index.php 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440
  1. <?php
  2. error_reporting(E_ERROR);
  3. header('Content-type: application/json');
  4. header('Access-Control-Allow-Origin: *');
  5. require_once("../../header.php");
  6. if(!isset($_GET['action'])){
  7. $opts = getopt('a:',array('action:'));
  8. $_GET['action'] = isset($opts['action'])?$opts['action']:(isset($opts['a'])?$opts['a']:'');
  9. }
  10. $u = is_logged_in();
  11. switch($_GET['action']){
  12. case 'test':
  13. //$u or die();
  14. //print_r(atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'topic','#omnimaga'));
  15. //echo mkpasswd('root');
  16. break;
  17. case 'lang':
  18. echo file_get_contents(DIR.'/lang/'.LOCALE.'/C/LC_MESSAGES/omninet.po');
  19. die();
  20. break;
  21. case 'login':
  22. isset($_GET['username']) && isset($_GET['password']) or die('{"code":2,"message":"'.__('Missing username and/or password').'"}');
  23. isset($_GET['type']) or die('{"code":2,"message":"'.__('Missing user type').'"}');
  24. $r = login($_GET['username'],$_GET['password'],$_GET['type']);
  25. if($r !== true){
  26. die('{"code":2,"message":'.json_encode($r).'}');
  27. }else{
  28. die('{"code":0}');
  29. }
  30. break;
  31. case 'verify':
  32. isset($_GET['token']) or die('{"code":1,"message":"'.__('No token set').'"}');
  33. $r = verify($_GET['token']);
  34. if($r !== true){
  35. die('{"code":2,"message":"'.$r.'"}');
  36. }
  37. die('{"code":0,"message":"'.$r.'"}');
  38. break;
  39. case 'logout':
  40. logout();
  41. die('{"code":0}');
  42. break;
  43. case 'get-memos':
  44. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  45. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  46. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','list');
  47. if($res[0]){
  48. $res = explode('&#10;',$res[1]);
  49. $memos = array();
  50. foreach($res as $k => $row){
  51. if($k != 0 && $k != 1){
  52. $row = preg_split('/^-\s/',$row);
  53. if(isset($row[1])){
  54. $row = explode(' ',$row[1]);
  55. $memo = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','read',array($row[0]));
  56. $memo = explode('&#10;',$memo[1]);
  57. array_push($memos,array(
  58. 'id'=>$row[0],
  59. 'from'=>$row[2],
  60. 'date'=>array(
  61. 'month'=>$row[4],
  62. 'day'=>$row[5],
  63. 'time'=>$row[6],
  64. 'year'=>$row[7]
  65. ),
  66. 'body'=>$memo[2]
  67. ));
  68. }
  69. }
  70. }
  71. die('{"code":0,"memos":'.json_encode($memos).'}');
  72. }else{
  73. die('{"code":1,"message":"'.__('Cannot fetch memos').'"}');
  74. }
  75. break;
  76. case 'get-news':
  77. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  78. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  79. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'InfoServ','list');
  80. if($res[0]){
  81. $res = explode('&#10;',$res[1]);
  82. $news = array();
  83. foreach($res as $k => $row){
  84. if($k != count($res)-1){
  85. array_push($news,array(
  86. 'id'=>preg_replace('/^(\d)+:.+$/i','\1',$row),
  87. 'title'=>preg_replace('/^\d+: \[(.+)\] .+/i','\1',$row),
  88. 'from'=>preg_replace('/^\d+: \[.+\] by (.+) at \d\d?:\d\d? on (\d\d)\/\d\d\/\d\d\d\d: .+/i','\1',$row),
  89. 'date'=>array(
  90. 'time'=>preg_replace('/^\d+: \[.+\] by .+ at (\d\d?:\d\d?) on .+/','\1',$row),
  91. 'day'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on (\d\d)\/\d\d\/\d\d\d\d: .+/i','\1',$row),
  92. 'month'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/(\d\d)\/\d\d\d\d: .+/i','\1',$row),
  93. 'year'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/\d\d\/(\d\d\d\d): .+/i','\1',$row)
  94. ),
  95. 'body'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/\d\d\/\d\d\d\d: (.+)/i','\1',$row)
  96. ));
  97. }
  98. }
  99. die('{"code":0,"news":'.json_encode($news).'}');
  100. }else{
  101. die('{"code":1,"message":"'.__('Cannot fetch news').'"}');
  102. }
