123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400 |
- <?php
- namespace Grav\Plugin\Admin;
- use Grav\Common\Cache;
- use Grav\Common\Config\Config;
- use Grav\Common\File\CompiledYamlFile;
- use Grav\Common\Filesystem\Folder;
- use Grav\Common\GPM\GPM as GravGPM;
- use Grav\Common\GPM\Installer;
- use Grav\Common\Grav;
- use Grav\Common\Data;
- use Grav\Common\Page\Media;
- use Grav\Common\Page\Medium\Medium;
- use Grav\Common\Page\Page;
- use Grav\Common\Page\Pages;
- use Grav\Common\Page\Collection;
- use Grav\Common\Security;
- use Grav\Common\User\User;
- use Grav\Common\Utils;
- use Grav\Common\Backup\ZipBackup;
- use Grav\Plugin\Admin\Twig\AdminTwigExtension;
- use Grav\Plugin\Login\TwoFactorAuth\TwoFactorAuth;
- use Grav\Common\Yaml;
- use RocketTheme\Toolbox\Event\Event;
- use RocketTheme\Toolbox\File\File;
- use RocketTheme\Toolbox\File\JsonFile;
- use RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator;
- /**
- * Class AdminController
- *
- * @package Grav\Plugin
- */
- class AdminController extends AdminBaseController
- {
- /**
- * @var Grav
- */
- public $grav;
- /**
- * @var string
- */
- public $view;
- /**
- * @var string
- */
- public $task;
- /**
- * @var string
- */
- public $route;
- /**
- * @var array
- */
- public $post;
- /**
- * @var array|null
- */
- public $data;
- /**
- * @var Admin
- */
- protected $admin;
- /**
- * @var string
- */
- protected $redirect;
- /**
- * @var \Grav\Common\Uri $uri
- */
- protected $uri;
- /**
- * @var int
- */
- protected $redirectCode;
- protected $upload_errors = [
- 0 => "There is no error, the file uploaded with success",
- 1 => "The uploaded file exceeds the max upload size",
- 2 => "The uploaded file exceeds the MAX_FILE_SIZE directive that was specified in the HTML",
- 3 => "The uploaded file was only partially uploaded",
- 4 => "No file was uploaded",
- 6 => "Missing a temporary folder",
- 7 => "Failed to write file to disk",
- 8 => "A PHP extension stopped the file upload"
- ];
- /**
- * @param Grav $grav
- * @param string $view
- * @param string $task
- * @param string $route
- * @param array $post
- */
- public function initialize(Grav $grav = null, $view = null, $task = null, $route = null, $post = null)
- {
- $this->grav = $grav;
- $this->view = $view;
- $this->task = $task ? $task : 'display';
- if (isset($post['data'])) {
- $this->data = $this->getPost($post['data']);
- unset($post['data']);
- } else {
- // Backwards compatibility for Form plugin <= 1.2
- $this->data = $this->getPost($post);
- }
- $this->post = $this->getPost($post);
- $this->route = $route;
- $this->admin = $this->grav['admin'];
- $this->grav->fireEvent('onAdminControllerInit', new Event(['controller' => &$this]));
- }
- /**
- * Handle login.
- *
- * @return bool True if the action was performed.
- */
- protected function taskLogin()
- {
- $this->admin->authenticate($this->data, $this->post);
- return true;
- }
- /**
- * @return bool True if the action was performed.
- */
- protected function taskTwofa()
- {
- $this->admin->twoFa($this->data, $this->post);
- return true;
- }
- /**
- * Handle logout.
- *
- * @return bool True if the action was performed.
- */
- protected function taskLogout()
- {
- $this->admin->logout($this->data, $this->post);
- return true;
- }
- /**
- * @param null $secret
- * @return bool
- */
- public function taskRegenerate2FASecret()
- {
- if (!$this->authorizeTask('regenerate 2FA Secret', ['admin.login'])) {
- return false;
- }
- try {
- /** @var User $user */
- $user = $this->grav['user'];
- /** @var TwoFactorAuth $twoFa */
- $twoFa = $this->grav['login']->twoFactorAuth();
- $secret = $twoFa->createSecret();
- $image = $twoFa->getQrImageData($user->username, $secret);
- // Save secret into the user file.
- $file = $user->file();
- if ($file->exists()) {
- $content = $file->content();
- $content['twofa_secret'] = $secret;
- $file->save($content);
- $file->free();
- }
- // Change secret in the session.
- $user->twofa_secret = $secret;
- $this->admin->json_response = ['status' => 'success', 'image' => $image, 'secret' => preg_replace('|(\w{4})|', '\\1 ', $secret)];
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- return true;
- }
- /**
- * Handle the reset password action.
- *
- * @return bool True if the action was performed.
- */
- public function taskReset()
- {
- $data = $this->data;
- if (isset($data['password'])) {
- $username = isset($data['username']) ? strip_tags(strtolower($data['username'])) : null;
- $user = $username ? User::load($username) : null;
- $password = isset($data['password']) ? $data['password'] : null;
- $token = isset($data['token']) ? $data['token'] : null;
- if ($user && $user->exists() && !empty($user->reset)) {
- list($good_token, $expire) = explode('::', $user->reset);
- if ($good_token === $token) {
- if (time() > $expire) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.RESET_LINK_EXPIRED'), 'error');
- $this->setRedirect('/forgot');
- return true;
- }
- unset($user->hashed_password, $user->reset);
- $user->password = $password;
- $user->validate();
- $user->filter();
- $user->save();
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.RESET_PASSWORD_RESET'), 'info');
- $this->setRedirect('/');
- return true;
- }
- }
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.RESET_INVALID_LINK'), 'error');
- $this->setRedirect('/forgot');
- return true;
- }
- $user = $this->grav['uri']->param('user');
- $token = $this->grav['uri']->param('token');
- if (empty($user) || empty($token)) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.RESET_INVALID_LINK'), 'error');
- $this->setRedirect('/forgot');
- return true;
- }
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.RESET_NEW_PASSWORD'), 'info');
- $this->admin->forgot = ['username' => $user, 'token' => $token];
- return true;
- }
- /**
- * Handle the email password recovery procedure.
- *
- * @return bool True if the action was performed.
