api.php 8.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282
  1. <?php
  2. /**
  3. * @name API
  4. * @author Philipp Maurer
  5. * @author Tobias Reich
  6. * @copyright 2014 by Philipp Maurer, Tobias Reich
  7. */
  8. @ini_set('max_execution_time', '200');
  9. @ini_set('post_max_size', '200M');
  10. @ini_set('upload_max_size', '200M');
  11. @ini_set('upload_max_filesize', '20M');
  12. @ini_set('max_file_uploads', '100');
  13. if (!empty($_POST['function'])||!empty($_GET['function'])) {
  14. session_start();
  15. define('LYCHEE', true);
  16. require('modules/db.php');
  17. require('modules/session.php');
  18. require('modules/settings.php');
  19. require('modules/upload.php');
  20. require('modules/album.php');
  21. require('modules/photo.php');
  22. require('modules/misc.php');
  23. if (file_exists('config.php')) require('config.php');
  24. else {
  25. /**
  26. * Installation Mode
  27. * Limited access to configure Lychee. Only available when the config.php file is missing.
  28. */
  29. switch ($_POST['function']) {
  30. case 'createConfig': if (isset($_POST['dbHost'])&&isset($_POST['dbUser'])&&isset($_POST['dbPassword'])&&isset($_POST['dbName']))
  31. echo createConfig($_POST['dbHost'], $_POST['dbUser'], $_POST['dbPassword'], $_POST['dbName']);
  32. break;
  33. default: echo 'Warning: No configuration!';
  34. break;
  35. }
  36. exit();
  37. }
  38. // Connect to DB
  39. $database = dbConnect();
  40. // Get Settings
  41. $settings = getSettings();
  42. // Security
  43. if (isset($_POST['albumID'])&&($_POST['albumID']==''||$_POST['albumID']<0)) exit('Error: Wrong parameter type for albumID!');
  44. if (isset($_POST['photoID'])&&$_POST['photoID']=='') exit('Error: Wrong parameter type for photoID!');
  45. foreach(array_keys($_POST) as $key) $_POST[$key] = mysqli_real_escape_string($database, urldecode($_POST[$key]));
  46. if (isset($_SESSION['login'])&&$_SESSION['login']==true) {
  47. /**
  48. * Admin Mode
  49. * Full access to Lychee. Only with correct password/session.
  50. */
  51. switch ($_POST['function']) {
  52. // Album Functions
  53. case 'getAlbums': echo json_encode(getAlbums(false));
  54. break;
  55. case 'getAlbum': if (isset($_POST['albumID']))
  56. echo json_encode(getAlbum($_POST['albumID']));
  57. break;
  58. case 'addAlbum': if (isset($_POST['title']))
  59. echo addAlbum($_POST['title']);
  60. break;
  61. case 'setAlbumTitle': if (isset($_POST['albumID'])&&isset($_POST['title']))
  62. echo setAlbumTitle($_POST['albumID'], $_POST['title']);
  63. break;
  64. case 'setAlbumDescription': if (isset($_POST['albumID'])&&isset($_POST['description']))
  65. echo setAlbumDescription($_POST['albumID'], $_POST['description']);
  66. break;
  67. case 'setAlbumPublic': if (isset($_POST['albumID']))
  68. echo setAlbumPublic($_POST['albumID'], $_POST['password']);
  69. break;
  70. case 'setAlbumPassword':if (isset($_POST['albumID'])&&isset($_POST['password']))
  71. echo setAlbumPassword($_POST['albumID'], $_POST['password']);
  72. break;
  73. case 'deleteAlbum': if (isset($_POST['albumID'])&&isset($_POST['delAll']))
  74. echo deleteAlbum($_POST['albumID'], $_POST['delAll']);
  75. break;
  76. // Photo Functions
  77. case 'getPhoto': if (isset($_POST['photoID'])&&isset($_POST['albumID']))
  78. echo json_encode(getPhoto($_POST['photoID'], $_POST['albumID']));
  79. break;
  80. case 'deletePhoto': if (isset($_POST['photoID']))
  81. echo deletePhoto($_POST['photoID']);
  82. break;
  83. case 'setAlbum': if (isset($_POST['photoID'])&&isset($_POST['albumID']))
  84. echo setAlbum($_POST['photoID'], $_POST['albumID']);
  85. break;
  86. case 'setPhotoTitle': if (isset($_POST['photoID'])&&isset($_POST['title']))
  87. echo setPhotoTitle($_POST['photoID'], $_POST['title']);
  88. break;
  89. case 'setPhotoStar': if (isset($_POST['photoID']))
  90. echo setPhotoStar($_POST['photoID']);
  91. break;
  92. case 'setPhotoPublic': if (isset($_POST['photoID'])&&isset($_POST['url']))
  93. echo setPhotoPublic($_POST['photoID'], $_POST['url']);
  94. break;
  95. case 'setPhotoDescription': if (isset($_POST['photoID'])&&isset($_POST['description']))
