mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-03-27 18:23:00 -04:00
Add a new AUDIT logging level (-5) between PANIC (-4) and NOLOG (shifted to -6) across C++, PHP, and Perl loggers. AUDIT entries use code 'AUD' and syslog priority LOG_NOTICE. They record who changed what, from where, for monitors, filters, users, config, roles, groups, zones, states, servers, storage, events, snapshots, control caps, and login/logout. AUDIT entries have their own retention period (ZM_LOG_AUDIT_DATABASE_LIMIT, default 1 year) separate from regular log pruning. The log pruning in zmstats.pl and zmaudit.pl now excludes AUDIT rows from regular pruning and prunes them independently. Critical safety: the C++ termination logic is changed from 'if (level <= FATAL)' to 'if (level == FATAL || level == PANIC)' to prevent AUDIT-level log calls from killing the process. Includes db migration zm_update-1.39.1.sql to shift any stored NOLOG config values from -5 to -6. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
55 lines
2.1 KiB
PHP
55 lines
2.1 KiB
PHP
<?php
|
|
//
|
|
// ZoneMinder web action
|
|
// Copyright (C) 2019 ZoneMinder LLC
|
|
//
|
|
// This program is free software; you can redistribute it and/or
|
|
// modify it under the terms of the GNU General Public License
|
|
// as published by the Free Software Foundation; either version 2
|
|
// of the License, or (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License for more details.
|
|
//
|
|
// You should have received a copy of the GNU General Public License
|
|
// along with this program; if not, write to the Free Software
|
|
// Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
|
//
|
|
|
|
// If there is an action on an event, then we must have an id.
|
|
if ( !empty($_REQUEST['eid']) ) {
|
|
ZM\Warning('No eid in action on event view');
|
|
return;
|
|
}
|
|
|
|
// Event scope actions, view permissions only required
|
|
if ( canEdit('Events') ) {
|
|
|
|
if ( ($action == 'rename') && isset($_REQUEST['eventName']) ) {
|
|
dbQuery('UPDATE Events SET Name=? WHERE Id=?', array($_REQUEST['eventName'], $_REQUEST['eid']));
|
|
ZM\AuditAction('rename', 'event', $_REQUEST['eid'], 'Name: '.$_REQUEST['eventName']);
|
|
} else if ( $action == 'eventdetail' ) {
|
|
dbQuery('UPDATE Events SET Cause=?, Notes=? WHERE Id=?',
|
|
array(
|
|
$_REQUEST['newEvent']['Cause'],
|
|
$_REQUEST['newEvent']['Notes'],
|
|
$_REQUEST['eid']
|
|
)
|
|
);
|
|
ZM\AuditAction('update', 'event', $_REQUEST['eid'], 'Detail update');
|
|
$refreshParent = true;
|
|
$closePopup = true;
|
|
} else if ( $action == 'archive' ) {
|
|
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(1, $_REQUEST['eid']));
|
|
} else if ( $action == 'unarchive' ) {
|
|
dbQuery('UPDATE Events SET Archived=? WHERE Id=?', array(0, $_REQUEST['eid']));
|
|
} else if ( $action == 'delete' ) {
|
|
deleteEvent($_REQUEST['eid']);
|
|
ZM\AuditAction('delete', 'event', $_REQUEST['eid'], '');
|
|
$refreshParent = true;
|
|
}
|
|
} // end if canEdit(Events)
|
|
?>
|