File size: 2,710 Bytes
36ddefa
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
<?php

ob_start();
require_once 'PostgreSQL_funcs.php';
require 'PostgreSQL_config.php';
require 'PostgreSQL_access.php';
ob_end_clean();

$world = $_REQUEST['world'];

session_start();

if (isset($_SESSION['userid'])) {
    $userid = $_SESSION['userid'];
} else {
    $userid = '-guest-';
}

$loggedin = false;
if (strcmp($userid, '-guest-')) {
    $loggedin = true;
}

header('Content-type: application/json; charset=utf-8');

if (strpos($world, '/') || strpos($world, '\\') || empty($world)) {
    echo "{ \"error\": \"invalid-world\" }";
    return;
}

if ($loginenabled) {
    $fname = 'updates_' . $world . '.php';
} else {
    $fname = 'updates_' . $world . '.json';
}

$useridlc = strtolower($userid);
$uid = '[' . $useridlc . ']';

if (isset($worldaccess[$world])) {
    $ss = stristr($worldaccess[$world], $uid);
    if ($ss === false) {
        echo "{ \"error\": \"access-denied\" }";
        return;
    }
}

$serverid = 0;
if (isset($_REQUEST['serverid'])) {
    $serverid = $_REQUEST['serverid'];
}

$content = getStandaloneFile('dynmap_' . $world . '.json');
if (!isset($content)) {
    header('HTTP/1.0 503 Database Unavailable');
    echo "<h1>503 Database Unavailable</h1>";
    echo 'Error reading database - ' . $fname . ' #' . $serverid;
    cleanupDb();
    exit;
}


if (!$loginenabled) {
    echo $content;
} elseif (isset($json->loginrequired) && $json->loginrequired && !$loggedin) {
    echo "{ \"error\": \"login-required\" }";
} else {
    $json = json_decode($content);
    $json->loggedin = $loggedin;
    if (isset($json->protected) && $json->protected) {
        $ss = stristr($seeallmarkers, $uid);
        if ($ss === false) {
            if (isset($playervisible[$useridlc])) {
                $plist = $playervisible[$useridlc];
                $pcnt = count($json->players);
                for ($i = 0; $i < $pcnt; $i++) {
                    $p = $json->players[$i];
                    if (!stristr($plist, '[' . $p->account . ']')) {
                        $p->world = "-some-other-bogus-world-";
                        $p->x = 0.0;
                        $p->y = 64.0;
                        $p->z = 0.0;
                    }
                }
            } else {
                $pcnt = count($json->players);
                for ($i = 0; $i < $pcnt; $i++) {
                    $p = $json->players[$i];
                    if (strcasecmp($userid, $p->account) != 0) {
                        $p->world = "-some-other-bogus-world-";
                        $p->x = 0.0;
                        $p->y = 64.0;
                        $p->z = 0.0;
                    }
                }
            }
        }
    }
    echo json_encode($json);
}
cleanupDb();