Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-50613

Enabling mobile web services results in 'Critical' status in security overview report

XMLWordPrintable

    • MOODLE_28_STABLE, MOODLE_29_STABLE
    • MOODLE_28_STABLE, MOODLE_29_STABLE
    • MDL-50613-master
    • Hide
      1. Do a clean Moodle installation
      2. Enable Mobile services in Plugins -> Web Services -> Mobile
      3. Go to the site Report -> Security Overview
      4. Ensure that the Default role for all users reports shows a OK
      5. Do an upgrade of an existing Moodle installation with Mobile Services Enabled
      6. Go to the site Report -> Security Overview and ensure that the Default role for all users reports shows a OK
      Show
      Do a clean Moodle installation Enable Mobile services in Plugins -> Web Services -> Mobile Go to the site Report -> Security Overview Ensure that the Default role for all users reports shows a OK Do an upgrade of an existing Moodle installation with Mobile Services Enabled Go to the site Report -> Security Overview and ensure that the Default role for all users reports shows a OK

      When mobile web services are enabled on a site (for Moodle Mobile app users), the security overview report shows the default role for all users with status 'Critical' due to the webservice capabilities being allowed for the authenticated user role.

      The Security report on default user role documentation explains this 'Critical' status and accompanying message 'The default user role "Authenticated user" is incorrectly defined!', however it remains a concern for admins, as mentioned in a recent forum post Re: Critical security issue with default role for all users.

      • Should the security report on default user role status be changed from 'Critical'?
      • Should the message be changed?
      • Should the documentation provide further explanation?

            jleyva Juan Leyva
            tsala Helen Foster
            Dani Palou Dani Palou
            David Monllaó David Monllaó
            Frédéric Massart Frédéric Massart
            Votes:
            0 Vote for this issue
            Watchers:
            11 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.