MDL-15819 - Review the RISK_XXX flags on all quiz and question capabilites.
This commit is contained in:
+5
-7
@@ -1,4 +1,4 @@
|
||||
<?php
|
||||
<?php // $Id$
|
||||
//
|
||||
// Capability definitions for Moodle core.
|
||||
//
|
||||
@@ -832,7 +832,7 @@ $moodle_capabilities = array(
|
||||
),
|
||||
|
||||
'moodle/question:managecategory' => array(
|
||||
|
||||
'riskbitmask' => RISK_SPAM | RISK_XSS,
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_COURSE,
|
||||
'legacy' => array(
|
||||
@@ -843,7 +843,7 @@ $moodle_capabilities = array(
|
||||
|
||||
//new in moodle 1.9
|
||||
'moodle/question:add' => array(
|
||||
'riskbitmask' => RISK_SPAM,
|
||||
'riskbitmask' => RISK_SPAM | RISK_XSS,
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_COURSE,
|
||||
'legacy' => array(
|
||||
@@ -853,7 +853,7 @@ $moodle_capabilities = array(
|
||||
'clonepermissionsfrom' => 'moodle/question:manage'
|
||||
),
|
||||
'moodle/question:editmine' => array(
|
||||
'riskbitmask' => RISK_SPAM,
|
||||
'riskbitmask' => RISK_SPAM | RISK_XSS,
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_COURSE,
|
||||
'legacy' => array(
|
||||
@@ -863,7 +863,7 @@ $moodle_capabilities = array(
|
||||
'clonepermissionsfrom' => 'moodle/question:manage'
|
||||
),
|
||||
'moodle/question:editall' => array(
|
||||
'riskbitmask' => RISK_SPAM,
|
||||
'riskbitmask' => RISK_SPAM | RISK_XSS,
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_COURSE,
|
||||
'legacy' => array(
|
||||
@@ -930,9 +930,7 @@ $moodle_capabilities = array(
|
||||
|
||||
// Configure the installed question types.
|
||||
'moodle/question:config' => array(
|
||||
|
||||
'riskbitmask' => RISK_CONFIG,
|
||||
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_SYSTEM,
|
||||
'legacy' => array(
|
||||
|
||||
+7
-12
@@ -1,4 +1,4 @@
|
||||
<?php // $Id$
|
||||
<?php // $Id$
|
||||
/**
|
||||
* Capability definitions for the quiz module.
|
||||
*
|
||||
@@ -9,7 +9,6 @@ $mod_quiz_capabilities = array(
|
||||
// Ability to see that the quiz exists, and the basic information
|
||||
// about it, for example the start date and time limit.
|
||||
'mod/quiz:view' => array(
|
||||
|
||||
'captype' => 'read',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array(
|
||||
@@ -23,7 +22,6 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// Ability to do the quiz as a 'student'.
|
||||
'mod/quiz:attempt' => array(
|
||||
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array(
|
||||
@@ -33,7 +31,7 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// Edit the quiz settings, add and remove questions.
|
||||
'mod/quiz:manage' => array(
|
||||
|
||||
'riskbitmask' => RISK_SPAM,
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array(
|
||||
@@ -44,7 +42,6 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// Preview the quiz.
|
||||
'mod/quiz:preview' => array(
|
||||
|
||||
'captype' => 'write', // Only just a write.
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array(
|
||||
@@ -56,7 +53,7 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// Manually grade and comment on student attempts at a question, and regrade quizzes.
|
||||
'mod/quiz:grade' => array(
|
||||
|
||||
'riskbitmask' => RISK_SPAM | RISK_XSS,
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array(
|
||||
@@ -68,7 +65,7 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// View the quiz reports.
|
||||
'mod/quiz:viewreports' => array(
|
||||
|
||||
'riskbitmask' => RISK_PERSONAL,
|
||||
'captype' => 'read',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array(
|
||||
@@ -80,7 +77,7 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// Delete attempts using the overview report.
|
||||
'mod/quiz:deleteattempts' => array(
|
||||
|
||||
'riskbitmask' => RISK_DATALOSS,
|
||||
'captype' => 'write',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array(
|
||||
@@ -88,7 +85,8 @@ $mod_quiz_capabilities = array(
|
||||
'admin' => CAP_ALLOW
|
||||
)
|
||||
),
|
||||
|
||||
|
||||
// Do not have the time limit imposed. Used for accessibility legislation compliance.
|
||||
'mod/quiz:ignoretimelimits' => array(
|
||||
'captype' => 'read',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
@@ -97,7 +95,6 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// Receive email confirmation of own quiz submission
|
||||
'mod/quiz:emailconfirmsubmission' => array(
|
||||
|
||||
'captype' => 'read',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array()
|
||||
@@ -105,11 +102,9 @@ $mod_quiz_capabilities = array(
|
||||
|
||||
// Receive email notification of other peoples quiz submissions
|
||||
'mod/quiz:emailnotifysubmission' => array(
|
||||
|
||||
'captype' => 'read',
|
||||
'contextlevel' => CONTEXT_MODULE,
|
||||
'legacy' => array()
|
||||
)
|
||||
);
|
||||
|
||||
?>
|
||||
|
||||
Reference in New Issue
Block a user