mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-03 07:55:22 -04:00
AppController mapped index/add/edit/view/keyvalue/category to Crud actions, and CrudControllerTrait answers any action a controller does not define with them. Those generic handlers apply none of the controller's permission or per-monitor checks: zones/view/<id> and zones/<id> returned any zone, including those of monitors the user is denied, and Controls add/edit and Configs add were reachable the same way. Map no Crud actions, so an undefined action is a 404, and give ZonesController a view() that checks the zone's monitor. ZonesController::index() passed its monitor filter as a find() option key rather than a condition, so it was ignored and every zone was listed. Use a real condition. Add AppController helpers the following fixes share: a viewable-monitor find() condition that matches nothing when the user may view no monitor (callers treated an empty list as unrestricted), reading a field or associated ids from request data, and requiring view or edit on a monitor or view on events. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
223 lines
6.6 KiB
PHP
223 lines
6.6 KiB
PHP
<?php
|
|
App::uses('AppController', 'Controller');
|
|
require_once __DIR__ .'/../../../includes/Monitor.php';
|
|
/**
|
|
* Zones Controller
|
|
*
|
|
* @property Zone $Zone
|
|
*/
|
|
class ZonesController extends AppController {
|
|
|
|
/**
|
|
* Components
|
|
*
|
|
* @var array
|
|
*/
|
|
public $components = array('RequestHandler');
|
|
|
|
public function beforeFilter() {
|
|
parent::beforeFilter();
|
|
|
|
global $user;
|
|
$canView = (!$user) || ($user->Monitors() != 'None');
|
|
if ( !$canView ) {
|
|
throw new UnauthorizedException(__('Insufficient Privileges'));
|
|
return;
|
|
}
|
|
}
|
|
|
|
// Zones belong to a monitor, so changing one needs edit on that monitor (requireMonitorEdit()
|
|
// in AppController), not just the global Monitors permission.
|
|
|
|
// The monitor that the zone being edited or deleted currently belongs to.
|
|
private function zoneMonitorId($id) {
|
|
$this->Zone->recursive = -1;
|
|
$zone = $this->Zone->find('first', array('conditions' => array('Zone.'.$this->Zone->primaryKey => $id)));
|
|
return $zone['Zone']['MonitorId'];
|
|
}
|
|
|
|
// The MonitorId given in request data, if any.
|
|
private function requestMonitorId() {
|
|
$data = $this->request->data;
|
|
if (isset($data['Zone']) and is_array($data['Zone'])) $data = $data['Zone'];
|
|
return isset($data['MonitorId']) ? $data['MonitorId'] : null;
|
|
}
|
|
|
|
// Find all zones which belong to a MonitorId
|
|
public function forMonitor($id = null) {
|
|
$this->loadModel('Monitor');
|
|
if ( !$this->Monitor->exists($id) ) {
|
|
throw new NotFoundException(__('Invalid monitor'));
|
|
}
|
|
|
|
# Monitors=View is coarse. Enforce the per-monitor ACL so zones of a monitor
|
|
# the user is denied are not listed by direct monitor Id.
|
|
$this->Monitor->recursive = -1;
|
|
$monitor = $this->Monitor->find('first', array(
|
|
'conditions' => array('Monitor.Id' => $id)
|
|
));
|
|
$MonitorObj = new ZM\Monitor($monitor['Monitor']);
|
|
if ( !$MonitorObj->canView() ) {
|
|
throw new UnauthorizedException(__('Insufficient Privileges'));
|
|
return;
|
|
}
|
|
|
|
$this->Zone->recursive = -1;
|
|
$zones = $this->Zone->find('all', array(
|
|
'conditions' => array('MonitorId' => $id)
|
|
));
|
|
$this->set(array(
|
|
'zones' => $zones,
|
|
'_serialize' => array('zones')
|
|
));
|
|
}
|
|
|
|
public function view($id = null) {
|
|
$this->Zone->recursive = -1;
|
|
$zone = $this->Zone->find('first', array('conditions' => array('Zone.'.$this->Zone->primaryKey => $id)));
|
|
if (!$zone) {
|
|
throw new NotFoundException(__('Invalid zone'));
|
|
}
|
|
$monitor = new ZM\Monitor($zone['Zone']['MonitorId']);
|
|
if (!$monitor->canView()) {
|
|
throw new UnauthorizedException(__('Insufficient Privileges'));
|
|
}
|
|
$this->set(array(
|
|
'zone' => $zone,
|
|
'_serialize' => array('zone')
|
|
));
|
|
}
|
|
|
|
public function index() {
|
|
$this->Zone->recursive = -1;
|
|
|
|
global $user;
