Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-61876

Fixes for $CFG->forceclean and move to experimental

    XMLWordPrintable

Details

    • MOODLE_35_STABLE
    • MOODLE_35_STABLE
    • wip-MDL-61876-master
    • Hide
      1. Install fresh copy of Moodle
      2. Make sure setting "forceclean" is set to no
      3. Create a quiz and add questions of types: "gapselect", "ddimageortext", "ddmarker" and "ddwtos" (click "Moodle docs for this page" in the bottom of the each "add question" page for instructions)
      4. Attempt quiz as a student, grade as a teacher, make sure all controls work as expected
      5. As a teacher add an instance of database module, add fields, set up template
      6. Add couple of records
      7. Search records, make sure search form works
      8. As a teacher add a folder resource with subfolders that is displayed on a course page
      9. Make sure it is displayed on the course page fine and you can expand/collapse subfolders
      10. Install a new install of Moodle 3.4
      11. Upgrade to 3.5
      12. Open Site administration and search for the forceclean option
        1. Confirm that it is not set
        2. Confirm that the setting is found under Experimental settings
      Show
      Install fresh copy of Moodle Make sure setting "forceclean" is set to no Create a quiz and add questions of types: "gapselect", "ddimageortext", "ddmarker" and "ddwtos" (click "Moodle docs for this page" in the bottom of the each "add question" page for instructions) Attempt quiz as a student, grade as a teacher, make sure all controls work as expected As a teacher add an instance of database module, add fields, set up template Add couple of records Search records, make sure search form works As a teacher add a folder resource with subfolders that is displayed on a course page Make sure it is displayed on the course page fine and you can expand/collapse subfolders Install a new install of Moodle 3.4 Upgrade to 3.5 Open Site administration and search for the forceclean option Confirm that it is not set Confirm that the setting is found under Experimental settings

    Description

      $CFG->forceclean was introduced in MDL-60940
      I suggest to set it by default to 1 for new installations which will greatly reduce confusions among users and multiple false reports of XSS vulnerabilities.

      Attachments

        1. screenshot-1.png
          screenshot-1.png
          228 kB
        2. screenshot-2.png
          screenshot-2.png
          25 kB
        3. screenshot-3.png
          screenshot-3.png
          58 kB
        4. screenshot-4.png
          screenshot-4.png
          114 kB

        Issue Links

          Activity

            People

              marina Marina Glancy
              marina Marina Glancy
              Mihail Geshoski Mihail Geshoski
              Andrew Lyons Andrew Lyons
              David Mudrák (@mudrd8mz) David Mudrák (@mudrd8mz)
              Andrew Lyons, Huong Nguyen, Jun Pataleta, Michael Hawkins, Shamim Rezaie, Simey Lameze
              Votes:
              2 Vote for this issue
              Watchers:
              12 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:
                17/May/18