mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 15:35:09 -04:00
The API alarm action and ajax/alarm.php checked no per-monitor permission and relied on zmu, which only requires that the user can see the monitor. A user with view on a monitor could force, cancel or disable its alarms. Changing alarm state now needs Monitor::canEdit(), and the API status query needs canView(). Monitors API edit and add also pin the record id, so an Id in the body cannot redirect the save to another monitor. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ZoneMinder API
This is the ZoneMinder API. It should be, for now, installed under the webroot e.g. /api.
app/Config/database.php.default must be configured and copied to app/Config/database.php
In addition, Security.salt and Security.cipherSeed in app/Config/core.php should be changed.
The API can run on a dedicated / separate instance, so long as it can access the database as configured in app/Config/database.php