| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971 | <?phpnamespace Grav\Plugin\Admin;use DateTime;use Grav\Common\Data;use Grav\Common\File\CompiledYamlFile;use Grav\Common\GPM\GPM;use Grav\Common\GPM\Licenses;use Grav\Common\GPM\Response;use Grav\Common\Grav;use Grav\Common\Helpers\YamlLinter;use Grav\Common\Language\LanguageCodes;use Grav\Common\Page\Collection;use Grav\Common\Page\Interfaces\PageInterface;use Grav\Common\Page\Page;use Grav\Common\Page\Pages;use Grav\Common\Plugins;use Grav\Common\Security;use Grav\Common\Session;use Grav\Common\Themes;use Grav\Common\Uri;use Grav\Common\User\Interfaces\UserCollectionInterface;use Grav\Common\User\User;use Grav\Common\Utils;use Grav\Framework\Collection\ArrayCollection;use Grav\Plugin\Login\Login;use Grav\Plugin\Login\TwoFactorAuth\TwoFactorAuth;use PicoFeed\Parser\MalformedXmlException;use RocketTheme\Toolbox\Event\Event;use RocketTheme\Toolbox\File\File;use RocketTheme\Toolbox\File\JsonFile;use RocketTheme\Toolbox\ResourceLocator\UniformResourceIterator;use RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator;use RocketTheme\Toolbox\Session\Message;use Grav\Common\Yaml;use Composer\Semver\Semver;use PicoFeed\Reader\Reader;define('LOGIN_REDIRECT_COOKIE', 'grav-login-redirect');class Admin{    const MEDIA_PAGINATION_INTERVAL = 20;    const TMP_COOKIE_NAME = 'tmp-admin-message';    /** @var Grav */    public $grav;    /** @var string */    public $base;    /** @var string */    public $location;    /** @var string */    public $route;    /** @var User */    public $user;    /** @var array */    public $forgot;    /** @var string */    public $task;    /** @var array */    public $json_response;    /** @var Collection */    public $collection;    /** @var bool */    public $multilang;    /** @var array */    public $languages_enabled;    /** @var Uri $uri */    protected $uri;    /** @var array */    protected $pages = [];    /** @var Session */    protected $session;    /** @var Data\Blueprints */    protected $blueprints;    /** @var GPM */    protected $gpm;    /** @var int */    protected $pages_count;    /** @var array */    protected $permissions;    /** @var bool */    protected $load_additional_files_in_background = false;    /** @var bool */    protected $loading_additional_files_in_background = false;    /** @var array */    protected $temp_messages = [];    /**     * Constructor.     *     * @param Grav   $grav     * @param string $base     * @param string $location     * @param string $route     */    public function __construct(Grav $grav, $base, $location, $route)    {        // Register admin to grav because of calling $grav['user'] requires it.        $grav['admin']     = $this;        $this->grav        = $grav;        $this->base        = $base;        $this->location    = $location;        $this->route       = $route;        $this->uri         = $grav['uri'];        $this->session     = $grav['session'];        $this->user        = $grav['user'];        $this->permissions = [];        $language          = $grav['language'];        // Load utility class        if ($language->enabled()) {            $this->multilang         = true;            $this->languages_enabled = (array)$this->grav['config']->get('system.languages.supported', []);            //Set the currently active language for the admin            $language = $this->grav['uri']->param('lang');            if (!$language) {                if (!$this->session->admin_lang) {                    $this->session->admin_lang = $this->grav['language']->getLanguage();                }                $language = $this->session->admin_lang;            }            $this->grav['language']->setActive($language ?: 'en');        } else {            $this->grav['language']->setActive('en');            $this->multilang = false;        }    }    /**     * Return the languages available in the admin     *     * @return array     */    public static function adminLanguages()    {        $languages = [];        $path = Grav::instance()['locator']->findResource('plugins://admin/languages');        /** @var \DirectoryIterator $directory */        foreach (new \DirectoryIterator($path) as $file) {            if ($file->isDir() || $file->isDot() || Utils::startsWith($file->getFilename(), '.')) {                continue;            }            $lang = $file->getBasename('.yaml');            $languages[$lang] = LanguageCodes::getNativeName($lang);        }        // sort languages        asort($languages);        return $languages;    }    /**     * Return the found configuration blueprints     *     * @return array     */    public static function configurations()    {        $configurations = [];        /** @var UniformResourceIterator $iterator */        $iterator = Grav::instance()['locator']->getIterator('blueprints://config');        foreach ($iterator as $file) {            if ($file->isDir() || !preg_match('/^[^.].*.yaml$/', $file->getFilename())) {                continue;            }            $configurations[] = $file->getBasename('.yaml');        }        return $configurations;    }    /**     * Return the tools found     *     * @return array     */    public static function tools()    {        $tools = [];        Grav::instance()->fireEvent('onAdminTools', new Event(['tools' => &$tools]));        return $tools;    }    public static function toolsPermissions()    {        $tools = static::tools();        $perms = [];        foreach ($tools as $tool) {            $perms = array_merge($perms, $tool[0]);        }        return array_unique($perms);    }    /**     * Return the languages available in the site     *     * @return array     */    public static function siteLanguages()    {        $languages = [];        $lang_data = (array) Grav::instance()['config']->get('system.languages.supported', []);        foreach ($lang_data as $index => $lang) {            $languages[$lang] = LanguageCodes::getNativeName($lang);        }        return $languages;    }    /**     * Static helper method to return the admin form nonce     *     * @return string     */    public static function getNonce()    {        $action = 'admin-form';        return Utils::getNonce($action);    }    /**     * Static helper method to return the last used page name     *     * @return string     */    public static function getLastPageName()    {        return Grav::instance()['session']->lastPageName ?: 'default';    }    /**     * Static helper method to return the last used page route     *     * @return string     */    public static function getLastPageRoute()    {        return Grav::instance()['session']->lastPageRoute ?: self::route();    }    /**     * Static helper method to return current route.     *     * @return string     */    public static function route()    {        $pages = Grav::instance()['pages'];        $route = '/' . ltrim(Grav::instance()['admin']->route, '/');        /** @var PageInterface $page */        $page         = $pages->dispatch($route);        $parent_route = null;        if ($page) {            /** @var PageInterface $parent */            $parent       = $page->parent();            $parent_route = $parent->rawRoute();        }        return $parent_route;    }    public static function getTempDir()    {        try {            $tmp_dir = Grav::instance()['locator']->findResource('tmp://', true, true);        } catch (\Exception $e) {            $tmp_dir = Grav::instance()['locator']->findResource('cache://', true, true) . '/tmp';        }        return $tmp_dir;    }    public static function getPageMedia()    {        $files = [];        $grav = Grav::instance();        $pages = $grav['pages'];        $route = '/' . ltrim($grav['admin']->route, '/');        /** @var PageInterface $page */        $page         = $pages->dispatch($route);        $parent_route = null;        if ($page) {            $media = $page->media()->all();            $files = array_keys($media);        }        return $files;    }    /**     * Get current session.     *     * @return Session     */    public function session()    {        return $this->session;    }    /**     * Fetch and delete messages from the session queue.     *     * @param string $type     *     * @return array     */    public function messages($type = null)    {        /** @var Message $messages */        $messages = $this->grav['messages'];        return $messages->fetch($type);    }    /**     * Authenticate user.     *     * @param  array $credentials User credentials.     */    public function authenticate($credentials, $post)    {        /** @var Login $login */        $login = $this->grav['login'];        // Remove login nonce from the form.        $credentials = array_diff_key($credentials, ['admin-nonce' => true]);        $twofa = $this->grav['config']->get('plugins.admin.twofa_enabled', false);        $rateLimiter = $login->getRateLimiter('login_attempts');        $userKey = (string)($credentials['username'] ?? '');        $ipKey = Uri::ip();        $redirect = $post['redirect'] ?? $this->base . $this->route;        // Pseudonymization of the IP        $ipKey = sha1($ipKey . $this->grav['config']->get('security.salt'));        // Check if the current IP has been used in failed login attempts.        $attempts = count($rateLimiter->getAttempts($ipKey, 'ip'));        $rateLimiter->registerRateLimitedAction($ipKey, 'ip')->registerRateLimitedAction($userKey);        // Check rate limit for both IP and user, but allow each IP a single try even if user is already rate limited.        if ($rateLimiter->isRateLimited($ipKey, 'ip') || ($attempts && $rateLimiter->isRateLimited($userKey))) {            $this->setMessage(static::translate(['PLUGIN_LOGIN.TOO_MANY_LOGIN_ATTEMPTS', $rateLimiter->getInterval()]), 'error');            $this->grav->redirect('/');        }        // Fire Login process.        $event = $login->login(            $credentials,            ['admin' => true, 'twofa' => $twofa],            ['authorize' => 'admin.login', 'return_event' => true]        );        $user = $event->getUser();        if ($user->authenticated) {            $rateLimiter->resetRateLimit($ipKey, 'ip')->resetRateLimit($userKey);            if ($user->authorized) {                $event->defMessage('PLUGIN_ADMIN.LOGIN_LOGGED_IN', 'info');                $event->defRedirect($post['redirect'] ?? $redirect);            } else {                $this->session->redirect = $redirect;            }        } else {            if ($user->authorized) {                $event->defMessage('PLUGIN_LOGIN.ACCESS_DENIED', 'error');            } else {                $event->defMessage('PLUGIN_LOGIN.LOGIN_FAILED', 'error');            }        }        $event->defRedirect($redirect);        $message = $event->getMessage();        if ($message) {            $this->setMessage(static::translate($message), $event->getMessageType());        }        $redirect = $event->getRedirect();        $this->grav->redirect($redirect, $event->getRedirectCode());    }    /**     * Check Two-Factor Authentication.     */    public function twoFa($data, $post)    {        /** @var Login $login */        $login = $this->grav['login'];        /** @var TwoFactorAuth $twoFa */        $twoFa = $login->twoFactorAuth();        $user = $this->grav['user'];        $code = $data['2fa_code'] ?? null;        $secret = $user->twofa_secret ?? null;        if (!$code || !$secret || !$twoFa->verifyCode($secret, $code)) {            $login->logout(['admin' => true]);            $this->grav['session']->setFlashCookieObject(Admin::TMP_COOKIE_NAME, ['message' => $this->translate('PLUGIN_ADMIN.2FA_FAILED'), 'status' => 'error']);            $this->grav->redirect($this->uri->route(), 303);        }        $this->setMessage($this->translate('PLUGIN_ADMIN.LOGIN_LOGGED_IN'), 'info');        $user->authorized = true;        $this->grav->redirect($post['redirect']);    }    /**     * Logout from admin.     */    public function logout($data, $post)    {        /** @var Login $login */        $login = $this->grav['login'];        $event = $login->logout(['admin' => true], ['return_event' => true]);        $event->defMessage('PLUGIN_ADMIN.LOGGED_OUT', 'info');        $message = $event->getMessage();        if ($message) {            $this->grav['session']->setFlashCookieObject(Admin::TMP_COOKIE_NAME, ['message' => $this->translate($message), 'status' => $event->getMessageType()]);        }        $this->grav->redirect($this->base);    }    /**     * @return bool     */    public static function doAnyUsersExist()    {        $accounts = Grav::instance()['accounts'] ?? null;        if ($accounts instanceof \Countable) {            return $accounts->count() > 0;        }        // TODO: remove old way to check for existence of a user account (Grav < v1.6.9)        $account_dir = $file_path = Grav::instance()['locator']->findResource('account://');        $user_check = glob($account_dir . '/*.yaml');        return $user_check;    }    /**     * Add message into the session queue.     *     * @param string $msg     * @param string $type     */    public function setMessage($msg, $type = 'info')    {        /** @var Message $messages */        $messages = $this->grav['messages'];        $messages->add($msg, $type);    }    public function addTempMessage($msg, $type)    {        $this->temp_messages[] = ['message' => $msg, 'scope' => $type];    }    public function getTempMessages()    {        return $this->temp_messages;    }    /**     * Translate a string to the user-defined language     *     * @param array|mixed $args     *     * @param mixed       $languages     *     * @return string     */    public static function translate($args, $languages = null)    {        $grav = Grav::instance();        if (is_array($args)) {            $lookup = array_shift($args);        } else {            $lookup = $args;            $args   = [];        }        if (!$languages) {            if ($grav['config']->get('system.languages.translations_fallback', true)) {                $languages = $grav['language']->getFallbackLanguages();            } else {                $languages = (array)$grav['language']->getDefault();            }            $languages = $grav['user']->authenticated ? [ $grav['user']->language ] : $languages;        } else {            $languages = (array)$languages;        }        foreach ((array)$languages as $lang) {            $translation = $grav['language']->getTranslation($lang, $lookup, true);            if (!$translation) {                $language    = $grav['language']->getDefault() ?: 'en';                $translation = $grav['language']->getTranslation($language, $lookup, true);            }            if (!$translation) {                $language    = 'en';                $translation = $grav['language']->getTranslation($language, $lookup, true);            }            if ($translation) {                if (count($args) >= 1) {                    return vsprintf($translation, $args);                }                return $translation;            }        }        return $lookup;    }    /**     * Checks user authorisation to the action.     *     * @param  string|string[] $action     *     * @return bool     */    public function authorize($action = 'admin.login')    {        $action = (array)$action;        foreach ($action as $a) {            if ($this->user->authorize($a)) {                return true;            }        }        return false;    }    /**     * Gets configuration data.     *     * @param string $type     * @param array  $post     *     * @return mixed     * @throws \RuntimeException     */    public function data($type, array $post = [])    {        static $data = [];        if (isset($data[$type])) {            return $data[$type];        }        if (!$post) {            $post = $this->grav['uri']->post();            $post = $post['data'] ?? [];        }        // Check to see if a data type is plugin-provided, before looking into core ones        $event = $this->grav->fireEvent('onAdminData', new Event(['type' => &$type]));        if ($event) {            if (isset($event['data_type'])) {                return $event['data_type'];            }            if (is_string($event['type'])) {                $type = $event['type'];            }        }        /** @var UniformResourceLocator $locator */        $locator  = $this->grav['locator'];        $filename = $locator->findResource("config://{$type}.yaml", true, true);        $file     = CompiledYamlFile::instance($filename);        if (preg_match('|plugins/|', $type)) {            /** @var Plugins $plugins */            $plugins = $this->grav['plugins'];            $obj     = $plugins->get(preg_replace('|plugins/|', '', $type));            if (!$obj) {                return [];            }            $obj->merge($post);            $obj->file($file);            $data[$type] = $obj;        } elseif (preg_match('|themes/|', $type)) {            /** @var Themes $themes */            $themes = $this->grav['themes'];            $obj    = $themes->get(preg_replace('|themes/|', '', $type));            if (!$obj) {                return [];            }            $obj->merge($post);            $obj->file($file);            $data[$type] = $obj;        } elseif (preg_match('|users?/|', $type)) {            /** @var UserCollectionInterface $users */            $users = $this->grav['accounts'];            $obj = $users->load(preg_replace('|users?/|', '', $type));            $obj->update($this->cleanUserPost($post));            $data[$type] = $obj;        } elseif (preg_match('|config/|', $type)) {            $type       = preg_replace('|config/|', '', $type);            $blueprints = $this->blueprints("config/{$type}");            $config     = $this->grav['config'];            $obj        = new Data\Data($config->get($type, []), $blueprints);            $obj->merge($post);            // FIXME: We shouldn't allow user to change configuration files in system folder!            $filename = $this->grav['locator']->findResource("config://{$type}.yaml")                ?: $this->grav['locator']->findResource("config://{$type}.yaml", true, true);            $file     = CompiledYamlFile::instance($filename);            $obj->file($file);            $data[$type] = $obj;        } elseif (preg_match('|media-manager/|', $type)) {            $filename = base64_decode(preg_replace('|media-manager/|', '', $type));            $file = File::instance($filename);            $obj = new \stdClass();            $obj->title = $file->basename();            $obj->path = $file->filename();            $obj->file = $file;            $obj->page = $this->grav['pages']->get(dirname($obj->path));            $fileInfo = pathinfo($obj->title);            $filename = str_replace(['@3x', '@2x'], '', $fileInfo['filename']);            if (isset($fileInfo['extension'])) {                $filename .= '.' . $fileInfo['extension'];            }            if ($obj->page && isset($obj->page->media()[$filename])) {                $obj->metadata = new Data\Data($obj->page->media()[$filename]->metadata());            }            $data[$type] = $obj;        } else {            throw new \RuntimeException("Data type '{$type}' doesn't exist!");        }        return $data[$type];    }    /**     * Clean user form post and remove extra stuff that may be passed along     *     * @param array $post     * @return array     */    public function cleanUserPost($post)    {        // Clean fields for all users        unset($post['hashed_password']);        // Clean field for users who shouldn't be able to modify these fields        if (!