fix: pin the record id in Zones, Frames and EventData API writes refs GHSA-f8h6-62c9-x6qr GHSA-993c-fc6p-hpxg

CakePHP's Model::set() takes the record id from a primary key in the
data passed to save(). edit() authorized the id in the URL and then saved
the request body, so Zone[Id]=<other> in the body wrote to that other
zone, past the per-monitor check just added. add() could likewise update
an existing row instead of creating one.

Add AppController::pinRequestId(), which drops the primary key from the
request data and sets the model id, and use it in these edits (pinned to
the URL id) and adds (cleared). Frames and EventData edit() never set the
model id at all, so a body without an Id inserted a new row rather than
updating; pinning fixes that too.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Isaac ConnorandClaude Opus 5.5 committed 2026-09-28 19:38:59 -04:00
1 parent 26dcb3f9d3
commit ffed77e4d3
4 files changed
+19

No files matched your search

@@ -152,6 +152,7 @@ class EventDataController extends AppController {
throw new UnauthorizedException(__('Insufficient Privileges'));
}
$this->requireRequestEventDataEdit(true);
$this->pinRequestId($this->EventData, null);
$this->EventData->create();
if ($this->EventData->save($this->request->data)) {
}
@@ -173,6 +174,7 @@ class EventDataController extends AppController {
}
$this->requireEventDataEdit($id);
if ($this->request->is(array('post', 'put'))) {
$this->pinRequestId($this->EventData, $id);
$this->requireRequestEventDataEdit(false);
if ($this->EventData->save($this->request->data)) {
}