-
Improvement
-
Resolution: Won't Do
-
Minor
-
None
-
2.9, 3.1, 3.4
-
MOODLE_29_STABLE, MOODLE_31_STABLE, MOODLE_34_STABLE
-
MDL-50292_m35v1 -
Easy
-
It is possible for guests to see the details of participants' choices and there is no capability to control this. There is a setting to control whether results should be shown, but there is no way to discriminate between guests and authenticated users.
This could potentially be considered a minor security issue as it is revealing student details to unauthorised users. There should be a capability that prevents guests from viewing choices made.
Replication steps:
- Log in as admin/teacher
- Log into a course that is open to guests or use the Front page
- Create a Choice activity with a few choices
- Set Publish results to Always show results to students
- Save the activity
- Log in as a student
- Make a choice
- Log out
- Access the Choice activity
Expected result
Results should not be available to guests or shown in an anonymised form.
Actual result
The image and name of students who have made a choice is visible.
- has a non-specific relationship to
-
MDL-49029 Add "mod/choice:view" permission to Choice Activity
-
- Closed
-