Files
zoneminder/web/includes
Isaac ConnorandClaude Opus 5.5 44339b0fe7 fix: authorize event delete, archive and edits on the event's monitor refs GHSA-34x2-mw89-c52f
The classic event actions checked only the global Events permission and
then acted on whatever event ids the request supplied, so a user denied a
monitor could still change that monitor's events:

- deleteEvent() deleted when the user had Events=Edit. It now requires
  Event::canEdit(), which also requires access to the event's monitor.
  This covers the events form, the event form and monitor deletion.
- The events form archive/unarchive updated Events by id. Each event now
  needs canEdit().
- ajax events archiveRequest() updated by id under the page-wide Events
  view check. Archive now needs canView() on the event and unarchive
  canEdit(), keeping the intent that viewers may archive.
- actions/event.php returned early whenever an eid was supplied, so none
  of its actions ran. Fix that inverted test, and require canEdit() on the
  event for rename, detail edits, archive, unarchive and delete, rather
  than the global permission.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 19:34:36 -04:00
..