Merge branch 'MOODLE_24_STABLE' into install_24_STABLE

This commit is contained in:
AMOS bot
2014-05-09 00:41:12 +00:00
6 changed files with 30 additions and 6 deletions
+5 -2
View File
@@ -33,7 +33,7 @@
* @todo MDL-36050 improve capability check on stick blocks, so we can check user capability before sending images.
*/
function block_html_pluginfile($course, $birecord_or_cm, $context, $filearea, $args, $forcedownload, array $options=array()) {
global $DB, $CFG;
global $DB, $CFG, $USER;
if ($context->contextlevel != CONTEXT_BLOCK) {
send_file_not_found();
@@ -53,8 +53,11 @@ function block_html_pluginfile($course, $birecord_or_cm, $context, $filearea, $a
if (!$category->visible) {
require_capability('moodle/category:viewhiddencategories', $parentcontext);
}
} else if ($parentcontext->contextlevel === CONTEXT_USER && $parentcontext->instanceid != $USER->id) {
// The block is in the context of a user, it is only visible to the user who it belongs to.
send_file_not_found();
}
// At this point there is no way to check SYSTEM or USER context, so ignoring it.
// At this point there is no way to check SYSTEM context, so ignoring it.
}
if ($filearea !== 'content') {
+4
View File
@@ -43,6 +43,10 @@ if ($course->id == SITEID) {
redirect("$CFG->wwwroot/");
}
if (!$course->visible && !has_capability('moodle/course:viewhiddencourses', context_course::instance($course->id))) {
print_error('coursehidden');
}
$PAGE->set_course($course);
$PAGE->set_pagelayout('course');
$PAGE->set_url('/enrol/index.php', array('id'=>$course->id));
+2
View File
@@ -160,6 +160,8 @@ if (!empty($user)) {
$token->creatorid = $user->id;
$token->timecreated = time();
$token->externalserviceid = $service_record->id;
// MDL-43119 Token valid for 3 months (12 weeks).
$token->validuntil = $token->timecreated + 12 * WEEKSECS;
$tokenid = $DB->insert_record('external_tokens', $token);
add_to_log(SITEID, 'webservice', 'automatically create user token', '' , 'User ID: ' . $user->id);
$token->id = $tokenid;
+15 -3
View File
@@ -560,9 +560,21 @@ class assign_grading_table extends table_sql implements renderable {
* @return string
*/
function col_select(stdClass $row) {
return '<label class="accesshide" for="selectuser_' . $row->userid . '">' .
get_string('selectuser', 'assign', fullname($row)) . '</label>
<input type="checkbox" id="selectuser_' . $row->userid . '" name="selectedusers" value="' . $row->userid . '"/>';
$selectcol = '<label class="accesshide" for="selectuser_' . $row->userid . '">';
$name = '';
if ($this->assignment->is_blind_marking()) {
$name = get_string('hiddenuser', 'assign') .
$this->assignment->get_uniqueid_for_user($row->userid);
} else {
$name = fullname($row);
}
$selectcol .= get_string('selectuser', 'assign', $name);
$selectcol .= '</label>';
$selectcol .= '<input type="checkbox"
id="selectuser_' . $row->userid . '"
name="selectedusers"
value="' . $row->userid . '"/>';
return $selectcol;
}
/**
+3
View File
@@ -3728,6 +3728,7 @@ class assign {
// Include extension form.
require_once($CFG->dirroot . '/mod/assign/extensionform.php');
require_sesskey();
// Need submit permission to submit an assignment.
require_capability('mod/assign:grantextension', $this->context);
@@ -3774,6 +3775,7 @@ class assign {
// Need grade permission
require_capability('mod/assign:grade', $this->context);
require_sesskey();
// make sure advanced grading is disabled
$gradingmanager = get_grading_manager($this->get_context(), 'mod_assign', 'submissions');
@@ -3977,6 +3979,7 @@ class assign {
// Need submit permission to submit an assignment
require_capability('mod/assign:grade', $this->context);
require_sesskey();
$mform = new mod_assign_grading_options_form(null, array('cm'=>$this->get_course_module()->id,
'contextid'=>$this->context->id,
+1 -1
View File
@@ -46,7 +46,7 @@ class repository_url extends repository {
public function __construct($repositoryid, $context = SYSCONTEXTID, $options = array()){
global $CFG;
parent::__construct($repositoryid, $context, $options);
$this->file_url = optional_param('file', '', PARAM_RAW);
$this->file_url = optional_param('file', '', PARAM_URL);
}
public function check_login() {