- * @todo LOGIN
- */
- protected function taskForgot()
- {
- $param_sep = $this->grav['config']->get('system.param_sep', ':');
- $post = $this->post;
- $data = $this->data;
- $login = $this->grav['login'];
- $username = isset($data['username']) ? strip_tags(strtolower($data['username'])) : '';
- $user = !empty($username) ? User::load($username) : null;
- if (!isset($this->grav['Email'])) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.FORGOT_EMAIL_NOT_CONFIGURED'), 'error');
- $this->setRedirect($post['redirect']);
- return true;
- }
- if (!$user || !$user->exists()) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.FORGOT_INSTRUCTIONS_SENT_VIA_EMAIL'),
- 'info');
- $this->setRedirect($post['redirect']);
- return true;
- }
- if (empty($user->email)) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.FORGOT_INSTRUCTIONS_SENT_VIA_EMAIL'),
- 'info');
- $this->setRedirect($post['redirect']);
- return true;
- }
- $count = $this->grav['config']->get('plugins.login.max_pw_resets_count', 0);
- $interval =$this->grav['config']->get('plugins.login.max_pw_resets_interval', 2);
- if ($login->isUserRateLimited($user, 'pw_resets', $count, $interval)) {
- $this->admin->setMessage($this->admin->translate(['PLUGIN_LOGIN.FORGOT_CANNOT_RESET_IT_IS_BLOCKED', $user->email, $interval]), 'error');
- $this->setRedirect($post['redirect']);
- return true;
- }
- $token = md5(uniqid(mt_rand(), true));
- $expire = time() + 604800; // next week
- $user->reset = $token . '::' . $expire;
- $user->save();
- $author = $this->grav['config']->get('site.author.name', '');
- $fullname = $user->fullname ?: $username;
- $reset_link = rtrim($this->grav['uri']->rootUrl(true), '/') . '/' . trim($this->admin->base,
- '/') . '/reset/task' . $param_sep . 'reset/user' . $param_sep . $username . '/token' . $param_sep . $token . '/admin-nonce' . $param_sep . Utils::getNonce('admin-form');
- $sitename = $this->grav['config']->get('site.title', 'Website');
- $from = $this->grav['config']->get('plugins.email.from');
- if (empty($from)) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.FORGOT_EMAIL_NOT_CONFIGURED'), 'error');
- $this->setRedirect($post['redirect']);
- return true;
- }
- $to = $user->email;
- $subject = $this->admin->translate(['PLUGIN_ADMIN.FORGOT_EMAIL_SUBJECT', $sitename]);
- $content = $this->admin->translate([
- 'PLUGIN_ADMIN.FORGOT_EMAIL_BODY',
- $fullname,
- $reset_link,
- $author,
- $sitename
- ]);
- $body = $this->grav['twig']->processTemplate('email/base.html.twig', ['content' => $content]);
- $message = $this->grav['Email']->message($subject, $body, 'text/html')->setFrom($from)->setTo($to);
- $sent = $this->grav['Email']->send($message);
- if ($sent < 1) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.FORGOT_FAILED_TO_EMAIL'), 'error');
- } else {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.FORGOT_INSTRUCTIONS_SENT_VIA_EMAIL'),
- 'info');
- }
- $this->setRedirect('/');
- return true;
- }
- /**
- * Enable a plugin.
- *
- * @return bool True if the action was performed.
- */
- public function taskEnable()
- {
- if (!$this->authorizeTask('enable plugin', ['admin.plugins', 'admin.super'])) {
- return false;
- }
- if ($this->view !== 'plugins') {
- return false;
- }
- // Filter value and save it.
- $this->post = ['enabled' => true];
- $obj = $this->prepareData($this->post);
- $obj->save();
- $this->post = ['_redirect' => 'plugins'];
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_ENABLED_PLUGIN'), 'info');
- return true;
- }
- /**
- * Gets the configuration data for a given view & post
- *
- * @param array $data
- *
- * @return object
- */
- protected function prepareData(array $data)
- {
- $type = trim("{$this->view}/{$this->admin->route}", '/');
- $data = $this->admin->data($type, $data);
- return $data;
- }
- /**
- * Disable a plugin.
- *
- * @return bool True if the action was performed.
- */
- public function taskDisable()
- {
- if (!$this->authorizeTask('disable plugin', ['admin.plugins', 'admin.super'])) {
- return false;
- }
- if ($this->view !== 'plugins') {
- return false;
- }
- // Filter value and save it.
- $this->post = ['enabled' => false];
- $obj = $this->prepareData($this->post);
- $obj->save();
- $this->post = ['_redirect' => 'plugins'];
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_DISABLED_PLUGIN'), 'info');
- return true;
- }
- /**
- * Set the default theme.
- *
- * @return bool True if the action was performed.
- */
- public function taskActivate()
- {
- if (!$this->authorizeTask('activate theme', ['admin.themes', 'admin.super'])) {
- return false;
- }
- if ($this->view !== 'themes') {
- return false;
- }
- $this->post = ['_redirect' => 'themes'];
- // Make sure theme exists (throws exception)
- $name = $this->route;
- $this->grav['themes']->get($name);
- // Store system configuration.
- $system = $this->admin->data('config/system');
- $system->set('pages.theme', $name);
- $system->save();
- // Force configuration reload and save.
- /** @var Config $config */
- $config = $this->grav['config'];
- $config->reload()->save();
- $config->set('system.pages.theme', $name);
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_CHANGED_THEME'), 'info');
- return true;
- }
- /**
- * Handles updating Grav
- *
- * @return bool False if user has no permissions.
- */
- public function taskUpdategrav()
- {
- if (!$this->authorizeTask('install grav', ['admin.super'])) {
- return false;
- }
- $gpm = Gpm::GPM();
- $version = $gpm->grav->getVersion();
- $result = Gpm::selfupgrade();
- if ($result) {
- $json_response = [
- 'status' => 'success',
- 'type' => 'updategrav',
- 'version' => $version,
- 'message' => $this->admin->translate('PLUGIN_ADMIN.GRAV_WAS_SUCCESSFULLY_UPDATED_TO') . ' ' . $version
- ];
- } else {
- $json_response = [
- 'status' => 'error',
- 'type' => 'updategrav',
- 'version' => GRAV_VERSION,
- 'message' => $this->admin->translate('PLUGIN_ADMIN.GRAV_UPDATE_FAILED') . ' <br>' . Installer::lastErrorMsg()
- ];
- }
- return $this->sendJsonResponse($json_response);
- }
- /**
- * Handles uninstalling plugins and themes
- *
- * @deprecated
- *
- * @return bool True if the action was performed
- */
- public function taskUninstall()
- {
- $type = $this->view === 'plugins' ? 'plugins' : 'themes';
- if (!$this->authorizeTask('uninstall ' . $type, ['admin.' . $type, 'admin.super'])) {
- return false;
- }
- $package = $this->route;
- $result = Gpm::uninstall($package, []);
- if ($result) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.UNINSTALL_SUCCESSFUL'), 'info');
- } else {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.UNINSTALL_FAILED'), 'error');
- }
- $this->post = ['_redirect' => $this->view];
- return true;
- }
- /**
- * Handles creating an empty page folder (without markdown file)
- *
- * @return bool True if the action was performed.
- */
- public function taskSaveNewFolder()
- {
- if (!$this->authorizeTask('save', $this->dataPermissions())) {
- return false;
- }
- $data = (array)$this->data;
- if ($data['route'] === '/') {
- $path = $this->grav['locator']->findResource('page://');
- } else {
- $path = $this->grav['page']->find($data['route'])->path();
- }
- $orderOfNewFolder = $this->getNextOrderInFolder($path);
- $new_path = $path . '/' . $orderOfNewFolder . '.' . $data['folder'];
- Folder::create($new_path);
- Cache::clearCache('standard');
- $this->grav->fireEvent('onAdminAfterSaveAs', new Event(['path' => $new_path]));
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_SAVED'), 'info');
- $multilang = $this->isMultilang();
- $admin_route = $this->admin->base;
- $redirect_url = '/' . ($multilang ? ($this->grav['session']->admin_lang) : '') . $admin_route . '/' . $this->view;
- $this->setRedirect($redirect_url);
- return true;
- }
- /**
- * Get the next available ordering number in a folder
- *
- * @param $path
- *
- * @return string the correct order string to prepend
- */
- public static function getNextOrderInFolder($path)
- {
- $files = Folder::all($path, ['recursive' => false]);
- $highestOrder = 0;
- foreach ($files as $file) {
- preg_match(PAGE_ORDER_PREFIX_REGEX, $file, $order);
- if (isset($order[0])) {
- $theOrder = (int)trim($order[0], '.');
- } else {
- $theOrder = 0;
- }
- if ($theOrder >= $highestOrder) {
- $highestOrder = $theOrder;
- }
- }
- $orderOfNewFolder = $highestOrder + 1;
- if ($orderOfNewFolder < 10) {
- $orderOfNewFolder = '0' . $orderOfNewFolder;
- }
- return $orderOfNewFolder;
- }
- /**
- * Handles form and saves the input data if its valid.
- *
- * @return bool True if the action was performed.
