MDL-79239 mod_bigbluebuttonbn: Server cred warning

* Added warning messages about credentials
* Activity still accessible when using test-moodle/test-install
This commit is contained in:
Shamiso.Jaravaza
2024-03-20 08:51:30 -06:00
parent 4a1544cfdc
commit b88cf030a3
16 changed files with 126 additions and 47 deletions
+23 -2
View File
@@ -65,8 +65,8 @@ class config {
*/
protected static function defaultvalues(): array {
return [
'server_url' => self::DEFAULT_SERVER_URL,
'shared_secret' => self::DEFAULT_SHARED_SECRET,
'server_url' => '',
'shared_secret' => '',
'voicebridge_editable' => false,
'importrecordings_enabled' => false,
'importrecordings_from_deleted_enabled' => false,
@@ -175,6 +175,27 @@ class config {
return (boolean) self::get('importrecordings_enabled');
}
/**
* Check if bbb server credentials are invalid.
*
* @return bool
*/
public static function server_credentials_invalid(): bool {
// Test server credentials across all versions of the plugin are flagged.
$parsedurl = parse_url(self::get('server_url'));
$defaultserverurl = parse_url(self::DEFAULT_SERVER_URL);
if (!isset($parsedurl['host'])) {
return false;
}
if (strpos($parsedurl['host'], $defaultserverurl['host']) === 0) {
return true;
}
if (strpos($parsedurl['host'], 'test-install.blindsidenetworks.com') === 0) {
return true;
}
return false;
}
/**
* Wraps current settings in an array.
*
@@ -66,14 +66,6 @@ class view_page implements renderable, templatable {
'joinurl' => $this->instance->get_join_url(),
];
if ($this->show_default_server_warning()) {
$templatedata->serverwarning = (new notification(
get_string('view_warning_default_server', 'mod_bigbluebuttonbn'),
notification::NOTIFY_WARNING,
false
))->export_for_template($output);
}
$viewwarningmessage = config::get('general_warning_message');
if ($this->show_view_warning() && !empty($viewwarningmessage)) {
$templatedata->sitenotification = (object) [
@@ -127,23 +119,6 @@ class view_page implements renderable, templatable {
return $templatedata;
}
/**
* Whether to show the default server warning.
*
* @return bool
*/
protected function show_default_server_warning(): bool {
if (!$this->instance->is_admin()) {
return false;
}
if (config::DEFAULT_SERVER_URL != config::get('server_url')) {
return false;
}
return true;
}
/**
* Whether to show the view warning.
*
+12 -3
View File
@@ -152,7 +152,7 @@ class settings {
* @throws \coding_exception
*/
protected function add_general_settings(): admin_settingpage {
global $CFG;
global $CFG, $OUTPUT;
$settingsgeneral = new admin_settingpage(
$this->section,
get_string('config_general', 'bigbluebuttonbn'),
@@ -167,11 +167,20 @@ class settings {
);
$settingsgeneral->add($item);
if (config::server_credentials_invalid()) {
// A notification should appear when default credentials are used.
$settingsgeneral->add(new admin_setting_heading(
'bigbluebuttonbn_notification',
'',
$OUTPUT->notification(get_string('credentials_warning', 'mod_bigbluebuttonbn'), 'error')
));
}
$item = new admin_setting_configtext(
'bigbluebuttonbn_server_url',
get_string('config_server_url', 'bigbluebuttonbn'),
get_string('config_server_url_description', 'bigbluebuttonbn'),
config::DEFAULT_SERVER_URL,
'',
PARAM_RAW
);
$item->set_updatedcallback(
@@ -190,7 +199,7 @@ class settings {
'bigbluebuttonbn_shared_secret',
get_string('config_shared_secret', 'bigbluebuttonbn'),
get_string('config_shared_secret_description', 'bigbluebuttonbn'),
config::DEFAULT_SHARED_SECRET
''
);
$this->add_conditional_element(
'shared_secret',
@@ -26,6 +26,7 @@ namespace mod_bigbluebuttonbn\test;
use context_module;
use mod_bigbluebuttonbn\instance;
use mod_bigbluebuttonbn\local\config;
use mod_bigbluebuttonbn\local\proxy\recording_proxy;
use mod_bigbluebuttonbn\meeting;
use stdClass;
@@ -158,6 +159,8 @@ trait testcase_helper_trait {
}
try {
$this->getDataGenerator()->get_plugin_generator('mod_bigbluebuttonbn')->reset_mock();
// Mock server expects a value. By default this field is empty.
