htmly.php 212 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800
  1. <?php
  2. if (!defined('HTMLY')) die('HTMLy');
  3. use PragmaRX\Google2FA\Google2FA;
  4. // Load the configuration file
  5. config('source', $config_file);
  6. // Get search query. Redir to /search/
  7. get_search_query();
  8. // Load the language file
  9. get_language();
  10. // Set the timezone
  11. if (config('timezone')) {
  12. date_default_timezone_set(config('timezone'));
  13. } else {
  14. date_default_timezone_set('Asia/Jakarta');
  15. }
  16. // Publish scheduled post
  17. publish_scheduled();
  18. // Load theme settings
  19. theme_settings();
  20. // The front page of the blog
  21. get('/index', function () {
  22. if (!login()) {
  23. file_cache($_SERVER['REQUEST_URI']);
  24. }
  25. $vroot = rtrim(config('views.root'), '/');
  26. $lt = $vroot . '/layout--front.html.php';
  27. if (file_exists($lt)) {
  28. $layout = 'layout--front';
  29. } else {
  30. $layout = '';
  31. }
  32. if (config('static.frontpage') == 'true') {
  33. $front = get_frontpage();
  34. $pv = $vroot . '/static--front.html.php';
  35. if (file_exists($pv)) {
  36. $pview = 'static--front';
  37. } else {
  38. $pview = 'static';
  39. }
  40. render($pview, array(
  41. 'title' => generate_title('is_front', null),
  42. 'description' => safe_html(strip_tags(blog_description())),
  43. 'canonical' => site_url(),
  44. 'metatags' => generate_meta(null, null),
  45. 'bodyclass' => 'in-front',
  46. 'breadcrumb' => '',
  47. 'p' => $front,
  48. 'static' => $front,
  49. 'type' => 'is_frontpage',
  50. 'is_front' => true
  51. ), $layout);
  52. } else {
  53. $page = from($_GET, 'page');
  54. $page = $page ? (int)$page : 1;
  55. $perpage = config('posts.perpage');
  56. $posts = get_posts(null, $page, $perpage);
  57. $total = count(get_blog_posts());
  58. $pv = $vroot . '/main--front.html.php';
  59. if (file_exists($pv)) {
  60. $pview = 'main--front';
  61. } else {
  62. $pview = 'main';
  63. }
  64. $tblog = new stdClass;
  65. $tblog->title = blog_tagline();
  66. $tblog->url = site_url();
  67. $tblog->count = count(get_blog_posts());
  68. $tblog->description = blog_description();
  69. $tblog->body = $tblog->description;
  70. $tblog->rss = site_url() . 'feed/rss';
  71. $tblog->slug = site_path();
  72. if (empty($posts) || $page < 1) {
  73. // a non-existing page
  74. render('no-posts', array(
  75. 'title' => generate_title('is_front', null),
  76. 'description' => safe_html(strip_tags(blog_description())),
  77. 'canonical' => site_url(),
  78. 'metatags' => generate_meta(null, null),
  79. 'breadcrumb' => '',
  80. 'bodyclass' => 'no-posts',
  81. 'type' => 'is_frontpage',
  82. 'is_front' => true
  83. ), $layout);
  84. die;
  85. }
  86. if ($page > 1) {
  87. $CanonicalPageNum = '?page=' . $page;
  88. } else {
  89. $CanonicalPageNum = NULL;
  90. }
  91. render($pview, array(
  92. 'title' => generate_title('is_front', null),
  93. 'description' => safe_html(strip_tags(blog_description())),
  94. 'canonical' => site_url() . $CanonicalPageNum,
  95. 'metatags' => generate_meta(null, null),
  96. 'page' => $page,
  97. 'posts' => $posts,
  98. 'taxonomy' => $tblog,
  99. 'bodyclass' => 'in-front',
  100. 'breadcrumb' => '',
  101. 'pagination' => has_pagination($total, $perpage, $page),
  102. 'type' => 'is_frontpage',
  103. 'is_front' => true,
  104. 'is_taxonomy' => true
  105. ), $layout);
  106. }
  107. });
  108. // Get submitted login data
  109. post('/login', function () {
  110. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  111. $captcha = config('login.protect.system');
  112. if (is_null($captcha) || $captcha === 'disabled') {
  113. $captcha = true;
  114. } elseif ($captcha === 'cloudflare') {
  115. $captcha = isTurnstile(from($_REQUEST, 'cf-turnstile-response'));
  116. } elseif ($captcha === 'google') {
  117. $captcha = isCaptcha(from($_REQUEST, 'g-recaptcha-response'));
  118. }
  119. $user = from($_REQUEST, 'user');
  120. $pass = from($_REQUEST, 'password');
  121. $mfa_secret = user('mfa_secret', $user);
  122. if ($proper && $captcha && !empty($user) && !empty($pass)) {
  123. if (!is_null($mfa_secret) && $mfa_secret !== "disabled" && config('mfa.state') === 'true') {
  124. config('views.root', 'system/admin/views');
  125. render('login-mfa', array(
  126. 'title' => generate_title('is_default', i18n('Login')),
  127. 'description' => i18n('Login') . ' ' . blog_title(),
  128. 'canonical' => site_url(),
  129. 'metatags' => generate_meta(null, null),
  130. 'username' => $user,
  131. 'password' => $pass,
  132. 'type' => 'is_login',
  133. 'is_login' => true,
  134. 'bodyclass' => 'in-login',
  135. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Login')
  136. ));
  137. } else {
  138. session($user, $pass);
  139. $log = session($user, $pass);
  140. if (!empty($log)) {
  141. config('views.root', 'system/admin/views');
  142. render('login', array(
  143. 'title' => generate_title('is_default', i18n('Login')),
  144. 'description' => i18n('Login') . ' ' . blog_title(),
  145. 'canonical' => site_url(),
  146. 'metatags' => generate_meta(null, null),
  147. 'error' => '<ul>' . $log . '</ul>',
  148. 'type' => 'is_login',
  149. 'is_login' => true,
  150. 'bodyclass' => 'in-login',
  151. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Login')
  152. ));
  153. }
  154. }
  155. } else {
  156. $message['error'] = '';
  157. if (empty($user)) {
  158. $message['error'] .= '<li class="alert alert-danger">' . i18n('User_Error') . '</li>';
  159. }
  160. if (empty($pass)) {
  161. $message['error'] .= '<li class="alert alert-danger">' . i18n('Pass_Error') . '</li>';
  162. }
  163. if (!$proper) {
  164. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  165. }
  166. if (!$captcha) {
  167. $message['error'] .= '<li class="alert alert-danger">' . i18n('Captcha_Error') . '</li>';
  168. }
  169. config('views.root', 'system/admin/views');
  170. render('login', array(
  171. 'title' => generate_title('is_default', i18n('Login')),
  172. 'description' => i18n('Login') . ' ' . blog_title(),
  173. 'canonical' => site_url(),
  174. 'metatags' => generate_meta(null, null),
  175. 'error' => '<ul>' . $message['error'] . '</ul>',
  176. 'username' => $user,
  177. 'password' => $pass,
  178. 'type' => 'is_login',
  179. 'is_login' => true,
  180. 'bodyclass' => 'in-login',
  181. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Login')
  182. ));
  183. }
  184. });
  185. // Verify MFA
  186. post('/login-mfa', function () {
  187. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  188. $user = $_SESSION["mfa_uid"];
  189. $pass = $_SESSION["mfa_pwd"];
  190. $mfacode = from($_REQUEST, 'mfacode');
  191. $mfa_secret = user('mfa_secret', $user);
  192. $google2fa = new Google2FA();
  193. if ($proper && $google2fa->verifyKey($mfa_secret, $mfacode, '1')) {
  194. session($user, $pass);
  195. $log = session($user, $pass);
  196. if (!empty($log)) {
  197. config('views.root', 'system/admin/views');
  198. render('login', array(
  199. 'title' => generate_title('is_default', i18n('Login')),
  200. 'description' => i18n('Login') . ' ' . blog_title(),
  201. 'canonical' => site_url(),
  202. 'metatags' => generate_meta(null, null),
  203. 'error' => '<ul>' . $log . '</ul>',
  204. 'type' => 'is_login',
  205. 'is_login' => true,
  206. 'bodyclass' => 'in-login',
  207. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Login')
  208. ));
  209. }
  210. } else {
  211. $message['error'] = '';
  212. if (!$proper) {
  213. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  214. } else {
  215. $message['error'] .= '<li class="alert alert-danger">' . i18n('MFA_Error') . '</li>';
  216. }
  217. config('views.root', 'system/admin/views');
  218. render('login-mfa', array(
  219. 'title' => generate_title('is_default', i18n('Login')),
  220. 'description' => i18n('Login') . ' ' . blog_title(),
  221. 'canonical' => site_url(),
  222. 'metatags' => generate_meta(null, null),
  223. 'error' => '<ul>' . $message['error'] . '</ul>',
  224. 'username' => $user,
  225. 'password' => $pass,
  226. 'type' => 'is_login',
  227. 'is_login' => true,
  228. 'bodyclass' => 'in-login',
  229. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Login')
  230. ));
  231. }
  232. });
  233. // Show the author page
  234. get('/author/:name', function ($name) {
  235. if (!login()) {
  236. file_cache($_SERVER['REQUEST_URI']);
  237. }
  238. $page = from($_GET, 'page');
  239. $page = $page ? (int)$page : 1;
  240. $perpage = config('profile.perpage');
  241. $total = '';
  242. $posts = get_profile_posts($name, $page, $perpage);
  243. if (!empty($posts)) {
  244. $total = $posts[1];
  245. $posts = $posts[0];
  246. }
  247. $author = get_author($name);
  248. if (isset($author[0])) {
  249. $author = $author[0];
  250. } else {
  251. $userConfig = 'config/users/' . $name . '.ini';
  252. if (file_exists($userConfig) || !empty($posts)) {
  253. $author = default_profile(safe_html(strip_tags($name)));
  254. } else {
  255. not_found();
  256. }
  257. }
  258. $vroot = rtrim(config('views.root'), '/');
  259. $lt = $vroot . '/layout--profile--' . strtolower($name) . '.html.php';
  260. $ls = $vroot . '/layout--profile.html.php';
  261. if (file_exists($lt)) {
  262. $layout = 'layout--profile--' . strtolower($name);
  263. } else if (file_exists($ls)) {
  264. $layout = 'layout--profile';
  265. } else {
  266. $layout = '';
  267. }
  268. $pv = $vroot . '/profile--'. strtolower($name) .'.html.php';
  269. if (file_exists($pv)) {
  270. $pview = 'profile--'. strtolower($name);
  271. } else {
  272. $pview = 'profile';
  273. }
  274. if (empty($posts) || $page < 1) {
  275. render($pview, array(
  276. 'title' => generate_title('is_profile', $author),
  277. 'description' => $author->description,
  278. 'canonical' => $author->url,
  279. 'metatags' => generate_meta('is_profile', $author),
  280. 'page' => $page,
  281. 'posts' => null,
  282. 'about' => $author->about,
  283. 'name' => $author->name,
  284. 'author' => $author,
  285. 'type' => 'is_profile',
  286. 'bodyclass' => 'in-profile author-' . $name,
  287. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Profile_for') . ' ' . $author->name,
  288. 'pagination' => has_pagination($total, $perpage, $page),
  289. 'is_profile' => true
  290. ), $layout);
  291. die;
  292. }
  293. if ($page > 1) {
  294. $CanonicalPageNum = '?page=' . $page;
  295. } else {
  296. $CanonicalPageNum = NULL;
  297. }
  298. render($pview, array(
  299. 'title' => generate_title('is_profile', $author),
  300. 'description' => $author->description,
  301. 'canonical' => $author->url . $CanonicalPageNum,
  302. 'metatags' => generate_meta('is_profile', $author),
  303. 'page' => $page,
  304. 'posts' => $posts,
  305. 'about' => $author->about,
  306. 'name' => $author->name,
  307. 'author' => $author,
  308. 'type' => 'is_profile',
  309. 'bodyclass' => 'in-profile author-' . $name,
  310. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Profile_for') . ' ' . $author->name,
  311. 'pagination' => has_pagination($total, $perpage, $page),
  312. 'is_profile' => true
  313. ), $layout);
  314. });
  315. // Show the RSS feed
  316. get('/author/:name/feed', function ($name) {
  317. header('Content-Type: application/rss+xml');
  318. $posts = array();
  319. $posts = get_profile_posts($name, 1, config('rss.count'));
  320. if ($posts) {
  321. $posts = $posts[0];
  322. }
  323. $author = get_author($name);
  324. if (isset($author[0])) {
  325. $author = $author[0];
  326. } else {
  327. $userConfig = 'config/users/' . $name . '.ini';
  328. if (file_exists($userConfig) || !empty($posts)) {
  329. $author = default_profile(safe_html(strip_tags($name)));
  330. } else {
  331. not_found();
  332. }
  333. }
  334. // Show an RSS feed
  335. echo generate_rss($posts, $author);
  336. });
  337. // Edit the profile
  338. get('/edit/profile', function () {
  339. if (login()) {
  340. config('views.root', 'system/admin/views');
  341. render('edit-page', array(
  342. 'title' => generate_title('is_default', i18n('Edit_profile')),
  343. 'description' => safe_html(strip_tags(blog_description())),
  344. 'canonical' => site_url(),
  345. 'metatags' => generate_meta(null, null),
  346. 'type' => 'is_profile',
  347. 'is_admin' => true,
  348. 'bodyclass' => 'edit-profile',
  349. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; '. i18n('Edit_profile'),
  350. ));
  351. } else {
  352. $login = site_url() . 'login';
  353. header("location: $login");
  354. }
  355. });
  356. // Get submitted data from edit profile page
  357. post('/edit/profile', function () {
  358. if(!login()) {
  359. $login = site_url() . 'login';
  360. header("location: $login");
  361. }
  362. $field = array();
  363. $aField = array();
  364. $field_file = 'content/data/field/profile.json';
  365. if (file_exists($field_file)) {
  366. $aField = json_decode(file_get_contents($field_file, true));
  367. }
  368. if(!empty($aField)) {
  369. foreach ($aField as $af) {
  370. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  371. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  372. } else {
  373. $field[$af->name] = from($_REQUEST, $af->name);
  374. }
  375. }
  376. }
  377. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  378. $user = $_SESSION[site_url()]['user'];
  379. $title = from($_REQUEST, 'title');
  380. $description = from($_REQUEST, 'description');
  381. $image = from($_REQUEST, 'image');
  382. $content = from($_REQUEST, 'content');
  383. if ($proper && !empty($title) && !empty($content)) {
  384. edit_profile($title, $content, $user, $description, $image, $field);
  385. } else {
  386. $message['error'] = '';
  387. if (empty($title)) {
  388. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  389. }
  390. if (empty($content)) {
  391. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  392. }
  393. if (!$proper) {
  394. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  395. }
  396. config('views.root', 'system/admin/views');
  397. render('edit-page', array(
  398. 'title' => generate_title('is_default', 'Edit profile'),
  399. 'description' => safe_html(strip_tags(blog_description())),
  400. 'canonical' => site_url(),
  401. 'metatags' => generate_meta(null, null),
  402. 'error' => '<ul>' . $message['error'] . '</ul>',
  403. 'postTitle' => $title,
  404. 'postContent' => $content,
  405. 'postImage' => $image,
  406. 'type' => 'is_profile',
  407. 'is_admin' => true,
  408. 'bodyclass' => 'edit-profile',
  409. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; Edit profile'
  410. ));
  411. }
  412. });
  413. get('/edit/password', function () {
  414. if (login()) {
  415. config('views.root', 'system/admin/views');
  416. render('edit-password', array(
  417. 'title' => generate_title('is_default', i18n('change_password')),
  418. 'description' => safe_html(strip_tags(blog_description())),
  419. 'canonical' => site_url(),
  420. 'metatags' => generate_meta(null, null),
  421. 'type' => 'is_profile',
  422. 'is_admin' => true,
  423. 'bodyclass' => 'edit-password',
  424. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; '. i18n('change_password'),
  425. ));
  426. } else {
  427. $login = site_url() . 'login';
  428. header("location: $login");
  429. }
  430. });
  431. post('/edit/password', function() {
  432. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  433. if (login() && $proper) {
  434. $username = from($_REQUEST, 'username');
  435. $new_password = from($_REQUEST, 'password');
  436. $user = $_SESSION[site_url()]['user'];
  437. $role = user('role', $user);
  438. $mfa = user('mfa_secret', $user);
  439. $old_password = user('password', $username);
  440. if ($user === $username) {
  441. $file = 'config/users/' . $user . '.ini';
  442. if (file_exists($file)) {
  443. if (!empty($new_password)) {
  444. update_user($user, $new_password, $role, $mfa);
  445. }
  446. }
  447. $redir = site_url() . 'admin';
  448. header("location: $redir");
  449. } else {
  450. $redir = site_url();
  451. header("location: $redir");
  452. }
  453. } else {
  454. $login = site_url() . 'login';
  455. header("location: $login");
  456. }
  457. });
  458. get('/edit/mfa', function () {
  459. if (login()) {
  460. config('views.root', 'system/admin/views');
  461. render('edit-mfa', array(
  462. 'title' => generate_title('is_default', i18n('config_mfa')),
  463. 'description' => safe_html(strip_tags(blog_description())),
  464. 'canonical' => site_url(),
  465. 'metatags' => generate_meta(null, null),
  466. 'type' => 'is_profile',
  467. 'is_admin' => true,
  468. 'bodyclass' => 'edit-mfa',
  469. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; '. i18n('config_mfa'),
  470. ));
  471. } else {
  472. $login = site_url() . 'login';
  473. header("location: $login");
  474. }
  475. });
  476. post('/edit/mfa', function() {
  477. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  478. if (login() && $proper) {
  479. $username = from($_REQUEST, 'username');
  480. $mfa_secret = from($_REQUEST, 'mfa_secret');
  481. $mfacode = from($_REQUEST, 'mfacode');
  482. $user = $_SESSION[site_url()]['user'];
  483. $role = user('role', $user);
  484. $old_password = user('password', $user);
  485. $password = from($_REQUEST, 'password');
  486. $message['error'] = '';
  487. if ($user === $username) {
  488. if (!is_null($mfa_secret) && $mfa_secret !== "disabled") {
  489. $google2fa = new Google2FA();
  490. if ($google2fa->verifyKey($mfa_secret, $mfacode)) {
  491. if (password_verify($password, $old_password)) {
  492. if (!empty($mfa_secret)) {
  493. update_user($user, $password, $role, $mfa_secret);
  494. }
  495. } else {
  496. $message['error'] .= '<li class="alert alert-danger">' . i18n('Pass_Error') . '</li>';
  497. }
  498. } else {
  499. $message['error'] .= '<li class="alert alert-danger">' . i18n('MFA_Error') . '</li>';
  500. }
  501. config('views.root', 'system/admin/views');
  502. render('edit-mfa', array(
  503. 'title' => generate_title('is_default', i18n('config_mfa')),
  504. 'description' => safe_html(strip_tags(blog_description())),
  505. 'canonical' => site_url(),
  506. 'metatags' => generate_meta(null, null),
  507. 'error' => '<ul>' . $message['error'] . '</ul>',
  508. 'type' => 'is_profile',
  509. 'is_admin' => true,
  510. 'bodyclass' => 'edit-mfa',
  511. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; '. i18n('config_mfa'),
  512. ));
  513. } else {
  514. if (password_verify($password, $old_password)) {
  515. update_user($user, $password, $role, 'disabled');
  516. } else {
  517. $message['error'] .= '<li class="alert alert-danger">' . i18n('Pass_Error') . '</li>';
  518. }
  519. config('views.root', 'system/admin/views');
  520. render('edit-mfa', array(
  521. 'title' => generate_title('is_default', i18n('config_mfa')),
  522. 'description' => safe_html(strip_tags(blog_description())),
  523. 'canonical' => site_url(),
  524. 'metatags' => generate_meta(null, null),
  525. 'error' => '<ul>' . $message['error'] . '</ul>',
  526. 'type' => 'is_profile',
  527. 'is_admin' => true,
  528. 'bodyclass' => 'edit-mfa',
  529. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; '. i18n('config_mfa'),
  530. ));
  531. }
  532. } else {
  533. $redir = site_url();
  534. header("location: $redir");
  535. }
  536. } else {
  537. $login = site_url() . 'login';
  538. header("location: $login");
  539. }
  540. });
  541. // Edit the frontpage
  542. get('/edit/frontpage', function () {
  543. $user = $_SESSION[site_url()]['user'];
  544. $role = user('role', $user);
  545. if (login()) {
  546. config('views.root', 'system/admin/views');
  547. if ($role === 'editor' || $role === 'admin') {
  548. render('edit-page', array(
  549. 'title' => generate_title('is_default', 'Edit frontpage'),
  550. 'description' => safe_html(strip_tags(blog_description())),
  551. 'canonical' => site_url(),
  552. 'metatags' => generate_meta(null, null),
  553. 'type' => 'is_frontpage',
  554. 'is_admin' => true,
  555. 'bodyclass' => 'edit-frontpage',
  556. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; Edit frontpage',
  557. ));
  558. } else {
  559. render('denied', array(
  560. 'title' => generate_title('is_default', i18n('Denied')),
  561. 'description' => safe_html(strip_tags(blog_description())),
  562. 'canonical' => site_url(),
  563. 'metatags' => generate_meta(null, null),
  564. 'type' => 'is_frontpage',
  565. 'is_admin' => true,
  566. 'bodyclass' => 'denied',
  567. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  568. ));
  569. }
  570. } else {
  571. $login = site_url() . 'login';
  572. header("location: $login");
  573. }
  574. });
  575. // Get submitted data from edit frontpage
  576. post('/edit/frontpage', function () {
  577. if(!login()) {
  578. $login = site_url() . 'login';
  579. header("location: $login");
  580. }
  581. $field = array();
  582. $aField = array();
  583. $field_file = 'content/data/field/page.json';
  584. if (file_exists($field_file)) {
  585. $aField = json_decode(file_get_contents($field_file, true));
  586. }
  587. if(!empty($aField)) {
  588. foreach ($aField as $af) {
  589. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  590. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  591. } else {
  592. $field[$af->name] = from($_REQUEST, $af->name);
  593. }
  594. }
  595. }
  596. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  597. $user = $_SESSION[site_url()]['user'];
  598. $role = user('role', $user);
  599. $title = from($_REQUEST, 'title');
  600. $content = from($_REQUEST, 'content');
  601. if ($role === 'editor' || $role === 'admin') {
  602. if ($proper && !empty($title) && !empty($content)) {
  603. edit_frontpage($title, $content, $field);
  604. } else {
  605. $message['error'] = '';
  606. if (empty($title)) {
  607. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  608. }
  609. if (empty($content)) {
  610. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  611. }
  612. if (!$proper) {
  613. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  614. }
  615. config('views.root', 'system/admin/views');
  616. render('edit-page', array(
  617. 'title' => generate_title('is_default', 'Edit frontpage'),
  618. 'description' => safe_html(strip_tags(blog_description())),
  619. 'canonical' => site_url(),
  620. 'metatags' => generate_meta(null, null),
  621. 'error' => '<ul>' . $message['error'] . '</ul>',
  622. 'postTitle' => $title,
  623. 'postContent' => $content,
  624. 'type' => 'is_frontpage',
  625. 'is_admin' => true,
  626. 'bodyclass' => 'edit-frontpage',
  627. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; Edit frontpage'
  628. ));
  629. }
  630. } else {
  631. $redir = site_url();
  632. header("location: $redir");
  633. }
  634. });
  635. // Edit the frontpage
  636. get('/front/edit', function () {
  637. if (login()) {
  638. $edit = site_url() . 'edit/frontpage';
  639. header("location: $edit");
  640. } else {
  641. $login = site_url() . 'login';
  642. header("location: $login");
  643. }
  644. });
  645. // Show the "Add content" page
  646. get('/add/content', function () {
  647. if (isset($_GET['type'])) {
  648. $req = _h($_GET['type']);
  649. } else {
  650. $req = 'post';
  651. }
  652. $type = 'is_' . $req;
  653. if (login()) {
  654. config('views.root', 'system/admin/views');
  655. render('add-content', array(
  656. 'title' => generate_title('is_default', i18n('Add_new_post')),
  657. 'description' => safe_html(strip_tags(blog_description())),
  658. 'canonical' => site_url(),
  659. 'metatags' => generate_meta(null, null),
  660. 'type' => $type,
  661. 'is_admin' => true,
  662. 'bodyclass' => 'add-content',
  663. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Add_new_post')
  664. ));
  665. } else {
  666. $login = site_url() . 'login';
  667. header("location: $login");
  668. }
  669. });
  670. // Submitted add post data
  671. post('/add/content', function () {
  672. if(!login()) {
  673. $login = site_url() . 'login';
  674. header("location: $login");
  675. }
  676. $field = array();
  677. $aField = array();
  678. $field_file = 'content/data/field/post.json';
  679. if (file_exists($field_file)) {