- */
- public function taskSave()
- {
- if (!$this->authorizeTask('save', $this->dataPermissions())) {
- return false;
- }
- $reorder = true;
- $data = (array)$this->data;
- $this->grav['twig']->twig_vars['current_form_data'] = $data;
- // Special handler for user data.
- if ($this->view === 'user') {
- if (!$this->grav['user']->exists()) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.NO_USER_EXISTS'),'error');
- return false;
- }
- if (!$this->admin->authorize(['admin.super', 'admin.users'])) {
- // no user file or not admin.super or admin.users
- if ($this->prepareData($data)->username !== $this->grav['user']->username) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.INSUFFICIENT_PERMISSIONS_FOR_TASK') . ' save.','error');
- return false;
- }
- }
- }
- // Special handler for pages data.
- if ($this->view === 'pages') {
- /** @var Pages $pages */
- $pages = $this->grav['pages'];
- // Find new parent page in order to build the path.
- $route = !isset($data['route']) ? dirname($this->admin->route) : $data['route'];
- /** @var Page $obj */
- $obj = $this->admin->page(true);
- if (!isset($data['folder']) || !$data['folder']) {
- $data['folder'] = $obj->slug();
- $this->data['folder'] = $obj->slug();
- }
- // Ensure route is prefixed with a forward slash.
- $route = '/' . ltrim($route, '/');
- // Check for valid frontmatter
- if (isset($data['frontmatter']) && !$this->checkValidFrontmatter($data['frontmatter'])) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.INVALID_FRONTMATTER_COULD_NOT_SAVE'),
- 'error');
- return false;
- }
- // XSS Checks for page content
- $xss_whitelist = $this->grav['config']->get('security.xss_whitelist', 'admin.super');
- if (!$this->admin->authorize($xss_whitelist)) {
- $check_what = ['header' => isset($data['header']) ? $data['header'] : '', 'frontmatter' => isset($data['frontmatter']) ? $data['frontmatter'] : '', 'content' => isset($data['content']) ? $data['content'] : ''];
- $results = Security::detectXssFromArray($check_what);
- if (!empty($results)) {
- $this->admin->setMessage('<i class="fa fa-ban"></i> ' . $this->admin->translate('PLUGIN_ADMIN.XSS_ONSAVE_ISSUE'),
- 'error');
- return false;
- }
- }
- $parent = $route && $route !== '/' && $route !== '.' && $route !== '/.' ? $pages->dispatch($route, true) : $pages->root();
- $original_order = (int)trim($obj->order(), '.');
- try {
- // Change parent if needed and initialize move (might be needed also on ordering/folder change).
- $obj = $obj->move($parent);
- $this->preparePage($obj, false, $obj->language());
- $obj->validate();
- } catch (\Exception $e) {
- $this->admin->setMessage($e->getMessage(), 'error');
- return false;
- }
- $obj->filter();
- // rename folder based on visible
- if ($original_order === 1000) {
- // increment order to force reshuffle
- $obj->order($original_order + 1);
- }
- if (isset($data['order']) && !empty($data['order'])) {
- $reorder = explode(',', $data['order']);
- }
- // add or remove numeric prefix based on ordering value
- if (isset($data['ordering'])) {
- if ($data['ordering'] && !$obj->order()) {
- $obj->order($this->getNextOrderInFolder($obj->parent()->path()));
- $reorder = false;
- } elseif (!$data['ordering'] && $obj->order()) {
- $obj->folder($obj->slug());
- }
- }
- } else {
- // Handle standard data types.
- $obj = $this->prepareData($data);
- try {
- $obj->validate();
- } catch (\Exception $e) {
- $this->admin->setMessage($e->getMessage(), 'error');
- return false;
- }
- $obj->filter();
- }
- $obj = $this->storeFiles($obj);
- if ($obj) {
- // Event to manipulate data before saving the object
- $this->grav->fireEvent('onAdminSave', new Event(['object' => &$obj]));
- $obj->save($reorder);
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_SAVED'), 'info');
- $this->grav->fireEvent('onAdminAfterSave', new Event(['object' => $obj]));
- }
- if ($this->view !== 'pages') {
- // Force configuration reload.
- /** @var Config $config */
- $config = $this->grav['config'];
- $config->reload();
- if ($this->view === 'user') {
- if ($obj->username === $this->grav['user']->username) {
- //Editing current user. Reload user object
- unset($this->grav['user']->avatar);
- $this->grav['user']->merge(User::load($this->admin->route)->toArray());
- }
- }
- }
- // Always redirect if a page route was changed, to refresh it
- if ($obj instanceof Page) {
- if (method_exists($obj, 'unsetRouteSlug')) {
- $obj->unsetRouteSlug();
- }
- $multilang = $this->isMultilang();
- if ($multilang) {
- if (!$obj->language()) {
- $obj->language($this->grav['session']->admin_lang);
- }
- }
- $admin_route = $this->admin->base;
- $route = $obj->rawRoute();
- $redirect_url = ($multilang ? '/' . $obj->language() : '') . $admin_route . '/' . $this->view . $route;
- $this->setRedirect($redirect_url);
- }
- return true;
- }
- /**
- * @param string $frontmatter
- *
- * @return bool
- */
- public function checkValidFrontmatter($frontmatter)
- {
- try {
- Yaml::parse($frontmatter);
- } catch (\RuntimeException $e) {
- return false;
- }
- return true;
- }
- /**
- * Continue to the new page.
- *
- * @return bool True if the action was performed.
- */
- public function taskContinue()
- {
- $data = (array)$this->data;
- if ($this->view === 'users') {
- $username = strip_tags(strtolower($data['username']));
- $this->setRedirect("{$this->view}/{$username}");
- return true;
- }
- if ($this->view === 'groups') {
- $this->setRedirect("{$this->view}/{$data['groupname']}");
- return true;
- }
- if ($this->view !== 'pages') {
- return false;
- }
- $route = $data['route'] !== '/' ? $data['route'] : '';
- $folder = $data['folder'];
- // Handle @slugify-{field} value, automatically slugifies the specified field
- if (0 === strpos($folder, '@slugify-')) {
- $folder = \Grav\Plugin\Admin\Utils::slug($data[substr($folder, 9)]);
- }
- $folder = ltrim($folder, '_');
- if (!empty($data['modular'])) {
- $folder = '_' . $folder;
- }
- $path = $route . '/' . $folder;
- $this->admin->session()->{$path} = $data;
- // Store the name and route of a page, to be used pre-filled defaults of the form in the future
- $this->admin->session()->lastPageName = $data['name'];
- $this->admin->session()->lastPageRoute = $data['route'];
- $this->setRedirect("{$this->view}/" . ltrim($path, '/'));
- return true;
- }
- /**
- * Toggle the gpm.releases setting
- */
- protected function taskGpmRelease()
- {
- if (!$this->authorizeTask('configuration', ['admin.configuration', 'admin.super'])) {
- return false;
- }
- // Default release state
- $release = 'stable';
- $reload = false;
- // Get the testing release value if set
- if ($this->post['release'] === 'testing') {
- $release = 'testing';
- }
- $config = $this->grav['config'];
- $current_release = $config->get('system.gpm.releases');
- // If the releases setting is different, save it in the system config
- if ($current_release !== $release) {
- $data = new Data\Data($config->get('system'));
- $data->set('gpm.releases', $release);
- // Get the file location
- $file = CompiledYamlFile::instance($this->grav['locator']->findResource('config://system.yaml'));
- $data->file($file);
- // Save the configuration
- $data->save();
- $config->reload();
- $reload = true;
- }
- $this->admin->json_response = ['status' => 'success', 'reload' => $reload];
- return true;
- }
- /**
- * Keep alive
- */
- protected function taskKeepAlive()
- {
- exit();
- }
- protected function taskGetNewsFeed()
- {
- if (!$this->authorizeTask('dashboard', ['admin.login', 'admin.super'])) {
- return false;
- }
- $cache = $this->grav['cache'];
- if ($this->post['refresh'] === 'true') {
- $cache->delete('news-feed');
- }
- $feed_data = $cache->fetch('news-feed');
- if (!$feed_data) {
- try {
- $feed = $this->admin->getFeed();
- if (is_object($feed)) {
- require_once __DIR__ . '/../classes/Twig/AdminTwigExtension.php';
- $adminTwigExtension = new AdminTwigExtension;
- $feed_items = $feed->getItems();
- // Feed should only every contain 10, but just in case!
