functions.pushover.inc.php 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199
  1. <?php
  2. function pushover($_action, $_data = null) {
  3. global $pdo;
  4. global $lang;
  5. switch ($_action) {
  6. case 'edit':
  7. if (!isset($_SESSION['acl']['pushover']) || $_SESSION['acl']['pushover'] != "1" ) {
  8. $_SESSION['return'][] = array(
  9. 'type' => 'danger',
  10. 'log' => array(__FUNCTION__, $_action, $_data),
  11. 'msg' => 'access_denied'
  12. );
  13. return false;
  14. }
  15. if (!is_array($_data['username'])) {
  16. $usernames = array();
  17. $usernames[] = $_data['username'];
  18. }
  19. else {
  20. $usernames = $_data['username'];
  21. }
  22. foreach ($usernames as $username) {
  23. if (!hasMailboxObjectAccess($_SESSION['mailcow_cc_username'], $_SESSION['mailcow_cc_role'], $username)) {
  24. $_SESSION['return'][] = array(
  25. 'type' => 'danger',
  26. 'log' => array(__FUNCTION__, $_action, $_data),
  27. 'msg' => 'access_denied'
  28. );
  29. continue;
  30. }
  31. $delete = $_data['delete'];
  32. if ($delete == "true") {
  33. $stmt = $pdo->prepare("DELETE FROM `pushover` WHERE `username` = :username");
  34. $stmt->execute(array(
  35. ':username' => $username
  36. ));
  37. $_SESSION['return'][] = array(
  38. 'type' => 'success',
  39. 'log' => array(__FUNCTION__, $_action, $_data, $_data),
  40. 'msg' => 'pushover_settings_edited'
  41. );
  42. continue;
  43. }
  44. $key = $_data['key'];
  45. $token = $_data['token'];
  46. $evaluate_x_prio = $_data['evaluate_x_prio'];
  47. $only_x_prio = $_data['only_x_prio'];
  48. $senders = array_map('trim', preg_split( "/( |,|;|\n)/", $_data['senders']));
  49. foreach ($senders as $i => &$sender) {
  50. if (empty($sender)) {
  51. continue;
  52. }
  53. if (!filter_var($sender, FILTER_VALIDATE_EMAIL) === true) {
  54. unset($senders[$i]);
  55. continue;
  56. }
  57. }
  58. $senders = array_filter($senders);
  59. if (empty($senders)) { $senders = ''; }
  60. $senders = implode(",", $senders);
  61. if (!ctype_alnum($key) || strlen($key) != 30) {
  62. $_SESSION['return'][] = array(
  63. 'type' => 'danger',
  64. 'log' => array(__FUNCTION__, $_action, $_data, $_data),
  65. 'msg' => 'pushover_key'
  66. );
  67. continue;
  68. }
  69. if (!ctype_alnum($token) || strlen($token) != 30) {
  70. $_SESSION['return'][] = array(
  71. 'type' => 'danger',
  72. 'log' => array(__FUNCTION__, $_action, $_data, $_data),
  73. 'msg' => 'pushover_token'
  74. );
  75. continue;
  76. }
  77. $title = $_data['title'];
  78. $text = $_data['text'];
  79. $active = intval($_data['active']);
  80. $po_attributes = json_encode(
  81. array(
  82. 'evaluate_x_prio' => strval(intval($evaluate_x_prio)),
  83. 'only_x_prio' => strval(intval($only_x_prio))
  84. )
  85. );
  86. $stmt = $pdo->prepare("REPLACE INTO `pushover` (`username`, `key`, `attributes`, `senders`, `token`, `title`, `text`, `active`)
  87. VALUES (:username, :key, :po_attributes, :senders, :token, :title, :text, :active)");
  88. $stmt->execute(array(
  89. ':username' => $username,
  90. ':key' => $key,
  91. ':po_attributes' => $po_attributes,
  92. ':senders' => $senders,
  93. ':token' => $token,
  94. ':title' => $title,
  95. ':text' => $text,
  96. ':active' => $active
  97. ));
  98. $_SESSION['return'][] = array(
