api.php 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317
  1. <?php
  2. /**
  3. * @name API
  4. * @author Philipp Maurer
  5. * @author Tobias Reich
  6. * @copyright 2014 by Philipp Maurer, Tobias Reich
  7. */
  8. @ini_set('max_execution_time', '200');
  9. @ini_set('post_max_size', '200M');
  10. @ini_set('upload_max_size', '200M');
  11. @ini_set('upload_max_filesize', '20M');
  12. @ini_set('max_file_uploads', '100');
  13. if (!empty($_POST['function'])||!empty($_GET['function'])) {
  14. session_start();
  15. define('LYCHEE', true);
  16. require('modules/db.php');
  17. require('modules/session.php');
  18. require('modules/settings.php');
  19. require('modules/upload.php');
  20. require('modules/album.php');
  21. require('modules/photo.php');
  22. require('modules/misc.php');
  23. if (file_exists('config.php')) require('config.php');
  24. else {
  25. /**
  26. * Installation Mode
  27. * Limited access to configure Lychee. Only available when the config.php file is missing.
  28. */
  29. switch ($_POST['function']) {
  30. case 'createConfig': if (isset($_POST['dbHost'])&&isset($_POST['dbUser'])&&isset($_POST['dbPassword'])&&isset($_POST['dbName']))
  31. echo createConfig($_POST['dbHost'], $_POST['dbUser'], $_POST['dbPassword'], $_POST['dbName']);
  32. break;
  33. default: echo 'Warning: No configuration!';
  34. break;
  35. }
  36. exit();
  37. }
  38. // Connect to DB
  39. $database = dbConnect();
  40. // Get Settings
  41. $settings = getSettings();
  42. // Escape
  43. foreach(array_keys($_POST) as $key) $_POST[$key] = mysqli_real_escape_string($database, urldecode($_POST[$key]));
  44. foreach(array_keys($_GET) as $key) $_GET[$key] = mysqli_real_escape_string($database, urldecode($_GET[$key]));
  45. // Validate parameters
  46. if (isset($_POST['albumIDs'])&&preg_match('/^[0-9\,]{1,}$/', $_POST['albumIDs'])!==1) exit('Error: Wrong parameter type for albumIDs!');
  47. if (isset($_POST['photoIDs'])&&preg_match('/^[0-9\,]{1,}$/', $_POST['photoIDs'])!==1) exit('Error: Wrong parameter type for photoIDs!');
  48. if (isset($_POST['albumID'])&&preg_match('/^[0-9sf]{1,}$/', $_POST['albumID'])!==1) exit('Error: Wrong parameter type for albumID!');
  49. if (isset($_POST['photoID'])&&preg_match('/^[0-9]{14}$/', $_POST['photoID'])!==1) exit('Error: Wrong parameter type for photoID!');
  50. if (isset($_SESSION['login'])&&$_SESSION['login']==true) {
  51. /**
  52. * Admin Mode
  53. * Full access to Lychee. Only with correct password/session.
  54. */
  55. switch ($_POST['function']) {
  56. // Album Functions
  57. case 'getAlbums': echo json_encode(getAlbums(false));
  58. break;
  59. case 'getAlbum': if (isset($_POST['albumID']))
  60. echo json_encode(getAlbum($_POST['albumID']));
  61. break;
  62. case 'addAlbum': if (isset($_POST['title']))
  63. echo addAlbum($_POST['title']);
  64. break;
  65. case 'setAlbumTitle': if (isset($_POST['albumIDs'])&&isset($_POST['title']))
  66. echo setAlbumTitle($_POST['albumIDs'], $_POST['title']);
  67. break;
  68. case 'setAlbumDescription': if (isset($_POST['albumID'])&&isset($_POST['description']))
  69. echo setAlbumDescription($_POST['albumID'], $_POST['description']);
  70. break;
  71. case 'setAlbumPublic': if (isset($_POST['albumID']))
  72. if (!isset($_POST['password'])) $_POST['password'] = '';
  73. echo setAlbumPublic($_POST['albumID'], $_POST['password']);
  74. break;
  75. case 'setAlbumPassword':if (isset($_POST['albumID'])&&isset($_POST['password']))
  76. echo setAlbumPassword($_POST['albumID'], $_POST['password']);
  77. break;
  78. case 'deleteAlbum': if (isset($_POST['albumIDs']))
  79. echo deleteAlbum($_POST['albumIDs']);
  80. break;
  81. // Photo Functions
  82. case 'getPhoto': if (isset($_POST['photoID'])&&isset($_POST['albumID']))
  83. echo json_encode(getPhoto($_POST['photoID'], $_POST['albumID']));
  84. break;
  85. case 'deletePhoto': if (isset($_POST['photoIDs']))
  86. echo deletePhoto($_POST['photoIDs']);
  87. break;
  88. case 'setAlbum': if (isset($_POST['photoIDs'])&&isset($_POST['albumID']))
  89. echo setAlbum($_POST['photoIDs'], $_POST['albumID']);
  90. break;
  91. case 'setPhotoTitle': if (isset($_POST['photoIDs'])&&isset($_POST['title']))
  92. echo setPhotoTitle($_POST['photoIDs'], $_POST['title']);
  93. break;
  94. case 'setPhotoStar': if (isset($_POST['photoIDs']))
  95. echo setPhotoStar($_POST['photoIDs']);
  96. break;
  97. case 'setPhotoPublic': if (isset($_POST['photoID'])&&isset($_POST['url']))
  98. echo setPhotoPublic($_POST['photoID'], $_POST['url']);
  99. break;
  100. case 'setPhotoDescription': if (isset($_POST['photoID'])&&isset($_POST['description']))
  101. echo setPhotoDescription($_POST['photoID'], $_POST['description']);
