mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 07:25:02 -04:00
ZM_Object::set() called any method whose name matched a key in its data, and changes() called it as a getter. That data is usually a request array (filter[...], newMonitor[...], user[...]), so a request could invoke save(), delete(), execute() and the like. filterdebug with fid=0 did exactly that before its authorization check: filter[save][...] stored an AutoExecute filter with a chosen command and filter[execute] ran zmfilter.pl on it, giving command execution to any logged-in user. The filter and events views pass filter[...] to set() the same way. set() and changes() now dispatch a key to a method only when the key is a field in $defaults or is listed in the class's new static $setters, the accessors outside $defaults that take a value (Filter's query accessors, Monitor::Model/Manufacturer/Groups, User::Role, and so on). Other method names are refused with a warning. filterdebug also requires Events view before it builds a filter from the request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
53 lines
1.4 KiB
PHP
53 lines
1.4 KiB
PHP
<?php
|
|
namespace ZM;
|
|
|
|
require_once('database.php');
|
|
require_once('Object.php');
|
|
require_once('Monitor.php');
|
|
require_once('User.php');
|
|
require_once('Group.php');
|
|
|
|
class Group_Permission extends ZM_Object {
|
|
protected static $setters = array('Group', 'User');
|
|
protected static $table = 'Groups_Permissions';
|
|
protected $defaults = array(
|
|
'Id' => null,
|
|
'GroupId' => null,
|
|
'UserId' => null,
|
|
'Permission' => 'Inherit',
|
|
);
|
|
private $Group;
|
|
private $User;
|
|
private $Monitors;
|
|
|
|
public static function find( $parameters = array(), $options = array() ) {
|
|
return ZM_Object::_find(self::class, $parameters, $options);
|
|
}
|
|
|
|
public static function find_one( $parameters = array(), $options = array() ) {
|
|
return ZM_Object::_find_one(self::class, $parameters, $options);
|
|
}
|
|
|
|
public function MonitorPermission($mid) {
|
|
if (!$this->Monitors)
|
|
$this->Monitors = array_to_hash_by_key('Id', $this->Group()->Monitors());
|
|
if (isset($this->Monitors[$mid])) return $this->Permission;
|
|
return 'Inherit';
|
|
}
|
|
|
|
public function Group($new=null) {
|
|
if ($new) $this->Group = $new;
|
|
if (!$this->Group)
|
|
$this->Group = Group::find_one(['Id'=>$this->GroupId]);
|
|
return $this->Group;
|
|
}
|
|
public function User($new=null) {
|
|
if ($new) $this->User = $new;
|
|
if (!$this->User)
|
|
$this->User = User::find_one(['Id'=>$this->UserId]);
|
|
return $this->User;
|
|
}
|
|
|
|
} # end class Group_Permission
|
|
?>
|