Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-85341

GET requests expose sesskey in course module "edit settings" and "more" controls

XMLWordPrintable

      Found when looking at MDL-85333.

      To replicate:

      1. Go to course home and make sure editing is enabled
      2. Click the vertical ellipsis menu for a course module
      3. Mouse over the "edit settings" link
        Expected: sesskey isn't present in the link to mod.php
        Actual: sesskey IS present in the link

      As in other issues of this nature, we should remove sesskey from GET requests and only include it when we're POSTing to make a change.

      Looking quickly at the path through mod.php in this case, it doesn't appear to do anything with sesskey anyway (nor should it really).

            jaked Jake Dallimore
            jaked Jake Dallimore
            Paul Holden Paul Holden
            Huong Nguyen Huong Nguyen
            Kim Jared Lucas Kim Jared Lucas
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 hour, 55 minutes
                1h 55m

                  Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.