Files
zoneminder/web/includes/Group_Permission.php
T
Isaac ConnorandClaude Opus 5.5 8d6c18db7e fix: only dispatch set()/changes() keys to field accessors refs GHSA-vvx7-ghpv-jq98
ZM_Object::set() called any method whose name matched a key in its data,
and changes() called it as a getter. That data is usually a request array
(filter[...], newMonitor[...], user[...]), so a request could invoke
save(), delete(), execute() and the like. filterdebug with fid=0 did
exactly that before its authorization check: filter[save][...] stored an
AutoExecute filter with a chosen command and filter[execute] ran
zmfilter.pl on it, giving command execution to any logged-in user. The
filter and events views pass filter[...] to set() the same way.

set() and changes() now dispatch a key to a method only when the key is
a field in $defaults or is listed in the class's new static $setters, the
accessors outside $defaults that take a value (Filter's query accessors,
Monitor::Model/Manufacturer/Groups, User::Role, and so on). Other method
names are refused with a warning.

filterdebug also requires Events view before it builds a filter from the
request.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 19:32:25 -04:00

53 lines
1.4 KiB
PHP

<?php
namespace ZM;
require_once('database.php');
require_once('Object.php');
require_once('Monitor.php');
require_once('User.php');
require_once('Group.php');
class Group_Permission extends ZM_Object {
protected static $setters = array('Group', 'User');
protected static $table = 'Groups_Permissions';
protected $defaults = array(
'Id' => null,
'GroupId' => null,
'UserId' => null,
'Permission' => 'Inherit',
);
private $Group;
private $User;
private $Monitors;
public static function find( $parameters = array(), $options = array() ) {
return ZM_Object::_find(self::class, $parameters, $options);
}
public static function find_one( $parameters = array(), $options = array() ) {
return ZM_Object::_find_one(self::class, $parameters, $options);
}
public function MonitorPermission($mid) {
if (!$this->Monitors)
$this->Monitors = array_to_hash_by_key('Id', $this->Group()->Monitors());
if (isset($this->Monitors[$mid])) return $this->Permission;
return 'Inherit';
}
public function Group($new=null) {
if ($new) $this->Group = $new;
if (!$this->Group)
$this->Group = Group::find_one(['Id'=>$this->GroupId]);
return $this->Group;
}
public function User($new=null) {
if ($new) $this->User = $new;
if (!$this->User)
$this->User = User::find_one(['Id'=>$this->UserId]);
return $this->User;
}
} # end class Group_Permission
?>