mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 15:35:09 -04:00
AppController mapped index/add/edit/view/keyvalue/category to Crud actions, and CrudControllerTrait answers any action a controller does not define with them. Those generic handlers apply none of the controller's permission or per-monitor checks: zones/view/<id> and zones/<id> returned any zone, including those of monitors the user is denied, and Controls add/edit and Configs add were reachable the same way. Map no Crud actions, so an undefined action is a 404, and give ZonesController a view() that checks the zone's monitor. ZonesController::index() passed its monitor filter as a find() option key rather than a condition, so it was ignored and every zone was listed. Use a real condition. Add AppController helpers the following fixes share: a viewable-monitor find() condition that matches nothing when the user may view no monitor (callers treated an empty list as unrestricted), reading a field or associated ids from request data, and requiring view or edit on a monitor or view on events. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Modern ZoneMinder Skin
This web frontend to ZoneMinder is a complete rewrite of the classic frontend, based on CakePHP.