mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 07:25:02 -04:00
The CSRF token check on the image proxy only runs when ZM_ENABLE_CSRF_MAGIC is on. Browsers that send Sec-Fetch-Site report when another site started a request, so refuse proxy requests whose value is anything but same-origin or none, whatever the CSRF setting. Browsers that do not send the header are unaffected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Modern ZoneMinder Skin
This web frontend to ZoneMinder is a complete rewrite of the classic frontend, based on CakePHP.