golden hour
/home/doctorbruno/public_html/taeionline.com/support/include
⬆️ Go Up
Upload
File/Folder
Size
Actions
.MANIFEST
194.97 KB
Del
OK
.htaccess
14 B
Del
OK
JSON.php
33.13 KB
Del
OK
PasswordHash.php
6.92 KB
Del
OK
Spyc.php
31.74 KB
Del
OK
UniversalClassLoader.php
8.61 KB
Del
OK
ajax.admin.php
7.29 KB
Del
OK
ajax.config.php
4.61 KB
Del
OK
ajax.content.php
9.76 KB
Del
OK
ajax.draft.php
13.03 KB
Del
OK
ajax.email.php
2.33 KB
Del
OK
ajax.export.php
1006 B
Del
OK
ajax.filter.php
874 B
Del
OK
ajax.forms.php
13.84 KB
Del
OK
ajax.i18n.php
5.1 KB
Del
OK
ajax.kbase.php
2.93 KB
Del
OK
ajax.note.php
2.05 KB
Del
OK
ajax.orgs.php
11.73 KB
Del
OK
ajax.plugins.php
2.15 KB
Del
OK
ajax.schedule.php
4.29 KB
Del
OK
ajax.search.php
12.72 KB
Del
OK
ajax.sequence.php
3.2 KB
Del
OK
ajax.staff.php
11.62 KB
Del
OK
ajax.tasks.php
33.87 KB
Del
OK
ajax.thread.php
8.81 KB
Del
OK
ajax.tickets.php
79.7 KB
Del
OK
ajax.tips.php
1.66 KB
Del
OK
ajax.upgrader.php
2.24 KB
Del
OK
ajax.users.php
18.33 KB
Del
OK
api.cron.php
1.06 KB
Del
OK
api.tickets.php
10.36 KB
Del
OK
class.2fa.php
7.76 KB
Del
OK
class.ajax.php
1.45 KB
Del
OK
class.api.php
15.31 KB
Del
OK
class.app.php
1.49 KB
Del
OK
class.attachment.php
6.95 KB
Del
OK
class.auth.php
50.73 KB
Del
OK
class.avatar.php
6.44 KB
Del
OK
class.banlist.php
2.58 KB
Del
OK
class.base32.php
4.07 KB
Del
OK
class.businesshours.php
7.08 KB
Del
OK
class.canned.php
9.05 KB
Del
OK
class.captcha.php
1.73 KB
Del
OK
class.category.php
11.14 KB
Del
OK
class.charset.php
3.41 KB
Del
OK
class.cli.php
9.48 KB
Del
OK
class.client.php
15.39 KB
Del
OK
class.collaborator.php
5.65 KB
Del
OK
class.company.php
2.65 KB
Del
OK
class.config.php
60.36 KB
Del
OK
class.controller.php
1.15 KB
Del
OK
class.cron.php
3.6 KB
Del
OK
class.crypto.php
18.92 KB
Del
OK
class.csrf.php
2.38 KB
Del
OK
class.dept.php
33.21 KB
Del
OK
class.dispatcher.php
7.12 KB
Del
OK
class.draft.php
6.23 KB
Del
OK
class.dynamic_forms.php
64.98 KB
Del
OK
class.email.php
49 KB
Del
OK
class.error.php
1.69 KB
Del
OK
class.export.php
32.92 KB
Del
OK
class.faq.php
15.05 KB
Del
OK
class.file.php
34.59 KB
Del
OK
class.filter.php
31.9 KB
Del
OK
class.filter_action.php
23.67 KB
Del
OK
class.format.php
44.3 KB
Del
OK
class.forms.php
195.58 KB
Del
OK
class.http.php
7.16 KB
Del
OK
class.i18n.php
24.28 KB
Del
OK
class.import.php
6.9 KB
Del
OK
class.json.php
2.71 KB
Del
OK
class.knowledgebase.php
5.8 KB
Del
OK
class.list.php
42 KB
Del
OK
class.lock.php
4.05 KB
Del
OK
class.log.php
1.55 KB
Del
OK
class.mail.php
35.76 KB
Del
OK
class.mailer.php
25.75 KB
Del
OK
class.mailfetch.php
9.72 KB
Del
OK
class.mailparse.php
30.99 KB
Del
OK
class.message.php
6.42 KB
Del
OK
class.migrater.php
5.2 KB
Del
OK
class.misc.php
7.5 KB
Del
OK
class.model.php
2.3 KB
Del
OK
class.nav.php
14.15 KB
Del
OK
class.note.php
2.39 KB
Del
OK
class.oauth2.php
4.04 KB
Del
OK
class.organization.php
22.45 KB
Del
OK
class.orm.php
120.9 KB
Del
OK
class.osticket.php
20.64 KB
Del
OK
class.ostsession.php
21.86 KB
Del
OK
class.page.php
10.59 KB
Del
OK
class.pagenate.php
5.53 KB
Del
OK
class.passwd.php
1.21 KB
Del
OK
class.pdf.php
3.83 KB
Del
OK
class.plugin.php
36.13 KB
Del
OK
class.priority.php
1.81 KB
Del
OK
class.queue.php
103.51 KB
Del
OK
class.report.php
11.76 KB
Del
OK
class.role.php
11.27 KB
Del
OK
class.schedule.php
46.28 KB
Del
OK
class.search.php
61.66 KB
Del
OK
class.sequence.php
7.27 KB
Del
OK
class.session.php
19.25 KB
Del
OK
class.setup.php
3.55 KB
Del
OK
class.signal.php
4.16 KB
Del
OK
class.sla.php
9.11 KB
Del
OK
class.staff.php
60.21 KB
Del
OK
class.task.php
56.21 KB
Del
OK
class.team.php
12.31 KB
Del
OK
class.template.php
23.45 KB
Del
OK
class.thread.php
108.96 KB
Del
OK
class.thread_actions.php
17.08 KB
Del
OK
class.ticket.php
167.39 KB
Del
OK
class.timezone.php
21.94 KB
Del
OK
class.topic.php
20.06 KB
Del
OK
class.translation.php
34.79 KB
Del
OK
class.upgrader.php
13.76 KB
Del
OK
class.user.php
43.4 KB
Del
OK
class.usersession.php
7.55 KB
Del
OK
class.util.php
10.07 KB
Del
OK
class.validator.php
12.94 KB
Del
OK
class.variable.php
11.93 KB
Del
OK
class.xml.php
3.23 KB
Del
OK
class.yaml.php
1.15 KB
Del
