The page kept two copies of the same secret: auth_relay, the query fragment
every AJAX call is authenticated with, and auth_hash, the bare hash stamped
into stream <img> URLs. Different responses updated different copies, so
they could drift, and a drifted auth_hash produced stream URLs that zms
rejects.
ZMAuth stores only the relay and derives the hash from it, so the two cannot
disagree. Its helpers cover the four shapes the call sites used:
zmAuth.hash derived, '' under the plain/none relay forms
zmAuth.update(data) absorb the auth fields of any response
zmAuth.appendTo(url) authenticate a url, no-op when auth is off
zmAuth.applyTo(src) point a stream url at the current credential
appendTo also removes the `x ? '&'+x : ''` guard repeated at every call
site, some of which had omitted it and emitted a dangling '?'.
Migrates all call sites across web/js and the classic skin, and drops both
globals from skin.js.php.
Tests: tests/js/auth-helpers.test.js, 44 passing.
The single-server branch added in 0950131b2 ignored the optional port
argument and always used location.host. Mirror the multi-server branch
by preferring port > location.host.
When ZM_SERVER_ID is unset, Servers[0] is a synthetic default whose
Hostname/Port come from PHP fallbacks (HTTP_HOST, HTTP_X_FORWARDED_PORT,
ZM_BASE_URL) which can disagree with the host:port the browser is
actually using. That caused montagereview XHR to land on the wrong
physical server (e.g. default :443 of a hostname where ZM lives on :81).
For Servers without an Id, derive host:port from location.host so XHR
follows the same connection as the UI. Multi-server entries with a real
Id keep using their configured Hostname/Port.
When accessing ZoneMinder through port forwarding, API requests were
made without the forwarded port, causing NS_ERROR_NET_TIMEOUT. The
url(), urlToZMS(), urlToJanus(), and urlToApi() methods now fall back
to this.Port then location.port when no explicit port is passed.
fixes#4675
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add eslint to travis.yml
* Update eslint package versions and apply new indent rules
* Enable the brace-style and block-style eslint rules
* Enable the 'curly' eslint rule
* Enable the 'keyword-spacing' eslint rule
* Enable the 'key-spacing' eslint rule
* Enable the 'object-curly-spacing' eslint rule
* Enable the 'no-new-object' eslint rule
* Only disable the no-caller eslint rule in the one affected file
* Enable the 'no-unused-vars' eslint rule for local variables
* Add linting of JS in .php files