- if (count($feed_items) > 10) {
- $feed_items = array_slice($feed_items, 0, 10);
- }
- foreach ($feed_items as $item) {
- $datetime = $adminTwigExtension->adminNicetimeFilter($item->getDate()->getTimestamp());
- $feed_data[] = '<li><span class="date">' . $datetime . '</span> <a href="' . $item->getUrl() . '" target="_blank" title="' . str_replace('"',
- '″', $item->getTitle()) . '">' . $item->getTitle() . '</a></li>';
- }
- }
- // cache for 1 hour
- $cache->save('news-feed', $feed_data, 60 * 60);
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- }
- $this->admin->json_response = ['status' => 'success', 'feed_data' => $feed_data];
- return true;
- }
- /**
- * Get update status from GPM
- */
- protected function taskGetUpdates()
- {
- if (!$this->authorizeTask('dashboard', ['admin.login', 'admin.super'])) {
- return false;
- }
- $data = $this->post;
- $flush = (isset($data['flush']) && $data['flush'] == true) ? true : false;
- if (isset($this->grav['session'])) {
- $this->grav['session']->close();
- }
- try {
- $gpm = new GravGPM($flush);
- $resources_updates = $gpm->getUpdatable();
- if ($gpm->grav != null) {
- $grav_updates = [
- 'isUpdatable' => $gpm->grav->isUpdatable(),
- 'assets' => $gpm->grav->getAssets(),
- 'version' => GRAV_VERSION,
- 'available' => $gpm->grav->getVersion(),
- 'date' => $gpm->grav->getDate(),
- 'isSymlink' => $gpm->grav->isSymlink()
- ];
- $this->admin->json_response = [
- 'status' => 'success',
- 'payload' => [
- 'resources' => $resources_updates,
- 'grav' => $grav_updates,
- 'installed' => $gpm->countInstalled(),
- 'flushed' => $flush
- ]
- ];
- } else {
- $this->admin->json_response = ['status' => 'error', 'message' => 'Cannot connect to the GPM'];
- return false;
- }
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- return true;
- }
- /**
- * Get Notifications from cache.
- *
- */
- protected function taskGetNotifications()
- {
- if (!$this->authorizeTask('dashboard', ['admin.login', 'admin.super'])) {
- return false;
- }
- $cache = $this->grav['cache'];
- if (!(bool)$this->grav['config']->get('system.cache.enabled') || !$notifications = $cache->fetch('notifications')) {
- //No notifications cache (first time)
- $this->admin->json_response = ['status' => 'success', 'notifications' => [], 'need_update' => true];
- return true;
- }
- $need_update = false;
- if (!$last_checked = $cache->fetch('notifications_last_checked')) {
- $need_update = true;
- } else {
- if (time() - $last_checked > 86400) {
- $need_update = true;
- }
- }
- try {
- $notifications = $this->admin->processNotifications($notifications);
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- $this->admin->json_response = [
- 'status' => 'success',
- 'notifications' => $notifications,
- 'need_update' => $need_update
- ];
- return true;
- }
- /**
- * Process Notifications. Store the notifications object locally.
- *
- * @return bool
- */
- protected function taskProcessNotifications()
- {
- if (!$this->authorizeTask('notifications', ['admin.login', 'admin.super'])) {
- return false;
- }
- $cache = $this->grav['cache'];
- $data = $this->post;
- $notifications = json_decode($data['notifications']);
- try {
- $notifications = $this->admin->processNotifications($notifications);
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- $show_immediately = false;
- if (!$cache->fetch('notifications_last_checked')) {
- $show_immediately = true;
- }
- $cache->save('notifications', $notifications);
- $cache->save('notifications_last_checked', time());
- $this->admin->json_response = [
- 'status' => 'success',
- 'notifications' => $notifications,
- 'show_immediately' => $show_immediately
- ];
- return true;
- }
- /**
- * Handle getting a new package dependencies needed to be installed
- *
- * @return bool
- */
- protected function taskGetPackagesDependencies()
- {
- $data = $this->post;
- $packages = isset($data['packages']) ? explode(',', $data['packages']) : '';
- $packages = (array)$packages;
- try {
- $this->admin->checkPackagesCanBeInstalled($packages);
- $dependencies = $this->admin->getDependenciesNeededToInstall($packages);
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- $this->admin->json_response = ['status' => 'success', 'dependencies' => $dependencies];
- return true;
- }
- protected function taskInstallDependenciesOfPackages()
- {
- $data = $this->post;
- $packages = isset($data['packages']) ? explode(',', $data['packages']) : '';
- $packages = (array)$packages;
- $type = isset($data['type']) ? $data['type'] : '';
- if (!$this->authorizeTask('install ' . $type, ['admin.' . $type, 'admin.super'])) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.INSUFFICIENT_PERMISSIONS_FOR_TASK')
- ];
- return false;
- }
- try {
- $dependencies = $this->admin->getDependenciesNeededToInstall($packages);
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- $result = Gpm::install(array_keys($dependencies), ['theme' => $type === 'theme']);
- if ($result) {
- $this->admin->json_response = ['status' => 'success', 'message' => 'Dependencies installed successfully'];
- } else {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.INSTALLATION_FAILED')
- ];
- }
- return true;
- }
- protected function taskInstallPackage($reinstall = false)
- {
- $data = $this->post;
- $package = isset($data['package']) ? $data['package'] : '';
- $type = isset($data['type']) ? $data['type'] : '';
- if (!$this->authorizeTask('install ' . $type, ['admin.' . $type, 'admin.super'])) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.INSUFFICIENT_PERMISSIONS_FOR_TASK')
- ];
- return false;
- }
- try {
- $result = Gpm::install($package, ['theme' => $type === 'theme']);
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- if ($result) {
- $this->admin->json_response = [
- 'status' => 'success',
- 'message' => $this->admin->translate(is_string($result) ? $result : sprintf($this->admin->translate($reinstall ?: 'PLUGIN_ADMIN.PACKAGE_X_REINSTALLED_SUCCESSFULLY',
- null), $package))
- ];
- } else {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate($reinstall ?: 'PLUGIN_ADMIN.INSTALLATION_FAILED')
- ];
- }
- return true;
- }
- /**
- * Handle removing a package
- *
- * @return bool
- */
- protected function taskRemovePackage()
- {
- $data = $this->post;
- $package = isset($data['package']) ? $data['package'] : '';
- $type = isset($data['type']) ? $data['type'] : '';
- if (!$this->authorizeTask('uninstall ' . $type, ['admin.' . $type, 'admin.super'])) {
- $json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.INSUFFICIENT_PERMISSIONS_FOR_TASK')
- ];
- return $this->sendJsonResponse($json_response, 403);
- }
- //check if there are packages that have this as a dependency. Abort and show which ones
- $dependent_packages = $this->admin->getPackagesThatDependOnPackage($package);
- if (count($dependent_packages) > 0) {
- if (count($dependent_packages) > 1) {
- $message = 'The installed packages <cyan>' . implode('</cyan>, <cyan>',
- $dependent_packages) . '</cyan> depends on this package. Please remove those first.';
- } else {
- $message = 'The installed package <cyan>' . implode('</cyan>, <cyan>',
- $dependent_packages) . '</cyan> depends on this package. Please remove it first.';
- }
- $json_response = ['status' => 'error', 'message' => $message];
- return $this->sendJsonResponse($json_response, 200);
- }
- try {
- $dependencies = $this->admin->dependenciesThatCanBeRemovedWhenRemoving($package);
- $result = Gpm::uninstall($package, []);
- } catch (\Exception $e) {
- $json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return $this->sendJsonResponse($json_response, 200);
- }
- if ($result) {
- $json_response = [
- 'status' => 'success',
- 'dependencies' => $dependencies,
- 'message' => $this->admin->translate(is_string($result) ? $result : 'PLUGIN_ADMIN.UNINSTALL_SUCCESSFUL')
- ];
- return $this->sendJsonResponse($json_response, 200);
- }
- $json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.UNINSTALL_FAILED')
- ];
- return $this->sendJsonResponse($json_response, 200);
- }
- /**
- * Handle reinstalling a package
- */
- protected function taskReinstallPackage()
- {
- $data = $this->post;
- $slug = isset($data['slug']) ? $data['slug'] : '';
- $type = isset($data['type']) ? $data['type'] : '';
- $package_name = isset($data['package_name']) ? $data['package_name'] : '';
- $current_version = isset($data['current_version']) ? $data['current_version'] : '';
- if (!$this->authorizeTask('install ' . $type, ['admin.' . $type, 'admin.super'])) {
- $json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.INSUFFICIENT_PERMISSIONS_FOR_TASK')
- ];
- $this->sendJsonResponse($json_response, 403);
- }
- $url = "https://getgrav.org/download/{$type}s/$slug/$current_version";
- $result = Gpm::directInstall($url);
- if ($result === true) {
- $this->admin->json_response = [
- 'status' => 'success',
- 'message' => $this->admin->translate(sprintf($this->admin->translate('PLUGIN_ADMIN.PACKAGE_X_REINSTALLED_SUCCESSFULLY',
- null), $package_name))
- ];
- } else {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.REINSTALLATION_FAILED')
- ];
- }
- }
- /**
- * Clear the cache.
