Uploaded image for project: 'Plugins'
  1. Plugins
  2. CONTRIB-6919

Capabilities with possible XSS risk should declare the RISK_XSS mask

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 3.3
    • Fix Version/s: 3.3
    • Component/s: Module: Questionnaire
    • Labels:
      None

      Description

      See the pull request at https://github.com/remotelearner/moodle-mod_questionnaire/pull/27

      In the db/access.php capabilities that allow the user to insert javascript should have their risk mask declare RISK_XSS for complete documentation.

      Update these capability declarations to declare this:

      mod/questionnaire:editquestions
      mod/questionnaire:manage

        Attachments

          Activity

            People

            • Assignee:
              mchurch Mike Churchward
              Reporter:
              mchurch Mike Churchward
              Participants:
              Component watchers:
              Mike Churchward
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Fix Release Date:
                15/May/17