  103. break;
  104. case 'get-channels':
  105. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  106. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  107. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'NickServ','listchans');
  108. if($res[0]){
  109. $res = explode('&#10;',$res[1]);
  110. $channels = array();
  111. foreach($res as $k => $row){
  112. if($k != count($res)-1){
  113. $flags_list = str_split(preg_replace('/^Access flag\(s\) \+(.+) in .+$/i','\1',$row));
  114. $name = preg_replace('/^Access flag\(s\) \+.+ in (.+)$/i','\1',$row);
  115. $chan = array(
  116. 'name'=>$name
  117. );
  118. if(in_array('F',$flags_list)){
  119. $chan['candrop'] = true;
  120. $chan['canaccess'] = true;
  121. }
  122. if(in_array('f',$flags_list)){
  123. $chan['canaccess'] = true;
  124. }
  125. $res2 = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','flags',array($name));
  126. $users = array();
  127. if($res2[0]){
  128. $res2 = explode('&#10;',$res2[1]);
  129. foreach($res2 as $kk => $row2){
  130. if($kk > 1 && $kk < count($res2)-2){
  131. $user = array(
  132. 'id'=>preg_replace('/^(\d+)\b.+$/','\1',$row2),
  133. 'name'=>trim(preg_replace('/^\d+\s+(.+)\s+\+.+/','\1',$row2)),
  134. 'flags'=>array()
  135. );
  136. $flags_list = str_split(preg_replace('/^\d+\s+.+\s+\+(.+)\s+\[.+/i','\1',$row2));
  137. foreach($flags_list as $kk => $flag){
  138. $name = channel_flag_name($flag);
  139. array_push($user['flags'],array(
  140. 'flag'=>$flag,
  141. 'name'=>$name
  142. ));
  143. }
  144. array_push($users,$user);
  145. }
  146. }
  147. }
  148. $chan['users'] = $users;
  149. array_push($channels,$chan);
  150. }
  151. }
  152. die('{"code":0,"channels":'.json_encode($channels).'}');
  153. }else{
  154. die('{"code":1,"message":"'.__('Cannot fetch channels').'"}');
  155. }
  156. break;
  157. case 'send-memo':
  158. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  159. isset($_GET['to']) && isset($_GET['message']) or die('{"code":1,"message":"'.__('No message or user entered').'"}');
  160. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','send',array($_GET['to'],$_GET['message']));
  161. if($res[0]){
  162. if(substr($res[1],-19) == ' is not registered.'){
  163. die('{"code":1,"message":"'.__('User').' '.$_GET['to'].' '.__('does not exist').'"}');
  164. }else{
  165. die('{"code":0,"message":"'.__('Memo Sent').'"}');
  166. }
  167. }else{
  168. die('{"code":1,"message":"'.__('Cannot send memo').': '.$res[1].'"}');
  169. }
  170. break;
  171. case 'delete-memo':
  172. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  173. isset($_GET['id']) or die('{"code":1,"message":"'.__('No id given').'"}');
  174. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','delete',array($_GET['id']));
  175. if(!$res[0]){
  176. die('{"code":1,"message":"'.__('Cannot delete memo').': '.$res[1].'"}');
  177. }
  178. die('{"code":0}');
  179. break;
  180. case 'delete-channel':
  181. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  182. isset($_GET['channel']) or die('{"code":1,"message":"'.__('No channel given').'"}');
  183. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','drop',array($_GET['channel']));
  184. if(!$res[0]){
  185. die('{"code":1,"message":"'.__('Cannot drop channel').': '.$res[1].'"}');
  186. }
  187. die('{"code":0}');
  188. break;
  189. case 'channel-flags':
  190. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  191. isset($_GET['channel']) or die('{"code":1,"message":"'.__('No channel given').'"}');
  192. isset($_GET['user']) or die('{"code":1,"message":"'.__('No user given').'"}');
  193. if(isset($_GET['flags'])){
  194. $flags = $_GET['flags'];
  195. }else{
  196. $flags = array();
  197. }
  198. $flags_on = '';
  199. $flags_off = '';
  200. $flags = sanitize_channel_flags($flags);
  201. foreach($flags as $flag => $val){
  202. if($val){