- *
- * @return bool True if the action was performed.
- */
- protected function taskClearCache()
- {
- if (!$this->authorizeTask('clear cache', ['admin.cache', 'admin.super', 'admin.maintenance'])) {
- return false;
- }
- // get optional cleartype param
- $clear_type = $this->grav['uri']->param('cleartype');
- if ($clear_type) {
- $clear = $clear_type;
- } else {
- $clear = 'standard';
- }
- $results = Cache::clearCache($clear);
- if (count($results) > 0) {
- $this->admin->json_response = [
- 'status' => 'success',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.CACHE_CLEARED') . ' <br />' . $this->admin->translate('PLUGIN_ADMIN.METHOD') . ': ' . $clear . ''
- ];
- } else {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.ERROR_CLEARING_CACHE')
- ];
- }
- return true;
- }
- /**
- * Clear the cache.
- *
- * @return bool True if the action was performed.
- */
- protected function taskHideNotification()
- {
- if (!$this->authorizeTask('hide notification', ['admin.login'])) {
- return false;
- }
- $notification_id = $this->grav['uri']->param('notification_id');
- if (!$notification_id) {
- $this->admin->json_response = [
- 'status' => 'error'
- ];
- return false;
- }
- $filename = $this->grav['locator']->findResource('user://data/notifications/' . $this->grav['user']->username . YAML_EXT,
- true, true);
- $file = CompiledYamlFile::instance($filename);
- $data = $file->content();
- $data[] = $notification_id;
- $file->save($data);
- $this->admin->json_response = [
- 'status' => 'success'
- ];
- return true;
- }
- /**
- * Handle the backup action
- *
- * @return bool True if the action was performed.
- */
- protected function taskBackup()
- {
- $param_sep = $this->grav['config']->get('system.param_sep', ':');
- if (!$this->authorizeTask('backup', ['admin.maintenance', 'admin.super'])) {
- return false;
- }
- $download = $this->grav['uri']->param('download');
- if ($download) {
- $file = base64_decode(urldecode($download));
- $backups_root_dir = $this->grav['locator']->findResource('backup://', true);
- if (0 !== strpos($file, $backups_root_dir)) {
- header('HTTP/1.1 401 Unauthorized');
- exit();
- }
- Utils::download($file, true);
- }
- $log = JsonFile::instance($this->grav['locator']->findResource("log://backup.log", true, true));
- try {
- $backup = ZipBackup::backup();
- } catch (\Exception $e) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.AN_ERROR_OCCURRED') . '. ' . $e->getMessage()
- ];
- return true;
- }
- $download = urlencode(base64_encode($backup));
- $url = rtrim($this->grav['uri']->rootUrl(false), '/') . '/' . trim($this->admin->base,
- '/') . '/task' . $param_sep . 'backup/download' . $param_sep . $download . '/admin-nonce' . $param_sep . Utils::getNonce('admin-form');
- $log->content([
- 'time' => time(),
- 'location' => $backup
- ]);
- $log->save();
- $this->admin->json_response = [
- 'status' => 'success',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.YOUR_BACKUP_IS_READY_FOR_DOWNLOAD') . '. <a href="' . $url . '" class="button">' . $this->admin->translate('PLUGIN_ADMIN.DOWNLOAD_BACKUP') . '</a>',
- 'toastr' => [
- 'timeOut' => 0,
- 'extendedTimeOut' => 0,
- 'closeButton' => true
- ]
- ];
- return true;
- }
- protected function taskGetChildTypes()
- {
- if (!$this->authorizeTask('get childtypes', ['admin.pages', 'admin.super'])) {
- return false;
- }
- $data = $this->post;
- $rawroute = !empty($data['rawroute']) ? $data['rawroute'] : null;
- if ($rawroute) {
- /** @var Page $page */
- $page = $this->grav['pages']->dispatch($rawroute);
- if ($page) {
- $child_type = $page->childType();
- if (isset($child_type)) {
- $this->admin->json_response = [
- 'status' => 'success',
- 'child_type' => $child_type
- ];
- return true;
- }
- }
- }
- $this->admin->json_response = [
- 'status' => 'success',
- 'child_type' => '',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.NO_CHILD_TYPE')
- ];
- return true;
- }
- /**
- * Handles filtering the page by modular/visible/routable in the pages list.
