mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-04 00:15:20 -04:00
fix: pin the record id in Zones, Frames and EventData API writes refs GHSA-f8h6-62c9-x6qr GHSA-993c-fc6p-hpxg
CakePHP's Model::set() takes the record id from a primary key in the data passed to save(). edit() authorized the id in the URL and then saved the request body, so Zone[Id]=<other> in the body wrote to that other zone, past the per-monitor check just added. add() could likewise update an existing row instead of creating one. Add AppController::pinRequestId(), which drops the primary key from the request data and sets the model id, and use it in these edits (pinned to the URL id) and adds (cleared). Frames and EventData edit() never set the model id at all, so a body without an Id inserted a new row rather than updating; pinning fixes that too. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
26dcb3f9d3
commit
ffed77e4d3
4 files changed
+19
No files matched your search
@@ -152,6 +152,7 @@ class EventDataController extends AppController {
|
||||
throw new UnauthorizedException(__('Insufficient Privileges'));
|
||||
}
|
||||
$this->requireRequestEventDataEdit(true);
|
||||
$this->pinRequestId($this->EventData, null);
|
||||
$this->EventData->create();
|
||||
if ($this->EventData->save($this->request->data)) {
|
||||
}
|
||||
@@ -173,6 +174,7 @@ class EventDataController extends AppController {
|
||||
}
|
||||
$this->requireEventDataEdit($id);
|
||||
if ($this->request->is(array('post', 'put'))) {
|
||||
$this->pinRequestId($this->EventData, $id);
|
||||
$this->requireRequestEventDataEdit(false);
|
||||
if ($this->EventData->save($this->request->data)) {
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user