mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-03 07:55:22 -04:00
A preference belongs to the user who set it, so ownership is the permission. The controller instead required System, which got it wrong in both directions: any System account could read and overwrite another user's preferences, and an ordinary user could not save their own at all, which is what the montage layout in montage_common.js does through this controller. Reads and writes are now scoped to the caller. index lists only the caller's rows, view, edit and delete refuse a row belonging to someone else, and add pins UserId to the authenticated user: the client sends its own id in the body, so taking that on trust let anyone write a preference onto another account. A System Edit account may still manage anyone's, so an administrator can clear a broken one. The find conditions named the table, User_Preferences, where CakePHP wanted the model alias, UserPreference, so view and edit returned a 500 for everyone. That is fixed here because it otherwise hides whether the ownership check works.
ZoneMinder API
This is the ZoneMinder API. It should be, for now, installed under the webroot e.g. /api.
app/Config/database.php.default must be configured and copied to app/Config/database.php
In addition, Security.salt and Security.cipherSeed in app/Config/core.php should be changed.
The API can run on a dedicated / separate instance, so long as it can access the database as configured in app/Config/database.php