- */
- protected function taskFilterPages()
- {
- if (!$this->authorizeTask('filter pages', ['admin.pages', 'admin.super'])) {
- return;
- }
- $data = $this->post;
- $flags = !empty($data['flags']) ? array_map('strtolower', explode(',', $data['flags'])) : [];
- $queries = !empty($data['query']) ? explode(',', $data['query']) : [];
- /** @var Collection $collection */
- $collection = $this->grav['pages']->all();
- if (count($flags)) {
- // Filter by state
- $pageStates = [
- 'modular',
- 'nonmodular',
- 'visible',
- 'nonvisible',
- 'routable',
- 'nonroutable',
- 'published',
- 'nonpublished'
- ];
- if (count(array_intersect($pageStates, $flags)) > 0) {
- if (in_array('modular', $flags, true)) {
- $collection = $collection->modular();
- }
- if (in_array('nonmodular', $flags, true)) {
- $collection = $collection->nonModular();
- }
- if (in_array('visible', $flags, true)) {
- $collection = $collection->visible();
- }
- if (in_array('nonvisible', $flags, true)) {
- $collection = $collection->nonVisible();
- }
- if (in_array('routable', $flags, true)) {
- $collection = $collection->routable();
- }
- if (in_array('nonroutable', $flags, true)) {
- $collection = $collection->nonRoutable();
- }
- if (in_array('published', $flags, true)) {
- $collection = $collection->published();
- }
- if (in_array('nonpublished', $flags, true)) {
- $collection = $collection->nonPublished();
- }
- }
- foreach ($pageStates as $pageState) {
- if (($pageState = array_search($pageState, $flags, true)) !== false) {
- unset($flags[$pageState]);
- }
- }
- // Filter by page type
- if ($flags) {
- $types = [];
- $pageTypes = array_keys(Pages::pageTypes());
- foreach ($pageTypes as $pageType) {
- if (($pageKey = array_search($pageType, $flags)) !== false) {
- $types[] = $pageType;
- unset($flags[$pageKey]);
- }
- }
- if (count($types)) {
- $collection = $collection->ofOneOfTheseTypes($types);
- }
- }
- // Filter by page type
- if ($flags) {
- $accessLevels = $flags;
- $collection = $collection->ofOneOfTheseAccessLevels($accessLevels);
- }
- }
- if (!empty($queries)) {
- foreach ($collection as $page) {
- foreach ($queries as $query) {
- $query = trim($query);
- if (stripos($page->getRawContent(), $query) === false && stripos($page->title(),
- $query) === false && stripos($page->slug(), \Grav\Plugin\Admin\Utils::slug($query)) === false && stripos($page->folder(),
- $query) === false
- ) {
- $collection->remove($page);
- }
- }
- }
- }
- $results = [];
- foreach ($collection as $path => $page) {
- $results[] = $page->route();
- }
- $this->admin->json_response = [
- 'status' => 'success',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.PAGES_FILTERED'),
- 'results' => $results
- ];
- $this->admin->collection = $collection;
- }
- /**
- * Determines the file types allowed to be uploaded
- *
- * @return bool True if the action was performed.
- */
- protected function taskListmedia()
- {
- if (!$this->authorizeTask('list media', ['admin.pages', 'admin.super'])) {
- return false;
- }
- $media = $this->getMedia();
- if (!$media) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.NO_PAGE_FOUND')
- ];
- return false;
- }
- $media_list = [];
- /**
- * @var string $name
- * @var Medium $medium
- */
- foreach ($media->all() as $name => $medium) {
- $metadata = [];
- $img_metadata = $medium->metadata();
- if ($img_metadata) {
- $metadata = $img_metadata;
- }
- // Get original name
- $source = $medium->higherQualityAlternative();
- $media_list[$name] = ['url' => $medium->display($medium->get('extension') === 'svg' ? 'source' : 'thumbnail')->cropZoom(400, 300)->url(), 'size' => $medium->get('size'), 'metadata' => $metadata, 'original' => $source->get('filename')];
- }
- $this->admin->json_response = ['status' => 'success', 'results' => $media_list];
- return true;
- }
- /**
- * @return Media
- */
- protected function getMedia()
- {
- $this->uri = $this->uri ?: $this->grav['uri'];
- $uri = $this->uri->post('uri');
- $order = $this->uri->post('order') ?: null;
- if ($uri) {
- /** @var UniformResourceLocator $locator */
- $locator = $this->grav['locator'];
- $media_path = $locator->isStream($uri) ? $uri : null;
- } else {
- $page = $this->admin->page(true);
- $media_path = $page ? $page->path() : null;
- }
- if ($order) {
- $order = array_map('trim', explode(',', $order));
- }
- return $media_path ? new Media($media_path, $order) : null;
- }
- /**
- * Handles adding a media file to a page
- *
- * @return bool True if the action was performed.
- */
- protected function taskAddmedia()
- {
- if (!$this->authorizeTask('add media', ['admin.pages', 'admin.super'])) {
- return false;
- }
- /** @var Config $config */
- $config = $this->grav['config'];
- if (!isset($_FILES['file']['error']) || is_array($_FILES['file']['error'])) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.INVALID_PARAMETERS')
- ];
- return false;
- }
- // Check $_FILES['file']['error'] value.
- switch ($_FILES['file']['error']) {
- case UPLOAD_ERR_OK:
- break;
- case UPLOAD_ERR_NO_FILE:
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.NO_FILES_SENT')
- ];
- return false;
- case UPLOAD_ERR_INI_SIZE:
- case UPLOAD_ERR_FORM_SIZE:
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.EXCEEDED_FILESIZE_LIMIT')
- ];
- return false;
- case UPLOAD_ERR_NO_TMP_DIR:
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.UPLOAD_ERR_NO_TMP_DIR')
- ];
- return false;
- default:
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.UNKNOWN_ERRORS')
- ];
- return false;
- }
- $filename = $_FILES['file']['name'];
- // Handle bad filenames.
- if (!Utils::checkFilename($filename)) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => sprintf($this->admin->translate('PLUGIN_ADMIN.FILEUPLOAD_UNABLE_TO_UPLOAD'),
- $filename, 'Bad filename')
- ];
- return false;
- }
- $grav_limit = $config->get('system.media.upload_limit', 0);
- // You should also check filesize here.
- if ($grav_limit > 0 && $_FILES['file']['size'] > $grav_limit) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.EXCEEDED_GRAV_FILESIZE_LIMIT')
- ];
- return false;
- }
- // Check extension
- $extension = strtolower(pathinfo($filename, PATHINFO_EXTENSION));
- // If not a supported type, return
- if (!$extension || !$config->get("media.types.{$extension}")) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.UNSUPPORTED_FILE_TYPE') . ': ' . $extension
- ];
- return false;
- }
- $media = $this->getMedia();
- if (!$media) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.NO_PAGE_FOUND')
- ];
- return false;
- }
- /** @var UniformResourceLocator $locator */
- $locator = $this->grav['locator'];
- $path = $media->path();
- if ($locator->isStream($path)) {
- $path = $locator->findResource($path, true, true);
- }
- // Upload it
- if (!move_uploaded_file($_FILES['file']['tmp_name'],
- sprintf('%s/%s', $path, $filename))
- ) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.FAILED_TO_MOVE_UPLOADED_FILE')
- ];
- return false;
- }
- // Add metadata if needed
- $include_metadata = Grav::instance()['config']->get('system.media.auto_metadata_exif', false);
- $basename = str_replace(['@3x', '@2x'], '', pathinfo($filename, PATHINFO_BASENAME));
- $metadata = [];
- if ($include_metadata && isset($media[$basename])) {
- $img_metadata = $media[$basename]->metadata();
- if ($img_metadata) {
- $metadata = $img_metadata;
- }
- }
- $page = $this->admin->page(true);
- if ($page) {
- $this->grav->fireEvent('onAdminAfterAddMedia', new Event(['page' => $page]));
- }
- $this->admin->json_response = [
- 'status' => 'success',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.FILE_UPLOADED_SUCCESSFULLY'),
- 'metadata' => $metadata,
- ];
- return true;
- }
- /**
- * Handles deleting a media file from a page
- *
- * @return bool True if the action was performed.
- */
- protected function taskDelmedia()
- {
- if (!$this->authorizeTask('delete media', ['admin.pages', 'admin.super'])) {
- return false;
- }
- $media = $this->getMedia();
- if (!$media) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.NO_PAGE_FOUND')
- ];
- return false;
- }
- $filename = !empty($this->post['filename']) ? $this->post['filename'] : null;
- // Handle bad filenames.