  680. $aField = json_decode(file_get_contents($field_file, true));
  681. }
  682. if(!empty($aField)) {
  683. foreach ($aField as $af) {
  684. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  685. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  686. } else {
  687. $field[$af->name] = from($_REQUEST, $af->name);
  688. }
  689. }
  690. }
  691. $is_image = from($_REQUEST, 'is_image');
  692. $is_audio = from($_REQUEST, 'is_audio');
  693. $is_video = from($_REQUEST, 'is_video');
  694. $is_quote = from($_REQUEST, 'is_quote');
  695. $is_link = from($_REQUEST, 'is_link');
  696. $is_post = from($_REQUEST, 'is_post');
  697. if (!empty($is_image)) {
  698. $type = 'is_image';
  699. } elseif (!empty($is_video)) {
  700. $type = 'is_video';
  701. } elseif (!empty($is_link)) {
  702. $type = 'is_link';
  703. } elseif (!empty($is_quote)) {
  704. $type = 'is_quote';
  705. } elseif (!empty($is_audio)) {
  706. $type = 'is_audio';
  707. } elseif (!empty($is_post)) {
  708. $type = 'is_post';
  709. }
  710. $link = from($_REQUEST, 'link');
  711. $image = from($_REQUEST, 'image');
  712. $audio = from($_REQUEST, 'audio');
  713. $video = from($_REQUEST, 'video');
  714. $quote = from($_REQUEST, 'quote');
  715. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  716. $title = from($_REQUEST, 'title');
  717. $tag = from($_REQUEST, 'tag');
  718. $url = from($_REQUEST, 'url');
  719. $content = from($_REQUEST, 'content');
  720. $description = from($_REQUEST, 'description');
  721. $user = $_SESSION[site_url()]['user'];
  722. $draft = from($_REQUEST, 'draft');
  723. $category = from($_REQUEST, 'category');
  724. $date = from($_REQUEST, 'date');
  725. $time = from($_REQUEST, 'time');
  726. $dateTime = null;
  727. if ($date !== null && $time !== null) {
  728. $dateTime = $date . ' ' . $time;
  729. }
  730. if (empty($url)) {
  731. $url = $title;
  732. }
  733. if (empty($is_post) && empty($is_image) && empty($is_video) && empty($is_audio) && empty($is_link) && empty($is_quote)) {
  734. $add = site_url() . 'admin/content';
  735. header("location: $add");
  736. }
  737. if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($is_post)) {
  738. add_content($title, $tag, $url, $content, $user, $draft, $category, 'post', $description, null, $dateTime, null, null, $field);
  739. } elseif ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($image)) {
  740. add_content($title, $tag, $url, $content, $user, $draft, $category, 'image', $description, $image, $dateTime, null, null, $field);
  741. } elseif ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($video)) {
  742. add_content($title, $tag, $url, $content, $user, $draft, $category, 'video', $description, $video, $dateTime, null, null, $field);
  743. } elseif ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($audio)) {
  744. add_content($title, $tag, $url, $content, $user, $draft, $category, 'audio', $description, $audio, $dateTime, null, null, $field);
  745. } elseif ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($quote)) {
  746. add_content($title, $tag, $url, $content, $user, $draft, $category, 'quote', $description, $quote, $dateTime, null, null, $field);
  747. } elseif ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($link)) {
  748. add_content($title, $tag, $url, $content, $user, $draft, $category, 'link', $description, $link, $dateTime, null, null, $field);
  749. } else {
  750. $message['error'] = '';
  751. if (empty($title)) {
  752. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  753. }
  754. if (empty($tag)) {
  755. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_tag') . '</li>';
  756. }
  757. if (empty($content)) {
  758. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  759. }
  760. if (!$proper) {
  761. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  762. }
  763. if (!empty($is_image)) {
  764. if (empty($image)) {
  765. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_image') . '</li>';
  766. }
  767. } elseif (!empty($is_video)) {
  768. if (empty($video)) {
  769. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_video') . '</li>';
  770. }
  771. } elseif (!empty($is_link)) {
  772. if (empty($link)) {
  773. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_link') . '</li>';
  774. }
  775. } elseif (!empty($is_quote)) {
  776. if (empty($quote)) {
  777. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_quote') . '</li>';
  778. }
  779. } elseif (!empty($is_audio)) {
  780. if (empty($audio)) {
  781. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_audio') . '</li>';
  782. }
  783. }
  784. config('views.root', 'system/admin/views');
  785. render('add-content', array(
  786. 'title' => generate_title('is_default', i18n('Add_content')),
  787. 'description' => safe_html(strip_tags(blog_description())),
  788. 'canonical' => site_url(),
  789. 'metatags' => generate_meta(null, null),
  790. 'error' => '<ul>' . $message['error'] . '</ul>',
  791. 'postTitle' => $title,
  792. 'postImage' => $image,
  793. 'postVideo' => $video,
  794. 'postLink' => $link,
  795. 'postQuote' => $quote,
  796. 'postAudio' => $audio,
  797. 'postTag' => $tag,
  798. 'postUrl' => $url,
  799. 'postContent' => $content,
  800. 'type' => $type,
  801. 'is_admin' => true,
  802. 'bodyclass' => 'add-content',
  803. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Add_content')
  804. ));
  805. }
  806. });
  807. // Show the static add page
  808. get('/add/page', function () {
  809. $user = $_SESSION[site_url()]['user'];
  810. $role = user('role', $user);
  811. if (login()) {
  812. config('views.root', 'system/admin/views');
  813. if ($role === 'editor' || $role === 'admin') {
  814. render('add-page', array(
  815. 'title' => generate_title('is_default', i18n('Add_new_page')),
  816. 'description' => safe_html(strip_tags(blog_description())),
  817. 'canonical' => site_url(),
  818. 'metatags' => generate_meta(null, null),
  819. 'type' => 'is_page',
  820. 'is_admin' => true,
  821. 'bodyclass' => 'add-page',
  822. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Add_new_page')
  823. ));
  824. } else {
  825. render('denied', array(
  826. 'title' => generate_title('is_default', i18n('Denied')),
  827. 'description' => safe_html(strip_tags(blog_description())),
  828. 'canonical' => site_url(),
  829. 'metatags' => generate_meta(null, null),
  830. 'type' => 'is_page',
  831. 'is_admin' => true,
  832. 'bodyclass' => 'denied',
  833. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  834. ));
  835. }
  836. } else {
  837. $login = site_url() . 'login';
  838. header("location: $login");
  839. }
  840. });
  841. // Submitted static add page data
  842. post('/add/page', function () {
  843. if(!login()) {
  844. $login = site_url() . 'login';
  845. header("location: $login");
  846. }
  847. $field = array();
  848. $aField = array();
  849. $field_file = 'content/data/field/page.json';
  850. if (file_exists($field_file)) {
  851. $aField = json_decode(file_get_contents($field_file, true));
  852. }
  853. if(!empty($aField)) {
  854. foreach ($aField as $af) {
  855. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  856. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  857. } else {
  858. $field[$af->name] = from($_REQUEST, $af->name);
  859. }
  860. }
  861. }
  862. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  863. $title = from($_REQUEST, 'title');
  864. $url = from($_REQUEST, 'url');
  865. $content = from($_REQUEST, 'content');
  866. $description = from($_REQUEST, 'description');
  867. $draft = from($_REQUEST, 'draft');
  868. $user = $_SESSION[site_url()]['user'];
  869. $role = user('role', $user);
  870. if (empty($url)) {
  871. $url = $title;
  872. }
  873. if ($role === 'editor' || $role === 'admin') {
  874. if ($proper && !empty($title) && !empty($content) && login()) {
  875. add_page($title, $url, $content, $draft, $description, null, null, $field);
  876. } else {
  877. $message['error'] = '';
  878. if (empty($title)) {
  879. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  880. }
  881. if (empty($content)) {
  882. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  883. }
  884. if (!$proper) {
  885. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  886. }
  887. config('views.root', 'system/admin/views');
  888. render('add-page', array(
  889. 'title' => generate_title('is_default', i18n('Add_new_page')),
  890. 'description' => safe_html(strip_tags(blog_description())),
  891. 'canonical' => site_url(),
  892. 'metatags' => generate_meta(null, null),
  893. 'error' => '<ul>' . $message['error'] . '</ul>',
  894. 'postTitle' => $title,
  895. 'postUrl' => $url,
  896. 'postContent' => $content,
  897. 'type' => 'is_page',
  898. 'is_admin' => true,
  899. 'bodyclass' => 'add-page',
  900. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Add_new_page')
  901. ));
  902. }
  903. } else {
  904. $redir = site_url();
  905. header("location: $redir");
  906. }
  907. });
  908. // Autosave
  909. post('/admin/autosave', function () {
  910. if (login()) {
  911. $title = $_REQUEST['title'];
  912. $url = $_REQUEST['url'];
  913. $content = $_REQUEST['content'];
  914. $description = $_REQUEST['description'];
  915. $draft = 'draft';
  916. $posttype = $_REQUEST['posttype'];
  917. $autoSave = $_REQUEST['autoSave'];
  918. $oldfile = $_REQUEST['oldfile'];
  919. $addEdit = $_REQUEST['addEdit'];
  920. $user = $_SESSION[site_url()]['user'];
  921. $role = user('role', $user);
  922. $field = array();
  923. $aField = array();
  924. if ($posttype == 'is_post') {
  925. $field_file = 'content/data/field/post.json';
  926. if (file_exists($field_file)) {
  927. $aField = json_decode(file_get_contents($field_file, true));
  928. }
  929. } elseif ($posttype == 'is_page') {
  930. $field_file = 'content/data/field/page.json';
  931. if (file_exists($field_file)) {
  932. $aField = json_decode(file_get_contents($field_file, true));
  933. }
  934. } elseif ($posttype == 'is_subpage') {
  935. $field_file = 'content/data/field/subpage.json';
  936. if (file_exists($field_file)) {
  937. $aField = json_decode(file_get_contents($field_file, true));
  938. }
  939. }
  940. if(!empty($aField)) {
  941. foreach ($aField as $af) {
  942. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  943. $field[$af->name] = !empty($_REQUEST[$af->name]) ? "checked" : '';
  944. } else {
  945. $field[$af->name] = from($_REQUEST, $af->name);
  946. }
  947. }
  948. }
  949. if (empty($url)) {
  950. $url = $title;
  951. }
  952. if ($addEdit == 'edit') {
  953. $revertPage = '';
  954. $revertPost = '';
  955. $publishDraft = '';
  956. $destination = null;
  957. }
  958. if (!empty($title) && !empty($content)) {
  959. if ($posttype == 'is_page') {
  960. if ($role === 'editor' || $role === 'admin') {
  961. if ($addEdit == 'add') {
  962. $response = add_page($title, $url, $content, $draft, $description, $autoSave, $oldfile, $field);
  963. } else {
  964. $response = edit_page($title, $url, $content, $oldfile, $revertPage, $publishDraft, $destination, $description, null, $autoSave, $field);
  965. }
  966. }
  967. } elseif ($posttype == 'is_subpage') {
  968. if ($role === 'editor' || $role === 'admin') {
  969. $static = $_REQUEST['parent_page'];
  970. if ($addEdit == 'add') {
  971. $response = add_sub_page($title, $url, $content, $static, $draft, $description, $autoSave, $oldfile, $field);
  972. } else {
  973. $response = edit_page($title, $url, $content, $oldfile, $revertPage, $publishDraft, $destination, $description, $static, $autoSave, $field);
  974. }
  975. }
  976. } else {
  977. $tag = $_REQUEST['tag'];
  978. $category = $_REQUEST['category'];
  979. $dateTime = $_REQUEST['dateTime'];
  980. if ($posttype == 'is_image') {
  981. $type = 'image';
  982. $media = $_REQUEST['pimage'];
  983. } elseif ($posttype == 'is_video') {
  984. $type = 'video';
  985. $media = $_REQUEST['pvideo'];
  986. } elseif ($posttype == 'is_link') {
  987. $type = 'link';
  988. $media = $_REQUEST['plink'];
  989. } elseif ($posttype == 'is_quote') {
  990. $type = 'quote';
  991. $media = $_REQUEST['pquote'];
  992. } elseif ($posttype == 'is_audio') {
  993. $type = 'audio';
  994. $media = $_REQUEST['paudio'];
  995. } elseif ($posttype == 'is_post') {
  996. $type = 'post';
  997. $media = null;
  998. }
  999. if ($type == 'post') {
  1000. if (!empty($title) && !empty($tag) && !empty($content)) {
  1001. if ($addEdit == 'add') {
  1002. $response = add_content($title, $tag, $url, $content, $user, $draft, $category, $type, $description, $media, $dateTime, $autoSave, $oldfile, $field);
  1003. } else {
  1004. $arr = explode('/', $oldfile);
  1005. if ($user === $arr[1] || $role === 'editor' || $role === 'admin') {
  1006. $response = edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, $type, $destination, $description, $dateTime, $media, $autoSave, $field);
  1007. }
  1008. }
  1009. } else {
  1010. $response = json_encode(array('message' => '<strong>Cannot save draft!</strong><br>Please fill in all required fields', 'file' => ''));
  1011. }
  1012. } else {
  1013. if (!empty($title) && !empty($tag) && !empty($content) && !empty($media)) {
  1014. if ($addEdit == 'add') {
  1015. $response = add_content($title, $tag, $url, $content, $user, $draft, $category, $type, $description, $media, $dateTime, $autoSave, $oldfile, $field);
  1016. } else {
  1017. $arr = explode('/', $oldfile);
  1018. if ($user === $arr[1] || $role === 'editor' || $role === 'admin') {
  1019. $response = edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, $type, $destination, $description, $dateTime, $media, $autoSave, $field);
  1020. }
  1021. }
  1022. } else {
  1023. $response = json_encode(array('message' => '<strong>Cannot save draft!</strong><br>Please fill in all required fields', 'file' => ''));
  1024. }
  1025. }
  1026. }
  1027. } else {
  1028. $response = json_encode(array('message' => '<strong>Cannot save draft!</strong><br>Please fill in all required fields', 'file' => ''));
  1029. }
  1030. header('Content-Type: application/json');
  1031. echo $response;
  1032. } else {
  1033. error(401, "Not logged in");
  1034. }
  1035. });
  1036. // Show the add category
  1037. get('/add/category', function () {
  1038. $user = $_SESSION[site_url()]['user'];
  1039. $role = user('role', $user);
  1040. if (login()) {
  1041. config('views.root', 'system/admin/views');
  1042. if ($role === 'editor' || $role === 'admin') {
  1043. render('add-page', array(
  1044. 'title' => generate_title('is_default', i18n('Add_category')),
  1045. 'description' => safe_html(strip_tags(blog_description())),
  1046. 'canonical' => site_url(),
  1047. 'metatags' => generate_meta(null, null),
  1048. 'type' => 'is_category',
  1049. 'is_admin' => true,
  1050. 'bodyclass' => 'add-category',
  1051. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Add_category')
  1052. ));
  1053. } else {
  1054. render('denied', array(
  1055. 'title' => generate_title('is_default', i18n('Denied')),
  1056. 'description' => safe_html(strip_tags(blog_description())),
  1057. 'canonical' => site_url(),
  1058. 'metatags' => generate_meta(null, null),
  1059. 'type' => 'is_category',
  1060. 'is_admin' => true,
  1061. 'bodyclass' => 'denied',
  1062. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  1063. ));
  1064. }
  1065. } else {
  1066. $login = site_url() . 'login';
  1067. header("location: $login");
  1068. }
  1069. });
  1070. // Submitted add category
  1071. post('/add/category', function () {
  1072. if(!login()) {
  1073. $login = site_url() . 'login';
  1074. header("location: $login");
  1075. }
  1076. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  1077. $title = from($_REQUEST, 'title');
  1078. $url = from($_REQUEST, 'url');
  1079. $content = from($_REQUEST, 'content');
  1080. $description = from($_REQUEST, 'description');
  1081. $user = $_SESSION[site_url()]['user'];
  1082. $role = user('role', $user);
  1083. if (empty($url)) {
  1084. $url = $title;
  1085. }
  1086. if ($role === 'editor' || $role === 'admin') {
  1087. if ($proper && !empty($title) && !empty($content)) {
  1088. add_category($title, $url, $content, $description);
  1089. } else {
  1090. $message['error'] = '';
  1091. if (empty($title)) {
  1092. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  1093. }
  1094. if (empty($content)) {
  1095. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  1096. }
  1097. if (!$proper) {
  1098. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  1099. }
  1100. config('views.root', 'system/admin/views');
  1101. render('add-page', array(
  1102. 'title' => generate_title('is_default', i18n('Add_category')),
  1103. 'description' => safe_html(strip_tags(blog_description())),
  1104. 'canonical' => site_url(),
  1105. 'metatags' => generate_meta(null, null),
  1106. 'error' => '<ul>' . $message['error'] . '</ul>',
  1107. 'postTitle' => $title,
  1108. 'postUrl' => $url,
  1109. 'postContent' => $content,
  1110. 'type' => 'is_category',
  1111. 'is_admin' => true,
  1112. 'bodyclass' => 'add-category',
  1113. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Add_category')
  1114. ));
  1115. }
  1116. } else {
  1117. $redir = site_url();
  1118. header("location: $redir");
  1119. }
  1120. });
  1121. // Show admin/posts
  1122. get('/admin/posts', function () {
  1123. $user = $_SESSION[site_url()]['user'];
  1124. $role = user('role', $user);
  1125. if (login()) {
  1126. config('views.root', 'system/admin/views');
  1127. if ($role === 'editor' || $role === 'admin') {
  1128. config('views.root', 'system/admin/views');
  1129. $page = from($_GET, 'page');
  1130. $page = $page ? (int)$page : 1;
  1131. $perpage = 20;
  1132. $posts = get_posts(null, $page, $perpage);
  1133. $total = count(get_blog_posts());
  1134. if (empty($posts) || $page < 1) {
  1135. // a non-existing page
  1136. render('no-posts', array(
  1137. 'title' => generate_title('is_default', i18n('All_blog_posts')),
  1138. 'description' => safe_html(strip_tags(blog_description())),
  1139. 'canonical' => site_url(),
  1140. 'metatags' => generate_meta(null, null),
  1141. 'bodyclass' => 'no-posts',
  1142. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('All_blog_posts')
  1143. ));
  1144. die;
  1145. }
  1146. render('posts-list', array(
  1147. 'title' => generate_title('is_default', i18n('All_blog_posts')),
  1148. 'description' => safe_html(strip_tags(blog_description())),
  1149. 'canonical' => site_url(),
  1150. 'metatags' => generate_meta(null, null),
  1151. 'heading' => i18n('All_blog_posts'),
  1152. 'page' => $page,
  1153. 'posts' => $posts,
  1154. 'bodyclass' => 'all-posts',
  1155. 'type' => 'is_admin-posts',
  1156. 'is_admin' => true,
  1157. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('All_blog_posts'),
  1158. 'pagination' => has_pagination($total, $perpage, $page)
  1159. ));
  1160. } else {
  1161. render('denied', array(
  1162. 'title' => generate_title('is_default', i18n('All_blog_posts')),
  1163. 'description' => safe_html(strip_tags(blog_description())),
  1164. 'canonical' => site_url(),
  1165. 'metatags' => generate_meta(null, null),
  1166. 'type' => 'is_admin-posts',
  1167. 'is_admin' => true,
  1168. 'bodyclass' => 'denied',
  1169. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('All_blog_posts')
  1170. ));
  1171. }
  1172. } else {
  1173. $login = site_url() . 'login';
  1174. header("location: $login");
  1175. }
  1176. });
  1177. // Show admin/popular
  1178. get('/admin/popular', function () {
  1179. $user = $_SESSION[site_url()]['user'];
  1180. $role = user('role', $user);
  1181. if (login()) {
  1182. config('views.root', 'system/admin/views');
  1183. if ($role === 'editor' || $role === 'admin') {
  1184. config('views.root', 'system/admin/views');
  1185. $page = from($_GET, 'page');
  1186. $page = $page ? (int)$page : 1;
  1187. $perpage = 20;
  1188. $posts = popular_posts(true,$perpage);
  1189. $total = '';
  1190. if (empty($posts) || $page < 1) {
  1191. // a non-existing page
  1192. render('no-posts', array(
  1193. 'title' => generate_title('is_default', i18n('Popular_posts')),
  1194. 'description' => safe_html(strip_tags(blog_description())),
  1195. 'canonical' => site_url(),
  1196. 'metatags' => generate_meta(null, null),
  1197. 'is_admin' => true,
  1198. 'bodyclass' => 'admin-popular',
  1199. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Popular_posts')
  1200. ));
  1201. die;
  1202. }
  1203. render('popular-posts', array(
  1204. 'title' => generate_title('is_default', i18n('Popular_posts')),
  1205. 'description' => safe_html(strip_tags(blog_description())),
  1206. 'canonical' => site_url(),
  1207. 'metatags' => generate_meta(null, null),
  1208. 'heading' => i18n('Popular_posts'),
  1209. 'page' => $page,
  1210. 'posts' => $posts,
  1211. 'is_admin' => true,
  1212. 'bodyclass' => 'admin-popular',
  1213. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Popular_posts'),
  1214. 'pagination' => has_pagination($total, $perpage, $page)
  1215. ));
  1216. } else {
  1217. render('denied', array(
  1218. 'title' => generate_title('is_default', i18n('Popular_posts')),
  1219. 'description' => safe_html(strip_tags(blog_description())),
  1220. 'canonical' => site_url(),
  1221. 'metatags' => generate_meta(null, null),
  1222. 'is_admin' => true,
  1223. 'bodyclass' => 'denied',
  1224. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Popular_posts')
  1225. ));
  1226. }
  1227. } else {
  1228. $login = site_url() . 'login';
  1229. header("location: $login");
  1230. }
  1231. });
  1232. // Show admin/mine
  1233. get('/admin/mine', function () {
  1234. if (login()) {
  1235. config('views.root', 'system/admin/views');
  1236. $name = $_SESSION[site_url()]['user'];
  1237. $page = from($_GET, 'page');
  1238. $page = $page ? (int)$page : 1;
  1239. $perpage = config('profile.perpage');
  1240. $total = '';
  1241. $posts = get_profile_posts($name, $page, $perpage);
  1242. if (!empty($posts)) {
  1243. $total = $posts[1];
  1244. $posts = $posts[0];
  1245. }
  1246. $author = get_author($name);
  1247. if (isset($author[0])) {
  1248. $author = $author[0];
  1249. } else {
  1250. $author = default_profile($name);
  1251. }
  1252. if (empty($posts) || $page < 1) {
  1253. render('user-posts', array(
  1254. 'title' => generate_title('is_default', i18n('My_posts')),
  1255. 'description' => safe_html(strip_tags(blog_description())),
  1256. 'canonical' => site_url(),
  1257. 'metatags' => generate_meta(null, null),
  1258. 'page' => $page,
  1259. 'heading' => i18n('My_posts'),
  1260. 'posts' => null,
  1261. 'about' => $author->about,
  1262. 'name' => $author->name,
  1263. 'type' => 'is_admin-mine',
  1264. 'is_admin' => true,
  1265. 'bodyclass' => 'admin-mine',
  1266. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('My_posts') . ': '. $author->name,
  1267. 'pagination' => has_pagination($total, $perpage, $page)
  1268. ));
  1269. die;
  1270. }
  1271. render('user-posts', array(
  1272. 'title' => generate_title('is_default', i18n('My_posts')),
  1273. 'description' => safe_html(strip_tags(blog_description())),
  1274. 'canonical' => site_url(),
  1275. 'metatags' => generate_meta(null, null),
  1276. 'heading' => i18n('My_posts'),
  1277. 'page' => $page,
  1278. 'posts' => $posts,
  1279. 'about' => $author->about,
  1280. 'name' => $author->name,
  1281. 'type' => 'is_admin-mine',
  1282. 'is_admin' => true,
  1283. 'bodyclass' => 'admin-mine',
  1284. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('My_posts') . ': '. $author->name,
  1285. 'pagination' => has_pagination($total, $perpage, $page)
  1286. ));
  1287. } else {
  1288. $login = site_url() . 'login';
  1289. header("location: $login");
  1290. }
  1291. });
  1292. // Show admin/draft
  1293. get('/admin/draft', function () {
  1294. if (login()) {
  1295. config('views.root', 'system/admin/views');
  1296. $name = $_SESSION[site_url()]['user'];
  1297. $page = from($_GET, 'page');
  1298. $page = $page ? (int)$page : 1;
  1299. $perpage = config('profile.perpage');
  1300. $total = '';
  1301. $posts = get_draft($name, $page, $perpage);
  1302. if (!empty($posts)) {
  1303. $total = $posts[1];
  1304. $posts = $posts[0];