|
|
# null means no restriction. An empty list means the user may see no monitor, so no zone.
|
|
$allowedMonitors = ($user and $user->unviewableMonitorIds()) ? $user->viewableMonitorIds() : null;
|
|
$options = array();
|
|
if ($allowedMonitors !== null) {
|
|
$options['conditions'] = array('Zone.MonitorId' => $allowedMonitors);
|
|
}
|
|
$zones = $this->Zone->find('all', $options);
|
|
$this->set(array(
|
|
'zones' => $zones,
|
|
'_serialize' => array('zones')
|
|
));
|
|
}
|
|
|
|
/**
|
|
* add method
|
|
*
|
|
* @return void
|
|
*/
|
|
public function add() {
|
|
|
|
if ( !$this->request->is('post') ) {
|
|
throw new BadRequestException(__('Invalid method. Should be post'));
|
|
return;
|
|
}
|
|
|
|
global $user;
|
|
$canEdit = (!$user) || $user->Monitors() == 'Edit' || $user->Monitors() == 'Create';
|
|
if ( !$canEdit ) {
|
|
throw new UnauthorizedException(__('Insufficient Privileges'));
|
|
return;
|
|
}
|
|
|
|
$monitorId = $this->requestMonitorId();
|
|
if ($monitorId === null) {
|
|
throw new BadRequestException(__('MonitorId is required'));
|
|
}
|
|
$this->requireMonitorEdit($monitorId);
|
|
$this->pinRequestId($this->Zone, null);
|
|
|
|
$zone = null;
|
|
|
|
$this->Zone->create();
|
|
$zone = $this->Zone->save($this->request->data);
|
|
if ( $zone ) {
|
|
require_once __DIR__ .'/../../../includes/Monitor.php';
|
|
$monitor = new ZM\Monitor($zone['Zone']['MonitorId']);
|
|
$monitor->zmcControl('restart');
|
|
$message = 'Saved';
|
|
//$zone = $this->Zone->find('first', array('conditions' => array( array('Zone.' . $this->Zone->primaryKey => $this->Zone),
|
|
} else {
|
|
$message = 'Error: ';
|
|
// if there is a validation message, use it
|
|
if ( !$this->Zone->validates() ) {
|
|
$message = $this->Zone->validationErrors;
|
|
}
|
|
}
|
|
|
|
$this->set(array(
|
|
'message' => $message,
|
|
'zone' => $zone,
|
|
'_serialize' => array('message','zone')
|
|
));
|
|
} // end function add()
|
|
|
|
/**
|
|
* edit method
|
|
*
|
|
* @throws NotFoundException
|
|
* @param string $id
|
|
* @return void
|
|
*/
|
|
public function edit($id = null) {
|
|
$this->Zone->id = $id;
|
|
|
|
if ( !$this->Zone->exists($id) ) {
|
|
throw new NotFoundException(__('Invalid zone'));
|
|
}
|
|
$message = '';
|
|
if ( $this->request->is(array('post', 'put')) ) {
|
|
global $user;
|
|
$canEdit = (!$user) || $user->Monitors() == 'Edit' || $user->Monitors() == 'Create';
|
|
if ( !$canEdit ) {
|
|
throw new UnauthorizedException(__('Insufficient Privileges'));
|
|
return;
|
|
}
|
|
$this->pinRequestId($this->Zone, $id);
|
|
$this->requireMonitorEdit($this->zoneMonitorId($id));
|
|
$monitorId = $this->requestMonitorId();
|
|
if ($monitorId !== null) $this->requireMonitorEdit($monitorId);
|
|
if ( $this->Zone->save($this->request->data) ) {
|
|
$message = 'The zone has been saved.';
|
|
} else {
|
|
$message = 'Error ' . print_r($this->Zone->invalidFields());
|
|
}
|
|
}
|
|
$this->set(array(
|
|
'message' => $message,
|
|
'_serialize' => array('message')
|
|
));
|
|
}
|
|
|
|
/**
|
|
* delete method
|
|
*
|
|
* @throws NotFoundException
|
|
* @param string $id
|
|
* @return void
|
|
*/
|
|
public function delete($id = null) {
|
|
$this->Zone->id = $id;
|
|
if ( !$this->Zone->exists() ) {
|
|
throw new NotFoundException(__('Invalid zone'));
|
|
}
|
|
$this->request->allowMethod('post', 'delete');
|
|
global $user;
|
|
$canEdit = (!$user) || $user->Monitors() == 'Edit' || $user->Monitors() == 'Create';
|
|
if ( !$canEdit ) {
|
|
throw new UnauthorizedException(__('Insufficient Privileges'));
|
|
return;
|
|
}
|
|
$this->requireMonitorEdit($this->zoneMonitorId($id));
|
|
if ( $this->Zone->delete() ) {
|
|
return $this->flash(__('The zone has been deleted.'), array('action' => 'index'));
|
|
} else {
|
|
return $this->flash(__('The zone could not be deleted. Please, try again.'), array('action' => 'index'));
|
|
}
|
|
}
|
|
} // end class
|