- if (!Utils::checkFilename($filename)) {
- $filename = null;
- }
- if (!$filename) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.NO_FILE_FOUND')
- ];
- return false;
- }
- /** @var UniformResourceLocator $locator */
- $locator = $this->grav['locator'];
- $targetPath = $media->path() . '/' . $filename;
- if ($locator->isStream($targetPath)) {
- $targetPath = $locator->findResource($targetPath, true, true);
- }
- $fileParts = pathinfo($filename);
- $found = false;
- if (file_exists($targetPath)) {
- $found = true;
- $result = unlink($targetPath);
- if (!$result) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.FILE_COULD_NOT_BE_DELETED') . ': ' . $filename
- ];
- return false;
- }
- }
- // Remove Extra Files
- foreach (scandir($media->path(), SCANDIR_SORT_NONE) as $file) {
- if (preg_match("/{$fileParts['filename']}@\d+x\.{$fileParts['extension']}(?:\.meta\.yaml)?$|{$filename}\.meta\.yaml$/", $file)) {
- $targetPath = $media->path() . '/' . $file;
- if ($locator->isStream($targetPath)) {
- $targetPath = $locator->findResource($targetPath, true, true);
- }
- $result = unlink($targetPath);
- if (!$result) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.FILE_COULD_NOT_BE_DELETED') . ': ' . $filename
- ];
- return false;
- }
- $found = true;
- }
- }
- if (!$found) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.FILE_NOT_FOUND') . ': ' . $filename
- ];
- return false;
- }
- $page = $this->admin->page(true);
- if ($page) {
- $this->grav->fireEvent('onAdminAfterDelMedia', new Event(['page' => $page]));
- }
- $this->admin->json_response = [
- 'status' => 'success',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.FILE_DELETED') . ': ' . $filename
- ];
- return true;
- }
- /**
- * Process the page Markdown
- *
- * @return bool True if the action was performed.
- */
- protected function taskProcessMarkdown()
- {
- if (!$this->authorizeTask('process markdown', ['admin.pages', 'admin.super'])) {
- return false;
- }
- try {
- $page = $this->admin->page(true);
- if (!$page) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.NO_PAGE_FOUND')
- ];
- return false;
- }
- $this->preparePage($page, true);
- $page->header();
- $page->templateFormat('html');
- // Add theme template paths to Twig loader
- $template_paths = $this->grav['locator']->findResources('theme://templates');
- $this->grav['twig']->twig->getLoader()->addLoader(new \Twig_Loader_Filesystem($template_paths));
- $html = $page->content();
- $this->admin->json_response = ['status' => 'success', 'preview' => $html];
- } catch (\Exception $e) {
- $this->admin->json_response = ['status' => 'error', 'message' => $e->getMessage()];
- return false;
- }
- return true;
- }
- /**
- * Prepare a page to be stored: update its folder, name, template, header and content
- *
- * @param \Grav\Common\Page\Page $page
- * @param bool $clean_header
- * @param string $language
- */
- protected function preparePage(Page $page, $clean_header = false, $language = '')
- {
- $input = (array)$this->data;
- if (isset($input['folder']) && $input['folder'] !== $page->value('folder')) {
- $order = $page->value('order');
- $ordering = $order ? sprintf('%02d.', $order) : '';
- $page->folder($ordering . $input['folder']);
- }
- if (isset($input['name']) && !empty($input['name'])) {
- $type = strtolower($input['name']);
- $name = preg_replace('|.*/|', '', $type);
- if ($language) {
- $name .= '.' . $language;
- } else {
- $language = $this->grav['language'];
- if ($language->enabled()) {
- $name .= '.' . $language->getLanguage();
- }
- }
- $name .= '.md';
- $page->name($name);
- $page->template($type);
- }
- // Special case for Expert mode: build the raw, unset content
- if (isset($input['frontmatter'], $input['content'])) {
- $page->raw("---\n" . (string)$input['frontmatter'] . "\n---\n" . (string)$input['content']);
- unset($input['content']);
- // Handle header normally
- } elseif (isset($input['header'])) {
- $header = $input['header'];
- foreach ($header as $key => $value) {
- if ($key === 'metadata' && is_array($header[$key])) {
- foreach ($header['metadata'] as $key2 => $value2) {
- if (isset($input['toggleable_header']['metadata'][$key2]) && !$input['toggleable_header']['metadata'][$key2]) {
- $header['metadata'][$key2] = '';
- }
- }
- } elseif ($key === 'taxonomy' && is_array($header[$key])) {
- foreach ($header[$key] as $taxkey => $taxonomy) {
- if (is_array($taxonomy) && count($taxonomy) == 1 && trim($taxonomy[0]) == '') {
- unset($header[$key][$taxkey]);
- }
- }
- } else {
- if (isset($input['toggleable_header'][$key]) && !$input['toggleable_header'][$key]) {
- $header[$key] = null;
- }
- }
- }
- if ($clean_header) {
- $header = Utils::arrayFilterRecursive($header, function ($k, $v) {
- return !(null === $v || $v === '');
- });
- }
- $page->header((object)$header);
- $page->frontmatter(Yaml::dump((array)$page->header()), 20);
- }
- // Fill content last because it also renders the output.
- if (isset($input['content'])) {
- $page->rawMarkdown((string)$input['content']);
- }
- }
- /**
- * Save page as a new copy.
- *
- * @return bool True if the action was performed.
- * @throws \RuntimeException
- */
- protected function taskCopy()
- {
- if (!$this->authorizeTask('copy page', ['admin.pages', 'admin.super'])) {
- return false;
- }
- // Only applies to pages.
- if ($this->view !== 'pages') {
- return false;
- }
- try {
- /** @var Pages $pages */
- $pages = $this->grav['pages'];
- // Get the current page.
- $original_page = $this->admin->page(true);
- // Find new parent page in order to build the path.
- $parent = $original_page->parent() ?: $pages->root();
- // Make a copy of the current page and fill the updated information into it.
- $page = $original_page->copy($parent);
- $order = 0;
- if ($page->order()) {
- $order = $this->getNextOrderInFolder($page->parent()->path());
- }
- // Make sure the header is loaded in case content was set through raw() (expert mode)
- $page->header();
- if ($page->order()) {
- $page->order($order);
- }
- $folder = $this->findFirstAvailable('folder', $page);
- $slug = $this->findFirstAvailable('slug', $page);
- $page->path($page->parent()->path() . DS . $page->order() . $folder);
- $page->route($page->parent()->route() . '/' . $slug);
- $page->rawRoute($page->parent()->rawRoute() . '/' . $slug);
- // Append progressive number to the copied page title
- $match = preg_split('/(\d+)(?!.*\d)/', $original_page->title(), 2, PREG_SPLIT_DELIM_CAPTURE);
- $header = $page->header();
- if (!isset($match[1])) {
- $header->title = $match[0] . ' 2';
- } else {
- $header->title = $match[0] . ((int)$match[1] + 1);
- }
- $page->header($header);
- $page->save(false);
- $redirect = $this->view . $page->rawRoute();
- $header = $page->header();
- if (isset($header->slug)) {
- $match = preg_split('/-(\d+)$/', $header->slug, 2, PREG_SPLIT_DELIM_CAPTURE);
- $header->slug = $match[0] . '-' . (isset($match[1]) ? (int)$match[1] + 1 : 2);
- }
- $page->header($header);
- $page->save();
- $this->grav->fireEvent('onAdminAfterSave', new Event(['page' => $page]));
- // Enqueue message and redirect to new location.
