Files
zoneminder/web
Isaac ConnorandClaude Opus 5.5 dbd2cb231d fix: refuse cross-site image proxy requests by Sec-Fetch-Site
The CSRF token check on the image proxy only runs when ZM_ENABLE_CSRF_MAGIC
is on. Browsers that send Sec-Fetch-Site report when another site started a
request, so refuse proxy requests whose value is anything but same-origin or
none, whatever the CSRF setting. Browsers that do not send the header are
unaffected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 07:56:03 -04:00
..
…
…

Modern ZoneMinder Skin

This web frontend to ZoneMinder is a complete rewrite of the classic frontend, based on CakePHP.