index.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322
  1. <?php
  2. header('Content-type: application/json');
  3. header('Access-Control-Allow-Origin: *');
  4. require_once("../../header.php");
  5. if(!isset($_GET['action'])){
  6. $opts = getopt('a:',Array('action:'));
  7. $_GET['action'] = isset($opts['action'])?$opts['action']:(isset($opts['a'])?$opts['a']:'');
  8. }
  9. $u = is_logged_in();
  10. switch($_GET['action']){
  11. case 'test':
  12. //$u or die();
  13. //print_r(atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'topic','#omnimaga'));
  14. echo mkpasswd('root');
  15. die();
  16. break;
  17. case 'login':
  18. isset($_GET['username']) && isset($_GET['password']) or die('{"code":2,"message":"Missing username and/or password"}');
  19. isset($_GET['type']) or die('{"code":2,"message":"Missing user type"}');
  20. $r = login($_GET['username'],$_GET['password'],$_GET['type']);
  21. if($r !== true){
  22. die('{"code":2,"message":"'.$r.'"}');
  23. }else{
  24. die('{"code":0}');
  25. }
  26. break;
  27. case 'verify':
  28. isset($_GET['token']) or die('{"code":1,"message":"No token set"}');
  29. $r = verify($_GET['token']);
  30. if($r !== true){
  31. die('{"code":2,"message":"'.$r.'"}');
  32. }
  33. die('{"code":0,"message":"'.$r.'"}');
  34. break;
  35. case 'logout':
  36. logout();
  37. die('{"code":0}');
  38. break;
  39. case 'get-memos':
  40. $u or die('{"code":1,"message":"You have been logged out"}');
  41. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  42. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','list');
  43. if($res[0]){
  44. $res = explode('&#10;',$res[1]);
  45. $memos = Array();
  46. foreach($res as $k => $row){
  47. if($k != 0 && $k != 1){
  48. $row = preg_split('/^-\s/',$row);
  49. if(isset($row[1])){
  50. $row = explode(' ',$row[1]);
  51. $memo = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','read',Array($row[0]));
  52. $memo = explode('&#10;',$memo[1]);
  53. array_push($memos,Array(
  54. 'id'=>$row[0],
  55. 'from'=>$row[2],
  56. 'date'=>Array(
  57. 'month'=>$row[4],
  58. 'day'=>$row[5],
  59. 'time'=>$row[6],
  60. 'year'=>$row[7]
  61. ),
  62. 'body'=>$memo[2]
  63. ));
  64. }
  65. }
  66. }
  67. die('{"code":0,"memos":'.json_encode($memos).'}');
  68. }else{
  69. die('{"code":1,"message":"Cannot fetch memos"}');
  70. }
  71. break;
  72. case 'get-news':
  73. $u or die('{"code":1,"message":"You have been logged out"}');
  74. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  75. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'InfoServ','list');
  76. if($res[0]){
  77. $res = explode('&#10;',$res[1]);
  78. $news = Array();
  79. foreach($res as $k => $row){
  80. if($k != count($res)-1){
  81. array_push($news,Array(
  82. 'id'=>preg_replace('/^(\d)+:.+$/i','\1',$row),
  83. 'title'=>preg_replace('/^\d+: \[(.+)\] .+/i','\1',$row),
  84. 'from'=>preg_replace('/^\d+: \[.+\] by (.+) at \d\d?:\d\d? on (\d\d)\/\d\d\/\d\d\d\d: .+/i','\1',$row),
  85. 'date'=>Array(
  86. 'time'=>preg_replace('/^\d+: \[.+\] by .+ at (\d\d?:\d\d?) on .+/','\1',$row),
  87. 'day'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on (\d\d)\/\d\d\/\d\d\d\d: .+/i','\1',$row),
  88. 'month'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/(\d\d)\/\d\d\d\d: .+/i','\1',$row),
  89. 'year'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/\d\d\/(\d\d\d\d): .+/i','\1',$row)
  90. ),