  1305. }
  1306. $draftPages = find_draft_page();
  1307. $draftSubpages = find_draft_subpage();
  1308. $author = get_author($name);
  1309. if (isset($author[0])) {
  1310. $author = $author[0];
  1311. } else {
  1312. $author = default_profile($name);
  1313. }
  1314. if (empty($posts) || $page < 1) {
  1315. render('user-draft', array(
  1316. 'title' => generate_title('is_default', i18n('My_draft')),
  1317. 'description' => safe_html(strip_tags(blog_description())),
  1318. 'canonical' => site_url(),
  1319. 'metatags' => generate_meta(null, null),
  1320. 'page' => $page,
  1321. 'heading' => i18n('My_draft'),
  1322. 'posts' => null,
  1323. 'draftPages' => $draftPages,
  1324. 'draftSubpages' => $draftSubpages,
  1325. 'about' => $author->about,
  1326. 'name' => $author->name,
  1327. 'type' => 'is_admin-draft',
  1328. 'is_admin' => true,
  1329. 'bodyclass' => 'admin-draft',
  1330. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('My_draft'). ': ' . $author->name,
  1331. 'pagination' => has_pagination($total, $perpage, $page)
  1332. ));
  1333. die;
  1334. }
  1335. render('user-draft', array(
  1336. 'title' => generate_title('is_default', i18n('My_draft')),
  1337. 'description' => safe_html(strip_tags(blog_description())),
  1338. 'canonical' => site_url(),
  1339. 'metatags' => generate_meta(null, null),
  1340. 'heading' => i18n('My_draft'),
  1341. 'page' => $page,
  1342. 'posts' => $posts,
  1343. 'draftPages' => $draftPages,
  1344. 'draftSubpages' => $draftSubpages,
  1345. 'about' => $author->about,
  1346. 'name' => $author->name,
  1347. 'type' => 'is_admin-draft',
  1348. 'is_admin' => true,
  1349. 'bodyclass' => 'admin-draft',
  1350. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('My_draft') . ': ' . $author->name,
  1351. 'pagination' => has_pagination($total, $perpage, $page)
  1352. ));
  1353. } else {
  1354. $login = site_url() . 'login';
  1355. header("location: $login");
  1356. }
  1357. });
  1358. // Show admin/scheduled
  1359. get('/admin/scheduled', function () {
  1360. if (login()) {
  1361. config('views.root', 'system/admin/views');
  1362. $name = $_SESSION[site_url()]['user'];
  1363. $page = from($_GET, 'page');
  1364. $page = $page ? (int)$page : 1;
  1365. $perpage = config('profile.perpage');
  1366. $total = '';
  1367. $posts = get_scheduled($name, $page, $perpage);
  1368. if (!empty($posts)) {
  1369. $total = $posts[1];
  1370. $posts = $posts[0];
  1371. }
  1372. $author = get_author($name);
  1373. if (isset($author[0])) {
  1374. $author = $author[0];
  1375. } else {
  1376. $author = default_profile($name);
  1377. }
  1378. if (empty($posts) || $page < 1) {
  1379. render('scheduled', array(
  1380. 'title' => generate_title('is_default', i18n('Scheduled_posts')),
  1381. 'description' => safe_html(strip_tags(blog_description())),
  1382. 'canonical' => site_url(),
  1383. 'metatags' => generate_meta(null, null),
  1384. 'page' => $page,
  1385. 'heading' => i18n('Scheduled_posts'),
  1386. 'posts' => null,
  1387. 'about' => $author->about,
  1388. 'name' => $author->name,
  1389. 'type' => 'is_admin-scheduled',
  1390. 'is_admin' => true,
  1391. 'bodyclass' => 'admin-scheduled',
  1392. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Scheduled_posts') . ': ' . $author->name,
  1393. 'pagination' => has_pagination($total, $perpage, $page)
  1394. ));
  1395. die;
  1396. }
  1397. render('scheduled', array(
  1398. 'title' => generate_title('is_default', i18n('Scheduled_posts')),
  1399. 'description' => safe_html(strip_tags(blog_description())),
  1400. 'canonical' => site_url(),
  1401. 'metatags' => generate_meta(null, null),
  1402. 'heading' => i18n('Scheduled_posts'),
  1403. 'page' => $page,
  1404. 'posts' => $posts,
  1405. 'about' => $author->about,
  1406. 'name' => $author->name,
  1407. 'type' => 'is_admin-scheduled',
  1408. 'is_admin' => true,
  1409. 'bodyclass' => 'admin-scheduled',
  1410. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Scheduled_posts') . ': ' . $author->name,
  1411. 'pagination' => has_pagination($total, $perpage, $page)
  1412. ));
  1413. } else {
  1414. $login = site_url() . 'login';
  1415. header("location: $login");
  1416. }
  1417. });
  1418. // Show admin/content
  1419. get('/admin/content', function () {
  1420. if (login()) {
  1421. config('views.root', 'system/admin/views');
  1422. render('content-type', array(
  1423. 'title' => generate_title('is_default', i18n('Add_content')),
  1424. 'description' => safe_html(strip_tags(blog_description())),
  1425. 'canonical' => site_url(),
  1426. 'metatags' => generate_meta(null, null),
  1427. 'type' => 'is_admin-content',
  1428. 'is_admin' => true,
  1429. 'bodyclass' => 'admin-content',
  1430. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Add_content')
  1431. ));
  1432. } else {
  1433. $login = site_url() . 'login';
  1434. header("location: $login");
  1435. }
  1436. });
  1437. // Show admin/pages
  1438. get('/admin/pages', function () {
  1439. $user = $_SESSION[site_url()]['user'];
  1440. $role = user('role', $user);
  1441. if (login()) {
  1442. config('views.root', 'system/admin/views');
  1443. if ($role === 'editor' || $role === 'admin') {
  1444. render('static-pages', array(
  1445. 'title' => generate_title('is_default', i18n('Static_pages')),
  1446. 'description' => safe_html(strip_tags(blog_description())),
  1447. 'canonical' => site_url(),
  1448. 'metatags' => generate_meta(null, null),
  1449. 'type' => 'is_admin-pages',
  1450. 'is_admin' => true,
  1451. 'bodyclass' => 'admin-pages',
  1452. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Static_pages')
  1453. ));
  1454. } else {
  1455. render('denied', array(
  1456. 'title' => generate_title('is_default', i18n('Denied')),
  1457. 'description' => safe_html(strip_tags(blog_description())),
  1458. 'canonical' => site_url(),
  1459. 'metatags' => generate_meta(null, null),
  1460. 'type' => 'is_admin-config',
  1461. 'is_admin' => true,
  1462. 'bodyclass' => 'denied',
  1463. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  1464. ));
  1465. }
  1466. } else {
  1467. $login = site_url() . 'login';
  1468. header("location: $login");
  1469. }
  1470. });
  1471. post('/admin/pages', function () {
  1472. if (login()) {
  1473. $user = $_SESSION[site_url()]['user'];
  1474. $role = user('role', $user);
  1475. if ($role === 'editor' || $role === 'admin') {
  1476. $json = $_REQUEST['json'];
  1477. reorder_pages($json);
  1478. echo json_encode(array(
  1479. 'message' => 'Page order saved successfully!',
  1480. ));
  1481. }
  1482. }
  1483. });
  1484. // Show admin/pages
  1485. get('/admin/pages/:static', function ($static)
  1486. {
  1487. $user = $_SESSION[site_url()]['user'];
  1488. $role = user('role', $user);
  1489. if (login()) {
  1490. config('views.root', 'system/admin/views');
  1491. if ($role === 'editor' || $role === 'admin') {
  1492. $post = find_page($static);
  1493. if (!$post) {
  1494. not_found();
  1495. }
  1496. if (array_key_exists('prev', $post)) {
  1497. $prev = $post['prev'];
  1498. } else {
  1499. $prev = array();
  1500. }
  1501. if (array_key_exists('next', $post)) {
  1502. $next = $post['next'];
  1503. } else {
  1504. $next = array();
  1505. }
  1506. $post = $post['current'];
  1507. render('static-subpages', array(
  1508. 'title' => generate_title('is_default', $post->title),
  1509. 'description' => $post->description,
  1510. 'canonical' => $post->url,
  1511. 'metatags' => generate_meta(null, null),
  1512. 'bodyclass' => 'in-page ' . strtolower($static),
  1513. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . '<a href="'. site_url() .'admin/pages">' .i18n('pages').'</a> &#187; ' . $post->title,
  1514. 'p' => $post,
  1515. 'static' => $post,
  1516. 'type' => 'is_subpage',
  1517. 'prev' => static_prev($prev),
  1518. 'next' => static_next($next),
  1519. 'is_page' => true
  1520. ));
  1521. } else {
  1522. render('denied', array(
  1523. 'title' => generate_title('is_default', 'Pages'),
  1524. 'description' => safe_html(strip_tags(blog_description())),
  1525. 'canonical' => site_url(),
  1526. 'metatags' => generate_meta(null, null),
  1527. 'type' => 'is_subpage',
  1528. 'is_admin' => true,
  1529. 'bodyclass' => 'denied',
  1530. 'breadcrumb' => '',
  1531. ));
  1532. }
  1533. } else {
  1534. $login = site_url() . 'login';
  1535. }
  1536. });
  1537. post('/admin/pages/:static', function ($static) {
  1538. if (login()) {
  1539. $user = $_SESSION[site_url()]['user'];
  1540. $role = user('role', $user);
  1541. if ($role === 'editor' || $role === 'admin') {
  1542. $json = $_REQUEST['json'];
  1543. reorder_subpages($json);
  1544. echo json_encode(array(
  1545. 'message' => 'Page order saved successfully!',
  1546. ));
  1547. }
  1548. }
  1549. });
  1550. // Show import page
  1551. get('/admin/import', function () {
  1552. $user = $_SESSION[site_url()]['user'];
  1553. $role = user('role', $user);
  1554. if (login()) {
  1555. config('views.root', 'system/admin/views');
  1556. if ($role === 'admin') {
  1557. render('import', array(
  1558. 'title' => generate_title('is_default', i18n('Import_Feed')),
  1559. 'description' => safe_html(strip_tags(blog_description())),
  1560. 'canonical' => site_url(),
  1561. 'metatags' => generate_meta(null, null),
  1562. 'type' => 'is_admin-import',
  1563. 'is_admin' => true,
  1564. 'bodyclass' => 'admin-import',
  1565. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Import_Feed')
  1566. ));
  1567. } else {
  1568. render('denied', array(
  1569. 'title' => generate_title('is_default', i18n('Denied')),
  1570. 'description' => safe_html(strip_tags(blog_description())),
  1571. 'canonical' => site_url(),
  1572. 'metatags' => generate_meta(null, null),
  1573. 'type' => 'is_admin-import',
  1574. 'is_admin' => true,
  1575. 'bodyclass' => 'denied',
  1576. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  1577. ));
  1578. }
  1579. } else {
  1580. $login = site_url() . 'login';
  1581. header("location: $login");
  1582. }
  1583. die;
  1584. });
  1585. // Submitted import page data
  1586. post('/admin/import', function () {
  1587. if(!login()) {
  1588. $login = site_url() . 'login';
  1589. header("location: $login");
  1590. }
  1591. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  1592. $url = from($_REQUEST, 'url');
  1593. $credit = from($_REQUEST, 'credit');
  1594. $user = $_SESSION[site_url()]['user'];
  1595. $role = user('role', $user);
  1596. if ($role === 'admin') {
  1597. if (!empty($url) && $proper) {
  1598. get_feed($url, $credit);
  1599. $log = get_feed($url, $credit);
  1600. if (!empty($log)) {
  1601. config('views.root', 'system/admin/views');
  1602. render('import', array(
  1603. 'title' => generate_title('is_default', i18n('Import_Feed')),
  1604. 'description' => safe_html(strip_tags(blog_description())),
  1605. 'canonical' => site_url(),
  1606. 'metatags' => generate_meta(null, null),
  1607. 'error' => '<ul>' . $log . '</ul>',
  1608. 'type' => 'is_admin-import',
  1609. 'is_admin' => true,
  1610. 'bodyclass' => 'admin-import',
  1611. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Import_Feed')
  1612. ));
  1613. }
  1614. } else {
  1615. $message['error'] = '';
  1616. if (empty($url)) {
  1617. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_feedurl') . '</li>';
  1618. }
  1619. if (!$proper) {
  1620. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  1621. }
  1622. config('views.root', 'system/admin/views');
  1623. render('import', array(
  1624. 'title' => generate_title('is_default', i18n('Import_Feed')),
  1625. 'description' => safe_html(strip_tags(blog_description())),
  1626. 'canonical' => site_url(),
  1627. 'metatags' => generate_meta(null, null),
  1628. 'error' => '<ul>' . $message['error'] . '</ul>',
  1629. 'url' => $url,
  1630. 'type' => 'is_admin-import',
  1631. 'is_admin' => true,
  1632. 'bodyclass' => 'admin-import',
  1633. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Import_Feed')
  1634. ));
  1635. }
  1636. } else {
  1637. $redir = site_url();
  1638. header("location: $redir");
  1639. }
  1640. });
  1641. // Show admin/search
  1642. get('/admin/search', function () {
  1643. $user = $_SESSION[site_url()]['user'];
  1644. $role = user('role', $user);
  1645. config('views.root', 'system/admin/views');
  1646. if (login()) {
  1647. if ($role === 'editor' || $role === 'admin' && config('fulltext.search') == "true") {
  1648. $page = from($_GET, 'page');
  1649. $page = $page ? (int)$page : 1;
  1650. $perpage = 40;
  1651. $tmp = array();
  1652. $search = array();
  1653. $total = '';
  1654. $searchFile = "content/data/search.json";
  1655. if (file_exists($searchFile)) {
  1656. $search = json_decode(file_get_contents($searchFile), true);
  1657. }
  1658. $posts = get_blog_posts();
  1659. foreach ($posts as $index => $v) {
  1660. $arr = explode('_', $v['filename']);
  1661. if (!isset($search['post_' . $arr[2]])) {
  1662. $tmp[] = $v;
  1663. }
  1664. }
  1665. if (!empty($tmp)) {
  1666. $posts = get_posts($tmp, $page, $perpage);
  1667. $total = count($tmp);
  1668. }
  1669. if (empty($tmp) || $page < 1) {
  1670. render('search', array(
  1671. 'title' => generate_title('is_default', i18n('search_index')),
  1672. 'heading' => i18n('search_index'),
  1673. 'description' => safe_html(strip_tags(blog_description())),
  1674. 'canonical' => site_url(),
  1675. 'metatags' => generate_meta(null, null),
  1676. 'bodyclass' => 'no-posts',
  1677. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('search_index')
  1678. ));
  1679. die;
  1680. }
  1681. render('search', array(
  1682. 'title' => generate_title('is_default', i18n('search_index')),
  1683. 'description' => safe_html(strip_tags(blog_description())),
  1684. 'canonical' => site_url(),
  1685. 'metatags' => generate_meta(null, null),
  1686. 'heading' => i18n('search_index'),
  1687. 'page' => $page,
  1688. 'posts' => $posts,
  1689. 'bodyclass' => 'all-index-posts',
  1690. 'type' => 'is_admin-index-posts',
  1691. 'is_admin' => true,
  1692. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('search_index'),
  1693. 'pagination' => has_pagination($total, $perpage, $page)
  1694. ));
  1695. } else {
  1696. render('denied', array(
  1697. 'title' => generate_title('is_default', i18n('search_index')),
  1698. 'description' => safe_html(strip_tags(blog_description())),
  1699. 'canonical' => site_url(),
  1700. 'metatags' => generate_meta(null, null),
  1701. 'type' => 'is_admin-index-posts',
  1702. 'is_admin' => true,
  1703. 'bodyclass' => 'denied',
  1704. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('search_index')
  1705. ));
  1706. }
  1707. } else {
  1708. $login = site_url() . 'login';
  1709. header("location: $login");
  1710. }
  1711. });
  1712. post('/admin/search', function () {
  1713. if (login()) {
  1714. $user = $_SESSION[site_url()]['user'];
  1715. $role = user('role', $user);
  1716. if ($role === 'editor' || $role === 'admin') {
  1717. $json = $_REQUEST['json'];
  1718. if ($json == 'content/data/search.json') {
  1719. unlink($json);
  1720. }
  1721. echo json_encode(array(
  1722. 'message' => 'Search Index cleared successfully!',
  1723. ));
  1724. }
  1725. }
  1726. });
  1727. post('/admin/search/reindex', function () {
  1728. if (login()) {
  1729. $user = $_SESSION[site_url()]['user'];
  1730. $role = user('role', $user);
  1731. $search = json_decode(htmlspecialchars_decode($_POST['search_index']));
  1732. config('views.root', 'system/admin/views');
  1733. if ($role === 'editor' || $role === 'admin' && config('fulltext.search') == "true") {
  1734. render('search-reindex', array(
  1735. 'title' => generate_title('is_default', i18n('search_index')),
  1736. 'description' => safe_html(strip_tags(blog_description())),
  1737. 'canonical' => site_url(),
  1738. 'metatags' => generate_meta(null, null),
  1739. 'type' => 'is_admin-search',
  1740. 'search' => $search,
  1741. 'is_admin' => true,
  1742. 'bodyclass' => 'admin-search',
  1743. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('search_index')
  1744. ));
  1745. }
  1746. }
  1747. });
  1748. // Show Config page
  1749. get('/admin/config', function () {
  1750. $user = $_SESSION[site_url()]['user'];
  1751. $role = user('role', $user);
  1752. if (login()) {
  1753. config('views.root', 'system/admin/views');
  1754. if ($role === 'admin') {
  1755. render('config', array(
  1756. 'title' => generate_title('is_default', i18n('Config')),
  1757. 'description' => safe_html(strip_tags(blog_description())),
  1758. 'canonical' => site_url(),
  1759. 'metatags' => generate_meta(null, null),
  1760. 'type' => 'is_admin-config',
  1761. 'is_admin' => true,
  1762. 'bodyclass' => 'admin-config',
  1763. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1764. ));
  1765. } else {
  1766. render('denied', array(
  1767. 'title' => generate_title('is_default', i18n('Config')),
  1768. 'description' => safe_html(strip_tags(blog_description())),
  1769. 'canonical' => site_url(),
  1770. 'metatags' => generate_meta(null, null),
  1771. 'type' => 'is_admin-config',
  1772. 'is_admin' => true,
  1773. 'bodyclass' => 'denied',
  1774. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1775. ));
  1776. }
  1777. } else {
  1778. $login = site_url() . 'login';
  1779. header("location: $login");
  1780. }
  1781. die;
  1782. });
  1783. // Submitted Config page data
  1784. post('/admin/config', function () {
  1785. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  1786. if (login() && $proper) {
  1787. $user = $_SESSION[site_url()]['user'];
  1788. $role = user('role', $user);
  1789. if ($role === 'admin') {
  1790. $new_config = array();
  1791. $new_Keys = array();
  1792. foreach ($_POST as $name => $value) {
  1793. if (substr($name, 0, 8) == "-config-") {
  1794. $name = str_replace("_", ".", substr($name, 8));
  1795. if(!is_null(config($name))) {
  1796. $new_config[$name] = $value;
  1797. } else {
  1798. $new_Keys[$name] = $value;
  1799. }
  1800. }
  1801. }
  1802. save_config($new_config, $new_Keys);
  1803. foreach (glob('cache/widget/archive*.cache', GLOB_NOSORT) as $file) {
  1804. unlink($file);
  1805. }
  1806. $redir = site_url() . 'admin/config';
  1807. header("location: $redir");
  1808. } else {
  1809. $redir = site_url();
  1810. header("location: $redir");
  1811. }
  1812. } else {
  1813. $login = site_url() . 'login';
  1814. header("location: $login");
  1815. }
  1816. });
  1817. // Show Config page
  1818. get('/admin/config/custom', function () {
  1819. $user = $_SESSION[site_url()]['user'];
  1820. $role = user('role', $user);
  1821. if (login()) {
  1822. config('views.root', 'system/admin/views');
  1823. if ($role === 'admin') {
  1824. render('config-custom', array(
  1825. 'title' => generate_title('is_default', i18n('Config')),
  1826. 'description' => safe_html(strip_tags(blog_description())),
  1827. 'canonical' => site_url(),
  1828. 'metatags' => generate_meta(null, null),
  1829. 'type' => 'is_admin-config',
  1830. 'is_admin' => true,
  1831. 'bodyclass' => 'admin-config',
  1832. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1833. ));
  1834. } else {
  1835. render('denied', array(
  1836. 'title' => generate_title('is_default', i18n('Config')),
  1837. 'description' => safe_html(strip_tags(blog_description())),
  1838. 'canonical' => site_url(),
  1839. 'metatags' => generate_meta(null, null),
  1840. 'type' => 'is_admin-config',
  1841. 'is_admin' => true,
  1842. 'bodyclass' => 'denied',
  1843. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1844. ));
  1845. }
  1846. } else {
  1847. $login = site_url() . 'login';
  1848. header("location: $login");
  1849. }
  1850. });
  1851. // Submitted Config page data
  1852. post('/admin/config/custom', function () {
  1853. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  1854. if (login() && $proper) {
  1855. $user = $_SESSION[site_url()]['user'];
  1856. $role = user('role', $user);
  1857. if ($role === 'admin') {
  1858. $newKey = from($_REQUEST, 'newKey');
  1859. $newValue = from($_REQUEST, 'newValue');
  1860. $new_config = array();
  1861. $new_Keys = array();
  1862. if (!empty($newKey)) {
  1863. $new_Keys[$newKey] = $newValue;
  1864. }
  1865. foreach ($_POST as $name => $value) {
  1866. if (substr($name, 0, 8) == "-config-") {
  1867. $name = str_replace("_", ".", substr($name, 8));
  1868. $new_config[$name] = $value;
  1869. }
  1870. }
  1871. save_config($new_config, $new_Keys);
  1872. $redir = site_url() . 'admin/config/custom';
  1873. header("location: $redir");
  1874. } else {
  1875. $redir = site_url();
  1876. header("location: $redir");
  1877. }
  1878. } else {
  1879. $login = site_url() . 'login';
  1880. header("location: $login");
  1881. }
  1882. });
  1883. // Show Config page
  1884. get('/admin/config/reading', function () {
  1885. $user = $_SESSION[site_url()]['user'];
  1886. $role = user('role', $user);
  1887. if (login()) {
  1888. config('views.root', 'system/admin/views');
  1889. if ($role === 'admin') {
  1890. render('config-reading', array(
  1891. 'title' => generate_title('is_default', i18n('Config')),
  1892. 'description' => safe_html(strip_tags(blog_description())),
  1893. 'canonical' => site_url(),
  1894. 'metatags' => generate_meta(null, null),
  1895. 'type' => 'is_admin-config',
  1896. 'is_admin' => true,
  1897. 'bodyclass' => 'admin-config',
  1898. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1899. ));
  1900. } else {
  1901. render('denied', array(
  1902. 'title' => generate_title('is_default', i18n('Config')),
  1903. 'description' => safe_html(strip_tags(blog_description())),
  1904. 'canonical' => site_url(),
  1905. 'metatags' => generate_meta(null, null),
  1906. 'type' => 'is_admin-config',
  1907. 'is_admin' => true,
  1908. 'bodyclass' => 'denied',
  1909. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1910. ));
  1911. }
  1912. } else {
  1913. $login = site_url() . 'login';
  1914. header("location: $login");
  1915. }
  1916. });
  1917. // Submitted Config page data
  1918. post('/admin/config/reading', function () {
  1919. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  1920. if (login() && $proper) {
  1921. $new_config = array();
  1922. $new_Keys = array();
  1923. $user = $_SESSION[site_url()]['user'];
  1924. $role = user('role', $user);
  1925. if ($role === 'admin') {
  1926. foreach ($_POST as $name => $value) {
  1927. if (substr($name, 0, 8) == "-config-") {
  1928. $name = str_replace("_", ".", substr($name, 8));
  1929. if(!is_null(config($name))) {
  1930. $new_config[$name] = $value;
  1931. } else {
  1932. $new_Keys[$name] = $value;
  1933. }
  1934. }
  1935. }
  1936. save_config($new_config, $new_Keys);
  1937. $redir = site_url() . 'admin/config/reading';
  1938. header("location: $redir");
  1939. } else {
  1940. $redir = site_url();
  1941. header("location: $redir");
  1942. }
  1943. } else {
  1944. $login = site_url() . 'login';
  1945. header("location: $login");
  1946. }
  1947. });
  1948. // Show Config page
  1949. get('/admin/config/writing', function () {
  1950. $user = $_SESSION[site_url()]['user'];
  1951. $role = user('role', $user);
  1952. if (login()) {
  1953. config('views.root', 'system/admin/views');
  1954. if ($role === 'admin') {
  1955. render('config-writing', array(
  1956. 'title' => generate_title('is_default', i18n('Config')),
  1957. 'description' => safe_html(strip_tags(blog_description())),
  1958. 'canonical' => site_url(),
  1959. 'metatags' => generate_meta(null, null),
  1960. 'type' => 'is_admin-config',
  1961. 'is_admin' => true,
  1962. 'bodyclass' => 'admin-config',
  1963. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1964. ));
  1965. } else {
  1966. render('denied', array(
  1967. 'title' => generate_title('is_default', i18n('Config')),
  1968. 'description' => safe_html(strip_tags(blog_description())),
  1969. 'canonical' => site_url(),
  1970. 'metatags' => generate_meta(null, null),
  1971. 'type' => 'is_admin-config',
  1972. 'is_admin' => true,
  1973. 'bodyclass' => 'denied',
  1974. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  1975. ));
  1976. }
  1977. } else {
  1978. $login = site_url() . 'login';