  203. $flags_on .= ' '.$flag;
  204. }else{
  205. $flags_off .= ' '.$flag;
  206. }
  207. }
  208. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','flags',array($_GET['channel'],$_GET['user'],'+'.$flags_on));
  209. if(!$res[0] && $res[2] != 12){
  210. die('{"code":1,"message":"'.__('Cannot change flag').': '.$res[1].'"}');
  211. }
  212. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','flags',array($_GET['channel'],$_GET['user'],'-'.$flags_off));
  213. if(!$res[0] && $res[2] != 12){
  214. die('{"code":1,"message":"'.__('Cannot change flag').': '.$res[1].'"}');
  215. }
  216. die('{"code":0,"flags":'.json_encode($flags).'}');
  217. break;
  218. case 'register-channel':
  219. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  220. isset($_GET['channel']) or die('{"code":1,"message":"'.__('No channel given').'"}');
  221. $channel = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'ChanServ','info',Array($_GET['channel']));
  222. if(!$channel[0]){
  223. $ret = irccommands(array(
  224. 'join '.$_GET['channel'],
  225. 'samode '.$_GET['channel'].' +o RehashServ',
  226. 'cs register '.$_GET['channel'],
  227. 'cs set '.$_GET['channel'].' keeptopic on',
  228. 'cs set '.$_GET['channel'].' founder '.$_COOKIE['user']
  229. ));
  230. if($ret['code'] !== 0){
  231. die(json_encode($ret));
  232. }
  233. $ret2 = irccommands(array(
  234. 'join '.$_GET['channel'],
  235. 'cs set '.$_GET['channel'].' founder '.$_COOKIE['user'],
  236. 'cs flags '.$_GET['channel'].' RehashServ -AORafhioqrstv'
  237. ),$_COOKIE['user']);
  238. if($ret2['code'] !== 0){
  239. $ret2['message'] = 'Failed to register channel. See log for information.';
  240. }
  241. @$ret2['log'] = $ret['log']."\r\n".$ret2['log'];
  242. }else{
  243. $ret = array(
  244. 'code'=>1,
  245. 'message'=>'Channel '.$_GET['channel'].' already exists.'
  246. );
  247. }
  248. die(json_encode($ret));
  249. break;
  250. case 'persona-login':
  251. if($u){
  252. $register = true;
  253. }else{
  254. $register = false;
  255. }
  256. $url = get_conf('persona-endpoint');
  257. $assert = filter_input(
  258. INPUT_POST,
  259. 'assertion',
  260. FILTER_UNSAFE_RAW,
  261. FILTER_FLAG_STRIP_LOW|FILTER_FLAG_STRIP_HIGH
  262. );
  263. $params = 'assertion='.urlencode($assert).'&audience='.urlencode(get_conf('persona-audience'));
  264. $ch = curl_init();
  265. $options = array(
  266. CURLOPT_URL => $url,
  267. CURLOPT_RETURNTRANSFER => TRUE,
  268. CURLOPT_POST => 2,
  269. CURLOPT_SSL_VERIFYPEER => 0,
  270. CURLOPT_SSL_VERIFYHOST => 2,
  271. CURLOPT_POSTFIELDS => $params
  272. );
  273. curl_setopt_array($ch, $options);
  274. $result = curl_exec($ch);
  275. curl_close($ch);
  276. $result = json_decode($result);
  277. if($result->status == 'okay'){
  278. if($register && !add_email($u['id'],$result->email)){
  279. die('{"code":1,"message":"'.__('Failed to add email').' '.$result->email.' '.__('to user').' '.$u['nick'].'"}');
  280. }elseif(!$register && !$u = get_user_for_email($result->email)){
  281. die('{"code":1,"message":"'.__('Email does not match any users').'"}');
  282. }
  283. setcookie('personaUser',$result->email,null,'/');
  284. $pass = null;
  285. if(isset($_SESSION['password']) && !is_null($_SESSION['password']) && $_SESSION['password'] != ''){
  286. $pass = $_SESSION['password'];
  287. }
  288. $types = get_user_types($u['id']);
  289. $r = login($u['nick'],$pass,'persona',$types[0]);
  290. if($r !== true){
  291. if($r){
  292. die('{"code":2,"message":"'.$r.'"}');
  293. }else{
  294. die('{"code":2}');
  295. }
  296. }else{
  297. die('{"code":0,"assertion":'.json_encode($result).'}');
  298. }
  299. }else{
  300. die('{"code":1,"message":"'.$result->reason.'"}');
  301. }
  302. break;
  303. case 'persona-remove':
  304. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  305. isset($_GET['id']) or die('{"code":1,"message":"'.__('No ID set').'"}');
