Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-79427

Provide a consistent response for non-existent courses and those a user does not have access to view

XMLWordPrintable

    • MOODLE_404_STABLE

      If a user (for example a student) tries to access a non-existent course pointing to its URL, Moodle returns a 404 error. If the course exists and the user isn't enrolled, Moodle returns a 303.

      Although knowing a list of course IDs this is not exploitable information, it would be good practice to treat a course page you do not have access to the same as if the page did not exist. This will also avoid any "fingerprinting" of the potential size of the site/institution based on number of courses.

            Unassigned Unassigned
            ghigio Federico Ghigini
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.