MDL-85754 question: Don't show banks where user has no permission

The Switch Banks UI was listing all question banks on the course where
the use had the managecategory permission, plus the other banks they had
used recently.

This conflicted with the check when it tried to load a selected bank,
which checked the useall/usemine permissions. This could lead to errors
if this permission had been removed.

This applies consistent checks to both lists with the useall/usermine
permissions instead.
This commit is contained in:
Mark Johnson
2025-07-08 11:52:25 +01:00
parent 45e3284a3d
commit 55e184caf5
3 changed files with 18 additions and 2 deletions
@@ -339,6 +339,7 @@ class question_bank_helper {
int $userid,
int $notincourseid = 0,
?context $filtercontext = null,
array $havingcap = [],
): array {
$prefs = get_user_preferences(self::RECENTLY_VIEWED, null, $userid);
$contextids = !empty($prefs) ? explode(',', $prefs) : [];
@@ -360,6 +361,9 @@ class question_bank_helper {
if (!empty($notincourseid) && $notincourseid == $cm->course) {
continue;
}
if (!empty($havingcap) && !(new question_edit_contexts($context))->have_one_cap($havingcap)) {
continue;
}
$record = self::get_formatted_bank($cm, filtercontext: $filtercontext);
$banks[] = $record;
}
@@ -62,12 +62,13 @@ class switch_question_bank implements \renderable, \templatable {
[, $cm] = get_module_from_cmid($this->quizcmid);
$cminfo = cm_info::create($cm);
$capabilities = ['moodle/question:useall', 'moodle/question:usemine'];
$coursesharedbanks = question_bank_helper::get_activity_instances_with_shareable_questions(
incourseids: [$this->courseid],
havingcap: ['moodle/question:managecategory'],
havingcap: $capabilities,
filtercontext: $cminfo->context,
);
$recentlyviewedbanks = question_bank_helper::get_recently_used_open_banks($this->userid);
$recentlyviewedbanks = question_bank_helper::get_recently_used_open_banks($this->userid, havingcap: $capabilities);
return [
'quizname' => $cminfo->get_formatted_name(),
@@ -293,6 +293,7 @@ final class question_bank_helper_test extends \advanced_testcase {
$user = self::getDataGenerator()->create_user();
$course1 = self::getDataGenerator()->create_course();
$course2 = self::getDataGenerator()->create_course();
self::getDataGenerator()->enrol_user($user->id, $course1->id, 'editingteacher');
$banks = [];
$banks[] = self::getDataGenerator()->create_module('qbank', ['course' => $course1->id]);
$banks[] = self::getDataGenerator()->create_module('qbank', ['course' => $course1->id]);
@@ -314,6 +315,16 @@ final class question_bank_helper_test extends \advanced_testcase {
// Check that the courseid filter works.
$recentlyviewed = question_bank_helper::get_recently_used_open_banks($user->id, $course1->id);
$this->assertCount(3, $recentlyviewed);
// We should have the viewed banks in course 2.
$courseviewed = array_slice($banks, 3, 3);
$this->assertEqualsCanonicalizing(array_column($recentlyviewed, 'modid'), array_column($courseviewed, 'cmid'));
// Check that the capability filter works.
$recentlyviewed = question_bank_helper::get_recently_used_open_banks($user->id, havingcap: ['moodle/question:useall']);
$this->assertCount(2, $recentlyviewed);
// We should have the 2 most recently viewed banks in course 1.
$capabilityviewed = array_slice($banks, 1, 2);
$this->assertEqualsCanonicalizing(array_column($recentlyviewed, 'modid'), array_column($capabilityviewed, 'cmid'));
$recentlyviewed = question_bank_helper::get_recently_used_open_banks($user->id);