mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 23:45:08 -04:00
LogsController::delete() never declared global $user, so its System=Edit check always passed and anyone with System view could delete log entries. Logs add, which ZM_LOG_INJECT opens to non-admins, could overwrite an existing entry by Id; pin it. ZonePresetsController had no permission checks. Reading presets stays open to signed-in users; changing them now needs System=Edit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ZoneMinder API
This is the ZoneMinder API. It should be, for now, installed under the webroot e.g. /api.
app/Config/database.php.default must be configured and copied to app/Config/database.php
In addition, Security.salt and Security.cipherSeed in app/Config/core.php should be changed.
The API can run on a dedicated / separate instance, so long as it can access the database as configured in app/Config/database.php