set_config('bigbluebuttonbn_shared_secret', config::DEFAULT_SHARED_SECRET);
} catch (\moodle_exception $e) {
$this->markTestSkipped(
'Cannot connect to the mock server for this test. Make sure that TEST_MOD_BIGBLUEBUTTONBN_MOCK_SERVER points
+16 -17
View File
@@ -26,6 +26,7 @@
defined('MOODLE_INTERNAL') || die();
$string['activityoverview'] = 'You have upcoming BigBlueButton sessions';
$string['credentials_warning'] = 'The use of default server credentials will soon expire (see note above to obtain new credentials).';
$string['bbbduetimeoverstartingtime'] = 'The close time must be later than the open time.';
$string['bbbdurationwarning'] = 'The maximum duration for this session is %duration% minutes.';
$string['bbbrecordwarning'] = 'This session may be recorded.';
@@ -73,6 +74,10 @@ $string['resetrecordings_help'] = 'Deleting the recordings will make them inacce
$string['search:activity'] = 'BigBlueButton - activity information';
$string['search:tags'] = 'BigBlueButton - tags information';
$string['settings'] = 'BigBlueButton settings';
$string['settings_credential_warning_no_capability'] = 'The use of default server credentials will soon expire. To use BigBlueButton your site will require new server credentials. Please contact your site administrator for help with this.';
$string['settings_credential_warning'] = 'Default BigBlueButton plugin credentials will soon expire. See BigBlueButton<a href="{$a->settingslink}" target="_blank"> plugin settings (opens in a new window)</a> for more information.';
$string['privacy:metadata:bigbluebuttonbn'] = 'BigBlueButton session configuration';
$string['privacy:metadata:bigbluebuttonbn:participants'] = 'A list of rules that define the role users will have in the BigBlueButton session. A user ID may be stored as permissions can be granted per role or per user.';
$string['privacy:metadata:bigbluebuttonbn_logs'] = 'Stores events triggered when using the plugin.';
@@ -126,19 +131,13 @@ $string['config_guestaccess_enabled'] = 'External guest access';
$string['config_guestaccess_enabled_description'] = 'Allow users without an account on your site to access the room.';
$string['config_general'] = 'General settings';
$string['config_general_description'] = 'These settings are always used.';
$string['config_general_description'] = 'To set up BigBlueButton, you can either use your own BigBlueButton server and credentials, or obtain credentials through the <a href="https://registration-portal.blindsidenetworks.com/" target="_blank">Blindside Networks Registration Portal (opens in a new window)</a>.';
$string['config_profile_picture_enabled'] = 'Show profile pictures';
$string['config_profile_picture_enabled_description'] = 'Should profile pictures of participants be shown in BigBlueButton sessions?';
$string['config_server_url'] = 'BigBlueButton server URL';
$string['config_server_url_description'] = 'The default credentials are for a <a href="https://bigbluebutton.org/free-bigbluebutton-service-for-moodle/" target="_blank">free BigBlueButton service for Moodle (opens in new window)</a> provided by Blindside Networks with restrictions as follows:
<ol>
<li>The maximum length for each session is 60 minutes</li>
<li>The maximum number of concurrent users per session is 25</li>
<li>Recordings expire after seven (7) days and are not downloadable</li>
<li>Student webcams are only visible to the moderator.</li>
</ol>';
$string['config_server_url_description'] = 'The server URL of your BigBlueButton server ';
$string['config_shared_secret'] = 'BigBlueButton shared secret';
$string['config_shared_secret_description'] = 'The security secret of your BigBlueButton server. The default secret is for a free BigBlueButton service provided by Blindside Networks.';
$string['config_shared_secret_description'] = 'The security secret of your BigBlueButton server.';
$string['config_checksum_algorithm'] = 'BigBlueButton server checksum algorithm';
$string['config_checksum_algorithm_description'] = 'SHA1 is compatible with older servers. SHA256 and SHA512 are more secure. SHA512 is FIPS 140-2 compliant.';
@@ -622,13 +621,6 @@ $string['notification_recording_ready_subject'] = 'Recording available';
$string['view_error_meeting_not_running'] = 'Something went wrong; the session is not running.';
$string['view_error_current_state_not_found'] = 'Current state was not found. The recording may have been deleted or the BigBlueButton server is not compatible with the action performed.';
$string['view_error_action_not_completed'] = 'Action could not be completed';
$string['view_warning_default_server'] = 'This site is using a <a href="https://bigbluebutton.org/free-bigbluebutton-service-for-moodle/" target="_blank">free BigBlueButton service for Moodle (opens in new window)</a> provided by Blindside Networks with restrictions as follows:
<ol>
<li>The maximum length for each session is 60 minutes</li>
<li>The maximum number of concurrent users per session is 25</li>
<li>Recordings expire after seven (7) days and are not downloadable</li>
<li>Student webcams are only visible to the moderator.</li>
</ol>';
$string['view_room'] = 'View room';
$string['index_error_noinstances'] = 'There are no instances of BigBlueButton rooms';
@@ -660,7 +652,7 @@ $string['completionview'] = 'Require view';
$string['completionview_desc'] = 'View the room';
$string['completionattendancegroup_help'] = 'Attending the meeting for (n) minutes is required for completion.';
$string['completionengagementgroup_help'] = 'Active participation during the session is required for completion.';
// Deprecated since Moodle 4.4
// Deprecated since Moodle 4.4.