  91. 'body'=>preg_replace('/^\d+: \[.+\] by .+ at \d\d?:\d\d? on \d\d\/\d\d\/\d\d\d\d: (.+)/i','\1',$row)
  92. ));
  93. }
  94. }
  95. die('{"code":0,"news":'.json_encode($news).'}');
  96. }else{
  97. die('{"code":1,"message":"Cannot fetch news"}');
  98. }
  99. break;
  100. case 'get-channels':
  101. $u or die('{"code":1,"message":"You have been logged out"}');
  102. $u['type'] = 'user' && isset($_COOKIE['user']) && isset($_SESSION['password']) or die('{"code":0}');
  103. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'NickServ','listchans');
  104. if($res[0]){
  105. $res = explode('&#10;',$res[1]);
  106. $channels = Array();
  107. foreach($res as $k => $row){
  108. if($k != count($res)-1){
  109. $flags_list = str_split(preg_replace('/^Access flag\(s\) \+(.+) in .+$/i','\1',$row));
  110. $flags = array();
  111. foreach($flags_list as $kk => $flag){
  112. switch($flag){
  113. case 'v':$name='Voice';break;
  114. case 'V':$name='Automatic voice';break;
  115. case 'h':$name='Halfop';break;
  116. case 'H':$name='Automatic Halfop';break;
  117. case 'o':$name='Op';break;
  118. case 'O':$name='Automatic Op';break;
  119. case 'a':$name='Admin';break;
  120. case 'q':$name='Owner';break;
  121. case 's':$name='Set';break;
  122. case 'i':$name='Invite/Getkey';break;
  123. case 'r':$name='Kick/Ban';break;
  124. case 'R':$name='Recover/Clear';break;
  125. case 'f':$name='Modify access lists';break;
  126. case 't':$name='Topic';break;
  127. case 'A':$name='View access lists';break;
  128. case 'F':$name='Founder';break;
  129. case 'b':$name='Banned';break;
  130. default:$name=$flag;
  131. }
  132. array_push($flags,array(
  133. 'flag'=>$flag,
  134. 'name'=>$name
  135. ));
  136. }
  137. $name = preg_replace('/^Access flag\(s\) \+.+ in (.+)$/i','\1',$row);
  138. array_push($channels,Array(
  139. 'name'=>$name,
  140. 'flags'=>$flags
  141. ));
  142. }
  143. }
  144. die('{"code":0,"channels":'.json_encode($channels).'}');
  145. }else{
  146. die('{"code":1,"message":"Cannot fetch channels"}');
  147. }
  148. break;
  149. case 'send-memo':
  150. $u or die('{"code":1,"message":"You have been logged out"}');
  151. isset($_GET['to']) && isset($_GET['message']) or die('{"code":1,"message":"No message or user entered"}');
  152. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','send',Array($_GET['to'],$_GET['message']));
  153. if($res[0]){
  154. if(substr($res[1],-19) == ' is not registered.'){
  155. die('{"code":1,"message":"User '.$_GET['to'].' does not exist"}');
  156. }else{
  157. die('{"code":0,"message":"Memo Sent"}');
  158. }
  159. }else{
  160. die('{"code":1,"message":"Cannot send memo: '+$res[1]+'"}');
  161. }
  162. break;
  163. case 'delete-memo':
  164. $u or die('{"code":1,"message":"You have been logged out"}');
  165. isset($_GET['id']) or die('{"code":1,"message":"No id given"}');
  166. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$_COOKIE['user'],$_SESSION['password'],'MemoServ','delete',Array($_GET['id']));
  167. if(!$res[0]){
  168. die('{"code":1,"message":"Cannot send memo: '+$res[1]+'"}');
  169. }
  170. die('{"code":0}');
  171. break;
  172. case 'persona-login':
  173. if($u){
  174. $register = true;
  175. }else{
  176. $register = false;
  177. }
  178. $url = get_conf('persona-endpoint');
  179. $assert = filter_input(
  180. INPUT_POST,
  181. 'assertion',
  182. FILTER_UNSAFE_RAW,
  183. FILTER_FLAG_STRIP_LOW|FILTER_FLAG_STRIP_HIGH
  184. );
