mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-03 07:55:22 -04:00
LogsController::delete() never declared global $user, so its System=Edit check always passed and anyone with System view could delete log entries. Logs add, which ZM_LOG_INJECT opens to non-admins, could overwrite an existing entry by Id; pin it. ZonePresetsController had no permission checks. Reading presets stays open to signed-in users; changing them now needs System=Edit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
111 lines
3.0 KiB
PHP
111 lines
3.0 KiB
PHP
<?php
|
|
App::uses('AppController', 'Controller');
|
|
/**
|
|
* ZonePresets Controller
|
|
*
|
|
* @property ZonePreset $ZonePreset
|
|
* @property PaginatorComponent $Paginator
|
|
*/
|
|
class ZonePresetsController extends AppController {
|
|
|
|
/**
|
|
* Components
|
|
*
|
|
* @var array
|
|
*/
|
|
public $components = array('RequestHandler');
|
|
|
|
# Zone presets are shared templates, not tied to a monitor. Anyone signed in may read them,
|
|
# changing them is system configuration.
|
|
public function beforeFilter() {
|
|
parent::beforeFilter();
|
|
global $user;
|
|
if ($user and !in_array($this->request->action, array('index', 'view')) and ($user->System() != 'Edit')) {
|
|
throw new UnauthorizedException(__('Insufficient Privileges'));
|
|
}
|
|
}
|
|
|
|
/**
|
|
* index method
|
|
*
|
|
* @return void
|
|
*/
|
|
public function index() {
|
|
$zonePresets = $this->ZonePreset->find('all');
|
|
$this->set(array(
|
|
'zonePresets' => $zonePresets,
|
|
'_serialize' => array('zonePresets')
|
|
));
|
|
}
|
|
|
|
/**
|
|
* view method
|
|
*
|
|
* @throws NotFoundException
|
|
* @param string $id
|
|
* @return void
|
|
*/
|
|
public function view($id = null) {
|
|
if ( !$this->ZonePreset->exists($id) ) {
|
|
throw new NotFoundException(__('Invalid zone preset'));
|
|
}
|
|
$options = array('conditions' => array('ZonePreset.' . $this->ZonePreset->primaryKey => $id));
|
|
$this->set('zonePreset', $this->ZonePreset->find('first', $options));
|
|
}
|
|
|
|
/**
|
|
* add method
|
|
*
|
|
* @return void
|
|
*/
|
|
public function add() {
|
|
if ( $this->request->is('post') ) {
|
|
$this->ZonePreset->create();
|
|
if ( $this->ZonePreset->save($this->request->data) ) {
|
|
return $this->flash(__('The zone preset has been saved.'), array('action' => 'index'));
|
|
}
|
|
}
|
|
}
|
|
|
|
/**
|
|
* edit method
|
|
*
|
|
* @throws NotFoundException
|
|
* @param string $id
|
|
* @return void
|
|
*/
|
|
public function edit($id = null) {
|
|
if ( !$this->ZonePreset->exists($id) ) {
|
|
throw new NotFoundException(__('Invalid zone preset'));
|
|
}
|
|
if ( $this->request->is(array('post', 'put')) ) {
|
|
if ( $this->ZonePreset->save($this->request->data) ) {
|
|
return $this->flash(__('The zone preset has been saved.'), array('action' => 'index'));
|
|
}
|
|
} else {
|
|
$options = array('conditions' => array('ZonePreset.' . $this->ZonePreset->primaryKey => $id));
|
|
$this->request->data = $this->ZonePreset->find('first', $options);
|
|
}
|
|
}
|
|
|
|
/**
|
|
* delete method
|
|
*
|
|
* @throws NotFoundException
|
|
* @param string $id
|
|
* @return void
|
|
*/
|
|
public function delete($id = null) {
|
|
$this->ZonePreset->id = $id;
|
|
if ( !$this->ZonePreset->exists() ) {
|
|
throw new NotFoundException(__('Invalid zone preset'));
|
|
}
|
|
$this->request->allowMethod('post', 'delete');
|
|
if ( $this->ZonePreset->delete() ) {
|
|
return $this->flash(__('The zone preset has been deleted.'), array('action' => 'index'));
|
|
} else {
|
|
return $this->flash(__('The zone preset could not be deleted. Please, try again.'), array('action' => 'index'));
|
|
}
|
|
}
|
|
} // end class ZonePresetsController
|