$this->authorize(['admin.user', 'admin.super'])) {            unset($post['access'], $post['state']);        }        return $post;    }    protected function hasErrorMessage()    {        $msgs = $this->grav['messages']->all();        foreach ($msgs as $msg) {            if (isset($msg['scope']) && $msg['scope'] === 'error') {                return true;            }        }        return false;    }    /**     * Returns blueprints for the given type.     *     * @param string $type     *     * @return Data\Blueprint     */    public function blueprints($type)    {        if ($this->blueprints === null) {            $this->blueprints = new Data\Blueprints('blueprints://');        }        return $this->blueprints->get($type);    }    /**     * Converts dot notation to array notation.     *     * @param  string $name     *     * @return string     */    public function field($name)    {        $path = explode('.', $name);        return array_shift($path) . ($path ? '[' . implode('][', $path) . ']' : '');    }    /**     * Get all routes.     *     * @param bool $unique     *     * @return array     */    public function routes($unique = false)    {        /** @var Pages $pages */        $pages = $this->grav['pages'];        if ($unique) {            $routes = array_unique($pages->routes());        } else {            $routes = $pages->routes();        }        return $routes;    }    /**     * Count the pages     *     * @return int     */    public function pagesCount()    {        if (!$this->pages_count) {            $this->pages_count = count($this->grav['pages']->all());        }        return $this->pages_count;    }    /**     * Get all template types     *     * @return array     */    public function types()    {        return Pages::types();    }    /**     * Get all modular template types     *     * @return array     */    public function modularTypes()    {        return Pages::modularTypes();    }    /**     * Get all access levels     *     * @return array     */    public function accessLevels()    {        if (method_exists($this->grav['pages'], 'accessLevels')) {            return $this->grav['pages']->accessLevels();        }        return [];    }    public function license($package_slug)    {        return Licenses::get($package_slug);    }    /**     * Generate an array of dependencies for a package, used to generate a list of     * packages that can be removed when removing a package.     *     * @param string $slug The package slug     *     * @return array|bool     */    public function dependenciesThatCanBeRemovedWhenRemoving($slug)    {        $gpm = $this->gpm();        if (!$gpm) {            return false;        }        $dependencies = [];        $package = $this->getPackageFromGPM($slug);        if ($package) {            if ($package->dependencies) {                foreach ($package->dependencies as $dependency) {//                    if (count($gpm->getPackagesThatDependOnPackage($dependency)) > 1) {//                        continue;//                    }                    if (isset($dependency['name'])) {                        $dependency = $dependency['name'];                    }                    if (!in_array($dependency, $dependencies, true)) {                        if (!in_array($dependency, ['admin', 'form', 'login', 'email', 'php'])) {                            $dependencies[] = $dependency;                        }                    }                }            }        }        return $dependencies;    }    /**     * Get the GPM instance     *     * @return GPM The GPM instance     */    public function gpm()    {        if (!$this->gpm) {            try {                $this->gpm = new GPM();            } catch (\Exception $e) {                $this->setMessage($e->getMessage(), 'error');            }        }        return $this->gpm;    }    public function getPackageFromGPM($package_slug)    {        $package = $this->plugins(true)[$package_slug];        if (!$package) {            $package = $this->themes(true)[$package_slug];        }        return $package;    }    /**     * Get all plugins.     *     * @param bool $local     *     * @return mixed     */    public function plugins($local = true)    {        $gpm = $this->gpm();        if (!$gpm) {            return false;        }        if ($local) {            return $gpm->getInstalledPlugins();        }        $plugins = $gpm->getRepositoryPlugins();        if ($plugins) {            return $plugins->filter(function ($package, $slug) use ($gpm) {                return !$gpm->isPluginInstalled($slug);            });        }        return [];    }    /**     * Get all themes.     *     * @param bool $local     *     * @return mixed     */    public function themes($local = true)    {        $gpm = $this->gpm();        if (!$gpm) {            return false;        }        if ($local) {            return $gpm->getInstalledThemes();        }        $themes = $gpm->getRepositoryThemes();        if ($themes) {            return $themes->filter(function ($package, $slug) use ($gpm) {                return !$gpm->isThemeInstalled($slug);            });        }        return [];    }    /**     * Get list of packages that depend on the passed package slug     *     * @param string $slug The package slug     *     * @return array|bool     */    public function getPackagesThatDependOnPackage($slug)    {        $gpm = $this->gpm();        if (!$gpm) {            return false;        }        return $gpm->getPackagesThatDependOnPackage($slug);    }    /**     * Check the passed packages list can be updated     *     * @param array $packages     *     * @throws \Exception     * @return bool     */    public function checkPackagesCanBeInstalled($packages)    {        $gpm = $this->gpm();        if (!$gpm) {            return false;        }        $this->gpm->checkPackagesCanBeInstalled($packages);        return true;    }    /**     * Get an array of dependencies needed to be installed or updated for a list of packages     * to be installed.     *     * @param array $packages The packages slugs     *     * @return array|bool     */    public function getDependenciesNeededToInstall($packages)    {        $gpm = $this->gpm();        if (!