From aefaca7bd75a31dfab8f3d953f425282e43492d3 Mon Sep 17 00:00:00 2001 From: Sara Arjona Date: Mon, 13 Oct 2025 17:12:40 +0200 Subject: [PATCH] MDL-86011 feedback: Prevent admin answering unless enrolled as student --- mod/feedback/classes/completion.php | 2 +- mod/feedback/tests/behat/questions.feature | 9 +++++++++ mod/feedback/tests/lib_test.php | 6 ++++++ 3 files changed, 16 insertions(+), 1 deletion(-) diff --git a/mod/feedback/classes/completion.php b/mod/feedback/classes/completion.php index 860d822594f..ccc72ddc3d9 100644 --- a/mod/feedback/classes/completion.php +++ b/mod/feedback/classes/completion.php @@ -613,7 +613,7 @@ class mod_feedback_completion extends mod_feedback_structure { global $CFG, $USER; $context = context_module::instance($this->cm->id); - if (has_capability('mod/feedback:complete', $context, $this->userid)) { + if (has_capability('mod/feedback:complete', $context, $this->userid, false)) { return true; } diff --git a/mod/feedback/tests/behat/questions.feature b/mod/feedback/tests/behat/questions.feature index 86b64eabd86..52d932c6fd2 100644 --- a/mod/feedback/tests/behat/questions.feature +++ b/mod/feedback/tests/behat/questions.feature @@ -91,3 +91,12 @@ Feature: Managing feedback questions And I click on "After \"(q3) I can see it in your smile\"" "link" in the "Move this question" "dialogue" And I click on "Move this question" "button" in the "Is it me you're looking for?" "mod_feedback > Question" And I click on "To the top of the list" "link" in the "Move this question" "dialogue" + + Scenario: Admin cannot answer questions if not enrolled as student + When I am on the "Learning experience course 1" "feedback activity" page logged in as admin + Then I should not see "Answer the questions" + But the following "course enrolments" exist: + | user | course | role | + | admin | C1 | student | + And I am on the "Learning experience course 1" "feedback activity" page logged in as admin + And I should see "Answer the questions" diff --git a/mod/feedback/tests/lib_test.php b/mod/feedback/tests/lib_test.php index 24625409fb1..d8cc664a9a0 100644 --- a/mod/feedback/tests/lib_test.php +++ b/mod/feedback/tests/lib_test.php @@ -183,6 +183,8 @@ final class lib_test extends \advanced_testcase { $now = time(); $course = $this->getDataGenerator()->create_course(); + // Enrol admin as a student so they can complete the feedback. + $this->getDataGenerator()->enrol_user(get_admin()->id, $course->id, 'student'); $feedback = $this->getDataGenerator()->create_module('feedback', ['course' => $course->id, 'timeopen' => $now - DAYSECS, 'timeclose' => $now + DAYSECS]); $event = $this->create_action_event($course->id, $feedback->id, FEEDBACK_EVENT_TYPE_OPEN); @@ -294,6 +296,8 @@ final class lib_test extends \advanced_testcase { $this->setAdminUser(); $course = $this->getDataGenerator()->create_course(); + // Enrol admin as a student so they can complete the feedback. + $this->getDataGenerator()->enrol_user(get_admin()->id, $course->id, 'student'); $feedback = $this->getDataGenerator()->create_module('feedback', ['course' => $course->id, 'timeopen' => time() + DAYSECS]); $event = $this->create_action_event($course->id, $feedback->id, FEEDBACK_EVENT_TYPE_OPEN); @@ -356,6 +360,8 @@ final class lib_test extends \advanced_testcase { $this->setAdminUser(); $course = $this->getDataGenerator()->create_course(); + // Enrol admin as a student so they can complete the feedback. + $this->getDataGenerator()->enrol_user(get_admin()->id, $course->id, 'student'); $feedback = $this->getDataGenerator()->create_module('feedback', ['course' => $course->id]); $event = $this->create_action_event($course->id, $feedback->id, FEEDBACK_EVENT_TYPE_OPEN);