Settings.php 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202
  1. <?php
  2. namespace Lychee\Modules;
  3. final class Settings {
  4. private static $cache = null;
  5. public static function get() {
  6. if (self::$cache) return self::$cache;
  7. // Execute query
  8. $query = Database::prepare(Database::get(), "SELECT * FROM ?", array(LYCHEE_TABLE_SETTINGS));
  9. $settings = Database::get()->query($query);
  10. // Add each to return
  11. while ($setting = $settings->fetch_object()) $return[$setting->key] = $setting->value;
  12. // Convert plugins to array
  13. $return['plugins'] = explode(';', $return['plugins']);
  14. self::$cache = $return;
  15. return $return;
  16. }
  17. private static function set($key, $value, $row = false) {
  18. if ($row===false) {
  19. $query = Database::prepare(Database::get(), "UPDATE ? SET value = '?' WHERE `key` = '?'", array(LYCHEE_TABLE_SETTINGS, $value, $key));
  20. } elseif ($row===true) {
  21. // Do not prepare $value because it has already been escaped or is a true statement
  22. $query = Database::prepare(Database::get(), "UPDATE ? SET value = '$value' WHERE `key` = '?'", array(LYCHEE_TABLE_SETTINGS, $key));
  23. } else {
  24. return false;
  25. }
  26. $result = Database::get()->query($query);
  27. if (!$result) return false;
  28. return true;
  29. }
  30. public static function setLogin($oldPassword = '', $username, $password) {
  31. if ($oldPassword===self::get()['password']||self::get()['password']===crypt($oldPassword, self::get()['password'])) {
  32. // Save username
  33. if (self::setUsername($username)!==true) exit('Error: Updating username failed!');
  34. // Save password
  35. if (self::setPassword($password)!==true) exit('Error: Updating password failed!');
  36. return true;
  37. }
  38. exit('Error: Current password entered incorrectly!');
  39. }
  40. private static function setUsername($username) {
  41. // Check dependencies
  42. Validator::required(isset($username), __METHOD__);
  43. // Hash username
  44. $username = getHashedString($username);
  45. // Execute query
  46. // Do not prepare $username because it is hashed and save
  47. // Preparing (escaping) the username would destroy the hash
  48. if (self::set('username', $username, true)===false) {
  49. Log::error(__METHOD__, __LINE__, Database::get()->error);
  50. return false;
  51. }
  52. return true;
  53. }
  54. private static function setPassword($password) {
  55. // Check dependencies
  56. Validator::required(isset($password), __METHOD__);
  57. // Hash password
  58. $password = getHashedString($password);
  59. // Do not prepare $password because it is hashed and save
  60. // Preparing (escaping) the password would destroy the hash
  61. if (self::set('password', $password, true)===false) {
  62. Log::error(__METHOD__, __LINE__, Database::get()->error);
  63. return false;
  64. }
  65. return true;
  66. }
  67. public static function setDropboxKey($dropboxKey) {
  68. if (strlen($dropboxKey)<1||strlen($dropboxKey)>50) {
  69. Log::notice(__METHOD__, __LINE__, 'Dropbox key is either too short or too long');
  70. return false;
  71. }
  72. if (self::set('dropboxKey', $dropboxKey)===false) {
  73. Log::error(__METHOD__, __LINE__, Database::get()->error);
  74. return false;
  75. }
  76. return true;
  77. }
  78. public static function setSortingPhotos($type, $order) {
  79. $sorting = 'ORDER BY ';
  80. // Set row
  81. switch ($type) {
  82. case 'id': $sorting .= 'id'; break;
  83. case 'title': $sorting .= 'title'; break;
  84. case 'description': $sorting .= 'description'; break;
  85. case 'public': $sorting .= 'public'; break;
  86. case 'type': $sorting .= 'type'; break;
  87. case 'star': $sorting .= 'star'; break;
  88. case 'takestamp': $sorting .= 'takestamp'; break;
  89. default: exit('Error: Unknown type for sorting!');
  90. }
  91. $sorting .= ' ';
  92. // Set order
  93. switch ($order) {
  94. case 'ASC': $sorting .= 'ASC'; break;
  95. case 'DESC': $sorting .= 'DESC'; break;
  96. default: exit('Error: Unknown order for sorting!');
  97. }
  98. // Do not prepare $sorting because it is a true statement
  99. // Preparing (escaping) the sorting would destroy it
  100. // $sorting is save and can't contain user-input
  101. if (self::set('sortingPhotos', $sorting, true)===false) {
  102. Log::error(__METHOD__, __LINE__, Database::get()->error);
  103. return false;
  104. }
  105. return true;
  106. }
  107. public static function setSortingAlbums($type, $order) {
  108. $sorting = 'ORDER BY ';
  109. // Set row
  110. switch ($type) {
  111. case 'id': $sorting .= 'id'; break;
  112. case 'title': $sorting .= 'title'; break;
  113. case 'description': $sorting .= 'description'; break;
  114. case 'public': $sorting .= 'public'; break;
  115. default: exit('Error: Unknown type for sorting!');
  116. }
  117. $sorting .= ' ';
  118. // Set order
  119. switch ($order) {
  120. case 'ASC': $sorting .= 'ASC'; break;
  121. case 'DESC': $sorting .= 'DESC'; break;
  122. default: exit('Error: Unknown order for sorting!');
  123. }
  124. // Do not prepare $sorting because it is a true statement
  125. // Preparing (escaping) the sorting would destroy it
  126. // $sorting is save and can't contain user-input
  127. if (self::set('sortingAlbums', $sorting, true)===false) {
  128. Log::error(__METHOD__, __LINE__, Database::get()->error);
  129. return false;
  130. }
  131. return true;
  132. }
  133. }
  134. ?>