  1979. header("location: $login");
  1980. }
  1981. });
  1982. // Submitted Config page data
  1983. post('/admin/config/writing', function () {
  1984. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  1985. if (login() && $proper) {
  1986. $new_config = array();
  1987. $new_Keys = array();
  1988. $user = $_SESSION[site_url()]['user'];
  1989. $role = user('role', $user);
  1990. if ($role === 'admin') {
  1991. foreach ($_POST as $name => $value) {
  1992. if (substr($name, 0, 8) == "-config-") {
  1993. $name = str_replace("_", ".", substr($name, 8));
  1994. if(!is_null(config($name))) {
  1995. $new_config[$name] = $value;
  1996. } else {
  1997. $new_Keys[$name] = $value;
  1998. }
  1999. }
  2000. }
  2001. save_config($new_config, $new_Keys);
  2002. $redir = site_url() . 'admin/config/writing';
  2003. header("location: $redir");
  2004. } else {
  2005. $redir = site_url();
  2006. header("location: $redir");
  2007. }
  2008. } else {
  2009. $login = site_url() . 'login';
  2010. header("location: $login");
  2011. }
  2012. });
  2013. // Show Config page
  2014. get('/admin/config/widget', function () {
  2015. $user = $_SESSION[site_url()]['user'];
  2016. $role = user('role', $user);
  2017. if (login()) {
  2018. config('views.root', 'system/admin/views');
  2019. if ($role === 'admin') {
  2020. render('config-widget', array(
  2021. 'title' => generate_title('is_default', i18n('Config')),
  2022. 'description' => safe_html(strip_tags(blog_description())),
  2023. 'canonical' => site_url(),
  2024. 'metatags' => generate_meta(null, null),
  2025. 'type' => 'is_admin-config',
  2026. 'is_admin' => true,
  2027. 'bodyclass' => 'admin-config',
  2028. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2029. ));
  2030. } else {
  2031. render('denied', array(
  2032. 'title' => generate_title('is_default', i18n('Config')),
  2033. 'description' => safe_html(strip_tags(blog_description())),
  2034. 'canonical' => site_url(),
  2035. 'metatags' => generate_meta(null, null),
  2036. 'type' => 'is_admin-config',
  2037. 'is_admin' => true,
  2038. 'bodyclass' => 'denied',
  2039. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2040. ));
  2041. }
  2042. } else {
  2043. $login = site_url() . 'login';
  2044. header("location: $login");
  2045. }
  2046. });
  2047. // Submitted Config page data
  2048. post('/admin/config/widget', function () {
  2049. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  2050. if (login() && $proper) {
  2051. $new_config = array();
  2052. $new_Keys = array();
  2053. $user = $_SESSION[site_url()]['user'];
  2054. $role = user('role', $user);
  2055. if ($role === 'admin') {
  2056. foreach ($_POST as $name => $value) {
  2057. if (substr($name, 0, 8) == "-config-") {
  2058. $name = str_replace("_", ".", substr($name, 8));
  2059. if(!is_null(config($name))) {
  2060. $new_config[$name] = $value;
  2061. } else {
  2062. $new_Keys[$name] = $value;
  2063. }
  2064. }
  2065. }
  2066. save_config($new_config, $new_Keys);
  2067. foreach (glob('cache/widget/tags*.cache', GLOB_NOSORT) as $file) {
  2068. unlink($file);
  2069. }
  2070. $redir = site_url() . 'admin/config/widget';
  2071. header("location: $redir");
  2072. } else {
  2073. $redir = site_url();
  2074. header("location: $redir");
  2075. }
  2076. } else {
  2077. $login = site_url() . 'login';
  2078. header("location: $login");
  2079. }
  2080. });
  2081. // Show Config page
  2082. get('/admin/config/metatags', function () {
  2083. $user = $_SESSION[site_url()]['user'];
  2084. $role = user('role', $user);
  2085. if (login()) {
  2086. config('views.root', 'system/admin/views');
  2087. if ($role === 'admin') {
  2088. render('config-metatags', array(
  2089. 'title' => generate_title('is_default', i18n('Config')),
  2090. 'description' => safe_html(strip_tags(blog_description())),
  2091. 'canonical' => site_url(),
  2092. 'metatags' => generate_meta(null, null),
  2093. 'type' => 'is_admin-config',
  2094. 'is_admin' => true,
  2095. 'bodyclass' => 'admin-config',
  2096. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2097. ));
  2098. } else {
  2099. render('denied', array(
  2100. 'title' => generate_title('is_default', i18n('Config')),
  2101. 'description' => safe_html(strip_tags(blog_description())),
  2102. 'canonical' => site_url(),
  2103. 'metatags' => generate_meta(null, null),
  2104. 'type' => 'is_admin-config',
  2105. 'is_admin' => true,
  2106. 'bodyclass' => 'denied',
  2107. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2108. ));
  2109. }
  2110. } else {
  2111. $login = site_url() . 'login';
  2112. header("location: $login");
  2113. }
  2114. die;
  2115. });
  2116. // Submitted Config page data
  2117. post('/admin/config/metatags', function () {
  2118. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  2119. if (login() && $proper) {
  2120. $new_config = array();
  2121. $new_Keys = array();
  2122. $user = $_SESSION[site_url()]['user'];
  2123. $role = user('role', $user);
  2124. if ($role === 'admin') {
  2125. foreach ($_POST as $name => $value) {
  2126. if (substr($name, 0, 8) == "-config-") {
  2127. $name = str_replace("_", ".", substr($name, 8));
  2128. if(!is_null(config($name))) {
  2129. $new_config[$name] = $value;
  2130. } else {
  2131. $new_Keys[$name] = $value;
  2132. }
  2133. }
  2134. }
  2135. save_config($new_config, $new_Keys);
  2136. foreach (glob('cache/widget/*.cache', GLOB_NOSORT) as $file) {
  2137. unlink($file);
  2138. }
  2139. $redir = site_url() . 'admin/config/metatags';
  2140. header("location: $redir");
  2141. } else {
  2142. $redir = site_url();
  2143. header("location: $redir");
  2144. }
  2145. } else {
  2146. $login = site_url() . 'login';
  2147. header("location: $login");
  2148. }
  2149. });
  2150. // Show Config page
  2151. get('/admin/config/security', function () {
  2152. $user = $_SESSION[site_url()]['user'];
  2153. $role = user('role', $user);
  2154. if (login()) {
  2155. config('views.root', 'system/admin/views');
  2156. if ($role === 'admin') {
  2157. render('config-security', array(
  2158. 'title' => generate_title('is_default', i18n('Config')),
  2159. 'description' => safe_html(strip_tags(blog_description())),
  2160. 'canonical' => site_url(),
  2161. 'metatags' => generate_meta(null, null),
  2162. 'type' => 'is_admin-config',
  2163. 'is_admin' => true,
  2164. 'bodyclass' => 'admin-config',
  2165. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2166. ));
  2167. } else {
  2168. render('denied', array(
  2169. 'title' => generate_title('is_default', i18n('Config')),
  2170. 'description' => safe_html(strip_tags(blog_description())),
  2171. 'canonical' => site_url(),
  2172. 'metatags' => generate_meta(null, null),
  2173. 'type' => 'is_admin-config',
  2174. 'is_admin' => true,
  2175. 'bodyclass' => 'denied',
  2176. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2177. ));
  2178. }
  2179. } else {
  2180. $login = site_url() . 'login';
  2181. header("location: $login");
  2182. }
  2183. });
  2184. // Submitted Config page data
  2185. post('/admin/config/security', function () {
  2186. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  2187. if (login() && $proper) {
  2188. $new_config = array();
  2189. $new_Keys = array();
  2190. $user = $_SESSION[site_url()]['user'];
  2191. $role = user('role', $user);
  2192. if ($role === 'admin') {
  2193. foreach ($_POST as $name => $value) {
  2194. if (substr($name, 0, 8) == "-config-") {
  2195. $name = str_replace("_", ".", substr($name, 8));
  2196. if(!is_null(config($name))) {
  2197. $new_config[$name] = $value;
  2198. } else {
  2199. $new_Keys[$name] = $value;
  2200. }
  2201. }
  2202. }
  2203. save_config($new_config, $new_Keys);
  2204. $redir = site_url() . 'admin/config/security';
  2205. header("location: $redir");
  2206. } else {
  2207. $redir = site_url();
  2208. header("location: $redir");
  2209. }
  2210. } else {
  2211. $login = site_url() . 'login';
  2212. header("location: $login");
  2213. }
  2214. });
  2215. // Show Config page
  2216. get('/admin/config/performance', function () {
  2217. $user = $_SESSION[site_url()]['user'];
  2218. $role = user('role', $user);
  2219. if (login()) {
  2220. config('views.root', 'system/admin/views');
  2221. if ($role === 'admin') {
  2222. render('config-performance', array(
  2223. 'title' => generate_title('is_default', i18n('Config')),
  2224. 'description' => safe_html(strip_tags(blog_description())),
  2225. 'canonical' => site_url(),
  2226. 'metatags' => generate_meta(null, null),
  2227. 'type' => 'is_admin-config',
  2228. 'is_admin' => true,
  2229. 'bodyclass' => 'admin-config',
  2230. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2231. ));
  2232. } else {
  2233. render('denied', array(
  2234. 'title' => generate_title('is_default', i18n('Config')),
  2235. 'description' => safe_html(strip_tags(blog_description())),
  2236. 'canonical' => site_url(),
  2237. 'metatags' => generate_meta(null, null),
  2238. 'type' => 'is_admin-config',
  2239. 'is_admin' => true,
  2240. 'bodyclass' => 'denied',
  2241. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Config')
  2242. ));
  2243. }
  2244. } else {
  2245. $login = site_url() . 'login';
  2246. header("location: $login");
  2247. }
  2248. die;
  2249. });
  2250. // Submitted Config page data
  2251. post('/admin/config/performance', function () {
  2252. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  2253. if (login() && $proper) {
  2254. $new_config = array();
  2255. $new_Keys = array();
  2256. $user = $_SESSION[site_url()]['user'];
  2257. $role = user('role', $user);
  2258. if ($role === 'admin') {
  2259. foreach ($_POST as $name => $value) {
  2260. if (substr($name, 0, 8) == "-config-") {
  2261. $name = str_replace("_", ".", substr($name, 8));
  2262. if(!is_null(config($name))) {
  2263. $new_config[$name] = $value;
  2264. } else {
  2265. $new_Keys[$name] = $value;
  2266. }
  2267. }
  2268. }
  2269. save_config($new_config, $new_Keys);
  2270. $redir = site_url() . 'admin/config/performance';
  2271. header("location: $redir");
  2272. } else {
  2273. $redir = site_url();
  2274. header("location: $redir");
  2275. }
  2276. } else {
  2277. $login = site_url() . 'login';
  2278. header("location: $login");
  2279. }
  2280. });
  2281. // Show Backup page
  2282. get('/admin/backup', function () {
  2283. $user = $_SESSION[site_url()]['user'];
  2284. $role = user('role', $user);
  2285. if (login()) {
  2286. config('views.root', 'system/admin/views');
  2287. if ($role === 'admin') {
  2288. render('backup', array(
  2289. 'title' => generate_title('is_default', i18n('Backup')),
  2290. 'description' => safe_html(strip_tags(blog_description())),
  2291. 'canonical' => site_url(),
  2292. 'metatags' => generate_meta(null, null),
  2293. 'type' => 'is_admin-backup',
  2294. 'is_admin' => true,
  2295. 'bodyclass' => 'admin-backup',
  2296. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Backup')
  2297. ));
  2298. } else {
  2299. render('denied', array(
  2300. 'title' => generate_title('is_default', i18n('Denied')),
  2301. 'description' => safe_html(strip_tags(blog_description())),
  2302. 'canonical' => site_url(),
  2303. 'metatags' => generate_meta(null, null),
  2304. 'type' => 'is_admin-config',
  2305. 'is_admin' => true,
  2306. 'bodyclass' => 'denied',
  2307. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2308. ));
  2309. }
  2310. } else {
  2311. $login = site_url() . 'login';
  2312. header("location: $login");
  2313. }
  2314. });
  2315. // Show Create backup page
  2316. get('/admin/backup-start', function () {
  2317. if (login()) {
  2318. config('views.root', 'system/admin/views');
  2319. $user = $_SESSION[site_url()]['user'];
  2320. $role = user('role', $user);
  2321. if ($role === 'admin') {
  2322. render('backup-start', array(
  2323. 'title' => generate_title('is_default', i18n('Create_backup')),
  2324. 'description' => safe_html(strip_tags(blog_description())),
  2325. 'canonical' => site_url(),
  2326. 'metatags' => generate_meta(null, null),
  2327. 'type' => 'is_admin-backup-start',
  2328. 'is_admin' => true,
  2329. 'bodyclass' => 'admin-backup-start',
  2330. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Create_backup')
  2331. ));
  2332. } else {
  2333. $redir = site_url();
  2334. header("location: $redir");
  2335. }
  2336. } else {
  2337. $login = site_url() . 'login';
  2338. header("location: $login");
  2339. }
  2340. });
  2341. // Show clear cache page
  2342. get('/admin/clear-cache', function () {
  2343. $user = $_SESSION[site_url()]['user'];
  2344. $role = user('role', $user);
  2345. if (login()) {
  2346. config('views.root', 'system/admin/views');
  2347. if ($role === 'editor' || $role === 'admin') {
  2348. render('clear-cache', array(
  2349. 'title' => generate_title('is_default', i18n('Clear_cache')),
  2350. 'description' => safe_html(strip_tags(blog_description())),
  2351. 'canonical' => site_url(),
  2352. 'metatags' => generate_meta(null, null),
  2353. 'type' => 'is_admin-clear-cache',
  2354. 'is_admin' => true,
  2355. 'bodyclass' => 'admin-clear-cache',
  2356. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Clear_cache')
  2357. ));
  2358. } else {
  2359. render('denied', array(
  2360. 'title' => generate_title('is_default', i18n('Denied')),
  2361. 'description' => safe_html(strip_tags(blog_description())),
  2362. 'canonical' => site_url(),
  2363. 'metatags' => generate_meta(null, null),
  2364. 'type' => 'is_admin-clear-cache',
  2365. 'is_admin' => true,
  2366. 'bodyclass' => 'denied',
  2367. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2368. ));
  2369. }
  2370. } else {
  2371. $login = site_url() . 'login';
  2372. header("location: $login");
  2373. }
  2374. });
  2375. // Show Update page
  2376. get('/admin/update', function () {
  2377. $user = $_SESSION[site_url()]['user'];
  2378. $role = user('role', $user);
  2379. if (login()) {
  2380. config('views.root', 'system/admin/views');
  2381. if ($role === 'admin') {
  2382. render('update', array(
  2383. 'title' => generate_title('is_default', i18n('Check_update')),
  2384. 'description' => safe_html(strip_tags(blog_description())),
  2385. 'canonical' => site_url(),
  2386. 'metatags' => generate_meta(null, null),
  2387. 'type' => 'is_admin-update',
  2388. 'is_admin' => true,
  2389. 'bodyclass' => 'admin-update',
  2390. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Check_update')
  2391. ));
  2392. } else {
  2393. render('denied', array(
  2394. 'title' => generate_title('is_default', i18n('Denied')),
  2395. 'description' => safe_html(strip_tags(blog_description())),
  2396. 'canonical' => site_url(),
  2397. 'metatags' => generate_meta(null, null),
  2398. 'type' => 'is_admin-config',
  2399. 'is_admin' => true,
  2400. 'bodyclass' => 'denied',
  2401. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2402. ));
  2403. }
  2404. } else {
  2405. $login = site_url() . 'login';
  2406. header("location: $login");
  2407. }
  2408. });
  2409. // Show the update now link
  2410. get('/admin/update/now/:csrf', function ($CSRF) {
  2411. $proper = is_csrf_proper($CSRF);
  2412. $updater = new \Kanti\HubUpdater(array(
  2413. 'name' => 'danpros/htmly',
  2414. 'prerelease' => !!config("prerelease"),
  2415. ));
  2416. if (login() && $proper && $updater->able()) {
  2417. $user = $_SESSION[site_url()]['user'];
  2418. $role = user('role', $user);
  2419. if ($role === 'admin') {
  2420. $updater->update();
  2421. config('views.root', 'system/admin/views');
  2422. render('updated-to', array(
  2423. 'title' => generate_title('is_default', i18n('Update')),
  2424. 'description' => safe_html(strip_tags(blog_description())),
  2425. 'canonical' => site_url(),
  2426. 'metatags' => generate_meta(null, null),
  2427. 'info' => $updater->getCurrentInfo(),
  2428. 'type' => 'is_admin-update',
  2429. 'is_admin' => true,
  2430. 'bodyclass' => 'admin-update',
  2431. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Update')
  2432. ));
  2433. } else {
  2434. $redir = site_url();
  2435. header("location: $redir");
  2436. }
  2437. } else {
  2438. $login = site_url() . 'login';
  2439. header("location: $login");
  2440. }
  2441. });
  2442. // Show Menu builder
  2443. get('/admin/menu', function () {
  2444. $user = $_SESSION[site_url()]['user'];
  2445. $role = user('role', $user);
  2446. if (login()) {
  2447. config('views.root', 'system/admin/views');
  2448. if ($role === 'editor' || $role === 'admin') {
  2449. render('menu', array(
  2450. 'title' => generate_title('is_default', i18n('Menus')),
  2451. 'description' => safe_html(strip_tags(blog_description())),
  2452. 'canonical' => site_url(),
  2453. 'metatags' => generate_meta(null, null),
  2454. 'type' => 'is_admin-menu',
  2455. 'is_admin' => true,
  2456. 'bodyclass' => 'admin-menu',
  2457. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Menus')
  2458. ));
  2459. } else {
  2460. render('denied', array(
  2461. 'title' => generate_title('is_default', i18n('Denied')),
  2462. 'description' => safe_html(strip_tags(blog_description())),
  2463. 'canonical' => site_url(),
  2464. 'metatags' => generate_meta(null, null),
  2465. 'type' => 'is_admin-menu',
  2466. 'is_admin' => true,
  2467. 'bodyclass' => 'denied',
  2468. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2469. ));
  2470. }
  2471. } else {
  2472. $login = site_url() . 'login';
  2473. header("location: $login");
  2474. }
  2475. });
  2476. post('/admin/menu', function () {
  2477. if (login()) {
  2478. $user = $_SESSION[site_url()]['user'];
  2479. $role = user('role', $user);
  2480. if ($role === 'editor' || $role === 'admin') {
  2481. $json = from($_REQUEST, 'json');
  2482. file_put_contents('content/data/menu.json', json_encode($json, JSON_UNESCAPED_UNICODE));
  2483. echo json_encode(array(
  2484. 'message' => 'Menu saved successfully!',
  2485. ));
  2486. } else {
  2487. $redir = site_url();
  2488. header("location: $redir");
  2489. }
  2490. }
  2491. });
  2492. // Manage users page
  2493. get('/admin/users', function () {
  2494. $user = $_SESSION[site_url()]['user'];
  2495. $role = user('role', $user);
  2496. if (login()) {
  2497. config('views.root', 'system/admin/views');
  2498. if ($role === 'admin') {
  2499. render('users', array(
  2500. 'title' => generate_title('is_default', i18n('User')),
  2501. 'description' => safe_html(strip_tags(blog_description())),
  2502. 'canonical' => site_url(),
  2503. 'metatags' => generate_meta(null, null),
  2504. 'type' => 'is_admin-users',
  2505. 'is_admin' => true,
  2506. 'bodyclass' => 'admin-users',
  2507. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('User')
  2508. ));
  2509. } else {
  2510. render('denied', array(
  2511. 'title' => generate_title('is_default', i18n('Denied')),
  2512. 'description' => safe_html(strip_tags(blog_description())),
  2513. 'canonical' => site_url(),
  2514. 'metatags' => generate_meta(null, null),
  2515. 'type' => 'is_admin-menu',
  2516. 'is_admin' => true,
  2517. 'bodyclass' => 'denied',
  2518. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2519. ));
  2520. }
  2521. } else {
  2522. $login = site_url() . 'login';
  2523. header("location: $login");
  2524. }
  2525. });
  2526. get('/admin/add/user', function () {
  2527. $user = $_SESSION[site_url()]['user'];
  2528. $role = user('role', $user);
  2529. if (login()) {
  2530. config('views.root', 'system/admin/views');
  2531. if ($role === 'admin') {
  2532. render('add-user', array(
  2533. 'title' => generate_title('is_default', i18n('Add_user')),
  2534. 'description' => safe_html(strip_tags(blog_description())),
  2535. 'canonical' => site_url(),
  2536. 'metatags' => generate_meta(null, null),
  2537. 'type' => 'is_admin-users',
  2538. 'is_admin' => true,
  2539. 'bodyclass' => 'admin-users',
  2540. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('add_user')
  2541. ));
  2542. } else {
  2543. render('denied', array(
  2544. 'title' => generate_title('is_default', i18n('Denied')),
  2545. 'description' => safe_html(strip_tags(blog_description())),
  2546. 'canonical' => site_url(),
  2547. 'metatags' => generate_meta(null, null),
  2548. 'type' => 'is_admin-menu',
  2549. 'is_admin' => true,
  2550. 'bodyclass' => 'denied',
  2551. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2552. ));
  2553. }
  2554. } else {
  2555. $login = site_url() . 'login';
  2556. header("location: $login");
  2557. }
  2558. });
  2559. post('/admin/add/user', function () {
  2560. $user = $_SESSION[site_url()]['user'];
  2561. $role = user('role', $user);
  2562. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  2563. $username = from($_REQUEST, 'username');
  2564. $user_role = from($_REQUEST, 'user-role');
  2565. $password = from($_REQUEST, 'password');
  2566. if (login() && $proper) {
  2567. config('views.root', 'system/admin/views');
  2568. if ($role === 'admin') {
  2569. if (!empty($username) && !empty($password)) {
  2570. create_user($username, $password, $user_role);
  2571. } else {
  2572. $message['error'] = '';
  2573. if (empty($username)) {
  2574. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_username') . '</li>';
  2575. }
  2576. if (empty($password)) {
  2577. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_password') . '</li>';
  2578. }
  2579. render('add-user', array(
  2580. 'title' => generate_title('is_default', i18n('Add_user')),
  2581. 'description' => safe_html(strip_tags(blog_description())),
  2582. 'canonical' => site_url(),
  2583. 'metatags' => generate_meta(null, null),
  2584. 'error' => '<ul>' . $message['error'] . '</ul>',
  2585. 'type' => 'is_admin-users',
  2586. 'is_admin' => true,
  2587. 'username' => $username,
  2588. 'user_role' => $user_role,
  2589. 'password' => $password,
  2590. 'bodyclass' => 'admin-users',
  2591. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('add_user')
  2592. ));
  2593. }
  2594. $redir = site_url() . 'admin/users';
  2595. header("location: $redir");
  2596. } else {
  2597. $redir = site_url();
  2598. header("location: $redir");
  2599. }
  2600. } else {
  2601. $login = site_url() . 'login';
  2602. header("location: $login");
  2603. }
  2604. });
  2605. get('/admin/users/:username/edit', function ($username) {
  2606. $user = $_SESSION[site_url()]['user'];
  2607. $role = user('role', $user);
  2608. if (login()) {
  2609. config('views.root', 'system/admin/views');
  2610. if ($role === 'admin') {
  2611. render('edit-user', array(
  2612. 'title' => generate_title('is_default', $username),
  2613. 'description' => safe_html(strip_tags(blog_description())),
  2614. 'canonical' => site_url(),
  2615. 'metatags' => generate_meta(null, null),
  2616. 'type' => 'is_admin-users',
  2617. 'username' => $username,
  2618. 'is_admin' => true,
  2619. 'bodyclass' => 'admin-users',
  2620. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . $username
  2621. ));
  2622. } else {
  2623. render('denied', array(
  2624. 'title' => generate_title('is_default', i18n('Denied')),
  2625. 'description' => safe_html(strip_tags(blog_description())),
  2626. 'canonical' => site_url(),
  2627. 'metatags' => generate_meta(null, null),
  2628. 'type' => 'is_admin-menu',
  2629. 'is_admin' => true,
  2630. 'bodyclass' => 'denied',
  2631. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2632. ));
  2633. }
  2634. } else {
  2635. $login = site_url() . 'login';
  2636. header("location: $login");
  2637. }
  2638. });
  2639. // Submitted Config page data
  2640. post('/admin/users/:username/edit', function () {
  2641. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  2642. if (login() && $proper) {
  2643. $username = from($_REQUEST, 'username');
  2644. $user_role = from($_REQUEST, 'role-name');
  2645. $new_password = from($_REQUEST, 'password');
  2646. $user = $_SESSION[site_url()]['user'];
  2647. $role = user('role', $user);
  2648. $old_password = user('password', $username);
  2649. if ($role === 'admin') {
  2650. $file = 'config/users/' . $username . '.ini';
  2651. if (file_exists($file)) {
  2652. if (empty($new_password)) {
  2653. file_put_contents($file, "password = " . $old_password . "\n" .
  2654. "encryption = password_hash\n" .
