mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 23:45:08 -04:00
- index/view, Frames index and EventData index/view treated an empty viewable-monitor list as no restriction, so a user denied every monitor saw all of them. They now match nothing in that case. - search and consoleEvents had no monitor filter at all and returned events and per-monitor counts for denied monitors. - add saved any MonitorId; it now needs view on that monitor, as editing an event does, and cannot update an existing event named in the body. - edit checked the event in the URL but saved the body, which could name another event's Id or move the event to a denied monitor. Pin the id and check a new MonitorId. - createThumbnail and getMaxScoreAlarmFrameId were public, so routable, and checked nothing. They are internal helpers; make them private. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ZoneMinder API
This is the ZoneMinder API. It should be, for now, installed under the webroot e.g. /api.
app/Config/database.php.default must be configured and copied to app/Config/database.php
In addition, Security.salt and Security.cipherSeed in app/Config/core.php should be changed.
The API can run on a dedicated / separate instance, so long as it can access the database as configured in app/Config/database.php