The probe went out as zmAuth.appendTo(...), carrying the very hash it existed to replace. zm_authenticate_request() resolves a request against exactly one source: a non-empty auth= in the URL enters the ZM_AUTH_HASH_LOGINS branch (on by default), and when getAuthUser() rejects it the chain has already been taken, so the userFromSession() arm below it never runs. A live session cookie then authenticates as nobody. Past ZM_AUTH_HASH_TTL - a tab hidden longer than two hours on the defaults, which is exactly the case this change is for - the probe was therefore the one request guaranteed to fail, and its failure is read as 'login', so the user was bounced to the login page with a perfectly good session. That is worse than the 403s in the log this set out to remove. Send the probe bare. The session cookie is what answers, which is the question being asked: who am I, and what is my current hash? That also makes the failure handling mean what its comment claimed. A rejection now really is a dead session rather than a dead hash, so redirecting to login on it is right - and both 401 and 403 reach it, which the comment now says. Also correct the AUTH_STALE_MS comment: authIsStale() is a strict comparison, so a credential confirmed exactly AUTH_STALE_MS ago is still fresh, as the test asserts. Tests: tests/js/auth-helpers.test.js, 51 passed (4 new for revalidateAuth, covering the bare probe, shared in-flight request, callbacks surviving a transient failure, and login on a rejected session). Reverting the probe to the credentialed form fails two of them. refs #5093 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Nr76CednxtDt2nPuq6WrbL
ZoneMinder
All documentation for ZoneMinder is now online at https://zoneminder.readthedocs.org
Overview
ZoneMinder is an integrated set of applications which provide a complete surveillance solution allowing capture, analysis, recording and monitoring of any CCTV or security cameras attached to a Linux based machine. It is designed to run on distributions which support the Video For Linux (V4L) interface and has been tested with video cameras attached to BTTV cards, various USB cameras and also supports most IP network cameras.
Contacting the Development Team
Before creating an issue in our github forum, please read our posting rules: https://github.com/ZoneMinder/ZoneMinder/wiki/Github-Posting-Rules
Our Dockerfile has moved
Please file issues against the ZoneMinder Dockerfile here: https://github.com/ZoneMinder/zmdockerfiles
Installation Methods
Install from a Package Repository
This is the recommended method to install ZoneMinder onto your system. ZoneMinder packages are maintained for the following distros:
- Ubuntu via Isaac Connor's PPA
- Debian from their default repository
- RHEL/CentOS and clones via RPM Fusion
- Fedora via RPM Fusion
- OpenSuse via third party repository
- Mageia from their default repository
- Arch via the AUR
- Gentoo via Portage Overlays
If a repository that hosts ZoneMinder packages is not available for your distro, then you are encouraged to build your own package, rather than build from source. While each distro is different in ways that set it apart from all the others, they are often similar enough to allow you to adapt another distro's package building instructions to your own.
Building from Source is Discouraged
Historically, installing ZoneMinder onto your system required building from source code by issuing the traditional configure, make, make install commands. To get ZoneMinder to build, all of its dependencies had to be determined and installed beforehand. Init and logrotate scripts had to be manually copied into place following the build. Optional packages such as jscalendar and Cambozola had to be manually installed. Uninstalls could leave stale files around, which could cause problems during an upgrade. Speaking of upgrades, when it comes time to upgrade all these manual steps must be repeated again.
Better methods exist today that do much of this for you. The current development team, along with other volunteers, have taken great strides in providing the resources necessary to avoid building from source.
Building a ZoneMinder Package
Building ZoneMinder into a package is not any harder than building from source. As a matter of fact, if you have successfully built ZoneMinder from source in the past, then you may find these steps to be easier.
When building a package, it is best to do this work in a separate environment, dedicated to development purposes. This could be as simple as creating a virtual machine, using Docker, or using mock. All it takes is one “Oops” to regret doing this work on your production server.
Lastly, if you desire to build a development snapshot from the master branch, it is recommended you first build your package using an official release of ZoneMinder. This will help identify whether any problems you may encounter are caused by the build process or is a new issue in the master branch.
Please visit our ReadtheDocs site for distro specific instructions.
Package Maintainers
Many of the ZoneMinder configuration variable default values are not configurable at build time through autotools or cmake. A new tool called zmeditconfigdata.sh has been added to allow package maintainers to manipulate any variable stored in ConfigData.pm without patching the source.
For example, let's say I have created a new ZoneMinder package that contains the cambozola javascript file. However by default cambozola support is turned off. To fix that, add this to the packaging script:
./utils/zmeditconfigdata.sh ZM_OPT_CAMBOZOLA yes
Note that zmeditconfigdata.sh is intended to be called, from the root build folder, prior to running cmake or configure.
Docker
Docker is a system to run applications inside isolated containers. ZoneMinder, and the ZM webserver, will run using the Dockerfile contained in this repository. However, there is still work needed to ensure that the main ZM features work properly and are documented.
Contribution Model and Development
- Source hosted at GitHub
- Report issues at GitHub Issues
- Questions/feature requests in Slack or forums
Pull requests are very welcome! If you would like to contribute, please follow the following steps. While step 3 is optional, it is preferred.
- Fork the repo
- Open an issue at our GitHub Issues Tracker. Follow the issue template to describe the bug or security issue you found. Please note feature requests or questions should be posted in our user forum or Slack channel.
- Create your feature branch (
git checkout -b 456-my-new-feature) - Commit your changes (
git commit -am 'Added some feature') It is preferred that you 'commit early and often' instead of bunching all changes into a single commit. - Push your branch to your fork on github (
git push origin 456-my-new-feature) - Create new Pull Request
- The team will then review, discuss and hopefully merge your changes.
