mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 15:35:09 -04:00
The API alarm action and ajax/alarm.php checked no per-monitor permission and relied on zmu, which only requires that the user can see the monitor. A user with view on a monitor could force, cancel or disable its alarms. Changing alarm state now needs Monitor::canEdit(), and the API status query needs canView(). Monitors API edit and add also pin the record id, so an Id in the body cannot redirect the save to another monitor. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>