mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-06 17:31:58 -04:00
The classic event actions checked only the global Events permission and then acted on whatever event ids the request supplied, so a user denied a monitor could still change that monitor's events: - deleteEvent() deleted when the user had Events=Edit. It now requires Event::canEdit(), which also requires access to the event's monitor. This covers the events form, the event form and monitor deletion. - The events form archive/unarchive updated Events by id. Each event now needs canEdit(). - ajax events archiveRequest() updated by id under the page-wide Events view check. Archive now needs canView() on the event and unarchive canEdit(), keeping the intent that viewers may archive. - actions/event.php returned early whenever an eid was supplied, so none of its actions ran. Fix that inverted test, and require canEdit() on the event for rename, detail edits, archive, unarchive and delete, rather than the global permission. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
57 lines
2.2 KiB
PHP
57 lines
2.2 KiB
PHP
<?php
|
|
//
|
|
// ZoneMinder web action
|
|
// Copyright (C) 2019 ZoneMinder LLC
|
|
//
|
|
// This program is free software; you can redistribute it and/or
|
|
// modify it under the terms of the GNU General Public License
|
|
// as published by the Free Software Foundation; either version 2
|
|
// of the License, or (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License for more details.
|
|
//
|
|
// You should have received a copy of the GNU General Public License
|
|
// along with this program; if not, write to the Free Software
|
|
// Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
|
//
|
|
|
|
// If there is an action on an event, then we must have an id.
|
|
if ( empty($_REQUEST['eid']) ) {
|
|
ZM\Warning('No eid in action on event view');
|
|
return;
|
|
}
|
|
|
|
// Event scope actions. Require edit on this event, which includes access to its monitor.
|
|
$event = new ZM\Event($_REQUEST['eid']);
|
|
if ( $event->Id() and $event->canEdit() ) {
|
|
$_REQUEST['eid'] = $event->Id();
|
|
|
|
if ( ($action == 'rename') && isset($_REQUEST['eventName']) ) {
|
|
dbQuery('UPDATE Events SET Name=? WHERE Id=?', array($_REQUEST['eventName'], $_REQUEST['eid']));
|
|
ZM\AuditAction('rename', 'event', $_REQUEST['eid'], 'Name: '.$_REQUEST['eventName']);
|
|
} else if ( $action == 'eventdetail' ) {
|
|
dbQuery('UPDATE Events SET Cause=?, Notes=? WHERE Id=?',
|
|
array(
|
|
$_REQUEST['newEvent']['Cause'],
|
|
$_REQUEST['newEvent']['Notes'],
|
|
$_REQUEST['eid']
|
|
)
|
|
);
|
|
ZM\AuditAction('update', 'event', $_REQUEST['eid'], 'Detail update');
|
|
$refreshParent = true;
|
|
$closePopup = true;
|
|
} else if ( $action == 'archive' ) {
|
|
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(1, $_REQUEST['eid']));
|
|
} else if ( $action == 'unarchive' ) {
|
|
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(0, $_REQUEST['eid']));
|
|
} else if ( $action == 'delete' ) {
|
|
deleteEvent($_REQUEST['eid']);
|
|
ZM\AuditAction('delete', 'event', $_REQUEST['eid'], '');
|
|
$refreshParent = true;
|
|
}
|
|
} // end if event canEdit
|
|
?>
|