mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 07:25:02 -04:00
Saving a user from the web ui took the whole auth path down: PHP Fatal error: Uncaught TypeError: strcasecmp(): Argument #1 ($string1) must be of type string, array given in includes/auth.php:197 #0 auth.php(197): strcasecmp() #1 auth.php(528): getAuthUser() #2 auth.php(687): userFromSession() reached from ?view=user&uid=2. That page's form posts user[Username], user[Password], user[Name] and the rest, so $_REQUEST['user'] is an array on every save from it, and getAuthUser() read that parameter as the username to filter on and handed it to strcasecmp(). Under PHP 8 a string function given an array is a TypeError rather than a warning, so the request died with a 500. The same shape arrives from anyone who cares to send it, and not only on a page that needs a session. userFromSession() reads user, pass, username, password and auth straight out of the request, and the credential branches run before anyone is logged in, so ?username[]=x&password[]=y reaches validateUser() with arrays on an install that has never seen the caller before. requestString() returns a parameter only when it is a string and null otherwise, which is what the callers already do with a parameter that was not sent. An array is not a username, a password or an auth hash. master no longer has the strcasecmp line the report names, so it does not fatal in that exact spot, but it reads the same unvalidated values: $filterUser is bound as a query parameter and the credentials still reach validateUser(). This fixes the class rather than the one line, and backports to 1.38 where the reported line lives. The test lifts requestString() out of auth.php and evaluates it alone, because including auth.php needs a database; test_auth_no_include_side_effects.php sidesteps the same dependency the same way. 8 cases, covering the form's array, the login parameters, a nested array and the strings that must still pass through. 5 of them fail without this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> (cherry picked from commit 1f4aa1a16c1b63fdf34a6f2c6aef6590dbd45acd)