mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 07:25:02 -04:00
ZM_Object::set() called any method whose name matched a key in its data, and changes() called it as a getter. That data is usually a request array (filter[...], newMonitor[...], user[...]), so a request could invoke save(), delete(), execute() and the like. filterdebug with fid=0 did exactly that before its authorization check: filter[save][...] stored an AutoExecute filter with a chosen command and filter[execute] ran zmfilter.pl on it, giving command execution to any logged-in user. The filter and events views pass filter[...] to set() the same way. set() and changes() now dispatch a key to a method only when the key is a field in $defaults or is listed in the class's new static $setters, the accessors outside $defaults that take a value (Filter's query accessors, Monitor::Model/Manufacturer/Groups, User::Role, and so on). Other method names are refused with a warning. filterdebug also requires Events view before it builds a filter from the request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
46 lines
1.2 KiB
PHP
46 lines
1.2 KiB
PHP
<?php
|
|
namespace ZM;
|
|
|
|
require_once('database.php');
|
|
require_once('Object.php');
|
|
require_once('Monitor.php');
|
|
|
|
class Role_Monitor_Permission extends ZM_Object {
|
|
protected static $setters = array('Role', 'Monitor');
|
|
protected static $table = 'Role_Monitors_Permissions';
|
|
protected $defaults = array(
|
|
'Id' => null,
|
|
'RoleId' => null,
|
|
'MonitorId' => null,
|
|
'Permission' => 'Inherit',
|
|
);
|
|
private $Role;
|
|
private $Monitor;
|
|
|
|
public static function find($parameters = array(), $options = array()) {
|
|
return ZM_Object::_find(self::class, $parameters, $options);
|
|
}
|
|
|
|
public static function find_one($parameters = array(), $options = array()) {
|
|
return ZM_Object::_find_one(self::class, $parameters, $options);
|
|
}
|
|
|
|
public function Role($new = null) {
|
|
if ($new) $this->Role = $new;
|
|
if (!$this->Role) {
|
|
require_once('User_Role.php');
|
|
$this->Role = User_Role::find_one(['Id' => $this->RoleId()]);
|
|
}
|
|
return $this->Role;
|
|
}
|
|
|
|
public function Monitor($new = null) {
|
|
if ($new) $this->Monitor = $new;
|
|
if (!$this->Monitor)
|
|
$this->Monitor = Monitor::find_one(['Id' => $this->MonitorId()]);
|
|
return $this->Monitor;
|
|
}
|
|
|
|
} # end class Role_Monitor_Permission
|
|
?>
|