$gpm) {            return false;        }        return $this->gpm->getDependencies($packages);    }    /**     * Used by the Dashboard in the admin to display the X latest pages     * that have been modified     *     * @param  integer $count number of pages to pull back     *     * @return array|null     */    public function latestPages($count = 10)    {        /** @var Pages $pages */        $pages = $this->grav['pages'];        $latest = [];        if (null === $pages->routes()) {            return null;        }        foreach ($pages->routes() as $url => $path) {            $page = $pages->dispatch($url, true);            if ($page && $page->routable()) {                $latest[$page->route()] = ['modified' => $page->modified(), 'page' => $page];            }        }        // sort based on modified        uasort($latest, function ($a, $b) {            if ($a['modified'] == $b['modified']) {                return 0;            }            return ($a['modified'] > $b['modified']) ? -1 : 1;        });        // build new array with just pages in it        $list = [];        foreach ($latest as $item) {            $list[] = $item['page'];        }        return array_slice($list, 0, $count);    }    /**     * Get log file for fatal errors.     *     * @return string     */    public function logEntry()    {        $file    = File::instance($this->grav['locator']->findResource("log://{$this->route}.html"));        $content = $file->content();        $file->free();        return $content;    }    /**     * Search in the logs when was the latest backup made     *     * @return array Array containing the latest backup information     */    public function lastBackup()    {        $file    = JsonFile::instance($this->grav['locator']->findResource('log://backup.log'));        $content = $file->content();        if (empty($content)) {            return [                'days'        => '∞',                'chart_fill'  => 100,                'chart_empty' => 0            ];        }        $backup = new \DateTime();        $backup->setTimestamp($content['time']);        $diff = $backup->diff(new \DateTime());        $days       = $diff->days;        $chart_fill = $days > 30 ? 100 : round($days / 30 * 100);        return [            'days'        => $days,            'chart_fill'  => $chart_fill,            'chart_empty' => 100 - $chart_fill        ];    }    /**     * Determine if the plugin or theme info passed is from Team Grav     *     * @param object $info Plugin or Theme info object     *     * @return bool     */    public function isTeamGrav($info)    {        return isset($info['author']['name']) && ($info['author']['name'] === 'Team Grav' || Utils::contains($info['author']['name'], 'Trilby Media'));    }    /**     * Determine if the plugin or theme info passed is premium     *     * @param object $info Plugin or Theme info object     *     * @return bool     */    public function isPremiumProduct($info)    {        return isset($info['premium']);    }    /**     * Renders phpinfo     *     * @return string The phpinfo() output     */    function phpinfo()    {        if (function_exists('phpinfo')) {            ob_start();            phpinfo();            $pinfo = ob_get_contents();            ob_end_clean();            $pinfo = preg_replace('%^.*<body>(.*)</body>.*$%ms', '$1', $pinfo);            return $pinfo;        }        return 'phpinfo() method is not available on this server.';    }    /**     * Guest date format based on euro/US     *     * @param string $date     *     * @return string     */    public function guessDateFormat($date)    {        static $guess;        $date_formats = [            'm/d/y',            'm/d/Y',            'n/d/y',            'n/d/Y',            'd-m-Y',            'd-m-y',        ];        $time_formats = [            'H:i',            'G:i',            'h:ia',            'g:ia'        ];        if (!isset($guess[$date])) {            foreach ($date_formats as $date_format) {                foreach ($time_formats as $time_format) {                    if ($this->validateDate($date, "$date_format $time_format")) {                        $guess[$date] = "$date_format $time_format";                        break 2;                    }                    if ($this->validateDate($date, "$time_format $date_format")) {                        $guess[$date] = "$time_format $date_format";                        break 2;                    }                }            }            if (!isset($guess[$date])) {                $guess[$date] = 'd-m-Y H:i';            }        }        return $guess[$date];    }    public function validateDate($date, $format)    {        $d = DateTime::createFromFormat($format, $date);        return $d && $d->format($format) == $date;    }    /**     * @param string $php_format     *     * @return string     */    public function dateformatToMomentJS($php_format)    {        $SYMBOLS_MATCHING = [            // Day            'd' => 'DD',            'D' => 'ddd',            'j' => 'D',            'l' => 'dddd',            'N' => 'E',            'S' => 'Do',            'w' => 'd',            'z' => 'DDD',            // Week            'W' => 'W',            // Month            'F' => 'MMMM',            'm' => 'MM',            'M' => 'MMM',            'n' => 'M',            't' => '',            // Year            'L' => '',            'o' => 'GGGG',            'Y' => 'YYYY',            'y' => 'yy',            // Time            'a' => 'a',            'A' => 'A',            'B' => 'SSS',            'g' => 'h',            'G' => 'H',            'h' => 'hh',            'H' => 'HH',            'i' => 'mm',            's' => 'ss',            'u' => '',            // Timezone            'e' => '',            'I' => '',            'O' => 'ZZ',            'P' => 'Z',            'T' => 'z',            'Z' => '',            // Full Date/Time            'c' => '',            'r' => 'llll ZZ',            'U' => 'X'        ];        $js_format        = '';        $escaping         = false;        $len = strlen($php_format);        for ($i = 0; $i < $len; $i++) {            $char = $php_format[$i];            if ($char === '\\') // PHP date format escaping character            {                $i++;                if ($escaping) {                    $js_format .= $php_format[$i];                } else {                    $js_format .= '\'' . $php_format[$i];                }                $escaping = true;            } else {                if ($escaping) {                    $js_format .= "'";                    $escaping = false;                }                if (isset($SYMBOLS_MATCHING[$char])) {                    $js_format .= $SYMBOLS_MATCHING[$char];                } else {                    $js_format .