OK
cli
-
Del
OK
client
-
Del
OK
config
-
Del
OK
fpdf
-
Del
OK
htmLawed.php
53.53 KB
Del
OK
html2text.php
33.71 KB
Del
OK
i18n
-
Del
OK
index.php
37 B
Del
OK
laminas-mail
-
Del
OK
mpdf
-
Del
OK
mysqli.php
9.55 KB
Del
OK
ost-config.php
5.63 KB
Del
OK
ost-sampleconfig.php
6.24 KB
Del
OK
pear
-
Del
OK
plugins
-
Del
OK
staff
-
Del
OK
tnef_decoder.php
19.82 KB
Del
OK
upgrader
-
Del
OK
Edit: class.api.php
<?php /********************************************************************* class.api.php API Peter Rotich <peter@osticket.com> Copyright (c) 2006-2013 osTicket http://www.osticket.com Released under the GNU General Public License WITHOUT ANY WARRANTY. See LICENSE.TXT for details. vim: expandtab sw=4 ts=4 sts=4: **********************************************************************/ include_once INCLUDE_DIR.'class.controller.php'; class API { var $id; var $ht; function __construct($id) { $this->id = 0; $this->load($id); } function load($id=0) { if(!$id && !($id=$this->getId())) return false; $sql='SELECT * FROM '.API_KEY_TABLE.' WHERE id='.db_input($id); if(!($res=db_query($sql)) || !db_num_rows($res)) return false; $this->ht = db_fetch_array($res); $this->id = $this->ht['id']; return true; } function reload() { return $this->load(); } function getId() { return $this->id; } function getKey() { return $this->ht['apikey']; } function getIPAddr() { return $this->ht['ipaddr']; } function getNotes() { return $this->ht['notes']; } function getHashtable() { return $this->ht; } function isActive() { return ($this->ht['isactive']); } function canCreateTickets() { return ($this->ht['can_create_tickets']); } function canExecuteCron() { return ($this->ht['can_exec_cron']); } function update($vars, &$errors) { if(!API::save($this->getId(), $vars, $errors)) return false; $this->reload(); return true; } function delete() { $sql='DELETE FROM '.API_KEY_TABLE.' WHERE id='.db_input($this->getId()).' LIMIT 1'; return (db_query($sql) && ($num=db_affected_rows())); } /** Static functions **/ static function add($vars, &$errors) { return API::save(0, $vars, $errors); } static function validate($key, $ip) { return ($key && $ip && self::getIdByKey($key, $ip)); } static function getIdByKey($key, $ip='') { $sql='SELECT id FROM '.API_KEY_TABLE.' WHERE apikey='.db_input($key); if($ip) $sql.=' AND ipaddr='.db_input($ip); if(($res=db_query($sql)) && db_num_rows($res)) list($id) = db_fetch_row($res); return $id; } static function lookupByKey($key, $ip='') { return self::lookup(self::getIdByKey($key, $ip)); } static function lookup($id) { return ($id && is_numeric($id) && ($k= new API($id)) && $k->getId()==$id)?$k:null; } static function save($id, $vars, &$errors) { if(!$id && (!$vars['ipaddr'] || !Validator::is_ip($vars['ipaddr']))) $errors['ipaddr'] = __('Valid IP is required'); if($errors) return false; $sql=' updated=NOW() ' .',isactive='.db_input($vars['isactive']) .',can_create_tickets='.db_input($vars['can_create_tickets']) .',can_exec_cron='.db_input($vars['can_exec_cron']) .',notes='.db_input(Format::sanitize($vars['notes'])); if($id) { $sql='UPDATE '.API_KEY_TABLE.' SET '.$sql.' WHERE id='.db_input($id); if(db_query($sql)) return true; $errors['err']=sprintf(__('Unable to update %s.'), __('this API key')) .' '.__('Internal error occurred'); } else { $sql='INSERT INTO '.API_KEY_TABLE.' SET '.$sql .',created=NOW() ' .',ipaddr='.db_input($vars['ipaddr']) .',apikey='.db_input(strtoupper(md5(time().$vars['ipaddr'].md5(Misc::randCode(16))))); if(db_query($sql) && ($id=db_insert_id())) return $id; $errors['err']=sprintf('%s %s', sprintf(__('Unable to add %s.'), __('this API key')), __('Correct any errors below and try again.')); } return false; } } /** * Controller for API methods. Provides methods to check to make sure the * API key was sent and that the Client-IP and API-Key have been registered * in the database, and methods for parsing and validating data sent in the * API request. */ class ApiController extends Controller { private $sapi; private $key; public function __construct($sapi = null) { // Set API Interface the request is coming from $this->sapi = $sapi ?: (osTicket::is_cli() ? 