From 6a981b45c354a08cddbbbbc803c0aed87d657a9e Mon Sep 17 00:00:00 2001 From: Tim Hunt Date: Fri, 28 Mar 2014 18:37:21 +0000 Subject: [PATCH] MDL-31262 fix quiz review capability check. This change is logically the same as changing $this->has_capability('mod/quiz:viewreports') to $this->has_capability('mod/quiz:viewreports') || $this->has_capability('mod/quiz:preview') in the original code. However, I rewrote the logic so that we test the most common and performance-critical case first - that of a student lookign at their own attempt. --- mod/quiz/attemptlib.php | 30 ++++++++++++++++++++++++------ 1 file changed, 24 insertions(+), 6 deletions(-) diff --git a/mod/quiz/attemptlib.php b/mod/quiz/attemptlib.php index 3e7cfeefaf9..237ce19484d 100644 --- a/mod/quiz/attemptlib.php +++ b/mod/quiz/attemptlib.php @@ -789,13 +789,31 @@ class quiz_attempt { * If not, prints an error. */ public function check_review_capability() { - if (!$this->has_capability('mod/quiz:viewreports')) { - if ($this->get_attempt_state() == mod_quiz_display_options::IMMEDIATELY_AFTER) { - $this->require_capability('mod/quiz:attempt'); - } else { - $this->require_capability('mod/quiz:reviewmyattempts'); - } + if ($this->get_attempt_state() == mod_quiz_display_options::IMMEDIATELY_AFTER) { + $capability = 'mod/quiz:attempt'; + } else { + $capability = 'mod/quiz:reviewmyattempts'; } + + // These next tests are in a slighly funny order. The point is that the + // common and most performance-critical case is students attempting a quiz + // so we want to check that permisison first. + + if ($this->has_capability($capability)) { + // User has the permission that lets you do the quiz as a student. Fine. + return; + } + + if ($this->has_capability('mod/quiz:viewreports') || + $this->has_capability('mod/quiz:preview')) { + // User has the permission that lets teachers review. Fine. + return; + } + + // They should not be here. Trigger the standard no-permission error + // but using the name of the student capability. + // We know this will fail. We just want the stadard exception thown. + $this->require_capability($capability); } /**