mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 23:45:08 -04:00
Adds a web config option whose contents are rendered on the login view, between the title and the username and password fields. Useful for a site notice, an acceptable use or legal warning, or a note identifying which installation this is when running more than one. Defaults to empty, and nothing is emitted when it is empty or whitespace, so existing installs look exactly as they do now. The text is escaped rather than interpreted. The login page is served before anyone has authenticated, so it is not somewhere to emit admin-supplied markup, and no other config value in the skin is output unescaped either. Escaping runs before nl2br so the only tags reaching the browser are the line breaks we add ourselves; reversing that order would turn the setting into stored XSS. Uses the text type, so the Options UI renders a textarea and the value can span lines. The Config.Value column is already text and options.php normalises CRLF to LF on save, so no schema change is needed and nl2br sees consistent newlines. Guarded with defined() to match the surrounding code, so the view still renders where the database predates the option. Styled in base, classic and dark. Text contrast is 7.0:1 light and 7.5:1 dark, both above WCAG AA, and long unbroken tokens wrap rather than widening the fixed-width form. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>