'cli' : 'http'); } public function isCli() { return (strcasecmp($this->sapi, 'cli') === 0); } private function getInputStream() { return $this->isCli() ? 'php://stdin' : 'php://input'; } protected function getRemoteAddr() { return $_SERVER['REMOTE_ADDR']; } protected function getApiKey() { return $_SERVER['HTTP_X_API_KEY']; } function requireApiKey() { // Require a valid API key sent as X-API-Key HTTP header // see getApiKey method. if (!($key=$this->getKey())) return $this->exerr(401, __('Valid API key required')); elseif (!$key->isActive() || $key->getIPAddr() != $this->getRemoteAddr()) return $this->exerr(401, __('API key not found/active or source IP not authorized')); return $key; } function getKey() { // Lookup record using sent API Key && IP Addr if (!$this->key && ($key=$this->getApiKey()) && ($ip=$this->getRemoteAddr())) $this->key = API::lookupByKey($key, $ip); return $this->key; } /** * Retrieves the body of the API request and converts it to a common * hashtable. For JSON formats, this is mostly a noop, the conversion * work will be done for XML requests */ function getRequest($format, $validate=true) { $input = $this->getInputStream(); if (!($stream = @fopen($input, 'r'))) $this->exerr(400, sprintf('%s (%s)', __("Unable to read request body"), $input)); return $this->parseRequest($stream, $format, $validate); } function getEmailRequest() { if (!($data=$this->getRequest('email', false))) $this->exerr(400, __("Unable to read email request")); return $data; } function parseRequest($stream, $format, $validate=true) { $parser = null; switch(strtolower($format)) { case 'xml': if (!function_exists('xml_parser_create')) return $this->exerr(501, __('XML extension not supported')); $parser = new ApiXmlDataParser(); break; case 'json': $parser = new ApiJsonDataParser(); break; case 'email': $parser = new ApiEmailDataParser(); break; default: return $this->exerr(415, __('Unsupported data format')); } if (!($data = $parser->parse($stream)) || !is_array($data)) { $this->exerr(400, $parser->lastError()); } //Validate structure of the request. if ($validate && $data) $this->validate($data, $format, false); return $data; } function parseEmail($content) { return $this->parseRequest($content, 'email', false); } /** * Structure to validate the request against -- must be overridden to be * useful */ function getRequestStructure($format, $data=null) { return array(); } /** * Simple validation that makes sure the keys of a parsed request are * expected. It is assumed that the functions actually implementing the * API will further validate the contents of the request */ function validateRequestStructure($data, $structure, $prefix="", $strict=true) { global $ost; foreach ($data as $key=>$info) { if (is_array($structure) && (is_array($info) || $info instanceof ArrayAccess)) { $search = (isset($structure[$key]) && !is_numeric($key)) ? $key : "*"; if (isset($structure[$search])) { $this->validateRequestStructure($info, $structure[$search], "$prefix$key/", $strict); continue; } } elseif (in_array($key, $structure)) { continue; } $error = sprintf(__("%s: Unexpected data received in API request"), "$prefix$key"); $this->onError(400, $error, __('Unexpected Data'), !$strict); } return true; } /** * Validate request. * */ function validate(&$data, $format, $strict=true) { return $this->validateRequestStructure( $data, $this->getRequestStructure($format, $data), "", $strict); } protected function debug($subj, $msg) { return $this->log($subj, $msg, LOG_DEBUG); } protected function logError($subj, $msg, $fatal=false) { // If error is not fatal then log it as a warning return $this->log($subj, $msg, $fatal ? LOG_ERR : LOG_WARN); } protected function log($title, $msg, $level = LOG_WARN) { global $ost; switch ($level) { case LOG_WARN: case LOG_ERR: // We are disabling email alerts on API errors / warnings // due to potential abuse or loops that might cause email DOS $ost->log($level, $title, $msg, false); break; case LOG_DEBUG: default: $ost->logDebug($title, $msg); } return true; } /** * API error & logging and response! * * final - don not override downstream. */ final public function onError($code, $error, $title = null, $logOnly = false) { // Unpack the errors to string if error is an array if ($error && is_array($error)) $error = Format::array_implode(": ", "\n", $error); // Log the error $msg = $error; // TODO: Only include API Key when in debug mode to avoid // potentialialy leaking a valid key in system logs if (($key=$this->getApiKey())) $msg .