mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-07 09:52:03 -04:00
The classic event actions checked only the global Events permission and then acted on whatever event ids the request supplied, so a user denied a monitor could still change that monitor's events: - deleteEvent() deleted when the user had Events=Edit. It now requires Event::canEdit(), which also requires access to the event's monitor. This covers the events form, the event form and monitor deletion. - The events form archive/unarchive updated Events by id. Each event now needs canEdit(). - ajax events archiveRequest() updated by id under the page-wide Events view check. Archive now needs canView() on the event and unarchive canEdit(), keeping the intent that viewers may archive. - actions/event.php returned early whenever an eid was supplied, so none of its actions ran. Fix that inverted test, and require canEdit() on the event for rename, detail edits, archive, unarchive and delete, rather than the global permission. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
71 lines
2.3 KiB
PHP
71 lines
2.3 KiB
PHP
<?php
|
|
//
|
|
// ZoneMinder web action file
|
|
// Copyright (C) 2019 ZoneMinder LLC
|
|
//
|
|
// This program is free software; you can redistribute it and/or
|
|
// modify it under the terms of the GNU General Public License
|
|
// as published by the Free Software Foundation; either version 2
|
|
// of the License, or (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License for more details.
|
|
//
|
|
// You should have received a copy of the GNU General Public License
|
|
// along with this program; if not, write to the Free Software
|
|
// Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
|
//
|
|
|
|
if ( !isset($_REQUEST['eids']) ) {
|
|
ZM\Warning('Events actions require eids');
|
|
return;
|
|
}
|
|
|
|
// Event scope actions, view permissions only required
|
|
if ( !canEdit('Events') ) {
|
|
ZM\Warning('Events actions require Edit permissions');
|
|
return;
|
|
} // end if ! canEdit(Events)
|
|
|
|
if ( $action == 'archive' ) {
|
|
$dbConn->beginTransaction();
|
|
$eids = getAffectedIds('eids');
|
|
ZM\Debug("E IDS" . print_r($eids, true));
|
|
foreach ( $eids as $markEid ) {
|
|
$event = new ZM\Event($markEid);
|
|
if (!$event->Id() or !$event->canEdit()) {
|
|
ZM\Warning('No permission to archive event '.$markEid);
|
|
continue;
|
|
}
|
|
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(1, $event->Id()));
|
|
}
|
|
$dbConn->commit();
|
|
$refreshParent = true;
|
|
} else if ( $action == 'unarchive' ) {
|
|
$dbConn->beginTransaction();
|
|
$eids = getAffectedIds('eids');
|
|
ZM\Debug("E IDS" . print_r($eids, true));
|
|
foreach ( $eids as $markEid ) {
|
|
$event = new ZM\Event($markEid);
|
|
if (!$event->Id() or !$event->canEdit()) {
|
|
ZM\Warning('No permission to unarchive event '.$markEid);
|
|
continue;
|
|
}
|
|
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(0, $event->Id()));
|
|
}
|
|
$dbConn->commit();
|
|
$refreshParent = true;
|
|
} else if ( $action == 'delete' ) {
|
|
$deletedEids = getAffectedIds('eids');
|
|
foreach ( $deletedEids as $markEid ) {
|
|
deleteEvent($markEid);
|
|
}
|
|
ZM\AuditAction('delete', 'events', 0, 'Count: '.count($deletedEids));
|
|
$refreshParent = true;
|
|
} else {
|
|
ZM\Warning("Unsupported action $action in events");
|
|
}
|
|
?>
|