api.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430
  1. <?php
  2. require_once('php/include.php');
  3. // TODO - Add API handling.
  4. $method = $_SERVER['REQUEST_METHOD'];
  5. $ret = array();
  6. if(isset($_GET['type'])){
  7. if(isset($_GET['id'])){
  8. $id = $_GET['id'];
  9. switch($_GET['type']){
  10. case 'user':
  11. back(true);
  12. $ret['template'] = array(
  13. 'type'=>'pages',
  14. 'name'=>'user'
  15. );
  16. if($user = userObj($id)){
  17. $context = array(
  18. 'name'=>$user['name'],
  19. 'email'=>$user['email']
  20. );
  21. if($LOGGEDIN){
  22. $context['key'] = true;
  23. $context['user'] = userObj($_SESSION['username']);
  24. };
  25. $ret['context'] = $context;
  26. }else{
  27. $ret['state'] = array(
  28. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  29. );
  30. }
  31. retj($ret,'User - '.$context['name']);
  32. break;
  33. case 'group':
  34. back(true);
  35. // TODO - handle group requests
  36. if(false){
  37. // TODO
  38. }else{
  39. $ret['state'] = array(
  40. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  41. );
  42. }
  43. retj($ret);
  44. break;
  45. case 'issue':
  46. back(true);
  47. $ret['template'] = array(
  48. 'type'=>'pages',
  49. 'name'=>'issue'
  50. );
  51. if($context = issueObj($id)){
  52. $context['user'] = userObj($context['user']);
  53. if($LOGGEDIN){
  54. $context['key'] = true;
  55. $context['user'] = userObj($_SESSION['username']);
  56. };
  57. $ret['context'] = $context;
  58. }else{
  59. $ret['state'] = array(
  60. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  61. );
  62. }
  63. retj($ret,'Issue #'.$id. ' - '.$context['title']);
  64. break;
  65. case 'scrum':
  66. back(true);
  67. // TODO - handle scrum requests
  68. if(false){
  69. // TODO
  70. }else{
  71. $ret['state'] = array(
  72. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  73. );
  74. }
  75. retj($ret);
  76. break;
  77. case 'project':
  78. back(true);
  79. $ret['template'] = array(
  80. 'type'=>'pages',
  81. 'name'=>'project'
  82. );
  83. if($context = projectObj($id)){
  84. $context['user'] = userObj($context['user']);
  85. if($LOGGEDIN){
  86. $context['key'] = true;
  87. $context['user'] = userObj($_SESSION['username']);
  88. };
  89. $ret['context'] = $context;
  90. }else{
  91. $ret['state'] = array(
  92. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  93. );
  94. }
  95. retj($ret,'Project - '.$context['title']);
  96. break;
  97. case 'message':
  98. // TODO - handle message requests
  99. $context = array();
  100. if(false){
  101. // TODO
  102. }else{
  103. $ret['state'] = array(
  104. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  105. );
  106. }
  107. retj($ret,'Project - '.$context['title']);
  108. break;
  109. case 'admin':
  110. back(true);
  111. // TODO - handle admin requests
  112. if(false){
  113. // TODO
  114. }else{
  115. $ret['state'] = array(
  116. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  117. );
  118. }
  119. retj($ret);
  120. break;
  121. case 'page':
  122. $title = $id;
  123. if(file_exists(PATH_DATA.'pages/'.$id.'.template')){
  124. $context = array();
  125. $ret['template'] = array(
  126. 'type'=>'pages',
  127. 'name'=>$id
  128. );
  129. if($LOGGEDIN){
  130. $context['key'] = true;
  131. $context['user'] = userObj($_SESSION['username']);
  132. };
  133. if(file_exists(PATH_DATA.'pages/'.$id.'.options')){
  134. $options = objectToarray(json_decode(file_get_contents(PATH_DATA.'pages/'.$id.'.options'),true));
  135. if(isset($options['secure'])&&$options['secure']&&!$LOGGEDIN){
  136. back(true);
  137. }
  138. if(isset($options['title'])){
  139. $title = $options['title'];
  140. }
  141. if(isset($options['context'])){
  142. foreach($options['context'] as $key){
  143. switch($key){
  144. case 'users':
  145. if($res = query("SELECT name FROM `users`;")){
  146. $context['users'] = fetch_all($res,MYSQLI_ASSOC);
  147. }
  148. break;
  149. case 'projects':
  150. if($res = query("SELECT p.title,p.id,p.description,u.name as user FROM `projects` p JOIN `users` u ON u.id = p.u_id")){
  151. $context['projects'] = fetch_all($res,MYSQLI_ASSOC);