  2655. "role = " . $user_role . "\n", LOCK_EX);
  2656. } else {
  2657. update_user($username, $new_password, $user_role);
  2658. }
  2659. }
  2660. $redir = site_url() . 'admin/users';
  2661. header("location: $redir");
  2662. } else {
  2663. $redir = site_url();
  2664. header("location: $redir");
  2665. }
  2666. } else {
  2667. $login = site_url() . 'login';
  2668. header("location: $login");
  2669. }
  2670. });
  2671. get('/admin/users/:username/delete', function ($username) {
  2672. $user = $_SESSION[site_url()]['user'];
  2673. $role = user('role', $user);
  2674. if (login()) {
  2675. config('views.root', 'system/admin/views');
  2676. if ($role === 'admin') {
  2677. render('delete-user', array(
  2678. 'title' => generate_title('is_default', $username),
  2679. 'description' => safe_html(strip_tags(blog_description())),
  2680. 'canonical' => site_url(),
  2681. 'metatags' => generate_meta(null, null),
  2682. 'type' => 'is_admin-users',
  2683. 'username' => $username,
  2684. 'is_admin' => true,
  2685. 'bodyclass' => 'admin-users',
  2686. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . $username
  2687. ));
  2688. } else {
  2689. render('denied', array(
  2690. 'title' => generate_title('is_default', i18n('Denied')),
  2691. 'description' => safe_html(strip_tags(blog_description())),
  2692. 'canonical' => site_url(),
  2693. 'metatags' => generate_meta(null, null),
  2694. 'type' => 'is_admin-menu',
  2695. 'is_admin' => true,
  2696. 'bodyclass' => 'denied',
  2697. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2698. ));
  2699. }
  2700. } else {
  2701. $login = site_url() . 'login';
  2702. header("location: $login");
  2703. }
  2704. });
  2705. post('/admin/users/:username/delete', function () {
  2706. $user = $_SESSION[site_url()]['user'];
  2707. $role = user('role', $user);
  2708. $file = from($_REQUEST, 'file');
  2709. $username = from($_REQUEST, 'username');
  2710. $user_role = user('role', $username);
  2711. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  2712. if ($proper && login()) {
  2713. if ($role === 'admin') {
  2714. if ($user_role !== 'admin') {
  2715. unlink($file);
  2716. }
  2717. }
  2718. $redir = site_url() . 'admin/users';
  2719. header("location: $redir");
  2720. } else {
  2721. $login = site_url() . 'login';
  2722. header("location: $login");
  2723. }
  2724. });
  2725. post('/admin/gallery', function () {
  2726. if (login()) {
  2727. $page = from($_REQUEST, 'page');
  2728. $images = image_gallery(null, $page, 40);
  2729. echo json_encode(array('images' => $images));
  2730. }
  2731. });
  2732. // Show category page
  2733. get('/admin/categories', function () {
  2734. $user = $_SESSION[site_url()]['user'];
  2735. $role = user('role', $user);
  2736. if (login()) {
  2737. config('views.root', 'system/admin/views');
  2738. if ($role === 'editor' || $role === 'admin') {
  2739. render('categories', array(
  2740. 'title' => generate_title('is_default', i18n('Categories')),
  2741. 'description' => safe_html(strip_tags(blog_description())),
  2742. 'canonical' => site_url(),
  2743. 'metatags' => generate_meta(null, null),
  2744. 'type' => 'is_admin-categories',
  2745. 'is_admin' => true,
  2746. 'bodyclass' => 'admin-categories',
  2747. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Categories')
  2748. ));
  2749. } else {
  2750. render('denied', array(
  2751. 'title' => generate_title('is_default', i18n('Denied')),
  2752. 'description' => safe_html(strip_tags(blog_description())),
  2753. 'canonical' => site_url(),
  2754. 'metatags' => generate_meta(null, null),
  2755. 'type' => 'is_admin-categories',
  2756. 'is_admin' => true,
  2757. 'bodyclass' => 'denied',
  2758. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  2759. ));
  2760. }
  2761. } else {
  2762. $login = site_url() . 'login';
  2763. header("location: $login");
  2764. }
  2765. });
  2766. // Show the category page
  2767. get('/admin/categories/:category', function ($category) {
  2768. $user = $_SESSION[site_url()]['user'];
  2769. $role = user('role', $user);
  2770. if (login()) {
  2771. config('views.root', 'system/admin/views');
  2772. if ($role === 'editor' || $role === 'admin') {
  2773. $page = from($_GET, 'page');
  2774. $page = $page ? (int)$page : 1;
  2775. $perpage = config('category.perpage');
  2776. $total = '';
  2777. if (empty($perpage)) {
  2778. $perpage = 10;
  2779. }
  2780. $posts = get_category($category, $page, $perpage);
  2781. if (!empty($posts)) {
  2782. $total = $posts[1];
  2783. $posts = $posts[0];
  2784. }
  2785. $desc = get_category_info($category);
  2786. if (empty($desc)) {
  2787. // a non-existing page
  2788. not_found();
  2789. }
  2790. $desc = $desc[0];
  2791. render('category-list', array(
  2792. 'title' => generate_title('is_default', $desc->title),
  2793. 'description' => $desc->description,
  2794. 'canonical' => $desc->url,
  2795. 'metatags' => generate_meta(null, null),
  2796. 'page' => $page,
  2797. 'posts' => $posts,
  2798. 'category' => $desc,
  2799. 'bodyclass' => 'in-category category-' . strtolower($category),
  2800. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="' . site_url() . 'admin/categories">' . i18n('Categories') .'</a> &#187; ' . $desc->title,
  2801. 'pagination' => has_pagination($total, $perpage, $page),
  2802. 'is_category' => true,
  2803. ));
  2804. } else {
  2805. render('denied', array(
  2806. 'title' => generate_title('is_default', 'Categories'),
  2807. 'description' => safe_html(strip_tags(blog_description())),
  2808. 'canonical' => site_url(),
  2809. 'metatags' => generate_meta(null, null),
  2810. 'type' => 'is_admin-categories',
  2811. 'is_admin' => true,
  2812. 'bodyclass' => 'denied',
  2813. 'breadcrumb' => '',
  2814. ));
  2815. }
  2816. } else {
  2817. $login = site_url() . 'login';
  2818. }
  2819. });
  2820. // Show admin/field
  2821. get('/admin/field', function () {
  2822. if (login()) {
  2823. config('views.root', 'system/admin/views');
  2824. render('custom-field', array(
  2825. 'title' => generate_title('is_default', i18n('custom_fields')),
  2826. 'description' => safe_html(strip_tags(blog_description())),
  2827. 'canonical' => site_url(),
  2828. 'metatags' => generate_meta(null, null),
  2829. 'type' => 'is_admin-content',
  2830. 'is_admin' => true,
  2831. 'bodyclass' => 'admin-content',
  2832. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('custom_fields')
  2833. ));
  2834. } else {
  2835. $login = site_url() . 'login';
  2836. header("location: $login");
  2837. }
  2838. });
  2839. // Show admin/field/post
  2840. get('/admin/field/post', function () {
  2841. if (login()) {
  2842. config('views.root', 'system/admin/views');
  2843. render('custom-field-post', array(
  2844. 'title' => generate_title('is_default', i18n('post')),
  2845. 'description' => safe_html(strip_tags(blog_description())),
  2846. 'canonical' => site_url(),
  2847. 'metatags' => generate_meta(null, null),
  2848. 'type' => 'is_admin-content',
  2849. 'is_admin' => true,
  2850. 'bodyclass' => 'admin-content',
  2851. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . '<a href="'. site_url() .'admin/field">' .i18n('custom_fields').'</a> &#187; ' . i18n('post')
  2852. ));
  2853. } else {
  2854. $login = site_url() . 'login';
  2855. header("location: $login");
  2856. }
  2857. });
  2858. post('/admin/field/post', function () {
  2859. if (login()) {
  2860. $user = $_SESSION[site_url()]['user'];
  2861. $role = user('role', $user);
  2862. if ($role === 'editor' || $role === 'admin') {
  2863. $dir = 'content/data/field/';
  2864. if (!is_dir($dir)) {
  2865. mkdir($dir, 0775, true);
  2866. }
  2867. $json = $_REQUEST['json'];
  2868. save_json_pretty('content/data/field/post.json', json_decode($json));
  2869. echo json_encode(array(
  2870. 'message' => 'Post fields saved successfully!',
  2871. ));
  2872. }
  2873. }
  2874. });
  2875. // Show admin/field/page
  2876. get('/admin/field/page', function () {
  2877. if (login()) {
  2878. config('views.root', 'system/admin/views');
  2879. render('custom-field-page', array(
  2880. 'title' => generate_title('is_default', i18n('page')),
  2881. 'description' => safe_html(strip_tags(blog_description())),
  2882. 'canonical' => site_url(),
  2883. 'metatags' => generate_meta(null, null),
  2884. 'type' => 'is_admin-content',
  2885. 'is_admin' => true,
  2886. 'bodyclass' => 'admin-content',
  2887. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . '<a href="'. site_url() .'admin/field">' .i18n('custom_fields').'</a> &#187; ' .i18n('page')
  2888. ));
  2889. } else {
  2890. $login = site_url() . 'login';
  2891. header("location: $login");
  2892. }
  2893. });
  2894. post('/admin/field/page', function () {
  2895. if (login()) {
  2896. $user = $_SESSION[site_url()]['user'];
  2897. $role = user('role', $user);
  2898. if ($role === 'editor' || $role === 'admin') {
  2899. $dir = 'content/data/field/';
  2900. if (!is_dir($dir)) {
  2901. mkdir($dir, 0775, true);
  2902. }
  2903. $json = $_REQUEST['json'];
  2904. save_json_pretty('content/data/field/page.json', json_decode($json));
  2905. echo json_encode(array(
  2906. 'message' => 'Page fields saved successfully!',
  2907. ));
  2908. }
  2909. }
  2910. });
  2911. // Show admin/field/subpage
  2912. get('/admin/field/subpage', function () {
  2913. if (login()) {
  2914. config('views.root', 'system/admin/views');
  2915. render('custom-field-subpage', array(
  2916. 'title' => generate_title('is_default', i18n('subpage')),
  2917. 'description' => safe_html(strip_tags(blog_description())),
  2918. 'canonical' => site_url(),
  2919. 'metatags' => generate_meta(null, null),
  2920. 'type' => 'is_admin-content',
  2921. 'is_admin' => true,
  2922. 'bodyclass' => 'admin-content',
  2923. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . '<a href="'. site_url() .'admin/field">' .i18n('custom_fields').'</a> &#187; ' .i18n('subpage')
  2924. ));
  2925. } else {
  2926. $login = site_url() . 'login';
  2927. header("location: $login");
  2928. }
  2929. });
  2930. post('/admin/field/subpage', function () {
  2931. if (login()) {
  2932. $user = $_SESSION[site_url()]['user'];
  2933. $role = user('role', $user);
  2934. if ($role === 'editor' || $role === 'admin') {
  2935. $dir = 'content/data/field/';
  2936. if (!is_dir($dir)) {
  2937. mkdir($dir, 0775, true);
  2938. }
  2939. $json = $_REQUEST['json'];
  2940. save_json_pretty('content/data/field/subpage.json', json_decode($json));
  2941. echo json_encode(array(
  2942. 'message' => 'Subpage fields saved successfully!',
  2943. ));
  2944. }
  2945. }
  2946. });
  2947. // Show admin/field/profile
  2948. get('/admin/field/profile', function () {
  2949. if (login()) {
  2950. config('views.root', 'system/admin/views');
  2951. render('custom-field-profile', array(
  2952. 'title' => generate_title('is_default', i18n('profile')),
  2953. 'description' => safe_html(strip_tags(blog_description())),
  2954. 'canonical' => site_url(),
  2955. 'metatags' => generate_meta(null, null),
  2956. 'type' => 'is_admin-content',
  2957. 'is_admin' => true,
  2958. 'bodyclass' => 'admin-content',
  2959. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . '<a href="'. site_url() .'admin/field">' .i18n('custom_fields').'</a> &#187; ' .i18n('profile')
  2960. ));
  2961. } else {
  2962. $login = site_url() . 'login';
  2963. header("location: $login");
  2964. }
  2965. });
  2966. post('/admin/field/profile', function () {
  2967. if (login()) {
  2968. $user = $_SESSION[site_url()]['user'];
  2969. $role = user('role', $user);
  2970. if ($role === 'editor' || $role === 'admin') {
  2971. $dir = 'content/data/field/';
  2972. if (!is_dir($dir)) {
  2973. mkdir($dir, 0775, true);
  2974. }
  2975. $json = $_REQUEST['json'];
  2976. save_json_pretty('content/data/field/profile.json', json_decode($json));
  2977. echo json_encode(array(
  2978. 'message' => 'Profile fields saved successfully!',
  2979. ));
  2980. }
  2981. }
  2982. });
  2983. // Show admin/themes
  2984. get('/admin/themes', function () {
  2985. if (login()) {
  2986. config('views.root', 'system/admin/views');
  2987. render('theme', array(
  2988. 'title' => generate_title('is_default', i18n('themes')),
  2989. 'description' => safe_html(strip_tags(blog_description())),
  2990. 'canonical' => site_url(),
  2991. 'metatags' => generate_meta(null, null),
  2992. 'type' => 'is_admin-content',
  2993. 'is_admin' => true,
  2994. 'bodyclass' => 'admin-content',
  2995. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('themes')
  2996. ));
  2997. } else {
  2998. $login = site_url() . 'login';
  2999. header("location: $login");
  3000. }
  3001. });
  3002. post('/admin/themes', function () {
  3003. if (login()) {
  3004. $new_config = array();
  3005. $new_Keys = array();
  3006. $user = $_SESSION[site_url()]['user'];
  3007. $role = user('role', $user);
  3008. if ($role === 'admin') {
  3009. $json = $_REQUEST['json'];
  3010. $new_config['views.root'] = $json;
  3011. save_config($new_config, $new_Keys);
  3012. echo json_encode(array(
  3013. 'message' => 'Theme activated!',
  3014. ));
  3015. }
  3016. }
  3017. });
  3018. // Show admin/themes/:theme
  3019. get('/admin/themes/:theme', function ($theme) {
  3020. $exp = explode('/', config('views.root'));
  3021. if ($theme !== $exp[1]) {
  3022. $redir = site_url() . 'admin/themes';
  3023. header("location: $redir");
  3024. }
  3025. if (login()) {
  3026. config('views.root', 'system/admin/views');
  3027. render('theme-settings', array(
  3028. 'title' => generate_title('is_default', $theme),
  3029. 'description' => safe_html(strip_tags(blog_description())),
  3030. 'canonical' => site_url(),
  3031. 'metatags' => generate_meta(null, null),
  3032. 'type' => 'is_admin-content',
  3033. 'theme' => $theme,
  3034. 'is_admin' => true,
  3035. 'bodyclass' => 'admin-content',
  3036. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="'. site_url() .'admin/themes">' . i18n('themes') . '</a> &#187; ' . $theme
  3037. ));
  3038. } else {
  3039. $login = site_url() . 'login';
  3040. header("location: $login");
  3041. }
  3042. });
  3043. // Submitted theme settings data
  3044. post('/admin/themes/:theme', function ($theme) {
  3045. $exp = explode('/', config('views.root'));
  3046. if ($theme !== $exp[1]) {
  3047. $redir = site_url() . 'admin/themes';
  3048. header("location: $redir");
  3049. }
  3050. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  3051. if (login() && $proper) {
  3052. $new_config = array();
  3053. $new_Keys = array();
  3054. $user = $_SESSION[site_url()]['user'];
  3055. $role = user('role', $user);
  3056. if ($role === 'admin') {
  3057. foreach ($_POST as $name => $value) {
  3058. if (substr($name, 0, 8) == "-config-") {
  3059. $name = substr($name, 8);
  3060. if(!is_null(theme_config($name))) {
  3061. $new_config[$name] = $value;
  3062. } else {
  3063. $new_Keys[$name] = $value;
  3064. }
  3065. }
  3066. }
  3067. save_theme_config($new_config, $new_Keys, $theme);
  3068. $redir = site_url() . 'admin/themes/' . $theme;
  3069. header("location: $redir");
  3070. } else {
  3071. $redir = site_url();
  3072. header("location: $redir");
  3073. }
  3074. } else {
  3075. $login = site_url() . 'login';
  3076. header("location: $login");
  3077. }
  3078. });
  3079. // Show the category page
  3080. get('/category/:category', function ($category) {
  3081. if (!login()) {
  3082. file_cache($_SERVER['REQUEST_URI']);
  3083. }
  3084. $page = from($_GET, 'page');
  3085. $page = $page ? (int)$page : 1;
  3086. $perpage = config('category.perpage');
  3087. $total = '';
  3088. if (empty($perpage)) {
  3089. $perpage = 10;
  3090. }
  3091. $posts = get_category($category, $page, $perpage);
  3092. if (!empty($posts)) {
  3093. $total = $posts[1];
  3094. $posts = $posts[0];
  3095. }
  3096. if (empty($posts) || $page < 1) {
  3097. // a non-existing page
  3098. not_found();
  3099. }
  3100. $desc = get_category_info($category);
  3101. if(!empty($desc)) {
  3102. $desc = $desc[0];
  3103. }
  3104. $vroot = rtrim(config('views.root'), '/');
  3105. $lt = $vroot . '/layout--category--'. strtolower($category) .'.html.php';
  3106. $ls = $vroot . '/layout--category.html.php';
  3107. if (file_exists($lt)) {
  3108. $layout = 'layout--category--' . strtolower($category);
  3109. } else if (file_exists($ls)) {
  3110. $layout = 'layout--category';
  3111. } else {
  3112. $layout = '';
  3113. }
  3114. $pv = $vroot . '/main--category--'. strtolower($category) .'.html.php';
  3115. $ps = $vroot . '/main--category.html.php';
  3116. if (file_exists($pv)) {
  3117. $pview = 'main--category--' . strtolower($category);
  3118. } else if (file_exists($ps)) {
  3119. $pview = 'main--category';
  3120. } else {
  3121. $pview = 'main';
  3122. }
  3123. if ($page > 1) {
  3124. $CanonicalPageNum = '?page=' . $page;
  3125. } else {
  3126. $CanonicalPageNum = NULL;
  3127. }
  3128. render($pview, array(
  3129. 'title' => generate_title('is_category', $desc),
  3130. 'description' => $desc->description,
  3131. 'canonical' => $desc->url . $CanonicalPageNum,
  3132. 'metatags' => generate_meta('is_category', $desc),
  3133. 'page' => $page,
  3134. 'posts' => $posts,
  3135. 'category' => $desc,
  3136. 'taxonomy' => $desc,
  3137. 'bodyclass' => 'in-category category-' . strtolower($category),
  3138. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . $desc->title,
  3139. 'pagination' => has_pagination($total, $perpage, $page),
  3140. 'is_category' => true,
  3141. 'is_taxonomy' => true
  3142. ), $layout);
  3143. });
  3144. // Show the RSS feed
  3145. get('/category/:category/feed', function ($category) {
  3146. header('Content-Type: application/rss+xml');
  3147. $posts = array();
  3148. $posts = get_category($category, 1, config('rss.count'));
  3149. if ($posts) {
  3150. $posts = $posts[0];
  3151. }
  3152. $data = get_category_info($category);
  3153. if(!empty($data)) {
  3154. $data = $data[0];
  3155. }
  3156. // Show an RSS feed
  3157. echo generate_rss($posts, $data);
  3158. });
  3159. // Show edit the category page
  3160. get('/category/:category/edit', function ($category) {
  3161. $user = $_SESSION[site_url()]['user'];
  3162. $role = user('role', $user);
  3163. if (login()) {
  3164. config('views.root', 'system/admin/views');
  3165. if ($role === 'editor' || $role === 'admin') {
  3166. $post = get_category_info($category);
  3167. if(empty($post)) {
  3168. not_found();
  3169. }
  3170. $post = $post[0];
  3171. render('edit-page', array(
  3172. 'title' => generate_title('is_default', i18n('Edit_category')),
  3173. 'description' => safe_html(strip_tags(blog_description())),
  3174. 'canonical' => site_url(),
  3175. 'metatags' => generate_meta(null, null),
  3176. 'type' => 'is_category',
  3177. 'is_admin' => true,
  3178. 'bodyclass' => 'edit-category',
  3179. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Category') . ': ' . $post->title,
  3180. 'p' => $post,
  3181. 'static' => $post,
  3182. ));
  3183. } else {
  3184. render('denied', array(
  3185. 'title' => generate_title('is_default', i18n('Denied')),
  3186. 'description' => safe_html(strip_tags(blog_description())),
  3187. 'canonical' => site_url(),
  3188. 'metatags' => generate_meta(null, null),
  3189. 'type' => 'is_category',
  3190. 'is_admin' => true,
  3191. 'bodyclass' => 'denied',
  3192. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  3193. ));
  3194. }
  3195. } else {
  3196. $login = site_url() . 'login';
  3197. header("location: $login");
  3198. }
  3199. });
  3200. // Get edited data from category page
  3201. post('/category/:category/edit', function () {
  3202. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  3203. if(!login()) {
  3204. $login = site_url() . 'login';
  3205. header("location: $login");
  3206. }
  3207. $title = from($_REQUEST, 'title');
  3208. $url = from($_REQUEST, 'url');
  3209. $content = from($_REQUEST, 'content');
  3210. $oldfile = from($_REQUEST, 'oldfile');
  3211. $destination = from($_GET, 'destination');
  3212. $description = from($_REQUEST, 'description');
  3213. $user = $_SESSION[site_url()]['user'];
  3214. $role = user('role', $user);
  3215. if (empty($url)) {
  3216. $url = $title;
  3217. }
  3218. if ($role === 'editor' || $role === 'admin') {
  3219. if ($proper && !empty($title) && !empty($content)) {
  3220. edit_category($title, $url, $content, $oldfile, $destination, $description);
  3221. } else {
  3222. $message['error'] = '';
  3223. if (empty($title)) {
  3224. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  3225. }
  3226. if (empty($content)) {
  3227. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  3228. }
  3229. if (!$proper) {
  3230. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  3231. }
  3232. config('views.root', 'system/admin/views');
  3233. render('edit-page', array(
  3234. 'title' => generate_title('is_default', i18n('Edit_category')),
  3235. 'description' => safe_html(strip_tags(blog_description())),
  3236. 'canonical' => site_url(),
  3237. 'metatags' => generate_meta(null, null),
  3238. 'error' => '<ul>' . $message['error'] . '</ul>',
  3239. 'oldfile' => $oldfile,
  3240. 'postTitle' => $title,
  3241. 'postUrl' => $url,
  3242. 'postContent' => $content,
  3243. 'type' => 'is_category',
  3244. 'is_admin' => true,
  3245. 'bodyclass' => 'edit-category',
  3246. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Edit_category')
  3247. ));
  3248. }
  3249. } else {
  3250. $redir = site_url();
  3251. header("location: $redir");
  3252. }
  3253. });
  3254. // Delete category
  3255. get('/category/:category/delete', function ($category) {
  3256. $user = $_SESSION[site_url()]['user'];
  3257. $role = user('role', $user);
  3258. if (login()) {
  3259. config('views.root', 'system/admin/views');
  3260. if ($role === 'editor' || $role === 'admin') {
  3261. $post = get_category_info($category);
  3262. if(empty($post)) {
  3263. not_found();
  3264. }
  3265. $post = $post[0];
  3266. render('delete-category', array(
  3267. 'title' => generate_title('is_default', i18n('Delete') . ' ' . i18n('Category')),
  3268. 'description' => safe_html(strip_tags(blog_description())),
  3269. 'canonical' => site_url(),
  3270. 'metatags' => generate_meta(null, null),
  3271. 'type' => 'is_category',
  3272. 'is_admin' => true,
  3273. 'bodyclass' => 'delete-category',
  3274. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Category') . ': ' . $post->title,
  3275. 'p' => $post,
  3276. 'static' => $post,
  3277. 'type' => 'categoryPage',
  3278. ));
  3279. } else {
  3280. render('denied', array(
  3281. 'title' => generate_title('is_default', i18n('Denied')),
  3282. 'description' => safe_html(strip_tags(blog_description())),
  3283. 'canonical' => site_url(),
  3284. 'metatags' => generate_meta(null, null),
  3285. 'type' => 'is_admin-config',
  3286. 'is_admin' => true,
  3287. 'bodyclass' => 'denied',
  3288. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  3289. ));
  3290. }
  3291. } else {
  3292. $login = site_url() . 'login';
  3293. header("location: $login");
  3294. }
  3295. });
  3296. // Get deleted category data
  3297. post('/category/:category/delete', function () {
  3298. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  3299. if ($proper && login()) {
  3300. $user = $_SESSION[site_url()]['user'];
  3301. $role = user('role', $user);
  3302. if ($role === 'editor' || $role === 'admin') {
  3303. $file = from($_REQUEST, 'file');
  3304. $destination = from($_GET, 'destination');
  3305. delete_page($file, $destination);
  3306. } else {
  3307. $redir = site_url();
  3308. header("location: $redir");
  3309. }
  3310. }
  3311. });
  3312. // Show the type page
  3313. get('/type/:type', function ($type) {
  3314. if (!login()) {
  3315. file_cache($_SERVER['REQUEST_URI']);
  3316. }
  3317. $page = from($_GET, 'page');
  3318. $page = $page ? (int)$page : 1;
  3319. $perpage = config('type.perpage');
  3320. $total = '';
  3321. if (empty($perpage)) {
  3322. $perpage = 10;
  3323. }
  3324. $posts = get_type($type, $page, $perpage);
  3325. if (!empty($posts)) {
  3326. $total = $posts[1];
  3327. $posts = $posts[0];
  3328. }
  3329. if (empty($posts) || $page < 1) {
  3330. // a non-existing page
  3331. not_found();
  3332. }
  3333. $ttype = new stdClass;
  3334. $ttype->title = ucfirst($type);
  3335. $ttype->url = site_url() . 'type/' . strtolower($type);
  3336. $ttype->count = $total;
  3337. $ttype->description = i18n('Posts_with_type') . ' ' . ucfirst($type) . ' ' . i18n('by') . ' ' . blog_title();
  3338. $ttype->body = $ttype->description;
  3339. $ttype->rss = $ttype->url . '/feed';
  3340. $ttype->slug = strtolower($type);
  3341. $vroot = rtrim(config('views.root'), '/');
  3342. $lt = $vroot . '/layout--type--'. strtolower($type) .'.html.php';
  3343. $ls = $vroot . '/layout--type.html.php';
  3344. if (file_exists($lt)) {
  3345. $layout = 'layout--type--' . strtolower($type);
  3346. } else if (file_exists($ls)) {
  3347. $layout = 'layout--type';
  3348. } else {
  3349. $layout = '';
  3350. }
  3351. $pv = $vroot . '/main--type--'. strtolower($type) .'.html.php';
  3352. $ps = $vroot . '/main--type.html.php';
  3353. if (file_exists($pv)) {
  3354. $pview = 'main--type--' . strtolower($type);
  3355. } else if (file_exists($ps)) {
  3356. $pview = 'main--type';
  3357. } else {
  3358. $pview = 'main';
  3359. }
  3360. if ($page > 1) {
  3361. $CanonicalPageNum = '?page=' . $page;
  3362. } else {
  3363. $CanonicalPageNum = NULL;
  3364. }
  3365. render($pview, array(
  3366. 'title' => generate_title('is_type', $ttype),
  3367. 'description' => $ttype->description,
  3368. 'canonical' => $ttype->url . $CanonicalPageNum,
  3369. 'metatags' => generate_meta('is_type', $ttype),
  3370. 'page' => $page,
  3371. 'posts' => $posts,
  3372. 'type' => $ttype,
  3373. 'taxonomy' => $ttype,
  3374. 'bodyclass' => 'in-type type-' . strtolower($type),
  3375. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . ucfirst($type),
  3376. 'pagination' => has_pagination($total, $perpage, $page),
  3377. 'is_type' => true,
  3378. 'is_taxonomy' => true
  3379. ), $layout);
  3380. });
  3381. // Show the RSS feed
  3382. get('/type/:type/feed', function ($type) {
