json_api.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308
  1. <?php
  2. require_once 'inc/prerequisites.inc.php';
  3. error_reporting(E_ALL);
  4. if (isset($_SESSION['mailcow_cc_role']) || isset($_SESSION['pending_mailcow_cc_username'])) {
  5. if (isset($_GET['action']) && isset($_GET['cat'])) {
  6. $category = filter_input(INPUT_GET, 'cat', FILTER_SANITIZE_STRING);
  7. $action = filter_input(INPUT_GET, 'action', FILTER_SANITIZE_STRING);
  8. if (isset($_GET['object'])) {
  9. $object = filter_input(INPUT_GET, 'object', FILTER_SANITIZE_STRING);
  10. }
  11. switch ($action) {
  12. case "get":
  13. switch ($category) {
  14. case "domain":
  15. switch ($object) {
  16. case "all":
  17. $domains = mailbox_get_domains();
  18. if (!empty($domains)) {
  19. foreach ($domains as $domain) {
  20. $data[] = mailbox_get_domain_details($domain);
  21. }
  22. if (!isset($data) || empty($data)) {
  23. echo '{}';
  24. }
  25. else {
  26. echo json_encode($data, JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  27. }
  28. }
  29. else {
  30. echo '{}';
  31. }
  32. break;
  33. default:
  34. $data = mailbox_get_domain_details($object);
  35. if (!isset($data) || empty($data)) {
  36. echo '{}';
  37. }
  38. else {
  39. echo json_encode(mailbox_get_domain_details($object), JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  40. }
  41. break;
  42. }
  43. break;
  44. case "mailbox":
  45. switch ($object) {
  46. case "all":
  47. $domains = mailbox_get_domains();
  48. if (!empty($domains)) {
  49. foreach ($domains as $domain) {
  50. $mailboxes = mailbox_get_mailboxes($domain);
  51. if (!empty($mailboxes)) {
  52. foreach ($mailboxes as $mailbox) {
  53. $data[] = mailbox_get_mailbox_details($mailbox);
  54. }
  55. }
  56. }
  57. if (!isset($data) || empty($data)) {
  58. echo '{}';
  59. }
  60. else {
  61. echo json_encode($data, JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  62. }
  63. }
  64. else {
  65. echo '{}';
  66. }
  67. break;
  68. default:
  69. $data = mailbox_get_mailbox_details($object);
  70. if (!isset($data) || empty($data)) {
  71. echo '{}';
  72. }
  73. else {
  74. echo json_encode(mailbox_get_mailbox_details($object), JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  75. }
  76. break;
  77. }
  78. break;
  79. case "resource":
  80. switch ($object) {
  81. case "all":
  82. $domains = mailbox_get_domains();
  83. if (!empty($domains)) {
  84. foreach ($domains as $domain) {
  85. $resources = mailbox_get_resources($domain);
  86. if (!empty($resources)) {
  87. foreach ($resources as $resource) {
  88. $data[] = mailbox_get_resource_details($resource);
  89. }
  90. }
  91. }
  92. if (!isset($data) || empty($data)) {
  93. echo '{}';
  94. }
  95. else {
  96. echo json_encode($data, JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  97. }
  98. }
  99. else {
  100. echo '{}';
  101. }
  102. break;
  103. default:
  104. $data = mailbox_get_resource_details($object);
  105. if (!isset($data) || empty($data)) {
  106. echo '{}';
  107. }
  108. else {
  109. echo json_encode(mailbox_get_resource_details($object), JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  110. }
  111. break;
  112. }
  113. break;
  114. case "alias-domain":
  115. switch ($object) {
  116. case "all":
  117. $domains = mailbox_get_domains();
  118. if (!empty($domains)) {
  119. foreach ($domains as $domain) {
  120. $alias_domains = mailbox_get_alias_domains($domain);
  121. if (!empty($alias_domains)) {
  122. foreach ($alias_domains as $alias_domain) {
  123. $data[] = mailbox_get_alias_domain_details($alias_domain);
  124. }
  125. }
  126. }
  127. if (!isset($data) || empty($data)) {
  128. echo '{}';
  129. }
  130. else {
  131. echo json_encode($data, JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  132. }
  133. }
  134. else {
  135. echo '{}';
  136. }
  137. break;
  138. default:
  139. $data = mailbox_get_alias_domains($object);
  140. if (!isset($data) || empty($data)) {
  141. echo '{}';
  142. }
  143. else {
  144. echo json_encode(mailbox_get_alias_domains($object), JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  145. }
  146. break;
  147. }
  148. break;
  149. case "alias":