  185. $params = 'assertion='.urlencode($assert).'&audience='.urlencode(get_conf('persona-audience'));
  186. $ch = curl_init();
  187. $options = array(
  188. CURLOPT_URL => $url,
  189. CURLOPT_RETURNTRANSFER => TRUE,
  190. CURLOPT_POST => 2,
  191. CURLOPT_SSL_VERIFYPEER => 0,
  192. CURLOPT_SSL_VERIFYHOST => 2,
  193. CURLOPT_POSTFIELDS => $params
  194. );
  195. curl_setopt_array($ch, $options);
  196. $result = curl_exec($ch);
  197. curl_close($ch);
  198. $result = json_decode($result);
  199. if($result->status == 'okay'){
  200. if($register && !add_email($u['id'],$result->email)){
  201. die('{"code":1,"message":"Failed to add email '.$result->email.' to user '.$u['nick'].'"}');
  202. }elseif(!$register && !$u = get_user_for_email($result->email)){
  203. die('{"code":1,"message":"Email does not match any users"}');
  204. }
  205. setcookie('personaUser',$result->email,null,'/');
  206. $pass = null;
  207. if(isset($_SESSION['password']) && !is_null($_SESSION['password']) && $_SESSION['password'] != ''){
  208. $pass = $_SESSION['password'];
  209. }
  210. $types = get_user_types($u['id']);
  211. $r = login($u['nick'],$pass,'persona',$types[0]);
  212. if($r !== true){
  213. if($r){
  214. die('{"code":2,"message":"'.$r.'"}');
  215. }else{
  216. die('{"code":2}');
  217. }
  218. }else{
  219. die('{"code":0,"assertion":'.json_encode($result).'}');
  220. }
  221. }else{
  222. die('{"code":1,"message":"'.$result->reason.'"}');
  223. }
  224. break;
  225. case 'persona-remove':
  226. $u or die('{"code":1,"message":"You have been logged out"}');
  227. isset($_GET['id']) or die('{"code":1,"message":"No ID set"}');
  228. if(!remove_email($u['id'],$_GET['id'],true)){
  229. die('{"code":1,"message":"Could not remove email address"}');
  230. }
  231. die('{"code":0}');
  232. break;
  233. case '2-factor-register':
  234. $r = register_token();
  235. if($r !== true){
  236. die('{"code":1,"message":"'.$r.'"}');
  237. }
  238. die('{"code":0}');
  239. break;
  240. case '2-factor-delete':
  241. $u or die('{"code":1,"message":"You have been logged out"}');
  242. $r = delete_token($u['id']);
  243. if($r !== true){
  244. die('{"code":1,"message":"'.$r.'"}');
  245. }
  246. die('{"code":0,"message":"2-factor disabled."}');
  247. break;
  248. case 'ping':
  249. $u or die('{"code":1,"message":"You have been logged out"}');
  250. die('{"code":0}');
  251. break;
  252. case 'newpass':
  253. $u && isset($_GET['password']) && isset($_GET['newpass']) or die('{"code":2,"message":"Make sure that everything is filled in. Try reloading if it is."}');
  254. $u['password'] == mkpasswd($_GET['password'],$u['salt']) or die('{"code":2,"message":"Invalid password"}');
  255. $u['api_key'] == $_COOKIE['key'] or die('{"code":3,"message":"Not Logged in to use '.$u['nick'].' with key '.$u['api_key'].' != '.$_COOKIE['key'].'."}');
  256. if($_COOKIE['type'] == 'user'){
  257. $res = atheme_command(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),USER_IP,$u['nick'],$_GET['password'],'NickServ','set',Array('password',trim($_GET['newpass'])));
  258. if($res[0] === false){
  259. die('{"code":2,"message":"Could not update password with nickserv: '.$res[1].'"}');
  260. }else{
  261. $_SESSION['password'] = $_GET['newpass'];
  262. }
  263. }
  264. query("UPDATE users u SET u.password='%s' WHERE u.id=%d",Array(mkpasswd($_GET['newpass']),$u['id']));
  265. die('{"code":0}');
  266. break;
  267. case 'sync-pass':
