Commit Graph
62 Commits
Author SHA1 Message Date
Isaac Connor 9f3f6c6770 fix: only trust X-Forwarded-For from configured proxies for auth hash IPs
With ZM_AUTH_HASH_IPS on, the client address bound into the auth hash was
taken from the left-most X-Forwarded-For value whenever the header was
present, both when PHP generated the hash (getRemoteAddr()) and when PHP or
zms validated it (getAuthUser(), zmLoadAuthUser()). The header is client
controlled, so anyone holding a leaked hash could replay it from anywhere by
sending the address it was bound to.

Add ZM_AUTH_TRUSTED_PROXIES, a list of exact reverse proxy addresses.
X-Forwarded-For is now used only when REMOTE_ADDR is one of them, and is read
from the right, skipping hops that are themselves listed proxies, so values a
client prepends are never chosen. With the option empty, the default, the
header is ignored and REMOTE_ADDR is used.

PHP (web/includes/Network.php getRemoteAddr()) and C++ (ClientAddress() in
zm_utils, used by zmLoadAuthUser()) implement the same rule so generation and
validation continue to agree. Every PHP caller already routes through
getRemoteAddr(), so session.php and auth.php need no change.

Reverse proxy users who enable ZM_AUTH_HASH_IPS must list their proxy in the
new option; until they do, hashes bind to the proxy address, which still
validates but no longer distinguishes clients. This is the behaviour change
that the #4921 work avoided by trusting the header.

The option is added through ConfigData only, like other recent options;
zmupdate.pl --freshen inserts it, zms falls back to the compiled-in default and
PHP treats an undefined constant as empty, so no schema migration is needed.

Tests: ClientAddress Catch2 case; tests/php/test_remote_addr.php updated for
the trusted-proxy rule.