  3383. header('Content-Type: application/rss+xml');
  3384. $posts = array();
  3385. $posts = get_type($type, 1, config('rss.count'));
  3386. if ($posts) {
  3387. $posts = $posts[0];
  3388. }
  3389. $data = new stdClass;
  3390. $data->title = ucfirst($type);
  3391. $data->url = site_url() . 'type/' . strtolower($type);
  3392. $data->body = i18n('Posts_with_type') . ' ' . ucfirst($type) . ' ' . i18n('by') . ' ' . blog_title();
  3393. // Show an RSS feed
  3394. echo generate_rss($posts, $data);
  3395. });
  3396. // Show the tag page
  3397. get('/tag/:tag', function ($tag) {
  3398. if (!login()) {
  3399. file_cache($_SERVER['REQUEST_URI']);
  3400. }
  3401. $page = from($_GET, 'page');
  3402. $page = $page ? (int)$page : 1;
  3403. $perpage = config('tag.perpage');
  3404. $total = '';
  3405. $posts = get_tag($tag, $page, $perpage);
  3406. if (!empty($posts)) {
  3407. $total = $posts[1];
  3408. $posts = $posts[0];
  3409. }
  3410. if (empty($posts) || $page < 1) {
  3411. // a non-existing page
  3412. not_found();
  3413. }
  3414. $ttag = new stdClass;
  3415. $ttag->title = tag_i18n($tag);
  3416. $ttag->url = site_url() . 'tag/' . strtolower($tag);
  3417. $ttag->count = $total;
  3418. $ttag->description = i18n('All_posts_tagged') . ' ' . tag_i18n($tag) . ' ' . i18n('by') . ' ' . blog_title();
  3419. $ttag->body = $ttag->description;
  3420. $ttag->rss = $ttag->url . '/feed';
  3421. $ttag->slug = strtolower($tag);
  3422. $vroot = rtrim(config('views.root'), '/');
  3423. $lt = $vroot . '/layout--tag--' . strtolower($tag) . '.html.php';
  3424. $ls = $vroot . '/layout--tag.html.php';
  3425. if (file_exists($lt)) {
  3426. $layout = 'layout--tag--' . strtolower($tag);
  3427. } else if (file_exists($ls)) {
  3428. $layout = 'layout--tag';
  3429. } else {
  3430. $layout = '';
  3431. }
  3432. $pv = $vroot . '/main--tag--' . strtolower($tag) . '.html.php';
  3433. $ps = $vroot . '/main--tag.html.php';
  3434. if (file_exists($pv)) {
  3435. $pview = 'main--tag--' . strtolower($tag);
  3436. } elseif (file_exists($ps)) {
  3437. $pview = 'main--tag';
  3438. } else {
  3439. $pview = 'main';
  3440. }
  3441. if ($page > 1) {
  3442. $CanonicalPageNum = '?page=' . $page;
  3443. } else {
  3444. $CanonicalPageNum = NULL;
  3445. }
  3446. render($pview, array(
  3447. 'title' => generate_title('is_tag', $ttag),
  3448. 'description' => $ttag->description,
  3449. 'canonical' => $ttag->url . $CanonicalPageNum,
  3450. 'metatags' => generate_meta('is_tag', $ttag),
  3451. 'page' => $page,
  3452. 'posts' => $posts,
  3453. 'tag' => $ttag,
  3454. 'taxonomy' => $ttag,
  3455. 'bodyclass' => 'in-tag tag-' . strtolower($tag),
  3456. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Posts_tagged') . ' ' . tag_i18n($tag),
  3457. 'pagination' => has_pagination($total, $perpage, $page),
  3458. 'is_tag' => true,
  3459. 'is_taxonomy' => true
  3460. ), $layout);
  3461. });
  3462. // Show the RSS feed
  3463. get('/tag/:tag/feed', function ($tag) {
  3464. header('Content-Type: application/rss+xml');
  3465. $posts = array();
  3466. $posts = get_tag($tag, 1, config('rss.count'));
  3467. if ($posts) {
  3468. $posts = $posts[0];
  3469. }
  3470. $data = new stdClass;
  3471. $data->title = tag_i18n($tag);
  3472. $data->url = site_url() . 'tag/' . strtolower($tag);
  3473. $data->body = i18n('All_posts_tagged') . ' ' . tag_i18n($tag) . ' ' . i18n('by') . ' ' . blog_title();
  3474. // Show an RSS feed
  3475. echo generate_rss($posts, $data);
  3476. });
  3477. // Show the archive page
  3478. get('/archive/:req', function ($req) {
  3479. if (!login()) {
  3480. file_cache($_SERVER['REQUEST_URI']);
  3481. }
  3482. $page = from($_GET, 'page');
  3483. $page = $page ? (int)$page : 1;
  3484. $perpage = config('archive.perpage');
  3485. $total = '';
  3486. $posts = get_archive($req, $page, $perpage);
  3487. if (!empty($posts)) {
  3488. $total = $posts[1];
  3489. $posts = $posts[0];
  3490. }
  3491. if (empty($posts) || $page < 1) {
  3492. // a non-existing page
  3493. not_found();
  3494. }
  3495. $time = explode('-', $req);
  3496. $date = strtotime($req);
  3497. if (!$date) {
  3498. // a non-existing page
  3499. not_found();
  3500. }
  3501. if (isset($time[0]) && isset($time[1]) && isset($time[2])) {
  3502. $timestamp = format_date($date, 'd F Y');
  3503. } elseif (isset($time[0]) && isset($time[1])) {
  3504. $timestamp = format_date($date, 'F Y');
  3505. } else {
  3506. $timestamp = $req;
  3507. }
  3508. $tarchive = new stdClass;
  3509. $tarchive->title = $timestamp;
  3510. $tarchive->url = site_url() . 'archive/' . $req;
  3511. $tarchive->count = $total;
  3512. $tarchive->description = i18n('Archive_page_for') . ' ' . $timestamp . ' ' . i18n('by') . ' ' . blog_title();
  3513. $tarchive->body = $tarchive->description;
  3514. $tarchive->rss = $tarchive->url . '/feed';
  3515. $tarchive->slug = strtolower($req);
  3516. $vroot = rtrim(config('views.root'), '/');
  3517. $lt = $vroot . '/layout--archive.html.php';
  3518. if (file_exists($lt)) {
  3519. $layout = 'layout--archive';
  3520. } else {
  3521. $layout = '';
  3522. }
  3523. $pv = $vroot . '/main--archive.html.php';
  3524. if (file_exists($pv)) {
  3525. $pview = 'main--archive';
  3526. } else {
  3527. $pview = 'main';
  3528. }
  3529. if ($page > 1) {
  3530. $CanonicalPageNum = '?page=' . $page;
  3531. } else {
  3532. $CanonicalPageNum = NULL;
  3533. }
  3534. render($pview, array(
  3535. 'title' => generate_title('is_archive', $tarchive),
  3536. 'description' => $tarchive->description,
  3537. 'canonical' => $tarchive->url . $CanonicalPageNum,
  3538. 'metatags' => generate_meta('is_archive', $tarchive),
  3539. 'page' => $page,
  3540. 'posts' => $posts,
  3541. 'archive' => $tarchive,
  3542. 'taxonomy' => $tarchive,
  3543. 'bodyclass' => 'in-archive archive-' . strtolower($req),
  3544. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Archive_for') . ' ' . $timestamp,
  3545. 'pagination' => has_pagination($total, $perpage, $page),
  3546. 'is_archive' => true,
  3547. 'is_taxonomy' => true
  3548. ), $layout);
  3549. });
  3550. // Show the RSS feed
  3551. get('/archive/:req/feed', function ($req) {
  3552. header('Content-Type: application/rss+xml');
  3553. $posts = array();
  3554. $posts = get_archive($req, 1, config('rss.count'));
  3555. if ($posts) {
  3556. $posts = $posts[0];
  3557. }
  3558. $time = explode('-', $req);
  3559. $date = strtotime($req);
  3560. if (isset($time[0]) && isset($time[1]) && isset($time[2])) {
  3561. $timestamp = format_date($date, 'd F Y');
  3562. } elseif (isset($time[0]) && isset($time[1])) {
  3563. $timestamp = format_date($date, 'F Y');
  3564. } else {
  3565. $timestamp = $req;
  3566. }
  3567. $data = new stdClass;
  3568. $data->title = $timestamp;
  3569. $data->url = site_url() . 'archive/' . $req;
  3570. $data->body = i18n('Archive_page_for') . ' ' . $timestamp . ' ' . i18n('by') . ' ' . blog_title();
  3571. // Show an RSS feed
  3572. echo generate_rss($posts, $data);
  3573. });
  3574. // Show the search page
  3575. get('/search/:keyword', function ($keyword) {
  3576. if (!login()) {
  3577. file_cache($_SERVER['REQUEST_URI']);
  3578. }
  3579. $page = from($_GET, 'page');
  3580. $page = $page ? (int)$page : 1;
  3581. $perpage = config('search.perpage');
  3582. $total = '';
  3583. $posts = get_keyword($keyword, $page, $perpage);
  3584. if (!empty($posts)) {
  3585. $total = $posts[1];
  3586. $posts = $posts[0];
  3587. }
  3588. $vroot = rtrim(config('views.root'), '/');
  3589. $lt = $vroot . '/layout--search.html.php';
  3590. if (file_exists($lt)) {
  3591. $layout = 'layout--search';
  3592. } else {
  3593. $layout = '';
  3594. }
  3595. if (!$posts || $page < 1) {
  3596. // a non-existing page or no search result
  3597. render('404-search', array(
  3598. 'title' => i18n('Search_results_not_found') . ' - ' . blog_title(),
  3599. 'description' => i18n('Search_results_not_found'),
  3600. 'canonical' => site_url(),
  3601. 'metatags' => generate_meta(null, null),
  3602. 'search' => '',
  3603. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('No_search_results'),
  3604. 'canonical' => site_url(),
  3605. 'bodyclass' => 'error-404-search',
  3606. 'is_404search' => true,
  3607. ), $layout);
  3608. die;
  3609. }
  3610. $tsearch = new stdClass;
  3611. $tsearch->title = $keyword;
  3612. $tsearch->url = site_url() . 'search/' . strtolower($keyword);
  3613. $tsearch->count = $total;
  3614. $tsearch->description = i18n('Search_results_for') . ' ' . $keyword . ' ' . i18n('by') . ' ' . blog_title();
  3615. $tsearch->body = $tsearch->description;
  3616. $tsearch->rss = $tsearch->url . '/feed';
  3617. $tsearch->slug = strtolower($keyword);
  3618. $pv = $vroot . '/main--search.html.php';
  3619. if (file_exists($pv)) {
  3620. $pview = 'main--search';
  3621. } else {
  3622. $pview = 'main';
  3623. }
  3624. if ($page > 1) {
  3625. $CanonicalPageNum = '?page=' . $page;
  3626. } else {
  3627. $CanonicalPageNum = NULL;
  3628. }
  3629. render($pview, array(
  3630. 'title' => generate_title('is_search', $tsearch),
  3631. 'description' => $tsearch->description,
  3632. 'canonical' => $tsearch->url . $CanonicalPageNum,
  3633. 'metatags' => generate_meta('is_search', $tsearch),
  3634. 'page' => $page,
  3635. 'posts' => $posts,
  3636. 'search' => $tsearch,
  3637. 'taxonomy' => $tsearch,
  3638. 'bodyclass' => 'in-search search-' . strtolower($keyword),
  3639. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Search_results_for') . ' ' . $keyword,
  3640. 'pagination' => has_pagination($total, $perpage, $page),
  3641. 'is_search' => true,
  3642. 'is_taxonomy' => true
  3643. ), $layout);
  3644. });
  3645. // Show the RSS feed
  3646. get('/search/:keyword/feed', function ($keyword) {
  3647. header('Content-Type: application/rss+xml');
  3648. $posts = array();
  3649. $posts = get_keyword($keyword, 1, config('rss.count'));
  3650. if ($posts) {
  3651. $posts = $posts[0];
  3652. }
  3653. $data = new stdClass;
  3654. $data->title = $keyword;
  3655. $data->url = site_url() . 'search/' . strtolower($keyword);
  3656. $data->body = i18n('Search_results_for') . ' ' . $keyword . ' ' . i18n('by') . ' ' . blog_title();
  3657. // Show an RSS feed
  3658. echo generate_rss($posts, $data);
  3659. });
  3660. // The JSON API
  3661. get('/api/json', function () {
  3662. header('Content-type: application/json');
  3663. $page = from($_GET, 'page');
  3664. $page = $page ? (int)$page : 1;
  3665. $perpage = config('json.count');
  3666. echo generate_json(get_posts(null, $page, $perpage));
  3667. });
  3668. // Show the RSS feed
  3669. get('/feed/rss', function () {
  3670. header('Content-Type: application/rss+xml');
  3671. // Show an RSS feed with the 30 latest posts
  3672. echo generate_rss(get_posts(null, 1, config('rss.count')));
  3673. });
  3674. // Generate OPML file
  3675. get('/feed/opml', function () {
  3676. header('Content-Type: text/xml');
  3677. // Generate OPML file for the RSS
  3678. echo generate_opml();
  3679. });
  3680. // Show blog post without year-month
  3681. get('/'. permalink_type() .'/:name', function ($name) {
  3682. if (permalink_type() == 'default') {
  3683. $post = find_post(null, null, $name);
  3684. if (is_null($post)) {
  3685. not_found();
  3686. } else {
  3687. $current = $post['current'];
  3688. }
  3689. $redir = site_url() . date('Y/m', $current->date) . '/' . $name;
  3690. header("location: $redir", TRUE, 301);
  3691. }
  3692. if (config("views.counter") != "true") {
  3693. if (!login()) {
  3694. file_cache($_SERVER['REQUEST_URI']);
  3695. }
  3696. } else {
  3697. add_view('post_' . $name);
  3698. if (!login()) {
  3699. file_cache($_SERVER['REQUEST_URI']);
  3700. }
  3701. }
  3702. $post = find_post(null, null, $name);
  3703. if (is_null($post)) {
  3704. not_found('post_' . $name);
  3705. } else {
  3706. $current = $post['current'];
  3707. }
  3708. $author = new stdClass;
  3709. $author->url = $current->authorUrl;
  3710. $author->name = $current->authorName;
  3711. $author->description = $current->authorDescription;
  3712. $author->about = $current->authorAbout;
  3713. $author->avatar = $current->authorAvatar;
  3714. $author->rss = $current->authorRss;
  3715. $author->slug = $current->author;
  3716. if (array_key_exists('prev', $post)) {
  3717. $prev = $post['prev'];
  3718. } else {
  3719. $prev = array();
  3720. }
  3721. if (array_key_exists('next', $post)) {
  3722. $next = $post['next'];
  3723. } else {
  3724. $next = array();
  3725. }
  3726. if (isset($current->image)) {
  3727. $var = 'imagePost';
  3728. } elseif (isset($current->link)) {
  3729. $var = 'linkPost';
  3730. } elseif (isset($current->quote)) {
  3731. $var = 'quotePost';
  3732. } elseif (isset($current->audio)) {
  3733. $var = 'audioPost';
  3734. } elseif (isset($current->video)) {
  3735. $var = 'videoPost'; }
  3736. else {
  3737. $var = 'blogPost';
  3738. }
  3739. if (config('blog.enable') === 'true') {
  3740. $blog = '<li class="breadcrumb-item" itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"><a itemprop="item" href="' . site_url() . blog_path() .'"><span itemprop="name">' . blog_string() . '</span></a><meta itemprop="position" content="2" /></li> &#187; ';
  3741. } else {
  3742. $blog = '';
  3743. }
  3744. $vroot = rtrim(config('views.root'), '/');
  3745. $lt = $vroot . '/layout--post--' . $current->ct . '.html.php';
  3746. $pt = $vroot . '/layout--post--' . $current->type . '.html.php';
  3747. $ls = $vroot . '/layout--post.html.php';
  3748. if (file_exists($lt)) {
  3749. $layout = 'layout--post--' . $current->ct;
  3750. } else if (file_exists($pt)) {
  3751. $layout = 'layout--post--' . $current->type;
  3752. } else if (file_exists($ls)) {
  3753. $layout = 'layout--post';
  3754. } else {
  3755. $layout = '';
  3756. }
  3757. $pv = $vroot . '/post--' . $current->ct . '.html.php';
  3758. $pvt = $vroot . '/post--' . $current->type . '.html.php';
  3759. if (file_exists($pv)) {
  3760. $pview = 'post--' . $current->ct;
  3761. } else if(file_exists($pvt)) {
  3762. $pview = 'post--' . $current->type;
  3763. } else {
  3764. $pview = 'post';
  3765. }
  3766. render($pview, array(
  3767. 'title' => generate_title('is_post', $current),
  3768. 'description' => $current->description,
  3769. 'canonical' => $current->url,
  3770. 'metatags' => generate_meta('is_post', $current),
  3771. 'p' => $current,
  3772. 'post' => $current,
  3773. 'author' => $author,
  3774. 'bodyclass' => 'in-post category-' . $current->ct . ' type-' . $current->type,
  3775. 'breadcrumb' => '<style>.breadcrumb-list {margin:0; padding:0;} .breadcrumb-list li {display: inline-block; list-style: none;}</style><ol class="breadcrumb-list" itemscope itemtype="http://schema.org/BreadcrumbList"><li class="breadcrumb-item" itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"><a itemprop="item" href="' . site_url() . '"><span itemprop="name">' . config('breadcrumb.home') . '</span></a><meta itemprop="position" content="1" /></li> &#187; '. $blog . '<li class="breadcrumb-item" itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem">' . $current->categoryb . '<meta itemprop="position" content="3" /></li>' . ' &#187; ' . $current->title . '</ol>',
  3776. 'prev' => has_prev($prev),
  3777. 'next' => has_next($next),
  3778. 'type' => $var,
  3779. 'is_post' => true
  3780. ), $layout);
  3781. });
  3782. // Edit blog post
  3783. get('/'. permalink_type() .'/:name/edit', function ($name) {
  3784. if (login()) {
  3785. $user = $_SESSION[site_url()]['user'];
  3786. $role = user('role', $user);
  3787. config('views.root', 'system/admin/views');
  3788. $post = find_post(null, null, $name);
  3789. if (!$post) {
  3790. $post = find_draft(null, null, $name);
  3791. if (!$post) {
  3792. $post = find_scheduled(null, null, $name);
  3793. if (!$post) {
  3794. not_found();
  3795. }
  3796. }
  3797. }
  3798. $current = $post['current'];
  3799. if (isset($current->image)) {
  3800. $type= 'is_image';
  3801. } elseif (isset($current->link)) {
  3802. $type = 'is_link';
  3803. } elseif (isset($current->quote)) {
  3804. $type = 'is_quote';
  3805. } elseif (isset($current->audio)) {
  3806. $type = 'is_audio';
  3807. } elseif (isset($current->video)) {
  3808. $type = 'is_video';
  3809. } else {
  3810. $type = 'is_post';
  3811. }
  3812. if ($user === $current->author || $role === 'editor' || $role === 'admin') {
  3813. render('edit-content', array(
  3814. 'title' => generate_title('is_default', $current->title),
  3815. 'description' => safe_html(strip_tags(blog_description())),
  3816. 'canonical' => site_url(),
  3817. 'metatags' => generate_meta(null, null),
  3818. 'p' => $current,
  3819. 'post' => $current,
  3820. 'type' => $type,
  3821. 'is_admin' => true,
  3822. 'bodyclass' => 'edit-post',
  3823. 'breadcrumb' => '<span><a href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  3824. ));
  3825. } else {
  3826. render('denied', array(
  3827. 'title' => generate_title('is_default', $current->title),
  3828. 'description' => safe_html(strip_tags(blog_description())),
  3829. 'canonical' => site_url(),
  3830. 'metatags' => generate_meta(null, null),
  3831. 'p' => $current,
  3832. 'post' => $current,
  3833. 'bodyclass' => 'denied',
  3834. 'is_admin' => true,
  3835. 'breadcrumb' => '<span><a href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  3836. ));
  3837. }
  3838. } else {
  3839. $login = site_url() . 'login';
  3840. header("location: $login");
  3841. }
  3842. });
  3843. // Get edited data from blog post
  3844. post('/'. permalink_type() .'/:name/edit', function () {
  3845. if(!login()) {
  3846. $login = site_url() . 'login';
  3847. header("location: $login");
  3848. }
  3849. $field = array();
  3850. $aField = array();
  3851. $field_file = 'content/data/field/post.json';
  3852. if (file_exists($field_file)) {
  3853. $aField = json_decode(file_get_contents($field_file, true));
  3854. }
  3855. if(!empty($aField)) {
  3856. foreach ($aField as $af) {
  3857. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  3858. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  3859. } else {
  3860. $field[$af->name] = from($_REQUEST, $af->name);
  3861. }
  3862. }
  3863. }
  3864. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  3865. $title = from($_REQUEST, 'title');
  3866. $is_post = from($_REQUEST, 'is_post');
  3867. $image = from($_REQUEST, 'image');
  3868. $is_image = from($_REQUEST, 'is_image');
  3869. $video = from($_REQUEST, 'video');
  3870. $is_video = from($_REQUEST, 'is_video');
  3871. $link = from($_REQUEST, 'link');
  3872. $is_link = from($_REQUEST, 'is_link');
  3873. $audio = from($_REQUEST, 'audio');
  3874. $is_audio = from($_REQUEST, 'is_audio');
  3875. $quote = from($_REQUEST, 'quote');
  3876. $is_quote = from($_REQUEST, 'is_quote');
  3877. $tag = from($_REQUEST, 'tag');
  3878. $url = from($_REQUEST, 'url');
  3879. $content = from($_REQUEST, 'content');
  3880. $oldfile = from($_REQUEST, 'oldfile');
  3881. $destination = from($_GET, 'destination');
  3882. $description = from($_REQUEST, 'description');
  3883. $date = from($_REQUEST, 'date');
  3884. $time = from($_REQUEST, 'time');
  3885. $dateTime = null;
  3886. $revertPost = from($_REQUEST, 'revertpost');
  3887. $publishDraft = from($_REQUEST, 'publishdraft');
  3888. $category = from($_REQUEST, 'category');
  3889. if ($date !== null && $time !== null) {
  3890. $dateTime = $date . ' ' . $time;
  3891. }
  3892. if (!empty($is_image)) {
  3893. $type = 'is_image';
  3894. } elseif (!empty($is_video)) {
  3895. $type = 'is_video';
  3896. } elseif (!empty($is_link)) {
  3897. $type = 'is_link';
  3898. } elseif (!empty($is_quote)) {
  3899. $type = 'is_quote';
  3900. } elseif (!empty($is_audio)) {
  3901. $type = 'is_audio';
  3902. } elseif (!empty($is_post)) {
  3903. $type = 'is_post';
  3904. }
  3905. if (empty($url)) {
  3906. $url = $title;
  3907. }
  3908. $arr = explode('/', $oldfile);
  3909. $user = $_SESSION[site_url()]['user'];
  3910. $role = user('role', $user);
  3911. if ($user === $arr[1] || $role === 'editor' || $role === 'admin') {
  3912. if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($image)) {
  3913. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'image', $destination, $description, $dateTime, $image,null, $field);
  3914. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($video)) {
  3915. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'video', $destination, $description, $dateTime, $video,null, $field);
  3916. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($link)) {
  3917. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'link', $destination, $description, $dateTime, $link,null, $field);
  3918. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($quote)) {
  3919. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'quote', $destination, $description, $dateTime, $quote,null, $field);
  3920. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($audio)) {
  3921. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'audio', $destination, $description, $dateTime, $audio,null, $field);
  3922. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($is_post)) {
  3923. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'post', $destination, $description, $dateTime, null,null, $field);
  3924. } else {
  3925. $message['error'] = '';
  3926. if (empty($title)) {
  3927. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  3928. }
  3929. if (empty($tag)) {
  3930. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_tag') . '</li>';
  3931. }
  3932. if (empty($content)) {
  3933. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  3934. }
  3935. if (!$proper) {
  3936. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  3937. }
  3938. if (!empty($is_image)) {
  3939. if (empty($image)) {
  3940. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_image') . '</li>';
  3941. }
  3942. } elseif (!empty($is_video)) {
  3943. if (empty($video)) {
  3944. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_video') . '</li>';
  3945. }
  3946. } elseif (!empty($is_link)) {
  3947. if (empty($link)) {
  3948. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_link') . '</li>';
  3949. }
  3950. } elseif (!empty($is_quote)) {
  3951. if (empty($quote)) {
  3952. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_quote') . '</li>';
  3953. }
  3954. } elseif (!empty($is_audio)) {
  3955. if (empty($audio)) {
  3956. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_audio') . '</li>';
  3957. }
  3958. }
  3959. config('views.root', 'system/admin/views');
  3960. render('edit-content', array(
  3961. 'title' => generate_title('is_default', $title),
  3962. 'description' => safe_html(strip_tags(blog_description())),
  3963. 'canonical' => site_url(),
  3964. 'metatags' => generate_meta(null, null),
  3965. 'error' => '<ul>' . $message['error'] . '</ul>',
  3966. 'oldfile' => $oldfile,
  3967. 'postTitle' => $title,
  3968. 'postImage' => $image,
  3969. 'postVideo' => $video,
  3970. 'postLink' => $link,
  3971. 'postQuote' => $quote,
  3972. 'postAudio' => $audio,
  3973. 'postTag' => $tag,
  3974. 'postUrl' => $url,
  3975. 'type' => $type,
  3976. 'is_admin' => true,
  3977. 'postContent' => $content,
  3978. 'bodyclass' => 'edit-post',
  3979. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Edit_content')
  3980. ));
  3981. }
  3982. } else {
  3983. $redir = site_url();
  3984. header("location: $redir");
  3985. }
  3986. });
  3987. // Delete blog post
  3988. get('/'. permalink_type() .'/:name/delete', function ($name) {
  3989. if (login()) {
  3990. $user = $_SESSION[site_url()]['user'];
  3991. $role = user('role', $user);
  3992. config('views.root', 'system/admin/views');
  3993. $post = find_post(null, null, $name);
  3994. if (!$post) {
  3995. $post = find_draft(null, null, $name);
  3996. if (!$post) {
  3997. $post = find_scheduled(null, null, $name);
  3998. if (!$post) {
  3999. not_found();
  4000. }
  4001. }
  4002. }
  4003. $current = $post['current'];
  4004. if (config('blog.enable') === 'true') {
  4005. $blog = '<li class="breadcrumb-item" itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"><a itemprop="item" href="' . site_url() . 'blog"><span itemprop="name">Blog</span></a><meta itemprop="position" content="2" /></li> &#187; ';
  4006. } else {
  4007. $blog = '';
  4008. }
  4009. if ($user === $current->author || $role === 'editor' || $role === 'admin') {
  4010. render('delete-post', array(
  4011. 'title' => generate_title('is_default', i18n('Delete')),
  4012. 'description' => safe_html(strip_tags(blog_description())),
  4013. 'canonical' => site_url(),
  4014. 'metatags' => generate_meta(null, null),
  4015. 'p' => $current,
  4016. 'post' => $current,
  4017. 'is_admin' => true,
  4018. 'bodyclass' => 'delete-post',
  4019. 'breadcrumb' => '<span><a href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  4020. ));
  4021. } else {
  4022. render('denied', array(
  4023. 'title' => generate_title('is_default', 'Delete post'),
  4024. 'description' => safe_html(strip_tags(blog_description())),
  4025. 'canonical' => site_url(),
  4026. 'metatags' => generate_meta(null, null),
  4027. 'p' => $current,
  4028. 'post' => $current,
  4029. 'is_admin' => true,
  4030. 'bodyclass' => 'delete-post',
  4031. 'breadcrumb' => '<span><a href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  4032. ));
  4033. }
  4034. } else {
  4035. $login = site_url() . 'login';
  4036. header("location: $login");
  4037. }
  4038. });
  4039. // Get deleted data from blog post
  4040. post('/'. permalink_type() .'/:name/delete', function () {
  4041. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  4042. if ($proper && login()) {
  4043. $file = from($_REQUEST, 'file');
  4044. $destination = from($_GET, 'destination');
  4045. $arr = explode('/', $file);
  4046. $user = $_SESSION[site_url()]['user'];
  4047. $role = user('role', $user);
  4048. if ($user === $arr[1] || $role === 'editor' || $role === 'admin') {
  4049. delete_post($file, $destination);
  4050. } else {
  4051. $redir = site_url();
  4052. header("location: $redir");
  4053. }
  4054. }
  4055. });
  4056. // Show various page (top-level), admin, login, sitemap, static page.
