mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-03 07:55:22 -04:00
CakePHP's Model::set() takes the record id from a primary key in the data passed to save(). edit() authorized the id in the URL and then saved the request body, so Zone[Id]=<other> in the body wrote to that other zone, past the per-monitor check just added. add() could likewise update an existing row instead of creating one. Add AppController::pinRequestId(), which drops the primary key from the request data and sets the model id, and use it in these edits (pinned to the URL id) and adds (cleared). Frames and EventData edit() never set the model id at all, so a body without an Id inserted a new row rather than updating; pinning fixes that too. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>