From 9306db49a4492b5172b60b0a143fc817fd22679c Mon Sep 17 00:00:00 2001 From: Ferran Recio Date: Mon, 4 May 2020 17:12:26 +0200 Subject: [PATCH] MDL-68430 filter_mathjaxloader: update default CDN to 2.7.8 --- filter/mathjaxloader/db/upgrade.php | 12 ++++++++++++ filter/mathjaxloader/readme_moodle.txt | 7 ++++++- filter/mathjaxloader/settings.php | 2 +- filter/mathjaxloader/version.php | 2 +- 4 files changed, 20 insertions(+), 3 deletions(-) diff --git a/filter/mathjaxloader/db/upgrade.php b/filter/mathjaxloader/db/upgrade.php index 3080092a6d8..b405d4adf9b 100644 --- a/filter/mathjaxloader/db/upgrade.php +++ b/filter/mathjaxloader/db/upgrade.php @@ -186,5 +186,17 @@ MathJax.Hub.Config({ // Automatically generated Moodle v3.5.0 release upgrade line. // Put any upgrade step following this. + if ($oldversion < 2018051401) { + // Update CDN url. + $originalurl = 'https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.2/MathJax.js'; + $newurl = 'https://cdn.jsdelivr.net/npm/mathjax@2.7.8/MathJax.js'; + $currenturl = get_config('filter_mathjaxloader', 'httpsurl'); + if ($currenturl == $originalurl) { + set_config('httpsurl', $newurl, 'filter_mathjaxloader'); + } + + upgrade_plugin_savepoint(true, 2018051401, 'filter', 'mathjaxloader'); + } + return true; } diff --git a/filter/mathjaxloader/readme_moodle.txt b/filter/mathjaxloader/readme_moodle.txt index 055a986e8b6..32a4fc00067 100644 --- a/filter/mathjaxloader/readme_moodle.txt +++ b/filter/mathjaxloader/readme_moodle.txt @@ -1,7 +1,7 @@ Description of MathJAX library integration in Moodle ==================================================== -* Default MathJax version: 2.7.2 +* Default MathJax version: 2.7.8 * License: Apache 2.0 * Source: https://www.mathjax.org/ @@ -18,3 +18,8 @@ Upgrading the default MathJax version 3. Check and eventually update the list of language mappings in filter.php. Also see the unit test for the language mappings. +Changes +------- + +* The MathJax 2.7.2 seems to have a possible security issue, the CDN default value have been +updated to point to the recommended 2.7.8 version. See MDL-68430 for details. diff --git a/filter/mathjaxloader/settings.php b/filter/mathjaxloader/settings.php index a911788d89b..06ceee8f102 100644 --- a/filter/mathjaxloader/settings.php +++ b/filter/mathjaxloader/settings.php @@ -33,7 +33,7 @@ if ($ADMIN->fulltree) { $item = new admin_setting_configtext('filter_mathjaxloader/httpsurl', new lang_string('httpsurl', 'filter_mathjaxloader'), new lang_string('httpsurl_help', 'filter_mathjaxloader'), - 'https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.2/MathJax.js', + 'https://cdn.jsdelivr.net/npm/mathjax@2.7.8/MathJax.js', PARAM_RAW); $settings->add($item); diff --git a/filter/mathjaxloader/version.php b/filter/mathjaxloader/version.php index ea8efe86090..b3c35c631a3 100644 --- a/filter/mathjaxloader/version.php +++ b/filter/mathjaxloader/version.php @@ -24,6 +24,6 @@ defined('MOODLE_INTERNAL') || die(); -$plugin->version = 2018051400; +$plugin->version = 2018051401; $plugin->requires = 2018050800; // Requires this Moodle version. $plugin->component= 'filter_mathjaxloader';