  102. break;
  103. // Add Functions
  104. case 'upload': if (isset($_FILES)&&isset($_POST['albumID']))
  105. echo upload($_FILES, $_POST['albumID']);
  106. break;
  107. case 'importUrl': if (isset($_POST['url'])&&isset($_POST['albumID']))
  108. echo importUrl($_POST['url'], $_POST['albumID']);
  109. break;
  110. case 'importServer': if (isset($_POST['albumID']))
  111. echo importServer($_POST['albumID']);
  112. break;
  113. // Search Function
  114. case 'search': if (isset($_POST['term']))
  115. echo json_encode(search($_POST['term']));
  116. break;
  117. // Session Function
  118. case 'init': echo json_encode(init('admin'));
  119. break;
  120. case 'login': if (isset($_POST['user'])&&isset($_POST['password']))
  121. echo login($_POST['user'], $_POST['password']);
  122. break;
  123. case 'logout': logout();
  124. break;
  125. // Settings
  126. case 'setLogin': if (isset($_POST['username'])&&isset($_POST['password']))
  127. if (!isset($_POST['oldPassword'])) $_POST['oldPassword'] = '';
  128. echo setLogin($_POST['oldPassword'], $_POST['username'], $_POST['password']);
  129. break;
  130. case 'setSorting': if (isset($_POST['type'])&&isset($_POST['order']))
  131. echo setSorting($_POST['type'], $_POST['order']);
  132. break;
  133. // Miscellaneous
  134. case 'update': echo update();
  135. default: if (isset($_GET['function'])&&$_GET['function']=='getAlbumArchive'&&isset($_GET['albumID']))
  136. // Album Download
  137. getAlbumArchive($_GET['albumID']);
  138. else if (isset($_GET['function'])&&$_GET['function']=='getPhotoArchive'&&isset($_GET['photoID']))
  139. // Photo Download
  140. getPhotoArchive($_GET['photoID']);
  141. else if (isset($_GET['function'])&&$_GET['function']=='update')
  142. // Update Lychee
  143. echo update();
  144. else
  145. // Function unknown
  146. exit('Error: Function not found! Please check the spelling of the called function.');
  147. break;
  148. }
  149. } else {
  150. /**
  151. * Public Mode
  152. * Access to view all public folders and photos in Lychee.
  153. */
  154. switch ($_POST['function']) {
  155. // Album Functions
  156. case 'getAlbums': echo json_encode(getAlbums(true));
  157. break;
  158. case 'getAlbum': if (isset($_POST['albumID'])&&isset($_POST['password'])) {
  159. if (isAlbumPublic($_POST['albumID'])) {
  160. // Album Public
  161. if (checkAlbumPassword($_POST['albumID'], $_POST['password']))
  162. echo json_encode(getAlbum($_POST['albumID']));
  163. else
  164. echo 'Warning: Wrong password!';
  165. } else {
  166. // Album Private
  167. echo 'Warning: Album private!';
  168. }
  169. }
  170. break;
  171. case 'checkAlbumAccess':if (isset($_POST['albumID'])&&isset($_POST['password'])) {
  172. if (isAlbumPublic($_POST['albumID'])) {
  173. // Album Public
  174. if (checkAlbumPassword($_POST['albumID'], $_POST['password']))
  175. echo true;
  176. else
  177. echo false;
  178. } else {
  179. // Album Private
  180. echo false;
  181. }
  182. }
  183. break;
  184. // Photo Functions
  185. case 'getPhoto': if (isset($_POST['photoID'])&&isset($_POST['albumID'])&&isset($_POST['password'])) {
  186. if (isPhotoPublic($_POST['photoID'], $_POST['password']))
  187. echo json_encode(getPhoto($_POST['photoID'], $_POST['albumID']));
  188. else
  189. echo 'Warning: Wrong password!';
  190. }
  191. break;
  192. // Session Functions
  193. case 'init': echo json_encode(init('public'));
  194. break;
  195. case 'login': if (isset($_POST['user'])&&isset($_POST['password']))
  196. echo login($_POST['user'], $_POST['password']);
  197. break;
  198. // Miscellaneous
  199. default: if (isset($_GET['function'])&&$_GET['function']=='getAlbumArchive'&&isset($_GET['albumID'])&&isset($_GET['password'])) {
  200. // Album Download
  201. if (isAlbumPublic($_GET['albumID'])) {
  202. // Album Public
  203. if (checkAlbumPassword($_GET['albumID'], $_GET['password']))
  204. getAlbumArchive($_GET['albumID']);
  205. else
  206. exit('Warning: Wrong password!');
  207. } else {
  208. // Album Private
  209. exit('Warning: Album private or not downloadable!');
  210. }
  211. } else if (isset($_GET['function'])&&$_GET['function']=='getPhotoArchive'&&isset($_GET['photoID'])&&isset($_GET['password'])) {
  212. // Photo Download
  213. if (isPhotoPublic($_GET['photoID'], $_GET['password']))
  214. // Photo Public
  215. getPhotoArchive($_GET['photoID']);
  216. else
  217. // Photo Private
  218. exit('Warning: Photo private or not downloadable!');
  219. } else {
  220. // Function unknown
  221. exit('Error: Function not found! Please check the spelling of the called function.');
  222. }
  223. break;
  224. }
  225. }
  226. } else {
  227. exit('Error: No permission!');
  228. }
  229. ?>