  152. foreach($context['projects'] as $key => $project){
  153. $context['projects'][$key]['user'] = userObj($project['user']);
  154. }
  155. }
  156. break;
  157. case 'messages':
  158. if($LOGGEDIN){
  159. $context['messages'] = messages($context['user']['id'],'user');
  160. }else{
  161. $context['messages'] = array();
  162. }
  163. break;
  164. case 'issues':
  165. if($res = query("SELECT i.id,i.title,i.description,u.name as user,s.name as status,p.name as priority,p.color FROM `issues` i JOIN `users` u ON u.id = i.u_id LEFT JOIN `statuses` s ON s.id = i.st_id LEFT JOIN `priorities` p ON p.id = i.pr_id")){
  166. $context['issues'] = fetch_all($res,MYSQLI_ASSOC);
  167. foreach($context['issues'] as $key => $issue){
  168. $context['issues'][$key]['user'] = userObj($issue['user']);
  169. }
  170. }
  171. break;
  172. }
  173. }
  174. }
  175. if(isset($options['actions'])){
  176. foreach($options['actions'] as $key){
  177. switch($key){
  178. case 'pm_mark_read':
  179. query("UPDATE `users` SET last_pm_check=CURRENT_TIMESTAMP WHERE id='%d'; ",array(userId($_SESSION['username'])));
  180. break;
  181. }
  182. }
  183. }
  184. }
  185. $ret['context'] = $context;
  186. }else{
  187. $ret['error'] = 'That page does not exist';
  188. $ret['state'] = array(
  189. 'url'=>isset($_GET['back'])?$_GET['back']:'page-index'
  190. );
  191. }
  192. retj($ret,$title);
  193. break;
  194. case 'manifest':
  195. case 'pages':
  196. if(isset($_GET['id'])){
  197. if($_GET['id'] != 'emails'){
  198. $manifest = array();
  199. $files = array_diff(scandir(PATH_DATA.'/'.$_GET['id']),array('..', '.','.htaccess','version'));
  200. foreach($files as $k => $file){
  201. if(pathinfo(PATH_DATA.'/'.$_GET['id'].'/'.$file,PATHINFO_EXTENSION) == 'template'){
  202. array_push($manifest,array(
  203. 'name'=>basename($file,'.template'),
  204. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$file)
  205. ));
  206. }
  207. }
  208. retj(array(
  209. 'manifest'=>$manifest,
  210. 'type'=>$_GET['id']
  211. ));
  212. }else{
  213. retj(array(
  214. 'error'=>'Cannot return that manifest'
  215. ));
  216. }
  217. }else{
  218. retj(array(
  219. 'error'=>'Manifest ID not defined'
  220. ));
  221. }
  222. break;
  223. break;
  224. case 'template':
  225. if(isset($_GET['name'])){
  226. if($_GET['id'] != 'emails'){
  227. retj(array(
  228. 'template'=>file_get_contents(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template'),
  229. 'name'=>$_GET['name'],
  230. 'type'=>$_GET['id'],
  231. 'hash'=>md5_file(PATH_DATA.'/'.$_GET['id'].'/'.$_GET['name'].'.template')
  232. ));
  233. }else{
  234. retj(array(
  235. 'error'=>'Cannot return that type of template'
  236. ));
  237. }
  238. }else{
  239. retj(array(
  240. 'error'=>'Template name missing'
  241. ));
  242. }
  243. break;
  244. case 'action':
  245. switch($id){
  246. case 'login':
  247. $ret['state'] = array(
  248. 'data'=>array(
  249. 'type'=>'page',
  250. 'id'=>'login',
  251. )
  252. );
  253. if(isset($_GET['username'])&&isset($_GET['password'])){
  254. $key = login($_GET['username'],$_GET['password']);
  255. if($key){
  256. $_SESSION['username'] = $_GET['username'];
  257. }else{
  258. $ret['error'] = "Login failed. Username or Password didn't match.";
  259. }
  260. }else{
  261. $ret['error'] = "Please provide a valid username and password.";
  262. }
  263. retj($ret,$id);
  264. break;
  265. case 'register':
  266. $ret['state'] = array(
  267. 'data'=>array(
  268. 'type'=>'page',
  269. 'id'=>'register'
  270. )
  271. );
  272. if(is_valid('username')&& strpos($_GET['username'],' ') !== false&&is_valid('password')&&is_valid('password1')&&is_valid('email')&&is_valid('captcha')){
  273. if($_GET['password']==$_GET['password1']){
  274. if(compare_captcha($_GET['captcha'])){
  275. if(addUser($_GET['username'],$_GET['password'],$_GET['email'])){
  276. $key = login($_GET['username'],$_GET['password']);
  277. $_SESSION['username'] = $_GET['username'];
  278. sendMail('welcome','Welcome!',$_GET['email'],get('email'),array($_GET['username'],$_GET['password'],get('email')));
  279. }else{
  280. $ret['error'] = "Could not add user. ".$mysqli->error;