  306. if(!remove_email($u['id'],$_GET['id'],true)){
  307. die('{"code":1,"message":"'.__('Could not remove email address').'"}');
  308. }
  309. die('{"code":0}');
  310. break;
  311. case '2-factor-register':
  312. $r = register_token();
  313. if($r !== true){
  314. die('{"code":1,"message":"'.$r.'"}');
  315. }
  316. die('{"code":0}');
  317. break;
  318. case '2-factor-delete':
  319. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  320. $r = delete_token($u['id']);
  321. if($r !== true){
  322. die('{"code":1,"message":"'.$r.'"}');
  323. }
  324. die('{"code":0,"message":"'.__('2-factor disabled.').'"}');
  325. break;
  326. case 'ping':
  327. $u or die('{"code":1,"message":"'.__('You have been logged out').'"}');
  328. die('{"code":0}');
  329. break;
  330. case 'newpass':
  331. $u && isset($_GET['password']) && isset($_GET['newpass']) or die('{"code":2,"message":"'.__('Make sure that everything is filled in. Try reloading if it is.').'"}');
  332. $u['password'] == mkpasswd($_GET['password'],$u['salt']) or die('{"code":2,"message":"'.__('Invalid password').'"}');
  333. $u['api_key'] == $_COOKIE['key'] or die('{"code":3,"message":"Not Logged in to use '.$u['nick'].' with key '.$u['api_key'].' != '.$_COOKIE['key'].'."}');
  334. if($_COOKIE['type'] == 'user'){
  335. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$u['nick'],$_GET['password'],'NickServ','set',array('password',trim($_GET['newpass'])));
  336. if($res[0] === false){
  337. die('{"code":2,"message":"'.__('Could not update password with nickserv').': '.$res[1].'"}');
  338. }else{
  339. $_SESSION['password'] = $_GET['newpass'];
  340. }
  341. }
  342. query("UPDATE users u SET u.password='%s' WHERE u.id=%d",array(mkpasswd($_GET['newpass']),$u['id']));
  343. die('{"code":0}');
  344. break;
  345. case 'sync-pass':
  346. $u && isset($_SESSION['password'])or die('{"code":2,"message":"'.__('Not logged in').'"}');
  347. $u['api_key'] == $_COOKIE['key'] or die('{"code":3,"message":"'.__('Not Logged in to use').' '.$u['nick'].' '.__('with key').' '.$u['api_key'].' != '.$_COOKIE['key'].'."}');
  348. $_COOKIE['type'] == 'user' or die('{"code":3,"message":"'.__('Must be logged in with type user to sync pass').'"}');
  349. $res = atheme_login(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),$u['nick'],$_SESSION['password']);
  350. if($res[0] === false){
  351. die('{"code":2,"message":"'.__('Could not verify with nickserv').': '.$res[1].'"}');
  352. }
  353. query("UPDATE users u SET u.password='%s' WHERE u.id=%d",array(mkpasswd($_SESSION['password']),$u['id']));
  354. die('{"code":0,"message":"'.__('Nickserv password synchronized with main account').'"}');
  355. break;
  356. case 'sync-groups':
  357. $u && isset($_SESSION['password'])or die('{"code":2,"message":"'.__('Make sure that everything is filled in. Try reloading if it is.').'"}');
  358. $u['api_key'] == $_COOKIE['key'] or die('{"code":3,"message":"'.__('Not Logged in to use').' '.$u['nick'].' '.__('with key').' '.$u['api_key'].' != '.$_COOKIE['key'].'."}');
  359. $res = atheme_login(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),$u['nick'],$_SESSION['password']);
  360. if($res[0] === false){
  361. die('{"code":2,"message":"'.__('Could not verify with nickserv').': '.$res[1].'"}');
  362. }
  363. require_once(get_conf('smf-path').'/SSI.php');
  364. $res = $smcFunc['db_query']('',"SELECT id_group,additional_groups
  365. FROM {db_prefix}members
  366. WHERE id_member = {int:id_member}
  367. ",array(
  368. 'id_member'=>$user_info['id']
  369. ));
  370. while($row = $smcFunc['db_fetch_assoc']($res)){
  371. $groups = explode(',',$row['additional_groups']);
  372. if(!is_null($row['id_group'])){
  373. array_push($groups,$row['id_group']);
  374. }
  375. foreach($groups as $k => $group){