= $char;                }            }        }        return $js_format;    }    /**     * Gets the entire permissions array     *     * @return array     */    public function getPermissions()    {        return $this->permissions;    }    /**     * Sets the entire permissions array     *     * @param array $permissions     */    public function setPermissions($permissions)    {        $this->permissions = $permissions;    }    /**     * Adds a permission to the permissions array     *     * @param array $permissions     */    public function addPermissions($permissions)    {        $this->permissions = array_merge($this->permissions, $permissions);    }    public function getNotifications($force = false)    {        $last_checked = null;        $filename = $this->grav['locator']->findResource('user://data/notifications/' . md5($this->grav['user']->username) . YAML_EXT, true, true);        $notifications_file = CompiledYamlFile::instance($filename);        $notifications_content = (array)$notifications_file->content();        $last_checked = $notifications_content['last_checked'] ?? null;        $notifications = $notifications_content['data'] ?? array();        $timeout = $this->grav['config']->get('system.session.timeout', 1800);        if ($force || !$last_checked || empty($notifications) || (time() - $last_checked > $timeout)) {            $body = Response::get('https://getgrav.org/notifications.json?' . time());//            $body = Response::get('http://localhost/notifications.json?' . time());            $notifications = json_decode($body, true);            // Sort by date            usort($notifications, function ($a, $b) {                return strcmp($a['date'], $b['date']);            });            // Reverse order and create a new array            $notifications = array_reverse($notifications);            $cleaned_notifications = [];            foreach ($notifications as $key => $notification) {                if (isset($notification['permissions']) && !$this->authorize($notification['permissions'])) {                    continue;                }                if (isset($notification['dependencies'])) {                    foreach ($notification['dependencies'] as $dependency => $constraints) {                        if ($dependency === 'grav') {                            if (!Semver::satisfies(GRAV_VERSION, $constraints)) {                                continue;                            }                        } else {                            $packages = array_merge($this->plugins()->toArray(), $this->themes()->toArray());                            if (!isset($packages[$dependency])) {                                continue;                            } else {                                $version = $packages[$dependency]['version'];                                if (!Semver::satisfies($version, $constraints)) {                                    continue;                                }                            }                        }                    }                }                $cleaned_notifications[] = $notification;            }            // reset notifications            $notifications = [];            foreach($cleaned_notifications as $notification) {                foreach ($notification['location'] as $location) {                    $notifications = array_merge_recursive($notifications, [$location => [$notification]]);                }            }            $notifications_file->content(['last_checked' => time(), 'data' => $notifications]);            $notifications_file->save();        }        return $notifications;    }    /**     * Get https://getgrav.org news feed     *     * @return mixed     * @throws MalformedXmlException     */    public function getFeed($force = false)    {        $last_checked = null;        $filename = $this->grav['locator']->findResource('user://data/feed/' . md5($this->grav['user']->username) . YAML_EXT, true, true);        $feed_file = CompiledYamlFile::instance($filename);        $feed_content = (array)$feed_file->content();        $last_checked = $feed_content['last_checked'] ?? null;        $feed = $feed_content['data'] ?? array();        $timeout = $this->grav['config']->get('system.session.timeout', 1800);        if ($force || !$last_checked || empty($feed) || ($last_checked && (time() - $last_checked > $timeout))) {            $feed_url = 'https://getgrav.org/blog.atom';            $body = Response::get($feed_url);            $reader = new Reader();            $parser = $reader->getParser($feed_url, $body, 'utf-8');            $data = $parser->execute()->getItems();            // Get top 10            $data = array_slice($data, 0, 10);            $feed = array_map(function ($entry) {                $simple_entry['title'] = $entry->getTitle();                $simple_entry['url'] = $entry->getUrl();                $simple_entry['date'] = $entry->getDate()->getTimestamp();                $simple_entry['nicetime'] = $this->adminNiceTime($simple_entry['date']);                return $simple_entry;            }, $data);            $feed_file->content(['last_checked' => time(), 'data' => $feed]);            $feed_file->save();        }        return $feed;    }    public function adminNiceTime($date, $long_strings = true)    {        if (empty($date)) {            return $this->translate('GRAV.NICETIME.NO_DATE_PROVIDED', null);        }        if ($long_strings) {            $periods = [                'NICETIME.SECOND',                'NICETIME.MINUTE',                'NICETIME.HOUR',                'NICETIME.DAY',                'NICETIME.WEEK',                'NICETIME.MONTH',                'NICETIME.YEAR',                'NICETIME.DECADE'            ];        } else {            $periods = [                'NICETIME.SEC',                'NICETIME.MIN',                'NICETIME.HR',                'NICETIME.DAY',                'NICETIME.WK',                'NICETIME.MO',                'NICETIME.YR',                'NICETIME.DEC'            ];        }        $lengths = ['60', '60', '24', '7', '4.35', '12', '10'];        $now = time();        // check if unix timestamp        if ((string)(int)$date === (string)$date) {            $unix_date = $date;        } else {            $unix_date = strtotime($date);        }        // check validity of date        if (empty($unix_date)) {            return $this->translate('GRAV.NICETIME.BAD_DATE', null);        }        // is it future date or past date        if ($now > $unix_date) {            $difference = $now - $unix_date;            $tense      = $this->translate('GRAV.NICETIME.AGO', null);        } else {            $difference = $unix_date - $now;            $tense      = $this->translate('GRAV.NICETIME.FROM_NOW', null);        }        $len = count($lengths) - 1;        for ($j = 0; $difference >= $lengths[$j] && $j < $len; $j++) {            $difference /= $lengths[$j];        }        $difference = round($difference);        if ($difference !