$string['acceptdpa'] = 'I understand and accept the data processing agreement';
$string['bigbluebuttondisablednotification_subject'] = 'BigBlueButton activity module disabled.';
$string['bigbluebuttondisablednotification'] = 'The BigBlueButton activity module has been disabled and any existing BigBlueButton course activities are currently not accessible. Prior to re-enabling this plugin, please ensure that you have read and accepted the <a href="{$a}" target="_blank">data processing agreement</a> with Blindside Networks Inc.';
@@ -668,3 +660,10 @@ $string['enablingbigbluebutton'] = 'Enabling BigBlueButton activity';
$string['enablingbigbluebuttondpainfo'] = 'In order to meet your data protection obligations, prior to enabling this plugin, you may need to ensure that you have read and accepted the <a href="{$a}" target="_blank">Blindside Networks data processing agreement</a>. Please consult with your own privacy professionals for advice.';
$string['dpainfonotsigned'] = 'Before enabling this plugin, you must confirm that you have read and accepted the <a href="{$a}">Blindside Networks data processing agreement</a>.';
$string['config_dpa_note'] = 'Note: In order to meet your data protection obligations, before using a service provider for this plugin, you must ensure that you have read and accepted the service provider\'s data processing agreement. For the default free BigBlueButton service, this is the <a href="{$a}" target="_blank">Blindside Networks data processing agreement</a>. Please consult with your own privacy professionals for advice.';
$string['view_warning_default_server'] = 'This site is using a <a href="https://bigbluebutton.org/free-bigbluebutton-service-for-moodle/" target="_blank">free BigBlueButton service for Moodle (opens in new window)</a> provided by Blindside Networks with restrictions as follows:
<ol>
<li>The maximum length for each session is 60 minutes</li>
<li>The maximum number of concurrent users per session is 25</li>
<li>Recordings expire after seven (7) days and are not downloadable</li>
<li>Student webcams are only visible to the moderator.</li>
</ol>';
@@ -9,3 +9,4 @@ enablingbigbluebutton,mod_bigbluebuttonbn
enablingbigbluebuttondpainfo,mod_bigbluebuttonbn
dpainfonotsigned,mod_bigbluebuttonbn
config_dpa_note,mod_bigbluebuttonbn
view_warning_default_server,mod_bigbluebuttonbn
@@ -0,0 +1,48 @@
@mod @mod_bigbluebuttonbn @javascript
Feature: I can create a bigbluebuttonbn instance with default server
In case the BigBlueButton server has not been configured
As a user
I want to see a notification message
Background: Make sure that a course is created
Given I enable "bigbluebuttonbn" "mod" plugin
And the following "courses" exist:
| fullname | shortname | category |
| Test course | Test course | 0 |
And the following "users" exist:
| username | firstname | lastname | email |
| user1 | User1G1 | 1 | user1@example.com |
| teacher1 | TeacherG1 | 1 | teacher1@example.com |
And the following "course enrolments" exist:
| user | course | role |
| user1 | Test course | student |
| teacher1 | Test course | editingteacher |
And the following "activities" exist:
| activity | course | name | type |
| bigbluebuttonbn | Test course | BBB Instance name | 0 |
| bigbluebuttonbn | Test course | BBB Instance name 2 | 1 |
| bigbluebuttonbn | Test course | BBB Instance name 3 | 2 |
And I am on the "Test course" "course" page logged in as "admin"
Scenario Outline: Add an activity using default server for the three types of instance types
When I change window size to "large"
And I add a bigbluebuttonbn activity to course "Test course" section "1"
And I select "<type>" from the "Instance type" singleselect
Then I should see "Restrict access"
Examples:
| type |
| Room with recordings |
| Room only |
