mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-11 03:45:19 -04:00
fix: prevent auth bypass when token validation fails
validateToken() returns array(false, $errorMessage) when a token is invalid or its signature fails. The token branch in auth.php assigned $user = $ret[0] unconditionally, leaving $user as boolean false on failure. Because isset($false) is true in PHP, the ZM_OPT_USE_AUTH gate in index.php (!isset($user)) was skipped, allowing unauthenticated access via any malformed ?token= value. It also permitted an unauthenticated DoS: downstream $user->Username() on a bool fatals. Check !$ret[0] and unset($user) on failure, mirroring the existing validateUser branch, so $user stays undefined and the auth gate blocks the request. The API call sites already throw UnauthorizedException on !$user and are unaffected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
346a4baa82
commit
6b94903e63
1 file changed
+9
-1
@@ -565,7 +565,15 @@ if (ZM_OPT_USE_AUTH) {
|
||||
// don't know the token type. That will
|
||||
// be checked later
|
||||
$ret = validateToken($_REQUEST['token'], 'any');
|
||||
$user = $ret[0];
|
||||
if (!$ret[0]) {
|
||||
// validateToken returns array(false, $errorMessage) on failure.
|
||||
// Assigning false to $user would leave isset($user) true, bypassing
|
||||
// the ZM_OPT_USE_AUTH gate in index.php. Unset so $user stays undefined.
|
||||
ZM\Warning($ret[1]);
|
||||
unset($user); // unset should be ok here because we aren't in a function
|
||||
} else {
|
||||
$user = $ret[0];
|
||||
}
|
||||
} else {
|
||||
// Non token based auth - session required for $_SESSION access
|
||||
if (!is_session_started()) {
|
||||
|
||||
Reference in new issue
Block a user