mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 15:35:09 -04:00
AppController mapped index/add/edit/view/keyvalue/category to Crud actions, and CrudControllerTrait answers any action a controller does not define with them. Those generic handlers apply none of the controller's permission or per-monitor checks: zones/view/<id> and zones/<id> returned any zone, including those of monitors the user is denied, and Controls add/edit and Configs add were reachable the same way. Map no Crud actions, so an undefined action is a 404, and give ZonesController a view() that checks the zone's monitor. ZonesController::index() passed its monitor filter as a find() option key rather than a condition, so it was ignored and every zone was listed. Use a real condition. Add AppController helpers the following fixes share: a viewable-monitor find() condition that matches nothing when the user may view no monitor (callers treated an empty list as unrestricted), reading a field or associated ids from request data, and requiring view or edit on a monitor or view on events. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ZoneMinder API
This is the ZoneMinder API. It should be, for now, installed under the webroot e.g. /api.
app/Config/database.php.default must be configured and copied to app/Config/database.php
In addition, Security.salt and Security.cipherSeed in app/Config/core.php should be changed.
The API can run on a dedicated / separate instance, so long as it can access the database as configured in app/Config/database.php