  150. switch ($object) {
  151. case "all":
  152. $domains = array_merge(mailbox_get_domains(), mailbox_get_alias_domains());
  153. if (!empty($domains)) {
  154. foreach ($domains as $domain) {
  155. $aliases = mailbox_get_aliases($domain);
  156. if (!empty($aliases)) {
  157. foreach ($aliases as $alias) {
  158. $data[] = mailbox_get_alias_details($alias);
  159. }
  160. }
  161. }
  162. if (!isset($data) || empty($data)) {
  163. echo '{}';
  164. }
  165. else {
  166. echo json_encode($data, JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  167. }
  168. }
  169. else {
  170. echo '{}';
  171. }
  172. break;
  173. default:
  174. $data = mailbox_get_alias_details($object);
  175. if (!isset($data) || empty($data)) {
  176. echo '{}';
  177. }
  178. else {
  179. echo json_encode(mailbox_get_alias_details($object), JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  180. }
  181. break;
  182. }
  183. break;
  184. case "domain-admin":
  185. switch ($object) {
  186. case "all":
  187. $domain_admins = get_domain_admins();
  188. if (!empty($domain_admins)) {
  189. foreach ($domain_admins as $domain_admin) {
  190. $data[] = get_domain_admin_details($domain_admin);
  191. }
  192. if (!isset($data) || empty($data)) {
  193. echo '{}';
  194. }
  195. else {
  196. echo json_encode($data, JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  197. }
  198. }
  199. else {
  200. echo '{}';
  201. }
  202. break;
  203. default:
  204. $data = get_domain_admin_details($object);
  205. if (!isset($data) || empty($data)) {
  206. echo '{}';
  207. }
  208. else {
  209. echo json_encode(get_domain_admin_details($object), JSON_UNESCAPED_UNICODE | JSON_PRETTY_PRINT);
  210. }
  211. break;
  212. }
  213. break;
  214. case "u2f-registration":
  215. if (($_SESSION["mailcow_cc_role"] == "admin" || $_SESSION["mailcow_cc_role"] == "domainadmin") && $_SESSION["mailcow_cc_username"] == $object) {
  216. $data = $u2f->getRegisterData(get_u2f_registrations($object));
  217. list($req, $sigs) = $data;
  218. $_SESSION['regReq'] = json_encode($req);
  219. echo 'var req = ' . json_encode($req) . '; var sigs = ' . json_encode($sigs) . ';';
  220. }
  221. else {
  222. return;
  223. }
  224. break;
  225. case "u2f-authentication":
  226. if (isset($_SESSION['pending_mailcow_cc_username']) && $_SESSION['pending_mailcow_cc_username'] == $object) {
  227. $reqs = json_encode($u2f->getAuthenticateData(get_u2f_registrations($object)));
  228. $_SESSION['authReq'] = $reqs;
  229. echo 'var req = ' . $reqs . ';';
  230. }
  231. else {
  232. return;
  233. }
  234. break;
  235. default:
  236. echo '{}';
  237. break;
  238. }
  239. break;
  240. case "delete":
  241. switch ($category) {
  242. case "alias":
  243. if (isset($_POST['address'])) {
  244. $address = json_decode($_POST['address'], true);
  245. if (is_array($address)) {
  246. if (mailbox_delete_alias(array('address' => $address)) === false) {
  247. echo json_encode(array(
  248. 'type' => 'error',
  249. 'message' => 'Deletion of item failed'
  250. ));
  251. exit();
  252. }
  253. echo json_encode(array(
  254. 'type' => 'success',
  255. 'message' => 'Task completed'
  256. ));
  257. }
  258. }
  259. else {
  260. echo json_encode(array(
  261. 'type' => 'error',
  262. 'message' => 'Cannot find address array in post data'
  263. ));
  264. }
  265. break;
  266. }
  267. break;
  268. case "edit":
  269. switch ($category) {
  270. case "alias":
  271. if (isset($_POST['address']) && isset($_POST['active'])) {
  272. $address = json_decode($_POST['address'], true);
  273. if (is_array($address)) {
  274. if (mailbox_edit_alias(array('address' => $address, 'active' => ($_POST['active'] == "1") ? $active = 1 : null)) === false) {
  275. echo json_encode(array(
  276. 'type' => 'error',
  277. 'message' => 'Edit item failed'
  278. ));
  279. exit();
  280. }
  281. echo json_encode(array(
  282. 'type' => 'success',
  283. 'message' => 'Task completed'
  284. ));
  285. }
  286. }
  287. else {
  288. echo json_encode(array(
  289. 'type' => 'error',
  290. 'message' => 'Cannot find address array in post data'
  291. ));
  292. }
  293. break;
  294. }
  295. break;
  296. }
  297. }
  298. }