MDL-63786 core: set $CFG->forceclean for logged in as sessions
Turn on the forceclean config setting when a user is logged in as a different user. This is a precautionary measure, which forces all user submitted content to be cleaned of JavaScript before rendering it to the logged in as user.
This commit is contained in:
@@ -2757,6 +2757,13 @@ function require_login($courseorid = null, $autologinguest = true, $cm = null, $
|
||||
// Make sure the USER has a sesskey set up. Used for CSRF protection.
|
||||
sesskey();
|
||||
|
||||
if (\core\session\manager::is_loggedinas()) {
|
||||
// During a "logged in as" session we should force all content to be cleaned because the
|
||||
// logged in user will be viewing potentially malicious user generated content.
|
||||
// See MDL-63786 for more details.
|
||||
$CFG->forceclean = true;
|
||||
}
|
||||
|
||||
// Do not bother admins with any formalities, except for activities pending deletion.
|
||||
if (is_siteadmin() && !($cm && $cm->deletioninprogress)) {
|
||||
// Set the global $COURSE.
|
||||
|
||||
Reference in New Issue
Block a user