  376. $res2 = query("SELECT irc_name FROM smf_groups WHERE id_group = %d",array($group));
  377. if($res2 && $res2->num_rows > 0){
  378. $res2 = $res2->fetch_assoc();
  379. $res3 = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,'RehashServ',get_conf('rehash-pass'),'GroupServ','flags',array('!'.$res2['irc_name'],$_COOKIE['user'],'+cvi'));
  380. if(!$res3[0]){
  381. die('{"code":'.$res3[2].',"message":"'.__('Unable to sync groups').': '.$res3[1].'"}');
  382. }
  383. }
  384. }
  385. $res3 = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,'RehashServ',get_conf('rehash-pass'),'GroupServ','flags',array('!Members',$_COOKIE['user'],'+cvi'));
  386. if(!$res3[0]){
  387. die('{"code":'.$res3[2].',"message":"'.__('Unable to sync groups').': '.$res3[1].'"}');
  388. }
  389. }
  390. $res3 = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,'RehashServ',get_conf('rehash-pass'),'NickServ','hold',array($_COOKIE['user'],'on'));
  391. if(!$res3[0]){
  392. die('{"code":'.$res3[2].',"message":"'.__('Unable to sync groups').': '.$res3[1].'"}');
  393. }
  394. die('{"code":0,"message":"'.__('Groups synced with SMF').'"}');
  395. break;
  396. case 'role':
  397. $u && isset($_GET['type']) or die('{"code":2,"message":"'.__('Not logged in').'"}');
  398. setcookie('type',$_GET['type'],null,'/');
  399. die('{"code":0}');
  400. break;
  401. case 'user':
  402. $u or die('{"code":10,"message":"'.__('Not logged in').'"}');
  403. isset($_GET['id']) or die('{"code":2,"message":"'.__('No user set.').'"}');
  404. isset($_GET['email']) or die('{"code":2,"message":"'.__('No email set.').'"}');
  405. isset($_GET['real_name']) or die('{"code":2,"message":"'.__('No real name set.').'"}');
  406. isset($_GET['nick']) or die('{"code":2,"message":"'.__('No nick set.').'"}');
  407. $user = get_user_from_id_obj($_GET['id']) or die('{"code":2,"message":"'.__('User with id').' '.$_GET['id'].' '.__('does not exist. You should reload the page.').'"}');
  408. if($u['id'] == $user['id']){
  409. setcookie('user',$_GET['nick'],null,'/');
  410. }
  411. query("UPDATE users u SET u.nick='%s', u.real_name='%s', u.email='%s' WHERE u.id=%d",array($_GET['nick'],$_GET['real_name'],$_GET['email'],$_GET['id'])) or die('{"code":2,"message":"'.__('Unable to update user').'"}');
  412. die(ircrehash());
  413. break;
  414. case 'oper':
  415. $u or die('{"code":10,"message":"'.__('Not logged in').'"}');
  416. isset($_GET['id']) or die('{"code":2,"message":"'.__('No user set.').'"}');
  417. isset($_GET['nick']) or die('{"code":2,"message":"'.__('No nick set.').'"}');
  418. isset($_GET['swhois']) or die('{"code":2,"message":"'.__('No profile set.').'"}');
  419. $oper = get_oper_from_id_obj($_GET['id']) or die('{"code":2,"message":"'.__('Oper with id').' '.$_GET['id'].' '.__('does not exist. You should reload the page.').'"}');
  420. if(isset($_GET['password']) && $_GET['password'] != ""){
  421. query("UPDATE opers o SET o.nick='%s', o.swhois='%s', o.password='%s', o.password_type_id=2 WHERE o.id=%d",array($_GET['nick'],$_GET['swhois'],mkpasswd($_GET['password']),$_GET['id'])) or die('{"code":2,"message":"'.__('Unable to update oper').'"}');
  422. }else{
  423. query("UPDATE opers o SET o.nick='%s', o.swhois='%s' WHERE o.id=%d",array($_GET['nick'],$_GET['swhois'],$_GET['id'])) or die('{"code":2,"message":"'.__('Unable to update oper').'"}');
  424. }
  425. die(ircrehash());
  426. break;
  427. case 'config':
  428. foreach($_GET as $key => $val){
  429. set_conf($key,$val,get_conf_type($key)) or die('{"code":1,"message":"'.__('Failed to update setting').': '.$key.' '.__('with value').': '.$val.'"}');
  430. }
  431. die('{"code":0}');
  432. break;
  433. case 'rehash':
  434. $u or die('{"code":10,"message":"'.__('Not logged in').'"}');
  435. die(ircrehash());
  436. break;
  437. default:
  438. die('{"code":1,"message":"'.__('Invalid Action').': '.$_GET['action'].'"}');
  439. }
  440. ?>