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_COPIED'), 'info');
- $this->setRedirect($redirect);
- } catch (\Exception $e) {
- throw new \RuntimeException('Copying page failed on error: ' . $e->getMessage());
- }
- return true;
- }
- /**
- * Find the first available $item ('slug' | 'folder') for a page
- * Used when copying a page, to determine the first available slot
- *
- * @param string $item
- * @param Page $page
- *
- * @return string The first available slot
- */
- protected function findFirstAvailable($item, $page)
- {
- if (!$page->parent()->children()) {
- return $page->$item();
- }
- $withoutPrefix = function ($string) {
- $match = preg_split('/^[0-9]+\./u', $string, 2, PREG_SPLIT_DELIM_CAPTURE);
- return isset($match[1]) ? $match[1] : $match[0];
- };
- $withoutPostfix = function ($string) {
- $match = preg_split('/-(\d+)$/', $string, 2, PREG_SPLIT_DELIM_CAPTURE);
- return $match[0];
- };
- /* $appendedNumber = function ($string) {
- $match = preg_split('/-(\d+)$/', $string, 2, PREG_SPLIT_DELIM_CAPTURE);
- $append = (isset($match[1]) ? (int)$match[1] + 1 : 2);
- return $append;
- };*/
- $highest = 1;
- $siblings = $page->parent()->children();
- $findCorrectAppendedNumber = function ($item, $page_item, $highest) use (
- $siblings,
- &$findCorrectAppendedNumber,
- &$withoutPrefix
- ) {
- foreach ($siblings as $sibling) {
- if ($withoutPrefix($sibling->$item()) == ($highest === 1 ? $page_item : $page_item . '-' . $highest)) {
- $highest = $findCorrectAppendedNumber($item, $page_item, $highest + 1);
- return $highest;
- }
- }
- return $highest;
- };
- $base = $withoutPrefix($withoutPostfix($page->$item()));
- $return = $base;
- $highest = $findCorrectAppendedNumber($item, $base, $highest);
- if ($highest > 1) {
- $return .= '-' . $highest;
- }
- return $return;
- }
- /**
- * Reorder pages.
- *
- * @return bool True if the action was performed.
- */
- protected function taskReorder()
- {
- if (!$this->authorizeTask('reorder pages', ['admin.pages', 'admin.super'])) {
- return false;
- }
- // Only applies to pages.
- if ($this->view !== 'pages') {
- return false;
- }
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.REORDERING_WAS_SUCCESSFUL'), 'info');
- return true;
- }
- /**
- * Delete page.
- *
- * @return bool True if the action was performed.
- * @throws \RuntimeException
- */
- protected function taskDelete()
- {
- if (!$this->authorizeTask('delete page', ['admin.pages', 'admin.super'])) {
- return false;
- }
- // Only applies to pages.
- if ($this->view !== 'pages') {
- return false;
- }
- try {
- $page = $this->admin->page();
- if (count($page->translatedLanguages()) > 1) {
- $page->file()->delete();
- } else {
- Folder::delete($page->path());
- }
- $this->grav->fireEvent('onAdminAfterDelete', new Event(['page' => $page]));
- Cache::clearCache('standard');
- // Set redirect to either referrer or pages list.
- $redirect = 'pages';
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_DELETED'), 'info');
- $this->setRedirect($redirect);
- } catch (\Exception $e) {
- throw new \RuntimeException('Deleting page failed on error: ' . $e->getMessage());
- }
- return true;
- }
- /**
- * Switch the content language. Optionally redirect to a different page.
- *
- */
- protected function taskSwitchlanguage()
- {
- if (!$this->authorizeTask('switch language', ['admin.pages', 'admin.super'])) {
- return false;
- }
- $data = (array)$this->data;
- if (isset($data['lang'])) {
- $language = $data['lang'];
- } else {
- $language = $this->grav['uri']->param('lang');
- }
- if (isset($data['redirect'])) {
- $redirect = 'pages/' . $data['redirect'];
- } else {
- $redirect = 'pages';
- }
- if ($language) {
- $this->grav['session']->admin_lang = $language ?: 'en';
- }
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_SWITCHED_LANGUAGE'), 'info');
- $admin_route = $this->admin->base;
- $this->setRedirect('/' . $language . $admin_route . '/' . $redirect);
- return true;
- }
- /**
- * Handle direct install.
- */
- protected function taskDirectInstall()
- {
- if (!$this->authorizeTask('install', ['admin.super'])) {
- return false;
- }
- $file_path = isset($this->data['file_path']) ? $this->data['file_path'] : null ;
- if (isset($_FILES['uploaded_file'])) {
- // Check $_FILES['file']['error'] value.
- switch ($_FILES['uploaded_file']['error']) {
- case UPLOAD_ERR_OK:
- break;
- case UPLOAD_ERR_NO_FILE:
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.NO_FILES_SENT'), 'error');
- return false;
- case UPLOAD_ERR_INI_SIZE:
- case UPLOAD_ERR_FORM_SIZE:
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.EXCEEDED_FILESIZE_LIMIT'), 'error');
- return false;
- case UPLOAD_ERR_NO_TMP_DIR:
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.UPLOAD_ERR_NO_TMP_DIR'), 'error');
- return false;
- default:
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.UNKNOWN_ERRORS'), 'error');
- return false;
- }
- $file_path = $_FILES['uploaded_file']['tmp_name'];
- // Handle bad filenames.
- if (!Utils::checkFilename(basename($file_path))) {
- $this->admin->json_response = [
- 'status' => 'error',
- 'message' => $this->admin->translate('PLUGIN_ADMIN.UNKNOWN_ERRORS')
- ];
- return false;
- }
- }
- $result = Gpm::directInstall($file_path);
- if ($result === true) {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.INSTALLATION_SUCCESSFUL'), 'info');
- } else {
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.INSTALLATION_FAILED') . ': ' . $result,
- 'error');
- }
- $this->setRedirect('/tools');
- return true;
- }
- /**
- * Save the current page in a different language. Automatically switches to that language.
- *
- * @return bool True if the action was performed.
- */
- protected function taskSaveas()
- {
- if (!$this->authorizeTask('save', $this->dataPermissions())) {
- return false;
- }
- $data = (array)$this->data;
- $language = $data['lang'];
- if ($language) {
- $this->grav['session']->admin_lang = $language ?: 'en';
- }
- $uri = $this->grav['uri'];
- $obj = $this->admin->page($uri->route());
- $this->preparePage($obj, false, $language);
- $file = $obj->file();
- if ($file) {
- $filename = $this->determineFilenameIncludingLanguage($obj->name(), $language);
- $path = $obj->path() . DS . $filename;
- $aFile = File::instance($path);
- $aFile->save();
- $aPage = new Page();
- $aPage->init(new \SplFileInfo($path), $language . '.md');
- $aPage->header($obj->header());
- $aPage->rawMarkdown($obj->rawMarkdown());
- $aPage->template($obj->template());
- $aPage->validate();
- $aPage->filter();
- $this->grav->fireEvent('onAdminSave', new Event(['page' => &$aPage]));
- $aPage->save();
- $this->grav->fireEvent('onAdminAfterSave', new Event(['page' => $aPage]));
- }
- $this->admin->setMessage($this->admin->translate('PLUGIN_ADMIN.SUCCESSFULLY_SWITCHED_LANGUAGE'), 'info');
- $this->setRedirect('/' . $language . $uri->route());
- return true;
- }
- /**
- * The what should be the new filename when saving as a new language
- *
- * @param string $current_filename the current file name, including .md. Example: default.en.md
- * @param string $language The new language it will be saved as. Example: 'it' or 'en-GB'.
- *
- * @return string The new filename. Example: 'default.it'
- */
- public function determineFilenameIncludingLanguage($current_filename, $language)
- {
- $filename = substr($current_filename, 0, -strlen('.md'));
- if (substr($filename, -3, 1) === '.') {
- $filename = str_replace(substr($filename, -2), $language, $filename);
- } elseif (substr($filename, -6, 1) === '.') {
- $filename = str_replace(substr($filename, -5), $language, $filename);
- } else {
- $filename .= '.' . $language;
- }
- return $filename . '.md';
- }
- }
|