Files
zoneminder/web/api
Isaac ConnorandClaude Opus 5.5 a57634871c fix: check permissions in Logs delete and the ZonePresets API
LogsController::delete() never declared global $user, so its System=Edit
check always passed and anyone with System view could delete log entries.
Logs add, which ZM_LOG_INJECT opens to non-admins, could overwrite an
existing entry by Id; pin it.

ZonePresetsController had no permission checks. Reading presets stays
open to signed-in users; changing them now needs System=Edit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 17:54:25 -04:00
..
2021-03-31 12:11:12 -04:00
2021-03-31 12:11:12 -04:00
2021-03-31 12:11:12 -04:00
2017-05-03 12:35:54 -05:00
2021-03-31 12:11:12 -04:00
2021-03-31 12:11:12 -04:00
2023-08-27 02:00:59 +02:00

ZoneMinder API

This is the ZoneMinder API. It should be, for now, installed under the webroot e.g. /api.

app/Config/database.php.default must be configured and copied to app/Config/database.php

In addition, Security.salt and Security.cipherSeed in app/Config/core.php should be changed.

The API can run on a dedicated / separate instance, so long as it can access the database as configured in app/Config/database.php