Uploaded image for project: 'Plugins'
  1. Plugins
  2. CONTRIB-6919

Capabilities with possible XSS risk should declare the RISK_XSS mask

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Minor Minor
    • 3.3
    • 3.3
    • Module: Questionnaire
    • None

      See the pull request at https://github.com/remotelearner/moodle-mod_questionnaire/pull/27

      In the db/access.php capabilities that allow the user to insert javascript should have their risk mask declare RISK_XSS for complete documentation.

      Update these capability declarations to declare this:

      mod/questionnaire:editquestions
      mod/questionnaire:manage

            mchurch Mike Churchward
            mchurch Mike Churchward
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.