  268. $u && isset($_SESSION['password'])or die('{"code":2,"message":"Make sure that everything is filled in. Try reloading if it is."}');
  269. $u['api_key'] == $_COOKIE['key'] or die('{"code":3,"message":"Not Logged in to use '.$u['nick'].' with key '.$u['api_key'].' != '.$_COOKIE['key'].'."}');
  270. $_COOKIE['type'] == 'user' or die('{"code":3,"message":"Must be logged in with type user to sync pass"}');
  271. $res = atheme_login(get_conf('xmlrpc-server'),get_conf('xmlrpc-port'),get_conf('xmlrpc-path'),$u['nick'],$_SESSION['password']);
  272. if($res[0] === false){
  273. die('{"code":2,"message":"Could not verify with nickserv: '.$res[1].'"}');
  274. }
  275. query("UPDATE users u SET u.password='%s' WHERE u.id=%d",Array(mkpasswd($_SESSION['password']),$u['id']));
  276. die('{"code":0,"message":"Nickserv password synchronized with main account"}');
  277. break;
  278. case 'role':
  279. $u && isset($_GET['type']) or die('{"code":2,"message":"Make sure that everything is filled in. Try reloading if it is."}');
  280. setcookie('type',$_GET['type'],null,'/');
  281. die('{"code":0}');
  282. break;
  283. case 'user':
  284. $u or die('{"code":10,"message":"Not logged in"}');
  285. isset($_GET['id']) or die('{"code":2,"message":"No user set."}');
  286. isset($_GET['email']) or die('{"code":2,"message":"No email set."}');
  287. isset($_GET['real_name']) or die('{"code":2,"message":"No real name set."}');
  288. isset($_GET['nick']) or die('{"code":2,"message":"No nick set."}');
  289. $user = get_user_from_id_obj($_GET['id']) or die('{"code":2,"message":"User with id '.$_GET['id'].' does not exist. You should reload the page."}');
  290. if($u['id'] == $user['id']){
  291. setcookie('user',$_GET['nick'],null,'/');
  292. }
  293. query("UPDATE users u SET u.nick='%s', u.real_name='%s', u.email='%s' WHERE u.id=%d",Array($_GET['nick'],$_GET['real_name'],$_GET['email'],$_GET['id'])) or die('{"code":2,"message":"Unable to update user"}');
  294. die(ircrehash());
  295. break;
  296. case 'oper':
  297. $u or die('{"code":10,"message":"Not logged in"}');
  298. isset($_GET['id']) or die('{"code":2,"message":"No user set."}');
  299. isset($_GET['nick']) or die('{"code":2,"message":"No nick set."}');
  300. isset($_GET['swhois']) or die('{"code":2,"message":"No profile set."}');
  301. $oper = get_oper_from_id_obj($_GET['id']) or die('{"code":2,"message":"Oper with id '.$_GET['id'].' does not exist. You should reload the page."}');
  302. if(isset($_GET['password']) && $_GET['password'] != ""){
  303. query("UPDATE opers o SET o.nick='%s', o.swhois='%s', o.password='%s', o.password_type_id=2 WHERE o.id=%d",Array($_GET['nick'],$_GET['swhois'],mkpasswd($_GET['password']),$_GET['id'])) or die('{"code":2,"message":"Unable to update oper"}');
  304. }else{
  305. query("UPDATE opers o SET o.nick='%s', o.swhois='%s' WHERE o.id=%d",Array($_GET['nick'],$_GET['swhois'],$_GET['id'])) or die('{"code":2,"message":"Unable to update oper"}');
  306. }
  307. die(ircrehash());
  308. break;
  309. case 'config':
  310. foreach($_GET as $key => $val){
  311. set_conf($key,$val,get_conf_type($key)) or die('{"code":1,"message":"Failed to update setting: '.$key.' with value: '.$val.'"}');
  312. }
  313. die('{"code":0}');
  314. break;
  315. case 'rehash':
  316. $u or die('{"code":10,"message":"Not logged in"}');
  317. die(ircrehash());
  318. break;
  319. default:
  320. die('{"code":1,"message":"Invalid Action '.$_GET['action'].'"}');
  321. }
  322. ?>