Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-85341

GET requests expose sesskey in course module "edit settings" and "more" controls

XMLWordPrintable

      Found when looking at MDL-85333.

      To replicate:

      1. Go to course home and make sure editing is enabled
      2. Click the vertical ellipsis menu for a course module
      3. Mouse over the "edit settings" link
        Expected: sesskey isn't present in the link to mod.php
        Actual: sesskey IS present in the link

      As in other issues of this nature, we should remove sesskey from GET requests and only include it when we're POSTing to make a change.

      Looking quickly at the path through mod.php in this case, it doesn't appear to do anything with sesskey anyway (nor should it really).

        1. (1) 10 Passed -- (Main)MDL-85341.png
          73 kB
          Kim Jared Lucas
        2. (1) 11 Passed -- (Main)MDL-85341.png
          127 kB
          Kim Jared Lucas
        3. (1) 5 Passed -- (Main)MDL-85341.png
          140 kB
          Kim Jared Lucas
        4. (1) 6 Passed -- (Main)MDL-85341.png
          130 kB
          Kim Jared Lucas
        5. (1) 9 Passed -- (Main)MDL-85341.png
          136 kB
          Kim Jared Lucas

            jaked Jake Dallimore
            jaked Jake Dallimore
            Paul Holden Paul Holden
            Huong Nguyen Huong Nguyen
            Kim Jared Lucas Kim Jared Lucas
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 hour, 55 minutes
                1h 55m

                  Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.