mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 07:25:02 -04:00
ZM_AUTH_HASH_SECRET signs the JWT access and refresh tokens, and its default is a fixed string in the public source. Nothing generated a per-install value and tokens signed with the default verified normally, so on an install with auth on and the secret untouched anyone could sign an admin token and be accepted by the web UI, the API and zms. - ZoneMinder::Config::saveConfigToDB() now replaces an empty or default secret with 32 random bytes from /dev/urandom, hex encoded. Package installs and upgrades run zmupdate.pl -f, which saves the config, so existing installs get a secret on upgrade. A secret the admin set is left alone. - validateToken() in PHP and zmLoadTokenUser() in C++ refuse to verify tokens while the secret is empty or the default, and the API refuses to issue them, as it already did for an empty secret. - zmLoadTokenUser() no longer writes the signing key to the debug log. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>