Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-49151

Reconsider risk bitmask on 'block/xxx:addinstance'

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Won't Do
    • Icon: Major Major
    • None
    • 2.8.3
    • Blocks
    • MOODLE_28_STABLE

      Most of 'block/xxx:addinstance' permissions have risk bitmask

      'riskbitmask' => RISK_SPAM | RISK_XSS,
      

      There is no XSS risk in any blocks except for html (and maybe one-two others). Also not sure what SPAM is for

            Unassigned Unassigned
            marina Marina Glancy
            Votes:
            2 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.