= "\n[$key]\n"; $title = sprintf('%s (%s)', $title ?: __('API Error'), $code); $this->logError($title, $msg, $logOnly); // If the error is not deemed fatal then simply return if ($logOnly) return; // If the API Interface is CLI then throw a TicketApiError exception // so the caller can handle the error gracefully. // Note that we set the error code as well if ($this->isCli()) throw new TicketApiError($error, $code); // Respond and exit since HTTP endpoint requests // are considered stateless $this->response($code, $error); } } include_once "class.xml.php"; class ApiXmlDataParser extends XmlDataParser { function parse($stream) { return $this->fixup(parent::parse($stream)); } /** * Perform simple operations to make data consistent between JSON and * XML data types */ function fixup($current) { global $cfg; if (isset($current['ticket'])) $current = $current['ticket']; if (!is_array($current)) return $current; foreach ($current as $key=>&$value) { if ($key == "phone" && is_array($value)) { $value = $value[":text"]; } else if ($key == "alert") { $value = (bool) (strtolower($value) === 'false' ? false : $value); } else if ($key == "autorespond") { $value = (bool) (strtolower($value) === 'false' ? false : $value); } else if ($key == "message") { if (!is_array($value)) { $value = array( "body" => $value, "type" => "text/plain", # Use encoding from root <xml> node ); } else { $value["body"] = $value[":text"]; unset($value[":text"]); } if (isset($value['encoding'])) $value['body'] = Charset::utf8($value['body'], $value['encoding']); if (!strcasecmp($value['type'], 'text/html')) $value = new HtmlThreadEntryBody($value['body']); else $value = new TextThreadEntryBody($value['body']); } else if ($key == "attachments") { if(isset($value['file']) && !isset($value['file'][':text'])) $value = $value['file']; if($value && is_array($value)) { foreach ($value as &$info) { $info["data"] = $info[":text"]; unset($info[":text"]); } unset($info); } } else if(is_array($value)) { $value = $this->fixup($value); } } unset($value); return $current; } } include_once "class.json.php"; class ApiJsonDataParser extends JsonDataParser { static function parse($stream, $tidy=false) { return self::fixup(parent::parse($stream)); } static function fixup($current) { if (!is_array($current)) return $current; foreach ($current as $key=>&$value) { if ($key == "phone") { $value = strtoupper($value); } else if ($key == "alert") { $value = (bool)$value; } else if ($key == "autorespond") { $value = (bool)$value; } elseif ($key == "message") { // Allow message specified in RFC 2397 format $data = Format::strip_emoticons(Format::parseRfc2397($value, 'utf-8')); if (isset($data['type']) && $data['type'] == 'text/html') $value = new HtmlThreadEntryBody($data['data']); else $value = new TextThreadEntryBody($data['data']); } else if ($key == "attachments") { foreach ($value as &$info) { $data = reset($info); # PHP5: fopen("data://$data[5:]"); $contents = Format::parseRfc2397($data, 'utf-8', false); $info = array( "data" => $contents['data'], "type" => $contents['type'], "name" => key($info), ); } unset($info); } } unset($value); return $current; } } /* Email parsing */ include_once "class.mailparse.php"; class ApiEmailDataParser extends EmailDataParser { function parse($stream) { return $this->fixup(parent::parse($stream)); } function fixup($data) { global $cfg; if (!$data) return $data; $data['source'] = 'Email'; if (!$data['subject']) $data['subject'] = '[No Subject]'; if (!$data['emailId']) $data['emailId'] = $cfg->getDefaultEmailId(); if( !$cfg->useEmailPriority()) unset($data['priorityId']); return $data; } } ?>
Save