  4057. get('/:static', function ($static) {
  4058. if (strpos($static, ".xml") !== false) {
  4059. if ($static === 'sitemap.xml') {
  4060. $sitemap = 'index.xml';
  4061. } else {
  4062. $sitemap = str_replace('sitemap.', '', $static);
  4063. }
  4064. header('Content-Type: text/xml');
  4065. generate_sitemap($sitemap);
  4066. die;
  4067. } elseif ($static === 'admin') {
  4068. if (login()) {
  4069. config('views.root', 'system/admin/views');
  4070. render('main', array(
  4071. 'title' => generate_title('is_default', i18n('Admin')),
  4072. 'description' => safe_html(strip_tags(blog_description())),
  4073. 'canonical' => site_url(),
  4074. 'metatags' => generate_meta(null, null),
  4075. 'bodyclass' => 'admin-front',
  4076. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Admin')
  4077. ));
  4078. } else {
  4079. $login = site_url() . 'login';
  4080. header("location: $login");
  4081. }
  4082. die;
  4083. } elseif ($static === 'login') {
  4084. if (session_status() == PHP_SESSION_NONE) session_start();
  4085. config('views.root', 'system/admin/views');
  4086. render('login', array(
  4087. 'title' => generate_title('is_default', i18n('Login')),
  4088. 'description' => 'Login page from ' . blog_title() . '.',
  4089. 'canonical' => site_url() . '/login',
  4090. 'metatags' => generate_meta(null, null),
  4091. 'bodyclass' => 'in-login',
  4092. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Login')
  4093. ));
  4094. die;
  4095. } elseif ($static === 'logout') {
  4096. if (login()) {
  4097. config('views.root', 'system/admin/views');
  4098. render('logout', array(
  4099. 'title' => generate_title('is_default', i18n('Logout')),
  4100. 'description' => safe_html(strip_tags(blog_description())),
  4101. 'canonical' => site_url(),
  4102. 'metatags' => generate_meta(null, null),
  4103. 'bodyclass' => 'in-logout',
  4104. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Logout')
  4105. ));
  4106. } else {
  4107. $login = site_url() . 'login';
  4108. header("location: $login");
  4109. }
  4110. die;
  4111. } elseif ($static === blog_path()) {
  4112. if(config('blog.enable') !== 'true') {
  4113. $url = site_url();
  4114. header("Location: $url");
  4115. }
  4116. if (!login()) {
  4117. file_cache($_SERVER['REQUEST_URI']);
  4118. }
  4119. $page = from($_GET, 'page');
  4120. $page = $page ? (int)$page : 1;
  4121. $perpage = config('posts.perpage');
  4122. $posts = get_posts(null, $page, $perpage);
  4123. $total = count(get_blog_posts());
  4124. $vroot = rtrim(config('views.root'), '/');
  4125. $lt = $vroot . '/layout--blog.html.php';
  4126. if (file_exists($lt)) {
  4127. $layout = 'layout--blog';
  4128. } else {
  4129. $layout = '';
  4130. }
  4131. $pv = $vroot . '/main--blog.html.php';
  4132. if (file_exists($pv)) {
  4133. $pview = 'main--blog';
  4134. } else {
  4135. $pview = 'main';
  4136. }
  4137. $tblog = new stdClass;
  4138. $tblog->title = blog_string();
  4139. $tblog->url = site_url() . blog_path();
  4140. $tblog->count = count(get_blog_posts());
  4141. $tblog->description = i18n('all_blog_posts') . ' ' . i18n('by') . ' ' . blog_title();
  4142. $tblog->body = $tblog->description;
  4143. $tblog->rss = site_url() . 'feed/rss';
  4144. $tblog->slug = blog_path();
  4145. if (empty($posts) || $page < 1) {
  4146. // a non-existing page
  4147. render('no-posts', array(
  4148. 'title' => generate_title('is_blog', null),
  4149. 'description' => blog_title() . ' ' . blog_string(),
  4150. 'canonical' => site_url(),
  4151. 'metatags' => generate_meta('is_blog', null),
  4152. 'bodyclass' => 'no-posts',
  4153. 'is_front' => true,
  4154. ), $layout);
  4155. die;
  4156. }
  4157. if ($page > 1) {
  4158. $CanonicalPageNum = '?page=' . $page;
  4159. } else {
  4160. $CanonicalPageNum = NULL;
  4161. }
  4162. render($pview, array(
  4163. 'title' => generate_title('is_blog', null),
  4164. 'description' => blog_title() . ' ' . blog_string(),
  4165. 'canonical' => site_url() . blog_path() . $CanonicalPageNum,
  4166. 'metatags' => generate_meta('is_blog', null),
  4167. 'page' => $page,
  4168. 'posts' => $posts,
  4169. 'taxonomy' => $tblog,
  4170. 'bodyclass' => 'in-blog',
  4171. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . blog_string(),
  4172. 'pagination' => has_pagination($total, $perpage, $page),
  4173. 'is_blog' => true,
  4174. 'is_taxonomy' => true
  4175. ), $layout);
  4176. } elseif ($static === 'front') {
  4177. $redir = site_url();
  4178. header("location: $redir", TRUE, 301);
  4179. } else {
  4180. $pages = '';
  4181. if (config("views.counter") != "true") {
  4182. if (!login()) {
  4183. file_cache($_SERVER['REQUEST_URI']);
  4184. }
  4185. } else {
  4186. $pages = get_static_pages();
  4187. if (!empty($pages)) {
  4188. foreach ($pages as $index => $v) {
  4189. if (stripos($v['basename'], $static . '.md') !== false) {
  4190. add_view('page_' . $static);
  4191. }
  4192. }
  4193. }
  4194. if (!login()) {
  4195. file_cache($_SERVER['REQUEST_URI']);
  4196. }
  4197. }
  4198. $post = find_page($static, $pages);
  4199. if (!$post) {
  4200. not_found('page_' . $static);
  4201. }
  4202. if (array_key_exists('prev', $post)) {
  4203. $prev = $post['prev'];
  4204. } else {
  4205. $prev = array();
  4206. }
  4207. if (array_key_exists('next', $post)) {
  4208. $next = $post['next'];
  4209. } else {
  4210. $next = array();
  4211. }
  4212. $post = $post['current'];
  4213. $vroot = rtrim(config('views.root'), '/');
  4214. $lt = $vroot . '/layout--' . strtolower($static) . '.html.php';
  4215. $ls = $vroot . '/layout--static.html.php';
  4216. if (file_exists($lt)) {
  4217. $layout = 'layout--' . strtolower($static);
  4218. } else if (file_exists($ls)) {
  4219. $layout = 'layout--static';
  4220. } else {
  4221. $layout = '';
  4222. }
  4223. $pv = $vroot . '/static--' . strtolower($static) . '.html.php';
  4224. if (file_exists($pv)) {
  4225. $pview = 'static--' . strtolower($static);
  4226. } else {
  4227. $pview = 'static';
  4228. }
  4229. render($pview, array(
  4230. 'title' => generate_title('is_page', $post),
  4231. 'description' => $post->description,
  4232. 'canonical' => $post->url,
  4233. 'metatags' => generate_meta('is_page', $post),
  4234. 'bodyclass' => 'in-page ' . strtolower($static),
  4235. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . $post->title,
  4236. 'p' => $post,
  4237. 'static' => $post,
  4238. 'type' => 'is_page',
  4239. 'prev' => static_prev($prev),
  4240. 'next' => static_next($next),
  4241. 'is_page' => true
  4242. ), $layout);
  4243. }
  4244. });
  4245. // Show the add sub static page
  4246. get('/:static/add', function ($static) {
  4247. $user = $_SESSION[site_url()]['user'];
  4248. $role = user('role', $user);
  4249. if (login()) {
  4250. config('views.root', 'system/admin/views');
  4251. if ($role === 'editor' || $role === 'admin') {
  4252. $post = find_page($static);
  4253. if (!$post) {
  4254. not_found();
  4255. }
  4256. $post = $post['current'];
  4257. render('add-page', array(
  4258. 'title' => generate_title('is_default', i18n('Add_new_page')),
  4259. 'description' => safe_html(strip_tags(blog_description())),
  4260. 'canonical' => site_url(),
  4261. 'metatags' => generate_meta(null, null),
  4262. 'type' => 'is_subpage',
  4263. 'parent' => $static,
  4264. 'is_admin' => true,
  4265. 'bodyclass' => 'add-page',
  4266. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="' . site_url() . 'admin/pages/' . $post->slug . '">' . $post->title . '</a> &#187; ' . i18n('Add_new_page')
  4267. ));
  4268. } else {
  4269. render('denied', array(
  4270. 'title' => generate_title('is_default', i18n('Denied')),
  4271. 'description' => safe_html(strip_tags(blog_description())),
  4272. 'canonical' => site_url(),
  4273. 'metatags' => generate_meta(null, null),
  4274. 'type' => 'is_admin-config',
  4275. 'is_admin' => true,
  4276. 'bodyclass' => 'denied',
  4277. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  4278. ));
  4279. }
  4280. } else {
  4281. $login = site_url() . 'login';
  4282. header("location: $login");
  4283. }
  4284. });
  4285. // Submitted data from add sub static page
  4286. post('/:static/add', function ($static) {
  4287. if(!login()) {
  4288. $login = site_url() . 'login';
  4289. header("location: $login");
  4290. }
  4291. $field = array();
  4292. $aField = array();
  4293. $field_file= 'content/data/field/subpage.json';
  4294. if (file_exists($field_file)) {
  4295. $aField = json_decode(file_get_contents($field_file, true));
  4296. }
  4297. if(!empty($aField)) {
  4298. foreach ($aField as $af) {
  4299. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  4300. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  4301. } else {
  4302. $field[$af->name] = from($_REQUEST, $af->name);
  4303. }
  4304. }
  4305. }
  4306. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  4307. $title = from($_REQUEST, 'title');
  4308. $url = from($_REQUEST, 'url');
  4309. $content = from($_REQUEST, 'content');
  4310. $description = from($_REQUEST, 'description');
  4311. $draft = from($_REQUEST, 'draft');
  4312. $user = $_SESSION[site_url()]['user'];
  4313. $role = user('role', $user);
  4314. if (empty($url)) {
  4315. $url = $title;
  4316. }
  4317. if ($role === 'editor' || $role === 'admin') {
  4318. if ($proper && !empty($title) && !empty($content)) {
  4319. add_sub_page($title, $url, $content, $static, $draft, $description, null, null, $field);
  4320. } else {
  4321. $message['error'] = '';
  4322. if (empty($title)) {
  4323. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  4324. }
  4325. if (empty($content)) {
  4326. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  4327. }
  4328. if (!$proper) {
  4329. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  4330. }
  4331. config('views.root', 'system/admin/views');
  4332. render('add-page', array(
  4333. 'title' => generate_title('is_default', i18n('Add_new_page')),
  4334. 'description' => safe_html(strip_tags(blog_description())),
  4335. 'canonical' => site_url(),
  4336. 'metatags' => generate_meta(null, null),
  4337. 'error' => '<ul>' . $message['error'] . '</ul>',
  4338. 'postTitle' => $title,
  4339. 'postUrl' => $url,
  4340. 'postContent' => $content,
  4341. 'type' => 'is_subpage',
  4342. 'is_admin' => true,
  4343. 'bodyclass' => 'add-page',
  4344. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="' . $title . '">' . $title . '</a> &#187; ' . i18n('Add_new_page')
  4345. ));
  4346. }
  4347. } else {
  4348. $redir = site_url();
  4349. header("location: $redir");
  4350. }
  4351. });
  4352. // Show edit the static page
  4353. get('/:static/edit', function ($static) {
  4354. $user = $_SESSION[site_url()]['user'];
  4355. $role = user('role', $user);
  4356. if (login()) {
  4357. config('views.root', 'system/admin/views');
  4358. if ($role === 'editor' || $role === 'admin') {
  4359. $post = find_page($static);
  4360. if (!$post) {
  4361. $post = find_draft_page($static);
  4362. if (!$post) {
  4363. not_found();
  4364. } else {
  4365. $post = $post[0];
  4366. }
  4367. } else {
  4368. $post = $post['current'];
  4369. }
  4370. render('edit-page', array(
  4371. 'title' => generate_title('is_default', i18n('Edit') . ': ' . $post->title),
  4372. 'description' => safe_html(strip_tags(blog_description())),
  4373. 'canonical' => site_url(),
  4374. 'metatags' => generate_meta(null, null),
  4375. 'bodyclass' => 'edit-page',
  4376. 'is_admin' => true,
  4377. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="'. site_url() .'admin/pages">' .i18n('pages').'</a> &#187; ' . $post->title,
  4378. 'p' => $post,
  4379. 'static' => $post,
  4380. 'type' => 'is_page',
  4381. 'parent' => ''
  4382. ));
  4383. } else {
  4384. render('denied', array(
  4385. 'title' => generate_title('is_default', i18n('Denied')),
  4386. 'description' => safe_html(strip_tags(blog_description())),
  4387. 'canonical' => site_url(),
  4388. 'metatags' => generate_meta(null, null),
  4389. 'type' => 'is_page',
  4390. 'is_admin' => true,
  4391. 'bodyclass' => 'denied',
  4392. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  4393. ));
  4394. }
  4395. } else {
  4396. $login = site_url() . 'login';
  4397. header("location: $login");
  4398. }
  4399. });
  4400. // Get edited data from static page
  4401. post('/:static/edit', function () {
  4402. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  4403. if(!login()) {
  4404. $login = site_url() . 'login';
  4405. header("location: $login");
  4406. }
  4407. $field = array();
  4408. $aField = array();
  4409. $field_file = 'content/data/field/page.json';
  4410. if (file_exists($field_file)) {
  4411. $aField = json_decode(file_get_contents($field_file, true));
  4412. }
  4413. if(!empty($aField)) {
  4414. foreach ($aField as $af) {
  4415. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  4416. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  4417. } else {
  4418. $field[$af->name] = from($_REQUEST, $af->name);
  4419. }
  4420. }
  4421. }
  4422. $title = from($_REQUEST, 'title');
  4423. $url = from($_REQUEST, 'url');
  4424. $content = from($_REQUEST, 'content');
  4425. $oldfile = from($_REQUEST, 'oldfile');
  4426. $destination = from($_GET, 'destination');
  4427. $description = from($_REQUEST, 'description');
  4428. $revertPage = from($_REQUEST, 'revertpage');
  4429. $publishDraft = from($_REQUEST, 'publishdraft');
  4430. $user = $_SESSION[site_url()]['user'];
  4431. $role = user('role', $user);
  4432. if (empty($url)) {
  4433. $url = $title;
  4434. }
  4435. if ($role === 'editor' || $role === 'admin') {
  4436. if ($proper && !empty($title) && !empty($content)) {
  4437. edit_page($title, $url, $content, $oldfile, $revertPage, $publishDraft, $destination, $description, null, null, $field);
  4438. } else {
  4439. $message['error'] = '';
  4440. if (empty($title)) {
  4441. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  4442. }
  4443. if (empty($content)) {
  4444. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  4445. }
  4446. if (!$proper) {
  4447. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  4448. }
  4449. config('views.root', 'system/admin/views');
  4450. render('edit-page', array(
  4451. 'title' => generate_title('is_default', i18n('Edit') . ': ' . $title),
  4452. 'description' => safe_html(strip_tags(blog_description())),
  4453. 'canonical' => site_url(),
  4454. 'metatags' => generate_meta(null, null),
  4455. 'error' => '<ul>' . $message['error'] . '</ul>',
  4456. 'oldfile' => $oldfile,
  4457. 'postTitle' => $title,
  4458. 'postUrl' => $url,
  4459. 'postContent' => $content,
  4460. 'bodyclass' => 'edit-page',
  4461. 'is_admin' => true,
  4462. 'type' => 'is_page',
  4463. 'parent' => '',
  4464. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Edit')
  4465. ));
  4466. }
  4467. } else {
  4468. $redir = site_url();
  4469. header("location: $redir");
  4470. }
  4471. });
  4472. // Deleted the static page
  4473. get('/:static/delete', function ($static) {
  4474. $user = $_SESSION[site_url()]['user'];
  4475. $role = user('role', $user);
  4476. if (login()) {
  4477. config('views.root', 'system/admin/views');
  4478. if ($role === 'editor' || $role === 'admin') {
  4479. $post = find_page($static);
  4480. if (!$post) {
  4481. $post = find_draft_page($static);
  4482. if (!$post) {
  4483. not_found();
  4484. } else {
  4485. $post = $post[0];
  4486. }
  4487. } else {
  4488. $post = $post['current'];
  4489. }
  4490. render('delete-page', array(
  4491. 'title' => generate_title('is_default', i18n('Delete') . ': ' . $post->title),
  4492. 'description' => safe_html(strip_tags(blog_description())),
  4493. 'canonical' => site_url(),
  4494. 'metatags' => generate_meta(null, null),
  4495. 'bodyclass' => 'delete-page',
  4496. 'is_admin' => true,
  4497. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Delete') . ': ' . $post->title,
  4498. 'p' => $post,
  4499. 'static' => $post,
  4500. 'type' => 'is_page',
  4501. ));
  4502. } else {
  4503. render('denied', array(
  4504. 'title' => generate_title('is_default', i18n('Denied')),
  4505. 'description' => safe_html(strip_tags(blog_description())),
  4506. 'canonical' => site_url(),
  4507. 'metatags' => generate_meta(null, null),
  4508. 'type' => 'is_admin-config',
  4509. 'is_admin' => true,
  4510. 'bodyclass' => 'denied',
  4511. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  4512. ));
  4513. }
  4514. } else {
  4515. $login = site_url() . 'login';
  4516. header("location: $login");
  4517. }
  4518. });
  4519. // Get deleted data for static page
  4520. post('/:static/delete', function () {
  4521. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  4522. if ($proper && login()) {
  4523. $user = $_SESSION[site_url()]['user'];
  4524. $role = user('role', $user);
  4525. if ($role === 'editor' || $role === 'admin') {
  4526. $file = from($_REQUEST, 'file');
  4527. $destination = from($_GET, 'destination');
  4528. delete_page($file, $destination);
  4529. } else {
  4530. $redir = site_url();
  4531. header("location: $redir");
  4532. }
  4533. }
  4534. });
  4535. // Show the sb static page
  4536. get('/:static/:sub', function ($static, $sub) {
  4537. if ($static === 'front') {
  4538. $redir = site_url();
  4539. header("location: $redir", TRUE, 301);
  4540. }
  4541. $sub_pages = '';
  4542. if (config("views.counter") != "true") {
  4543. if (!login()) {
  4544. file_cache($_SERVER['REQUEST_URI']);
  4545. }
  4546. } else {
  4547. $sub_pages = array_values(get_static_subpages($static));
  4548. if (!empty($sub_pages)) {
  4549. foreach ($sub_pages as $index => $v) {
  4550. if (stripos($v['basename'], $sub . '.md') !== false) {
  4551. add_view('subpage_' . $static.'.'.$sub);
  4552. }
  4553. }
  4554. }
  4555. if (!login()) {
  4556. file_cache($_SERVER['REQUEST_URI']);
  4557. }
  4558. }
  4559. $parent_post = find_page($static);
  4560. if (!$parent_post) {
  4561. not_found('subpage_' . $static.'.'.$sub);
  4562. }
  4563. $post = find_subpage($static, $sub, $sub_pages);
  4564. if (!$post) {
  4565. not_found('subpage_' . $static.'.'.$sub);
  4566. }
  4567. if (array_key_exists('prev', $post)) {
  4568. $prev = $post['prev'];
  4569. } else {
  4570. $prev = array();
  4571. }
  4572. if (array_key_exists('next', $post)) {
  4573. $next = $post['next'];
  4574. } else {
  4575. $next = array();
  4576. }
  4577. $post = $post['current'];
  4578. $vroot = rtrim(config('views.root'), '/');
  4579. $lt = $vroot . '/layout--' . strtolower($static) . '--' . strtolower($sub) . '.html.php';
  4580. $ls = $vroot . '/layout--' . strtolower($static) . '.html.php';
  4581. $lf = $vroot . '/layout--static.html.php';
  4582. $lsp = $vroot . '/layout--' . strtolower($sub) . '.html.php';
  4583. $lsps = $vroot . '/layout--substatic.html.php';
  4584. if (file_exists($lt)) {
  4585. $layout = 'layout--' . strtolower($static) . '--' . strtolower($sub);
  4586. } else if (file_exists($lsp)) {
  4587. $layout = 'layout--' . strtolower($sub);
  4588. } else if (file_exists($lsps)) {
  4589. $layout = 'layout--substatic';
  4590. } else if (file_exists($ls)) {
  4591. $layout = 'layout--' . strtolower($static);
  4592. } else if (file_exists($lf)) {
  4593. $layout = 'layout--static';
  4594. } else {
  4595. $layout = '';
  4596. }
  4597. $pv = $vroot . '/static--' . strtolower($static) . '--' . strtolower($sub) . '.html.php';
  4598. $ps = $vroot . '/static--' . strtolower($static) . '.html.php';
  4599. $psp = $vroot . '/substatic--' . strtolower($sub) . '.html.php';
  4600. $psps = $vroot . '/substatic.html.php';
  4601. if (file_exists($pv)) {
  4602. $pview = 'static--' . strtolower($static) . '--' . strtolower($sub);
  4603. } else if (file_exists($psp)) {
  4604. $pview = 'substatic--' . strtolower($sub);
  4605. } else if (file_exists($psps)) {
  4606. $pview = 'substatic';
  4607. } else if (file_exists($ps)) {
  4608. $pview = 'static--' . strtolower($static);
  4609. } else {
  4610. $pview = 'static';
  4611. }
  4612. render($pview, array(
  4613. 'title' => generate_title('is_subpage', $post),
  4614. 'description' => $post->description,
  4615. 'canonical' => $post->url,
  4616. 'metatags' => generate_meta('is_subpage', $post),
  4617. 'bodyclass' => 'in-page ' . strtolower($static) . ' ' . strtolower($sub) ,
  4618. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="' . $parent_post['current']->url . '">' . $parent_post['current']->title . '</a> &#187; ' . $post->title,
  4619. 'p' => $post,
  4620. 'static' => $post,
  4621. 'parent' => $parent_post,
  4622. 'prev' => static_prev($prev),
  4623. 'next' => static_next($next),
  4624. 'type' => 'is_subpage',
  4625. 'is_subpage' => true
  4626. ), $layout);
  4627. });
  4628. // Edit the sub static page
  4629. get('/:static/:sub/edit', function ($static, $sub) {
  4630. $user = $_SESSION[site_url()]['user'];
  4631. $role = user('role', $user);
  4632. if (login()) {
  4633. config('views.root', 'system/admin/views');
  4634. if ($role === 'editor' || $role === 'admin') {
  4635. $post = find_page($static);
  4636. if (!$post) {
  4637. not_found();
  4638. }
  4639. $post = $post['current'];
  4640. $page = find_subpage($static, $sub);
  4641. if (!$page) {
  4642. $page = find_draft_subpage($static, $sub);
  4643. if (!$page) {
  4644. not_found();
  4645. } else {
  4646. $page = $page[0];
  4647. }
  4648. } else {
  4649. $page = $page['current'];
  4650. }
  4651. render('edit-page', array(
