From 179bfdf5c50531fcf95e71a19bf9d676f4adf00e Mon Sep 17 00:00:00 2001 From: Juan Leyva Date: Thu, 4 Apr 2024 11:16:21 +0200 Subject: [PATCH] MDL-81405 tool_mobile: Set Partitioned cookie when required --- admin/tool/mobile/classes/event_handler.php | 45 +++++++++++++++++++++ admin/tool/mobile/db/events.php | 33 +++++++++++++++ admin/tool/mobile/lib.php | 13 ++++++ admin/tool/mobile/version.php | 2 +- lib/tests/component_test.php | 2 +- 5 files changed, 93 insertions(+), 2 deletions(-) create mode 100644 admin/tool/mobile/classes/event_handler.php create mode 100644 admin/tool/mobile/db/events.php diff --git a/admin/tool/mobile/classes/event_handler.php b/admin/tool/mobile/classes/event_handler.php new file mode 100644 index 00000000000..5b9bd3476e4 --- /dev/null +++ b/admin/tool/mobile/classes/event_handler.php @@ -0,0 +1,45 @@ +. + +namespace tool_mobile; + +use core\session\utility\cookie_helper; +use core\event\user_loggedin; + +/** + * Event handler for tool_mobile. + * + * @package tool_mobile + * @copyright 2024 Juan Leyva + * @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later + */ +class event_handler { + + /** + * Allows the plugin to augment Set-Cookie headers when the user_loggedin event is fired as part of complete_user_login() calls. + * + * @param user_loggedin $event the event + * @return void + */ + public static function handle_user_loggedin(user_loggedin $event): void { + global $CFG; + + // Set Partitioned and Secure attributes to the MoodleSession cookie if the user is using the Moodle app. + if (\core_useragent::is_moodle_app()) { + cookie_helper::add_attributes_to_cookie_response_header('MoodleSession'.$CFG->sessioncookie, ['Secure', 'Partitioned']); + } + } +} diff --git a/admin/tool/mobile/db/events.php b/admin/tool/mobile/db/events.php new file mode 100644 index 00000000000..f0d2ab02c1e --- /dev/null +++ b/admin/tool/mobile/db/events.php @@ -0,0 +1,33 @@ +. + +/** + * tool_mobile plugin event handler definition. + * + * @package tool_mobile + * @category event + * @copyright 2024 Juan Leyva + * @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later + */ + +defined('MOODLE_INTERNAL') || die(); + +$observers = [ + [ + 'eventname' => '\core\event\user_loggedin', + 'callback' => '\tool_mobile\event_handler::handle_user_loggedin', + ], +]; diff --git a/admin/tool/mobile/lib.php b/admin/tool/mobile/lib.php index 3014c9dbc27..9f7a67e1ff0 100644 --- a/admin/tool/mobile/lib.php +++ b/admin/tool/mobile/lib.php @@ -265,3 +265,16 @@ function tool_mobile_pre_processor_message_send($procname, $data) { $data->fullmessagehtml .= html_writer::tag('p', get_string('readingthisemailgettheapp', 'tool_mobile', $url->out())); } } + +/** + * Callback to add headers before the HTTP headers are sent. + * + */ +function tool_mobile_before_http_headers() { + global $CFG; + + // Set Partitioned and Secure attributes to the MoodleSession cookie if the user is using the Moodle app. + if (\core_useragent::is_moodle_app()) { + \core\session\utility\cookie_helper::add_attributes_to_cookie_response_header('MoodleSession'.$CFG->sessioncookie, ['Secure', 'Partitioned']); + } +} diff --git a/admin/tool/mobile/version.php b/admin/tool/mobile/version.php index f950b8677ac..d77b4f048a9 100644 --- a/admin/tool/mobile/version.php +++ b/admin/tool/mobile/version.php @@ -23,7 +23,7 @@ */ defined('MOODLE_INTERNAL') || die(); -$plugin->version = 2022112800; // The current plugin version (Date: YYYYMMDDXX). +$plugin->version = 2022112801; // The current plugin version (Date: YYYYMMDDXX). $plugin->requires = 2022111800; // Requires this Moodle version. $plugin->component = 'tool_mobile'; // Full name of the plugin (used for diagnostics). $plugin->dependencies = array( diff --git a/lib/tests/component_test.php b/lib/tests/component_test.php index ad9ae0b8139..46d396158ce 100644 --- a/lib/tests/component_test.php +++ b/lib/tests/component_test.php @@ -523,7 +523,7 @@ class component_test extends advanced_testcase { $this->assertCount(5, core_component::get_component_classes_in_namespace('core_user', 'output\\myprofile')); // Without namespace it returns classes/ classes. - $this->assertCount(5, core_component::get_component_classes_in_namespace('tool_mobile', '')); + $this->assertCount(6, core_component::get_component_classes_in_namespace('tool_mobile', '')); $this->assertCount(2, core_component::get_component_classes_in_namespace('tool_filetypes')); // When no component is specified, classes are returned for the namespace in all components.