  96. echo setPhotoDescription($_POST['photoID'], $_POST['description']);
  97. break;
  98. // Add Functions
  99. case 'upload': if (isset($_FILES)&&isset($_POST['albumID']))
  100. echo upload($_FILES, $_POST['albumID']);
  101. break;
  102. case 'importUrl': if (isset($_POST['url'])&&isset($_POST['albumID']))
  103. echo importUrl($_POST['url'], $_POST['albumID']);
  104. break;
  105. case 'importServer': if (isset($_POST['albumID']))
  106. echo importServer($_POST['albumID']);
  107. break;
  108. // Search Function
  109. case 'search': if (isset($_POST['term']))
  110. echo json_encode(search($_POST['term']));
  111. break;
  112. // Session Function
  113. case 'init': echo json_encode(init('admin'));
  114. break;
  115. case 'login': if (isset($_POST['user'])&&isset($_POST['password']))
  116. echo login($_POST['user'], $_POST['password']);
  117. break;
  118. case 'logout': logout();
  119. break;
  120. // Settings
  121. case 'setLogin': if (isset($_POST['username'])&&isset($_POST['password']))
  122. echo setLogin($_POST['oldPassword'], $_POST['username'], $_POST['password']);
  123. break;
  124. case 'setSorting': if (isset($_POST['type'])&&isset($_POST['order']))
  125. echo setSorting($_POST['type'], $_POST['order']);
  126. break;
  127. // Miscellaneous
  128. case 'update': echo update();
  129. default: if (isset($_GET['function'])&&$_GET['function']=='getAlbumArchive'&&isset($_GET['albumID']))
  130. // Album Archive
  131. getAlbumArchive($_GET['albumID']);
  132. else if (isset($_GET['function'])&&$_GET['function']=='update')
  133. // Update Lychee
  134. echo update();
  135. else
  136. exit('Error: Function not found! Please check the spelling of the called function.');
  137. break;
  138. }
  139. } else {
  140. /**
  141. * Public Mode
  142. * Access to view all public folders and photos in Lychee.
  143. */
  144. switch ($_POST['function']) {
  145. // Album Functions
  146. case 'getAlbums': echo json_encode(getAlbums(true));
  147. break;
  148. case 'getAlbum': if (isset($_POST['albumID'])&&isset($_POST['password'])) {
  149. if (isAlbumPublic($_POST['albumID'])) {
  150. // Album Public
  151. if (checkAlbumPassword($_POST['albumID'], $_POST['password']))
  152. echo json_encode(getAlbum($_POST['albumID']));
  153. else
  154. echo 'Warning: Wrong password!';
  155. } else {
  156. // Album Private
  157. echo 'Warning: Album private!';
  158. }
  159. }
  160. break;
  161. case 'checkAlbumAccess':if (isset($_POST['albumID'])&&isset($_POST['password'])) {
  162. if (isAlbumPublic($_POST['albumID'])) {
  163. // Album Public
  164. if (checkAlbumPassword($_POST['albumID'], $_POST['password']))
  165. echo true;
  166. else
  167. echo false;
  168. } else {
  169. // Album Private
  170. echo false;
  171. }
  172. }
  173. break;
  174. // Photo Functions
  175. case 'getPhoto': if (isset($_POST['photoID'])&&isset($_POST['albumID'])&&isset($_POST['password'])) {
  176. if (isPhotoPublic($_POST['photoID'], $_POST['password']))
  177. echo json_encode(getPhoto($_POST['photoID'], $_POST['albumID']));
  178. else
  179. echo 'Warning: Wrong password!';
  180. }
  181. break;
  182. // Session Functions
  183. case 'init': echo json_encode(init('public'));
  184. break;
  185. case 'login': if (isset($_POST['user'])&&isset($_POST['password']))
  186. echo login($_POST['user'], $_POST['password']);
  187. break;
  188. // Miscellaneous
  189. default: if (isset($_GET['function'])&&$_GET['function']=='getAlbumArchive'&&isset($_GET['albumID'])&&isset($_GET['password'])) {
  190. if (isAlbumPublic($_GET['albumID'])) {
  191. // Album Public
  192. if (checkAlbumPassword($_GET['albumID'], $_GET['password']))
  193. getAlbumArchive($_GET['albumID']);
  194. else
  195. echo 'Warning: Wrong password!';
  196. } else {
  197. // Album Private
  198. echo 'Warning: Album private or not downloadable!';
  199. }
  200. } else {
  201. exit('Error: Function not found! Please check the spelling of the called function.');
  202. }
  203. break;
  204. }
  205. }
  206. } else {
  207. exit('Error: No permission!');
  208. }
  209. ?>