Files
zoneminder/web/includes/actions/zones.php
Isaac Connor e6ace6fcf4 feat: add AUDIT logging level for tracking administrative changes
Add a new AUDIT logging level (-5) between PANIC (-4) and NOLOG (shifted
to -6) across C++, PHP, and Perl loggers. AUDIT entries use code 'AUD'
and syslog priority LOG_NOTICE. They record who changed what, from where,
for monitors, filters, users, config, roles, groups, zones, states,
servers, storage, events, snapshots, control caps, and login/logout.

AUDIT entries have their own retention period (ZM_LOG_AUDIT_DATABASE_LIMIT,
default 1 year) separate from regular log pruning. The log pruning in
zmstats.pl and zmaudit.pl now excludes AUDIT rows from regular pruning
and prunes them independently.

Critical safety: the C++ termination logic is changed from
'if (level <= FATAL)' to 'if (level == FATAL || level == PANIC)' to
prevent AUDIT-level log calls from killing the process.

Includes db migration zm_update-1.39.1.sql to shift any stored NOLOG
config values from -5 to -6.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-23 18:19:20 -05:00

60 lines
2.2 KiB
PHP

<?php
//
// ZoneMinder web action file
// Copyright (C) 2019 ZoneMinder LLC
//
// This program is free software; you can redistribute it and/or
// modify it under the terms of the GNU General Public License
// as published by the Free Software Foundation; either version 2
// of the License, or (at your option) any later version.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License
// along with this program; if not, write to the Free Software
// Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
//
require_once('includes/Zone.php');
global $error_message;
global $redirect;
if ($action == 'delete') {
if (isset($_REQUEST['markZids'])) {
$monitors_to_restart = array();
foreach ($_REQUEST['markZids'] as $markZid) {
$zone = new ZM\Zone(validCardinal($markZid));
if (!$zone->Id()) {
$error_message .= 'Zone not found for id ' . $markZid.'<br/>';
continue;
}
$monitor = $zone->Monitor();
if (!$monitor->canEdit()) {
$error_message .= 'You do not have permission to edit zones for monitor ' . $monitor->Name().'.<br/>';
continue;
}
# Could use true but store the object instead for easy access later
$monitors_to_restart[] = $monitor;
$error_message .= $zone->delete();
ZM\AuditAction('delete', 'zone', $markZid, 'MonitorId: '.$monitor->Id());
} # end foreach Zone
if (daemonCheck()) {
foreach ($monitors_to_restart as $monitor) {
if ($monitor->Type() != 'WebSite') {
$monitor->zmcControl('restart');
}
}
}
$refreshParent = true;
if (!$error_message)
$redirect = '?view=zones'.(isset($_REQUEST['mids']) ? '&'.implode('&', array_map(function($mid){ return 'mids[]='.$mid; }, $_REQUEST['mids'])): '');
} else {
$error_message .= 'No Zones marked for deletion.<br/>';
} // end if isset($_REQUEST['markZids'])
} // end if action
?>