mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-03 07:55:22 -04:00
A preference belongs to the user who set it, so ownership is the permission. The controller instead required System, which got it wrong in both directions: any System account could read and overwrite another user's preferences, and an ordinary user could not save their own at all, which is what the montage layout in montage_common.js does through this controller. Reads and writes are now scoped to the caller. index lists only the caller's rows, view, edit and delete refuse a row belonging to someone else, and add pins UserId to the authenticated user: the client sends its own id in the body, so taking that on trust let anyone write a preference onto another account. A System Edit account may still manage anyone's, so an administrator can clear a broken one. The find conditions named the table, User_Preferences, where CakePHP wanted the model alias, UserPreference, so view and edit returned a 500 for everyone. That is fixed here because it otherwise hides whether the ownership check works.