== 1) {            $periods[$j] .= '_PLURAL';        }        if ($this->grav['language']->getTranslation($this->grav['user']->language,            $periods[$j] . '_MORE_THAN_TWO')        ) {            if ($difference > 2) {                $periods[$j] .= '_MORE_THAN_TWO';            }        }        $periods[$j] = $this->translate('GRAV.'.$periods[$j], null);        return "{$difference} {$periods[$j]} {$tense}";    }    public function findFormFields($type, $fields, $found_fields = [])    {        foreach ($fields as $key => $field) {            if (isset($field['type']) && $field['type'] == $type) {                $found_fields[$key] = $field;            } elseif (isset($field['fields'])) {                $result = $this->findFormFields($type, $field['fields'], $found_fields);                if (!empty($result)) {                    $found_fields = array_merge($found_fields, $result);                }            }        }        return $found_fields;    }    public function getPagePathFromToken($path, $page = null)    {        return Utils::getPagePathFromToken($path, $page ?: $this->page(true));    }    /**     * Returns edited page.     *     * @param bool $route     *     * @param null $path     *     * @return PageInterface     */    public function page($route = false, $path = null)    {        if (!$path) {            $path = $this->route;        }        if ($route && !$path) {            $path = '/';        }        if (!isset($this->pages[$path])) {            $this->pages[$path] = $this->getPage($path);        }        return $this->pages[$path];    }    /**     * Returns the page creating it if it does not exist.     *     * @param string $path     *     * @return PageInterface|null     */    public function getPage($path)    {        /** @var Pages $pages */        $pages = $this->grav['pages'];        if ($path && $path[0] !== '/') {            $path = "/{$path}";        }        // Fix for entities in path causing looping...        $path = urldecode($path);        $page = $path ? $pages->dispatch($path, true) : $pages->root();        if (!$page) {            $slug = basename($path);            if ($slug === '') {                return null;            }            $ppath = str_replace('\\', '/', dirname($path));            // Find or create parent(s).            $parent = $this->getPage($ppath !== '/' ? $ppath : '');            // Create page.            $page = new Page();            $page->parent($parent);            $page->filePath($parent->path() . '/' . $slug . '/' . $page->name());            // Add routing information.            $pages->addPage($page, $path);            // Set if Modular            $page->modularTwig($slug[0] === '_');            // Determine page type.            if (isset($this->session->{$page->route()})) {                // Found the type and header from the session.                $data = $this->session->{$page->route()};                // Set the key header value                $header = ['title' => $data['title']];                if (isset($data['visible'])) {                    if ($data['visible'] === '' || $data['visible']) {                        // if auto (ie '')                        $pageParent = $page->parent();                        $children = $pageParent ? $pageParent->children() : [];                        foreach ($children as $child) {                            if ($child->order()) {                                // set page order                                $page->order(AdminController::getNextOrderInFolder($pageParent->path()));                                break;                            }                        }                    }                    if ((int)$data['visible'] === 1 && !$page->order()) {                        $header['visible'] = $data['visible'];                    }                }                if ($data['name'] === 'modular') {                    $header['body_classes'] = 'modular';                }                $name = $page->modular() ? str_replace('modular/', '', $data['name']) : $data['name'];                $page->name($name . '.md');                // Fire new event to allow plugins to manipulate page frontmatter                $this->grav->fireEvent('onAdminCreatePageFrontmatter', new Event(['header' => &$header,                        'data' => $data]));                $page->header($header);                $page->frontmatter(Yaml::dump((array)$page->header(), 20));            } else {                // Find out the type by looking at the parent.                $type = $parent->childType() ?: $parent->blueprints()->get('child_type', 'default');                $page->name($type . CONTENT_EXT);                $page->header();            }        }        return $page;    }    public function generateReports()    {        $reports = new ArrayCollection();        /** @var Pages $pages */        $pages = $this->grav['pages'];        // Default to XSS Security Report        $result = Security::detectXssFromPages($pages, true);        $reports['Grav Security Check'] = $this->grav['twig']->processTemplate('reports/security.html.twig', [            'result' => $result,        ]);        // Linting Issues        $result = YamlLinter::lint();        $reports['Grav Yaml Linter'] = $this->grav['twig']->processTemplate('reports/yamllinter.html.twig', [           'result' => $result,        ]);        // Fire new event to allow plugins to manipulate page frontmatter        $this->grav->fireEvent('onAdminGenerateReports', new Event(['reports' => $reports]));        return $reports;    }    public function getRouteDetails()    {        return [$this->base, $this->location, $this->route];    }    /**     * Get the files list     *     * @param bool $filtered     * @param int $page_index     * @return array|null     * @todo allow pagination     */    public function files($filtered = true, $page_index = 0)    {        $param_type = $this->grav['uri']->param('type');        $param_date = $this->grav['uri']->param('date');        $param_page = $this->grav['uri']->param('page');        $param_page = str_replace('\\', '/', $param_page);        $files_cache_key = 'media-manager-files';        if ($param_type) {            $files_cache_key .= "-{$param_type}";        }        if ($param_date) {            $files_cache_key .= "-{$param_date}";        }        if ($param_page) {            $files_cache_key .