-
Bug
-
Resolution: Unresolved
-
Minor
-
None
-
4.5.4, 5.0
ie editing an instance looks like:
/mod/lti/typessettings.php?action=update&id=2160&sesskey=QH19TmDKbE&returnto=toolconfigure
The first page should simply not require a sesskey at all, only the POST when saving it should.
At a quick glance it looks like many of the LTI pages suffer from the same problems, eg from this page:
/mod/lti/toolproxies.php
when you click 'Configure a new external tool registration' you get the same issue:
/mod/lti/registersettings.php?action=add&sesskey=QH19TmDKbE&tab=tool_proxy
- Testing discovered
-
MDL-85341 GET requests expose sesskey in course module "edit settings" and "more" controls
-
- Closed
-