Files
zoneminder/web/includes/actions/event.php
T
Isaac ConnorandClaude Opus 5.5 44339b0fe7 fix: authorize event delete, archive and edits on the event's monitor refs GHSA-34x2-mw89-c52f
The classic event actions checked only the global Events permission and
then acted on whatever event ids the request supplied, so a user denied a
monitor could still change that monitor's events:

- deleteEvent() deleted when the user had Events=Edit. It now requires
  Event::canEdit(), which also requires access to the event's monitor.
  This covers the events form, the event form and monitor deletion.
- The events form archive/unarchive updated Events by id. Each event now
  needs canEdit().
- ajax events archiveRequest() updated by id under the page-wide Events
  view check. Archive now needs canView() on the event and unarchive
  canEdit(), keeping the intent that viewers may archive.
- actions/event.php returned early whenever an eid was supplied, so none
  of its actions ran. Fix that inverted test, and require canEdit() on the
  event for rename, detail edits, archive, unarchive and delete, rather
  than the global permission.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 19:34:36 -04:00

57 lines
2.2 KiB
PHP

<?php
//
// ZoneMinder web action
// Copyright (C) 2019 ZoneMinder LLC
//
// This program is free software; you can redistribute it and/or
// modify it under the terms of the GNU General Public License
// as published by the Free Software Foundation; either version 2
// of the License, or (at your option) any later version.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License
// along with this program; if not, write to the Free Software
// Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
//
// If there is an action on an event, then we must have an id.
if ( empty($_REQUEST['eid']) ) {
ZM\Warning('No eid in action on event view');
return;
}
// Event scope actions. Require edit on this event, which includes access to its monitor.
$event = new ZM\Event($_REQUEST['eid']);
if ( $event->Id() and $event->canEdit() ) {
$_REQUEST['eid'] = $event->Id();
if ( ($action == 'rename') && isset($_REQUEST['eventName']) ) {
dbQuery('UPDATE Events SET Name=? WHERE Id=?', array($_REQUEST['eventName'], $_REQUEST['eid']));
ZM\AuditAction('rename', 'event', $_REQUEST['eid'], 'Name: '.$_REQUEST['eventName']);
} else if ( $action == 'eventdetail' ) {
dbQuery('UPDATE Events SET Cause=?, Notes=? WHERE Id=?',
array(
$_REQUEST['newEvent']['Cause'],
$_REQUEST['newEvent']['Notes'],
$_REQUEST['eid']
)
);
ZM\AuditAction('update', 'event', $_REQUEST['eid'], 'Detail update');
$refreshParent = true;
$closePopup = true;
} else if ( $action == 'archive' ) {
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(1, $_REQUEST['eid']));
} else if ( $action == 'unarchive' ) {
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(0, $_REQUEST['eid']));
} else if ( $action == 'delete' ) {
deleteEvent($_REQUEST['eid']);
ZM\AuditAction('delete', 'event', $_REQUEST['eid'], '');
$refreshParent = true;
}
} // end if event canEdit
?>