mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 15:35:09 -04:00
The ZM_OPT_USE_AUTH gate in index.php exempted view=login and view=none
so those pages can render without a session. The same condition also
guarded the ajax dispatcher, so view=none&request=<name> (or
view=login&request=<name>) reached web/ajax/<name>.php with no user.
ajax/stats.php's raw branch has no permission check of its own and
returned Events rows (Name, Cause, Notes, DiskSpace) joined with the
monitor name to anonymous clients.
Apply the login/none exemption only when there is no request, so any
request= without a user gets the 401. No ajax handler is meant to be
reached unauthenticated: login and logout are POST actions on views,
skin.js skips its polling on the login and none views, and the auth
revalidation probe already uses view=request and expects a 401/403 for
a dead session.
Also check canView('Events') at the top of ajax/stats.php, matching
getStatsTableHTML() used by its non-raw branch, so the raw branch no
longer depends on the gate alone.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 6699ae212ea8c5d7b9ee29f38c05c0135635fe8f)
41 lines
1.9 KiB
PHP
41 lines
1.9 KiB
PHP
<?php
|
|
if (!canView('Events')) ajaxError('Insufficient permissions');
|
|
if (empty($_REQUEST['eid'])) ajaxError('Event Id Not Provided');
|
|
if (empty($_REQUEST['fid'])) ajaxError('Frame Id Not Provided');
|
|
|
|
$eid = $_REQUEST['eid'];
|
|
$fid = $_REQUEST['fid'];
|
|
$row = ( isset($_REQUEST['row']) ) ? $_REQUEST['row'] : '';
|
|
$raw = isset($_REQUEST['raw']);
|
|
$data = array();
|
|
|
|
if ($raw) {
|
|
$data['raw'] = array();
|
|
$sql = 'SELECT S.*,E.*,Z.Name AS ZoneName,Z.Units,Z.Area,M.Name AS MonitorName
|
|
FROM Stats AS S LEFT JOIN Events AS E ON S.EventId = E.Id LEFT JOIN Zones AS Z ON S.ZoneId = Z.Id LEFT JOIN Monitors AS M ON E.MonitorId = M.Id
|
|
WHERE S.EventId = ? AND S.FrameId = ? ORDER BY S.ZoneId';
|
|
$stats = dbFetchAll($sql, NULL, array($eid, $fid));
|
|
foreach ($stats as $stat) {
|
|
$stat['ZoneName'] = validHtmlStr($stat['ZoneName']);
|
|
$stat['PixelDiff'] = validHtmlStr($stat['PixelDiff']);
|
|
$stat['AlarmPixels'] = sprintf('%d (%.1f%%)', $stat['AlarmPixels'], (100*$stat['AlarmPixels']/$stat['Area']));
|
|
$stat['FilterPixels'] = sprintf('%d (%.1f%%)', $stat['FilterPixels'], (100*$stat['FilterPixels']/$stat['Area']));
|
|
$stat['BlobPixels'] = sprintf('%d (%.1f%%)', $stat['BlobPixels'], (100*$stat['BlobPixels']/$stat['Area']));
|
|
$stat['Blobs'] = validHtmlStr($stat['Blobs']);
|
|
if ($stat['Blobs'] > 1) {
|
|
$stat['BlobSizes'] = sprintf('%d-%d (%.1f%%-%.1f%%)', $stat['MinBlobSize'], $stat['MaxBlobSize'], (100*$stat['MinBlobSize']/$stat['Area']), (100*$stat['MaxBlobSize']/$stat['Area']));
|
|
} else {
|
|
$stat['BlobSizes'] = sprintf('%d (%.1f%%)', $stat['MinBlobSize'], 100*$stat['MinBlobSize']/$stat['Area']);
|
|
}
|
|
$stat['AlarmLimits'] = validHtmlStr($stat['MinX'].','.$stat['MinY'].'-'.$stat['MaxX'].','.$stat['MaxY']);
|
|
$data['raw'][] = $stat;
|
|
} # end foreach stat/zone
|
|
} else {
|
|
$data['html'] = getStatsTableHTML($eid, $fid, $row);
|
|
$data['id'] = '#contentStatsTable' .$row;
|
|
}
|
|
|
|
ajaxResponse($data);
|
|
return;
|
|
?>
|