  281. }
  282. }else{
  283. $ret['error'] = "Captcha did not match.";
  284. }
  285. }else{
  286. $ret['error'] = "Passwords didn't match.";
  287. }
  288. }else{
  289. $ret['error'] = "Please fill in all the fields.";
  290. }
  291. retj($ret,$id);
  292. break;
  293. case 'project':
  294. back(true);
  295. $ret['state'] = array(
  296. 'data'=>array(
  297. 'type'=>'page',
  298. 'id'=>$id,
  299. )
  300. );
  301. if(isset($_GET['pid'])){
  302. $ret['error'] = 'Invalid Action';
  303. }elseif(is_valid('title')&&is_valid('description')){
  304. if(!newProject($_GET['title'],$_GET['description'])){
  305. $ret['error'] = 'Unable to create project.';
  306. }
  307. }else{
  308. $ret['error'] = 'Fill in all the details.';
  309. }
  310. retj($ret,$id);
  311. break;
  312. case 'issue':
  313. back(true);
  314. $ret['state'] = array(
  315. 'data'=>array(
  316. 'type'=>'page',
  317. 'id'=>$id,
  318. )
  319. );
  320. if(isset($_GET['pid'])){
  321. $ret['error'] = 'Invalid Action';
  322. }elseif(is_valid('title')&&is_valid('description')){
  323. if(!newIssue($_GET['title'],$_GET['description'])){
  324. $ret['error'] = 'Unable to create issue. ';
  325. }
  326. }else{
  327. $ret['error'] = 'Fill in all the details.';
  328. }
  329. retj($ret,$id);
  330. break;
  331. case 'message':
  332. back(true);
  333. if(isset($_GET['to'])&&isset($_GET['message'])){
  334. if($uid = userId($_GET['to'])){
  335. if(!personal_message($uid,$_GET['message'])){
  336. $ret['error'] = 'Could not send message';
  337. }
  338. }else{
  339. $ret['error'] = "That user doesn't exist";
  340. }
  341. }else{
  342. $ret['error'] = 'Empty details';
  343. }
  344. retj($ret,$id);
  345. break;
  346. case 'notifications':
  347. if($LOGGEDIN){
  348. if($res = query("SELECT count(m.id) as notifications,UNIX_TIMESTAMP(max(m.timestamp)) as timestamp FROM `messages` m JOIN `users` u ON u.id = m.to_id WHERE u.id = %d AND u.last_pm_check < m.timestamp;",array(userId($_SESSION['username'])))){
  349. $res = $res->fetch_assoc();
  350. $ret['count'] = $res['notifications'];
  351. $ret['timestamp'] = $res['timestamp'];
  352. }
  353. }
  354. retj($ret,$_GET['title']);
  355. break;
  356. case 'comment':
  357. if(isset($_GET['comment_type'])&&isset($_GET['comment_id'])&&isset($_GET['message'])){
  358. $cid = $_GET['comment_id'];
  359. $ret = array(
  360. 'state'=>stateObj($_GET['comment_type'],$cid)
  361. );
  362. switch($_GET['comment_type']){
  363. case 'project':
  364. if(!function_exists('project_comment')){
  365. $ret['error'] = "fn doesn't exist!";
  366. }
  367. if(!project_comment($cid,$_GET['message'])){
  368. $ret = array(
  369. 'error'=>'Could not comment on project'
  370. );
  371. }
  372. break;
  373. case 'issue':
  374. if(!function_exists('issue_comment')){
  375. $ret['error'] = "fn doesn't exist!";
  376. }
  377. if(!issue_comment($cid,$_GET['message'])){
  378. $ret = array(
  379. 'error'=>'Could not comment on project'
  380. );
  381. }
  382. break;
  383. default:
  384. $ret['error'] = 'Comment type not implemented';
  385. }
  386. }else{
  387. $ret['error'] = 'Missing comment paremeters';
  388. $ret['state'] = array(
  389. 'title'=>'error'
  390. );
  391. }
  392. retj($ret,$ret['state']['title']);
  393. break;
  394. case 'more':
  395. if(isset($_GET['of']) && isset($_GET['pid'])){
  396. $ret = array();
  397. $limit = array(
  398. isset($_GET['at'])?$_GET['at']:0,
  399. isset($_GET['amount'])?$_GET['amount']:10
  400. );
  401. $ret['messages'] = messages($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  402. $ret['params'] = array($_GET['pid'],$_GET['of'],$limit[0],$limit[1]);
  403. }else{
  404. $ret['error'] = 'Missing comment parameters';
  405. }
  406. retj($ret);
  407. break;
  408. default:
  409. retj(array(
  410. 'error'=>'Invalid action.'
  411. ));
  412. }
  413. break;
  414. default:
  415. retj(array(
  416. 'error'=>'Invalid type.'
  417. ));
  418. }
  419. }else{
  420. retj(array(
  421. 'error'=>'ID missing.'
  422. ));
  423. }
  424. }else{
  425. $_GET['type'] = '';
  426. retj(array(
  427. 'error'=>'Type missing.'
  428. ));
  429. }
  430. ?>