refs GHSA-72rf-54rm-798c

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit acea5889dec0826f595cb736147a5fdc9c94a2a9)
2026-09-24 19:51:27 -04:00
Alejandro Criado-Pérez a5d83e61b4 Corrections on rst files 2023-08-13 01:20:29 +02:00
megasaturnv 9d8e32b28c Modified description for ZM_CASE_INSENSITIVE_USERNAMES 2022-09-05 15:49:26 +01:00
megasaturnv 6c0f40f570 Renamed ZM_AUTH_CASE_INSENSITIVE_USERNAMES to ZM_CASE_INSENSITIVE_USERNAMES as name was too long ZoneMinder/zoneminder#3516 2022-09-02 12:03:47 +01:00
megasaturnv 63e5b63eec Added option ZM_AUTH_CASE_INSENSITIVE_USERNAMES to match mixed case usernames to lower case usernames in database ZoneMinder/zoneminder#3516 2022-09-02 11:58:02 +01:00
Håvard Flaget Aasen f2281d1017 Typos in documentation
This is typos noticed by lintian.
2021-10-17 13:29:00 +02:00
criadoperez 4a717820b1 Fixed broken wiki links 2021-09-08 15:18:52 +02:00
gmanproxtreme 84ccf10e65 Updated WEB_TITLE section from ToDo.
The Web_Title's use was unknown. I have seen the changed title appear on the login screen. Documentation updated to reflect this.
2021-08-27 20:21:02 +10:00
Isaac Connor 726f1f616d Merge branch 'update_docs_1_34' 2021-05-10 14:53:14 -04:00
Isaac Connor f0abcdf585 Merge branch 'release-1.34' into update_docs_1_34 2021-05-10 14:48:50 -04:00
Andrew Bauer dcab218a2e remove global config item CREATE_ANALYSIS_IMAGES 2020-07-06 12:22:41 -05:00
Isaac Connor 04b78ac7e6 typo and punctuation fixes. 2020-02-27 17:56:56 -05:00
Isaac Connor c3250dea00 fix typos and add some more text 2019-11-15 15:20:07 -05:00
Martin Kask 98a1cb8c29 Add storage docs 2019-11-14 08:00:52 +02:00
Pliable Pixels a171c2116c recommend you keep FAST_DELETE off unless the system is old 2019-10-27 16:15:09 -04:00
Pliable Pixels b3943e0c49 consistent naming of ES -> Event Notification Server 2019-10-27 10:47:09 -04:00
Pliable Pixels 05b06cd888 add FIFO animated gif and explanation tweaks 2019-10-27 09:40:55 -04:00
Pliable Pixels 4236d74a02 added FIFO, image pending 2019-10-27 08:16:26 -04:00
Pliable Pixels 343c939080 added todo - server needs to be refreshed 2019-10-25 11:59:28 -04:00
Pliable Pixels 309571afbb update display 2019-10-25 11:59:14 -04:00
Pliable Pixels d3906a0835 updated options->config 2019-10-25 11:56:25 -04:00
Pliable Pixels b939f22c17 nits 2019-10-25 11:50:29 -04:00
Pliable Pixels 555a94b776 fixup options->systems 2019-10-25 11:49:07 -04:00
Pliable Pixels 254456b038 remove eyeZM option image 2019-10-25 11:24:16 -04:00
Pliable Pixels 207643d53f updated users documentation with new options and an example 2019-10-25 11:16:20 -04:00
Pliable Pixels a2e1c4300c some text arrangement in options->bw 2019-10-25 09:57:14 -04:00
Pliable Pixels d3336fb96c update options->BW, remove phone BW as it no longer exist 2019-10-25 09:55:21 -04:00
Pliable Pixels 55d56f46df options X10 updated 2019-10-25 09:52:43 -04:00
Pliable Pixels 3bec14c651 options upload updated 2019-10-25 09:51:42 -04:00
Pliable Pixels b8819b540e updated options email, added EIMOD 2019-10-25 09:48:51 -04:00
Pliable Pixels b550db2418 options -> network updated 2019-10-25 09:40:07 -04:00
Pliable Pixels 9b614bebb4 options images upto date 2019-10-25 09:30:44 -04:00
Pliable Pixels 6bb031bac6 update options_web 2019-10-25 09:19:51 -04:00
Pliable Pixels 157bfa7409 remove options path image too 2019-10-25 09:07:31 -04:00
Pliable Pixels 795f380817 options API doc 2019-10-25 09:04:53 -04:00
Pliable Pixels d8bd0a04db path option no longer exists 2019-10-25 09:04:47 -04:00
Pliable Pixels ab7e4b9a7b sync options with current options, remove path 2019-10-25 08:54:51 -04:00
Pliable Pixels 958cedbbab fifo typo 2019-10-24 15:07:04 -04:00
Pliable Pixels f116adb50f fifo note 2019-10-24 15:06:03 -04:00
Pliable Pixels 2c3d72935b reworked logging 2019-10-24 15:05:45 -04:00
Isaac Connor b6c22139d6 update links in docs. Remove build examples using configure as it has been deprecated for a long time. 2019-10-18 18:16:59 -04:00
Isaac Connor 14381cc4da rough in storage documentation 2019-09-24 10:12:28 -04:00
Isaac Connor f557df9fc9 remove extra affect 2019-02-17 17:34:38 -05:00
j-marz bd7ce6ba13 fixed more more typo in options_logging userguide (#2526) 2019-02-17 11:32:10 -05:00
Andrew Bauer 3258d8e590 remove ZM_DIR_IMAGES (#2374) 2018-12-29 09:52:58 -05:00
Jonathan Meredith 6e7ecf4e89 Fix spelling mistake
Changed his to this
2018-12-27 22:20:24 -05:00
Vitaly Saversky 18c2ec6e17 Misspelling and grammar (#2202)
* Misspelling and grammar

* Misspelling something
2018-09-20 12:14:57 -04:00
SteveGilvarry 2f3ebd80da Remove zmf, die..die..die 2017-01-16 13:20:05 -08:00
SteveGilvarry d40bf89b17 Remove Phone BW settings used with mobile skin 2016-02-26 22:43:37 +11:00
SteveGilvarry 4837585601 Deleted eyezm options documentation and references to it in other areas of documentation. Removed zmstreamer.cpp.
Conflicts:
	src/zmstreamer.cpp
2016-02-26 22:37:23 +11:00