  4652. 'title' => generate_title('is_default', i18n('Edit') . ': ' . $page->title),
  4653. 'description' => safe_html(strip_tags(blog_description())),
  4654. 'canonical' => site_url(),
  4655. 'metatags' => generate_meta(null, null),
  4656. 'bodyclass' => 'edit-page',
  4657. 'is_admin' => true,
  4658. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="' . site_url() . 'admin/pages/' . $post->slug . '">' . $post->title . '</a> &#187; ' . $page->title,
  4659. 'p' => $page,
  4660. 'static' => $page,
  4661. 'type' => 'is_subpage',
  4662. 'parent' => $static
  4663. ));
  4664. } else {
  4665. render('denied', array(
  4666. 'title' => generate_title('is_default', i18n('Denied')),
  4667. 'description' => safe_html(strip_tags(blog_description())),
  4668. 'canonical' => site_url(),
  4669. 'metatags' => generate_meta(null, null),
  4670. 'type' => 'is_subpage',
  4671. 'is_admin' => true,
  4672. 'bodyclass' => 'denied',
  4673. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  4674. ));
  4675. }
  4676. } else {
  4677. $login = site_url() . 'login';
  4678. header("location: $login");
  4679. }
  4680. });
  4681. // Submitted data from edit sub static page
  4682. post('/:static/:sub/edit', function ($static, $sub) {
  4683. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  4684. if(!login()) {
  4685. $login = site_url() . 'login';
  4686. header("location: $login");
  4687. }
  4688. $field = array();
  4689. $aField = array();
  4690. $field_file = 'content/data/field/subpage.json';
  4691. if (file_exists($field_file)) {
  4692. $aField = json_decode(file_get_contents($field_file, true));
  4693. }
  4694. if(!empty($aField)) {
  4695. foreach ($aField as $af) {
  4696. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  4697. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  4698. } else {
  4699. $field[$af->name] = from($_REQUEST, $af->name);
  4700. }
  4701. }
  4702. }
  4703. $title = from($_REQUEST, 'title');
  4704. $url = from($_REQUEST, 'url');
  4705. $content = from($_REQUEST, 'content');
  4706. $oldfile = from($_REQUEST, 'oldfile');
  4707. $destination = from($_GET, 'destination');
  4708. $description = from($_REQUEST, 'description');
  4709. $revertPage = from($_REQUEST, 'revertpage');
  4710. $publishDraft = from($_REQUEST, 'publishdraft');
  4711. if ($destination === null) {
  4712. $destination = $static . "/" . $sub;
  4713. }
  4714. $user = $_SESSION[site_url()]['user'];
  4715. $role = user('role', $user);
  4716. if (empty($url)) {
  4717. $url = $title;
  4718. }
  4719. if ($role === 'editor' || $role === 'admin') {
  4720. if ($proper && !empty($title) && !empty($content)) {
  4721. edit_page($title, $url, $content, $oldfile, $revertPage, $publishDraft, $destination, $description, $static, null, $field);
  4722. } else {
  4723. $message['error'] = '';
  4724. if (empty($title)) {
  4725. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  4726. }
  4727. if (empty($content)) {
  4728. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  4729. }
  4730. if (!$proper) {
  4731. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  4732. }
  4733. config('views.root', 'system/admin/views');
  4734. render('edit-page', array(
  4735. 'title' => generate_title('is_default', i18n('Edit') . ': ' . $title),
  4736. 'description' => safe_html(strip_tags(blog_description())),
  4737. 'canonical' => site_url(),
  4738. 'metatags' => generate_meta(null, null),
  4739. 'error' => '<ul>' . $message['error'] . '</ul>',
  4740. 'oldfile' => $oldfile,
  4741. 'postTitle' => $title,
  4742. 'postUrl' => $url,
  4743. 'postContent' => $content,
  4744. 'static' => $static,
  4745. 'sub' => $sub,
  4746. 'type' => 'is_subpage',
  4747. 'bodyclass' => 'edit-page',
  4748. 'is_admin' => true,
  4749. 'parent' => $static,
  4750. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Edit')
  4751. ));
  4752. }
  4753. } else {
  4754. $redir = site_url();
  4755. header("location: $redir");
  4756. }
  4757. });
  4758. // Delete sub static page
  4759. get('/:static/:sub/delete', function ($static, $sub) {
  4760. $user = $_SESSION[site_url()]['user'];
  4761. $role = user('role', $user);
  4762. if (login()) {
  4763. config('views.root', 'system/admin/views');
  4764. if ($role === 'editor' || $role === 'admin') {
  4765. $post = find_page($static);
  4766. if (!$post) {
  4767. not_found();
  4768. }
  4769. $post = $post['current'];
  4770. $page = find_subpage($static, $sub);
  4771. if (!$page) {
  4772. $page = find_draft_subpage($static, $sub);
  4773. if (!$page) {
  4774. not_found();
  4775. } else {
  4776. $page = $page[0];
  4777. }
  4778. } else {
  4779. $page = $page['current'];
  4780. }
  4781. render('delete-page', array(
  4782. 'title' => generate_title('is_default', i18n('Delete') . ': ' . $page->title),
  4783. 'description' => safe_html(strip_tags(blog_description())),
  4784. 'canonical' => site_url(),
  4785. 'metatags' => generate_meta(null, null),
  4786. 'bodyclass' => 'delete-page',
  4787. 'is_admin' => true,
  4788. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; <a href="' . site_url() . 'admin/pages/' . $post->slug . '">' . $post->title . '</a> &#187; ' . $page->title,
  4789. 'p' => $page,
  4790. 'static' => $page,
  4791. 'type' => 'is_subpage',
  4792. ));
  4793. } else {
  4794. render('denied', array(
  4795. 'title' => generate_title('is_default', i18n('Denied')),
  4796. 'description' => safe_html(strip_tags(blog_description())),
  4797. 'canonical' => site_url(),
  4798. 'metatags' => generate_meta(null, null),
  4799. 'type' => 'is_subpage',
  4800. 'is_admin' => true,
  4801. 'bodyclass' => 'denied',
  4802. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . i18n('Denied')
  4803. ));
  4804. }
  4805. } else {
  4806. $login = site_url() . 'login';
  4807. header("location: $login");
  4808. }
  4809. });
  4810. // Submitted data from delete sub static page
  4811. post('/:static/:sub/delete', function () {
  4812. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  4813. if ($proper && login()) {
  4814. $user = $_SESSION[site_url()]['user'];
  4815. $role = user('role', $user);
  4816. if ($role === 'editor' || $role === 'admin') {
  4817. $file = from($_REQUEST, 'file');
  4818. $destination = from($_GET, 'destination');
  4819. delete_page($file, $destination);
  4820. } else {
  4821. $redir = site_url();
  4822. header("location: $redir");
  4823. }
  4824. }
  4825. });
  4826. // Show blog post with year-month
  4827. get('/:year/:month/:name', function ($year, $month, $name) {
  4828. if (permalink_type() !== 'default') {
  4829. $redir = site_url() . permalink_type() . '/' . $name;
  4830. header("location: $redir", TRUE, 301);
  4831. }
  4832. if (config("views.counter") != "true") {
  4833. if (!login()) {
  4834. file_cache($_SERVER['REQUEST_URI']);
  4835. }
  4836. } else {
  4837. add_view('post_' . $name);
  4838. if (!login()) {
  4839. file_cache($_SERVER['REQUEST_URI']);
  4840. }
  4841. }
  4842. $post = find_post($year, $month, $name);
  4843. if (is_null($post)) {
  4844. not_found('post_'. $name);
  4845. } else {
  4846. $current = $post['current'];
  4847. }
  4848. $author = new stdClass;
  4849. $author->url = $current->authorUrl;
  4850. $author->name = $current->authorName;
  4851. $author->description = $current->authorDescription;
  4852. $author->about = $current->authorAbout;
  4853. $author->avatar = $current->authorAvatar;
  4854. $author->rss = $current->authorRss;
  4855. $author->slug = $current->author;
  4856. if (array_key_exists('prev', $post)) {
  4857. $prev = $post['prev'];
  4858. } else {
  4859. $prev = array();
  4860. }
  4861. if (array_key_exists('next', $post)) {
  4862. $next = $post['next'];
  4863. } else {
  4864. $next = array();
  4865. }
  4866. if (isset($current->image)) {
  4867. $var = 'imagePost';
  4868. } elseif (isset($current->link)) {
  4869. $var = 'linkPost';
  4870. } elseif (isset($current->quote)) {
  4871. $var = 'quotePost';
  4872. } elseif (isset($current->audio)) {
  4873. $var = 'audioPost';
  4874. } elseif (isset($current->video)) {
  4875. $var = 'videoPost'; }
  4876. else {
  4877. $var = 'blogPost';
  4878. }
  4879. if (config('blog.enable') === 'true') {
  4880. $blog = '<li class="breadcrumb-item" itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"><a itemprop="item" href="' . site_url() . blog_path() . '"><span itemprop="name">' . blog_string() . '</span></a><meta itemprop="position" content="2" /></li> &#187; ';
  4881. } else {
  4882. $blog = '';
  4883. }
  4884. $vroot = rtrim(config('views.root'), '/');
  4885. $lt = $vroot . '/layout--post--' . $current->ct . '.html.php';
  4886. $pt = $vroot . '/layout--post--' . $current->type . '.html.php';
  4887. $ls = $vroot . '/layout--post.html.php';
  4888. if (file_exists($lt)) {
  4889. $layout = 'layout--post--' . $current->ct;
  4890. } else if (file_exists($pt)) {
  4891. $layout = 'layout--post--' . $current->type;
  4892. } else if (file_exists($ls)) {
  4893. $layout = 'layout--post';
  4894. } else {
  4895. $layout = '';
  4896. }
  4897. $pv = $vroot . '/post--' . $current->ct . '.html.php';
  4898. $pvt = $vroot . '/post--' . $current->type . '.html.php';
  4899. if (file_exists($pv)) {
  4900. $pview = 'post--' . $current->ct;
  4901. } else if(file_exists($pvt)) {
  4902. $pview = 'post--' . $current->type;
  4903. } else {
  4904. $pview = 'post';
  4905. }
  4906. render($pview, array(
  4907. 'title' => generate_title('is_post', $current),
  4908. 'description' => $current->description,
  4909. 'canonical' => $current->url,
  4910. 'metatags' => generate_meta('is_post', $current),
  4911. 'p' => $current,
  4912. 'post' => $current,
  4913. 'author' => $author,
  4914. 'bodyclass' => 'in-post category-' . $current->ct . ' type-' . $current->type,
  4915. 'breadcrumb' => '<style>.breadcrumb-list {margin:0; padding:0;} .breadcrumb-list li {display: inline-block; list-style: none;}</style><ol class="breadcrumb-list" itemscope itemtype="http://schema.org/BreadcrumbList"><li class="breadcrumb-item" itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"><a itemprop="item" href="' . site_url() . '"><span itemprop="name">' . config('breadcrumb.home') . '</span></a><meta itemprop="position" content="1" /></li> &#187; '. $blog . '<li class="breadcrumb-item" itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem">' . $current->categoryb . '<meta itemprop="position" content="3" /></li>' . ' &#187; ' . $current->title . '</ol>',
  4916. 'prev' => has_prev($prev),
  4917. 'next' => has_next($next),
  4918. 'type' => $var,
  4919. 'is_post' => true
  4920. ), $layout);
  4921. });
  4922. // Edit blog post
  4923. get('/:year/:month/:name/edit', function ($year, $month, $name) {
  4924. if (login()) {
  4925. $user = $_SESSION[site_url()]['user'];
  4926. $role = user('role', $user);
  4927. config('views.root', 'system/admin/views');
  4928. $post = find_post($year, $month, $name);
  4929. if (!$post) {
  4930. $post = find_draft($year, $month, $name);
  4931. if (!$post) {
  4932. $post = find_scheduled($year, $month, $name);
  4933. if (!$post) {
  4934. not_found();
  4935. }
  4936. }
  4937. }
  4938. $current = $post['current'];
  4939. if (isset($current->image)) {
  4940. $type= 'is_image';
  4941. } elseif (isset($current->link)) {
  4942. $type = 'is_link';
  4943. } elseif (isset($current->quote)) {
  4944. $type = 'is_quote';
  4945. } elseif (isset($current->audio)) {
  4946. $type = 'is_audio';
  4947. } elseif (isset($current->video)) {
  4948. $type = 'is_video';
  4949. } else {
  4950. $type = 'is_post';
  4951. }
  4952. if ($user === $current->author || $role === 'editor' || $role === 'admin') {
  4953. render('edit-content', array(
  4954. 'title' => generate_title('is_default', $current->title),
  4955. 'description' => safe_html(strip_tags(blog_description())),
  4956. 'canonical' => site_url(),
  4957. 'metatags' => generate_meta(null, null),
  4958. 'p' => $current,
  4959. 'post' => $current,
  4960. 'type' => $type,
  4961. 'bodyclass' => 'edit-post',
  4962. 'is_admin' => true,
  4963. 'breadcrumb' => '<span><a href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  4964. ));
  4965. } else {
  4966. render('denied', array(
  4967. 'title' => generate_title('is_default', $current->title),
  4968. 'description' => safe_html(strip_tags(blog_description())),
  4969. 'canonical' => site_url(),
  4970. 'metatags' => generate_meta(null, null),
  4971. 'p' => $current,
  4972. 'post' => $current,
  4973. 'bodyclass' => 'denied',
  4974. 'is_admin' => true,
  4975. 'breadcrumb' => '<span><a href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  4976. ));
  4977. }
  4978. } else {
  4979. $login = site_url() . 'login';
  4980. header("location: $login");
  4981. }
  4982. });
  4983. // Get edited data from blog post
  4984. post('/:year/:month/:name/edit', function () {
  4985. if(!login()) {
  4986. $login = site_url() . 'login';
  4987. header("location: $login");
  4988. }
  4989. $field = array();
  4990. $aField = array();
  4991. $field_file = 'content/data/field/post.json';
  4992. if (file_exists($field_file)) {
  4993. $aField = json_decode(file_get_contents($field_file, true));
  4994. }
  4995. if(!empty($aField)) {
  4996. foreach ($aField as $af) {
  4997. if ($af->type == 'checkbox' && isset($_REQUEST[$af->name])) {
  4998. $field[$af->name] = isset($_REQUEST[$af->name]) ? "checked" : 0;
  4999. } else {
  5000. $field[$af->name] = from($_REQUEST, $af->name);
  5001. }
  5002. }
  5003. }
  5004. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  5005. $title = from($_REQUEST, 'title');
  5006. $is_post = from($_REQUEST, 'is_post');
  5007. $image = from($_REQUEST, 'image');
  5008. $is_image = from($_REQUEST, 'is_image');
  5009. $video = from($_REQUEST, 'video');
  5010. $is_video = from($_REQUEST, 'is_video');
  5011. $link = from($_REQUEST, 'link');
  5012. $is_link = from($_REQUEST, 'is_link');
  5013. $audio = from($_REQUEST, 'audio');
  5014. $is_audio = from($_REQUEST, 'is_audio');
  5015. $quote = from($_REQUEST, 'quote');
  5016. $is_quote = from($_REQUEST, 'is_quote');
  5017. $tag = from($_REQUEST, 'tag');
  5018. $url = from($_REQUEST, 'url');
  5019. $content = from($_REQUEST, 'content');
  5020. $oldfile = from($_REQUEST, 'oldfile');
  5021. $destination = from($_GET, 'destination');
  5022. $description = from($_REQUEST, 'description');
  5023. $date = from($_REQUEST, 'date');
  5024. $time = from($_REQUEST, 'time');
  5025. $dateTime = null;
  5026. $revertPost = from($_REQUEST, 'revertpost');
  5027. $publishDraft = from($_REQUEST, 'publishdraft');
  5028. $category = from($_REQUEST, 'category');
  5029. if ($date !== null && $time !== null) {
  5030. $dateTime = $date . ' ' . $time;
  5031. }
  5032. if (!empty($is_image)) {
  5033. $type = 'is_image';
  5034. } elseif (!empty($is_video)) {
  5035. $type = 'is_video';
  5036. } elseif (!empty($is_link)) {
  5037. $type = 'is_link';
  5038. } elseif (!empty($is_quote)) {
  5039. $type = 'is_quote';
  5040. } elseif (!empty($is_audio)) {
  5041. $type = 'is_audio';
  5042. } elseif (!empty($is_post)) {
  5043. $type = 'is_post';
  5044. }
  5045. if (empty($url)) {
  5046. $url = $title;
  5047. }
  5048. $arr = explode('/', $oldfile);
  5049. $user = $_SESSION[site_url()]['user'];
  5050. $role = user('role', $user);
  5051. if ($user === $arr[1] || $role === 'editor' || $role === 'admin') {
  5052. if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($image)) {
  5053. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'image', $destination, $description, $dateTime, $image, null, $field);
  5054. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($video)) {
  5055. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'video', $destination, $description, $dateTime, $video,null, $field);
  5056. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($link)) {
  5057. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'link', $destination, $description, $dateTime, $link,null, $field);
  5058. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($quote)) {
  5059. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'quote', $destination, $description, $dateTime, $quote,null, $field);
  5060. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($audio)) {
  5061. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'audio', $destination, $description, $dateTime, $audio,null, $field);
  5062. } else if ($proper && !empty($title) && !empty($tag) && !empty($content) && !empty($is_post)) {
  5063. edit_content($title, $tag, $url, $content, $oldfile, $revertPost, $publishDraft, $category, 'post', $destination, $description, $dateTime, null,null, $field);
  5064. } else {
  5065. $message['error'] = '';
  5066. if (empty($title)) {
  5067. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_title') . '</li>';
  5068. }
  5069. if (empty($tag)) {
  5070. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_tag') . '</li>';
  5071. }
  5072. if (empty($content)) {
  5073. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_content') . '</li>';
  5074. }
  5075. if (!$proper) {
  5076. $message['error'] .= '<li class="alert alert-danger">' . i18n('Token_Error') . '</li>';
  5077. }
  5078. if (!empty($is_image)) {
  5079. if (empty($image)) {
  5080. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_image') . '</li>';
  5081. }
  5082. } elseif (!empty($is_video)) {
  5083. if (empty($video)) {
  5084. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_video') . '</li>';
  5085. }
  5086. } elseif (!empty($is_link)) {
  5087. if (empty($link)) {
  5088. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_link') . '</li>';
  5089. }
  5090. } elseif (!empty($is_quote)) {
  5091. if (empty($quote)) {
  5092. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_quote') . '</li>';
  5093. }
  5094. } elseif (!empty($is_audio)) {
  5095. if (empty($audio)) {
  5096. $message['error'] .= '<li class="alert alert-danger">' . i18n('msg_error_field_req_audio') . '</li>';
  5097. }
  5098. }
  5099. config('views.root', 'system/admin/views');
  5100. render('edit-content', array(
  5101. 'title' => generate_title('is_default', $title),
  5102. 'description' => safe_html(strip_tags(blog_description())),
  5103. 'canonical' => site_url(),
  5104. 'metatags' => generate_meta(null, null),
  5105. 'error' => '<ul>' . $message['error'] . '</ul>',
  5106. 'oldfile' => $oldfile,
  5107. 'postTitle' => $title,
  5108. 'postImage' => $image,
  5109. 'postVideo' => $video,
  5110. 'postLink' => $link,
  5111. 'postQuote' => $quote,
  5112. 'postAudio' => $audio,
  5113. 'postTag' => $tag,
  5114. 'postUrl' => $url,
  5115. 'type' => $type,
  5116. 'postContent' => $content,
  5117. 'is_admin' => true,
  5118. 'bodyclass' => 'edit-post',
  5119. 'breadcrumb' => '<a href="' . site_url() . '">' . config('breadcrumb.home') . '</a> &#187; ' . $title
  5120. ));
  5121. }
  5122. } else {
  5123. $redir = site_url();
  5124. header("location: $redir");
  5125. }
  5126. });
  5127. // Delete blog post
  5128. get('/:year/:month/:name/delete', function ($year, $month, $name) {
  5129. if (login()) {
  5130. $user = $_SESSION[site_url()]['user'];
  5131. $role = user('role', $user);
  5132. config('views.root', 'system/admin/views');
  5133. $post = find_post($year, $month, $name);
  5134. if (!$post) {
  5135. $post = find_draft($year, $month, $name);
  5136. if (!$post) {
  5137. $post = find_scheduled($year, $month, $name);
  5138. if (!$post) {
  5139. not_found();
  5140. }
  5141. }
  5142. }
  5143. $current = $post['current'];
  5144. if ($user === $current->author || $role === 'editor' || $role === 'admin') {
  5145. render('delete-post', array(
  5146. 'title' => generate_title('is_default', i18n('Delete')),
  5147. 'description' => safe_html(strip_tags(blog_description())),
  5148. 'canonical' => site_url(),
  5149. 'metatags' => generate_meta(null, null),
  5150. 'p' => $current,
  5151. 'post' => $current,
  5152. 'bodyclass' => 'delete-post',
  5153. 'is_admin' => true,
  5154. 'breadcrumb' => '<span><a rel="v:url" href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  5155. ));
  5156. } else {
  5157. render('denied', array(
  5158. 'title' => generate_title('is_default', i18n('Delete')),
  5159. 'description' => safe_html(strip_tags(blog_description())),
  5160. 'canonical' => site_url(),
  5161. 'metatags' => generate_meta(null, null),
  5162. 'p' => $current,
  5163. 'post' => $current,
  5164. 'bodyclass' => 'delete-post',
  5165. 'is_admin' => true,
  5166. 'breadcrumb' => '<span><a href="' . site_url() . '">' . config('breadcrumb.home') . '</a></span> &#187; ' . $current->categoryb . ' &#187; ' . $current->title
  5167. ));
  5168. }
  5169. } else {
  5170. $login = site_url() . 'login';
  5171. header("location: $login");
  5172. }
  5173. });
  5174. // Get deleted data from blog post
  5175. post('/:year/:month/:name/delete', function () {
  5176. $proper = is_csrf_proper(from($_REQUEST, 'csrf_token'));
  5177. if ($proper && login()) {
  5178. $file = from($_REQUEST, 'file');
  5179. $destination = from($_GET, 'destination');
  5180. $arr = explode('/', $file);
  5181. $user = $_SESSION[site_url()]['user'];
  5182. $role = user('role', $user);
  5183. if ($user === $arr[1] || $role === 'editor' || $role === 'admin') {
  5184. delete_post($file, $destination);
  5185. }
  5186. }
  5187. });
  5188. // If we get here, it means that
  5189. // nothing has been matched above
  5190. get('.*', function () {
  5191. not_found();
  5192. });
  5193. // Serve the blog
  5194. dispatch();