= "-{$param_page}";        }        $page_files = null;        $cache_enabled = $this->grav['config']->get('plugins.admin.cache_enabled');        if (!$cache_enabled) {            $this->grav['cache']->setEnabled(true);        }        $page_files = $this->grav['cache']->fetch(md5($files_cache_key));        if (!$cache_enabled) {            $this->grav['cache']->setEnabled(false);        }        if (!$page_files) {            $page_files = [];            $pages = $this->grav['pages'];            if ($param_page) {                $page = $pages->dispatch($param_page);                $page_files = $this->getFiles('images', $page, $page_files, $filtered);                $page_files = $this->getFiles('videos', $page, $page_files, $filtered);                $page_files = $this->getFiles('audios', $page, $page_files, $filtered);                $page_files = $this->getFiles('files', $page, $page_files, $filtered);            } else {                $allPages = $pages->all();                if ($allPages) foreach ($allPages as $page) {                    $page_files = $this->getFiles('images', $page, $page_files, $filtered);                    $page_files = $this->getFiles('videos', $page, $page_files, $filtered);                    $page_files = $this->getFiles('audios', $page, $page_files, $filtered);                    $page_files = $this->getFiles('files', $page, $page_files, $filtered);                }            }            if (count($page_files) >= self::MEDIA_PAGINATION_INTERVAL) {                $this->shouldLoadAdditionalFilesInBackground(true);            }            if (!$cache_enabled) {                $this->grav['cache']->setEnabled(true);            }            $this->grav['cache']->save(md5($files_cache_key), $page_files, 600); //cache for 10 minutes            if (!$cache_enabled) {                $this->grav['cache']->setEnabled(false);            }        }        if (count($page_files) >= self::MEDIA_PAGINATION_INTERVAL) {            $page_files = array_slice($page_files, $page_index * self::MEDIA_PAGINATION_INTERVAL, self::MEDIA_PAGINATION_INTERVAL);        }        return $page_files;    }    public function shouldLoadAdditionalFilesInBackground($status = null)    {        if ($status) {            $this->load_additional_files_in_background = true;        }        return $this->load_additional_files_in_background;    }    public function loadAdditionalFilesInBackground($status = null)    {        if (!$this->loading_additional_files_in_background) {            $this->loading_additional_files_in_background = true;            $this->files(false, false);            $this->shouldLoadAdditionalFilesInBackground(false);            $this->loading_additional_files_in_background = false;        }    }    private function getFiles($type, $page, $page_files, $filtered)    {        $page_files = $this->getMediaOfType($type, $page, $page_files);        if ($filtered) {            $page_files = $this->filterByType($page_files);            $page_files = $this->filterByDate($page_files);        }        return $page_files;    }    /**     * Get all the media of a type ('images' | 'audios' | 'videos' | 'files')     *     * @param string $type     * @param PageInterface|null $page     * @param array $files     *     * @return array     */    private function getMediaOfType($type, ?PageInterface $page, array $files)    {        if ($page) {            $media = $page->media();            $mediaOfType = $media->$type();            foreach($mediaOfType as $title => $file) {                $files[] = [                    'title' => $title,                    'type' => $type,                    'page_route' => $page->route(),                    'file' => $file->higherQualityAlternative()                ];            }            return $files;        }        return [];    }    /**     * Filter media by type     *     * @param array $filesFiltered     *     * @return array     */    private function filterByType($filesFiltered)    {        $filter_type = $this->grav['uri']->param('type');        if (!$filter_type) {            return $filesFiltered;        }        $filesFiltered = array_filter($filesFiltered, function ($file) use ($filter_type) {            return $file['type'] == $filter_type;        });        return $filesFiltered;    }    /**     * Filter media by date     *     * @param array $filesFiltered     *     * @return array     */    private function filterByDate($filesFiltered)    {        $filter_date = $this->grav['uri']->param('date');        if (!$filter_date) {            return $filesFiltered;        }        $year = substr($filter_date, 0, 4);        $month = substr($filter_date, 5, 2);        $filesFilteredByDate = [];        foreach($filesFiltered as $file) {            $filedate = $this->fileDate($file['file']);            $fileYear = $filedate->format('Y');            $fileMonth = $filedate->format('m');            if ($fileYear == $year && $fileMonth == $month) {                $filesFilteredByDate[] = $file;            }        }        return $filesFilteredByDate;    }    /**     * Return the DateTime object representation of a file modified date     *     * @param File $file     *     * @return DateTime     */    private function fileDate($file) {        $datetime = new \DateTime();        $datetime->setTimestamp($file->toArray()['modified']);        return $datetime;    }    /**     * Get the files dates list to be used in the Media Files filter     *     * @return array     */    public function filesDates()    {        $files = $this->files(false);        $dates = [];        foreach ($files as $file) {            $datetime = $this->fileDate($file['file']);            $year = $datetime->format('Y');            $month = $datetime->format('m');            if (!isset($dates[$year])) {                $dates[$year] = [];            }            if (!isset($dates[$year][$month])) {                $dates[$year][$month] = 1;            } else {                $dates[$year][$month]++;            }        }        return $dates;    }    /**     * Get the pages list to be used in the Media Files filter     *     * @return array     */    public function pages()    {        /** @var Collection $pages */        $pages = $this->grav['pages']->all();        $pagesWithFiles = [];        foreach ($pages as $page) {            if (count($page->media()->all())) {                $pagesWithFiles[] = $page;            }        }        return $pagesWithFiles;    }    /**     * Return HTTP_REFERRER if set     *     * @return null     */    public function getReferrer()    {        return $_SERVER['HTTP_REFERER'] ?? null;    }}
 |