');
  357. isset($_GET['nick']) or die('{"code":2,"message":"'.__('No nick set.').'"}');
  358. $user = get_user_from_id_obj($_GET['id']) or die('{"code":2,"message":"'.__('User with id').' '.$_GET['id'].' '.__('does not exist. You should reload the page.').'"}');
  359. if($u['id'] == $user['id']){
  360. setcookie('user',$_GET['nick'],null,'/');
  361. }
  362. query("UPDATE users u SET u.nick='%s', u.real_name='%s', u.email='%s' WHERE u.id=%d",array($_GET['nick'],$_GET['real_name'],$_GET['email'],$_GET['id'])) or die('{"code":2,"message":"'.__('Unable to update user').'"}');
  363. die(ircrehash());
  364. break;
  365. case 'oper':
  366. $u or die('{"code":10,"message":"'.__('Not logged in').'"}');
  367. isset($_GET['id']) or die('{"code":2,"message":"'.__('No user set.').'"}');
  368. isset($_GET['nick']) or die('{"code":2,"message":"'.__('No nick set.').'"}');
  369. isset($_GET['swhois']) or die('{"code":2,"message":"'.__('No profile set.').'"}');
  370. $oper = get_oper_from_id_obj($_GET['id']) or die('{"code":2,"message":"'.__('Oper with id').' '.$_GET['id'].' '.__('does not exist. You should reload the page.').'"}');
  371. if(isset($_GET['password']) && $_GET['password'] != ""){
  372. query("UPDATE opers o SET o.nick='%s', o.swhois='%s', o.password='%s', o.password_type_id=2 WHERE o.id=%d",array($_GET['nick'],$_GET['swhois'],mkpasswd($_GET['password']),$_GET['id'])) or die('{"code":2,"message":"'.__('Unable to update oper').'"}');
  373. }else{
  374. query("UPDATE opers o SET o.nick='%s', o.swhois='%s' WHERE o.id=%d",array($_GET['nick'],$_GET['swhois'],$_GET['id'])) or die('{"code":2,"message":"'.__('Unable to update oper').'"}');
  375. }
  376. die(ircrehash());
  377. break;
  378. case 'config':
  379. foreach($_GET as $key => $val){
  380. set_conf($key,$val,get_conf_type($key)) or die('{"code":1,"message":"'.__('Failed to update setting').': '.$key.' '.__('with value').': '.$val.'"}');
  381. }
  382. die('{"code":0}');
  383. break;
  384. case 'rehash':
  385. $u or die('{"code":10,"message":"'.__('Not logged in').'"}');
  386. die(ircrehash());
  387. break;
  388. default:
  389. die('{"code":1,"message":"'.__('Invalid Action').': '.$_GET['action'].'"}');
  390. }
  391. ?>