  99. 'type' => 'success',
  100. 'log' => array(__FUNCTION__, $_action, $_data, $_data),
  101. 'msg' => 'pushover_settings_edited'
  102. );
  103. }
  104. break;
  105. case 'get':
  106. if (!hasMailboxObjectAccess($_SESSION['mailcow_cc_username'], $_SESSION['mailcow_cc_role'], $_data)) {
  107. $_SESSION['return'][] = array(
  108. 'type' => 'danger',
  109. 'log' => array(__FUNCTION__, $_action, $_data),
  110. 'msg' => 'access_denied'
  111. );
  112. return false;
  113. }
  114. $stmt = $pdo->prepare("SELECT * FROM `pushover` WHERE `username` = :username");
  115. $stmt->execute(array(
  116. ':username' => $_data
  117. ));
  118. $data = $stmt->fetch(PDO::FETCH_ASSOC);
  119. $data['attributes'] = json_decode($data['attributes'], true);
  120. if (empty($data)) {
  121. return false;
  122. }
  123. else {
  124. return $data;
  125. }
  126. break;
  127. case 'test':
  128. if (!isset($_SESSION['acl']['pushover']) || $_SESSION['acl']['pushover'] != "1" ) {
  129. $_SESSION['return'][] = array(
  130. 'type' => 'danger',
  131. 'log' => array(__FUNCTION__, $_action, $_data),
  132. 'msg' => 'access_denied'
  133. );
  134. return false;
  135. }
  136. if (!is_array($_data['username'])) {
  137. $usernames = array();
  138. $usernames[] = $_data['username'];
  139. }
  140. else {
  141. $usernames = $_data['username'];
  142. }
  143. foreach ($usernames as $username) {
  144. if (!hasMailboxObjectAccess($_SESSION['mailcow_cc_username'], $_SESSION['mailcow_cc_role'], $username)) {
  145. $_SESSION['return'][] = array(
  146. 'type' => 'danger',
  147. 'log' => array(__FUNCTION__, $_action, $_data),
  148. 'msg' => 'access_denied'
  149. );
  150. continue;
  151. }
  152. $stmt = $pdo->prepare("SELECT * FROM `pushover`
  153. WHERE `username` = :username");
  154. $stmt->execute(array(
  155. ':username' => $username
  156. ));
  157. $api_data = $stmt->fetch(PDO::FETCH_ASSOC);
  158. if (!empty($api_data)) {
  159. $title = (!empty($api_data['title'])) ? $api_data['title'] : 'Mail';
  160. $text = (!empty($api_data['text'])) ? $api_data['text'] : 'You\'ve got mail 📧';
  161. curl_setopt_array($ch = curl_init(), array(
  162. CURLOPT_URL => "https://api.pushover.net/1/users/validate.json",
  163. CURLOPT_POSTFIELDS => array(
  164. "token" => $api_data['token'],
  165. "user" => $api_data['key']
  166. ),
  167. CURLOPT_SAFE_UPLOAD => true,
  168. CURLOPT_RETURNTRANSFER => true,
  169. ));
  170. $result = curl_exec($ch);
  171. $httpcode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
  172. curl_close($ch);
  173. if ($httpcode == 200) {
  174. $_SESSION['return'][] = array(
  175. 'type' => 'success',
  176. 'log' => array(__FUNCTION__, $_action, $_data),
  177. 'msg' => sprintf('Pushover API OK (%d): %s', $httpcode, $result)
  178. );
  179. }
  180. else {
  181. $_SESSION['return'][] = array(
  182. 'type' => 'danger',
  183. 'log' => array(__FUNCTION__, $_action, $_data),
  184. 'msg' => sprintf('Pushover API ERR (%d): %s', $httpcode, $result)
  185. );
  186. }
  187. }
  188. else {
  189. $_SESSION['return'][] = array(
  190. 'type' => 'danger',
  191. 'log' => array(__FUNCTION__, $_action, $_data),
  192. 'msg' => 'pushover_credentials_missing'
  193. );
  194. return false;
  195. }
  196. }
  197. break;
  198. }
  199. }