| Recordings only |
Scenario Outline: Users should see a notification message when accessing activities if the default server is used
When I am on the "BBB Instance name" Activity page logged in as <user>
Then "Join session" "link" should exist
And I <messageexist> "<shouldseemessage>"
Examples:
| user | shouldseemessage | messageexist |
| user1 | The use of default server credentials will soon expire.| should not see |
| teacher1 | The use of default server credentials will soon expire.| should see |
| admin | Default BigBlueButton plugin credentials will soon expire.| should see |
@@ -28,6 +28,7 @@ require_once(__DIR__ . '/../../../../lib/behat/behat_base.php');
use Behat\Behat\Hook\Scope\BeforeScenarioScope;
use Behat\Gherkin\Node\TableNode;
use mod_bigbluebuttonbn\instance;
use mod_bigbluebuttonbn\local\config;
use mod_bigbluebuttonbn\test\subplugins_test_helper_trait;
use Moodle\BehatExtension\Exception\SkippedException;
require_once(__DIR__ . '../../../classes/test/subplugins_test_helper_trait.php');
@@ -57,6 +58,9 @@ class behat_mod_bigbluebuttonbn extends behat_base {
if (defined('TEST_MOD_BIGBLUEBUTTONBN_MOCK_SERVER')) {
$this->send_mock_request('backoffice/reset');
}
// Fields are empty by default which causes tests to fail.
set_config('bigbluebuttonbn_server_url', config::DEFAULT_SERVER_URL);
set_config('bigbluebuttonbn_shared_secret', config::DEFAULT_SHARED_SECRET);
}
/**
+1
View File
@@ -61,6 +61,7 @@ class can_join_test extends \externallib_advanced_testcase {
* Test execute API CALL with no instance
*/
public function test_execute_no_instance() {
$this->resetAfterTest();
$canjoin = $this->can_join(1234, 5678);
$this->assertIsArray($canjoin);
@@ -63,6 +63,7 @@ class completion_validate_test extends \externallib_advanced_testcase {
* Test execute API CALL with no instance
*/
public function test_execute_no_instance() {
$this->resetAfterTest();
$result = $this->completion_validate(1234);
$this->assertIsArray($result);
@@ -63,6 +63,7 @@ class end_meeting_test extends \externallib_advanced_testcase {
* Test execute API CALL with no instance
*/
public function test_execute_no_instance() {
$this->resetAfterTest();
$this->expectException(moodle_exception::class);
$endmeeting = $this->end_meeting(1234, 5678);
}
@@ -63,6 +63,7 @@ class get_bigbluebuttons_by_courses_test extends \externallib_advanced_testcase
* Test execute API CALL with no instance
*/
public function test_execute_no_instance() {
$this->resetAfterTest();
$bbbactivities = $this->get_bigbluebuttons_by_courses([1234, 5678]);
$this->assertIsArray($bbbactivities);
@@ -63,6 +63,7 @@ class get_join_url_test extends \externallib_advanced_testcase {
* Test execute API CALL with no instance
*/
public function test_execute_no_instance() {
$this->resetAfterTest();
$this->expectExceptionMessageMatches('/No such instance.*/');
$joinurl = $this->get_join_url(1234, 5678);
@@ -63,6 +63,7 @@ class get_recordings_test extends \externallib_advanced_testcase {
* Test execute API CALL with no instance
*/
public function test_execute_wrong_instance() {
$this->resetAfterTest();
$getrecordings = $this->get_recordings(1234);
$this->assertIsArray($getrecordings);
@@ -63,6 +63,7 @@ class view_bigbluebuttonbn_test extends \externallib_advanced_testcase {
* Test execute API CALL with no instance
*/
public function test_execute_no_instance() {
$this->resetAfterTest();
$bbbactivities = $this->view_bigbluebuttonbn(1234);
$this->assertIsArray($bbbactivities);
+12
View File
@@ -26,6 +26,7 @@
*/
use mod_bigbluebuttonbn\instance;
use mod_bigbluebuttonbn\local\config;
use mod_bigbluebuttonbn\local\exceptions\server_not_available_exception;
use mod_bigbluebuttonbn\local\proxy\bigbluebutton_proxy;
use mod_bigbluebuttonbn\logger;
@@ -87,6 +88,17 @@ try {
echo $OUTPUT->header();
// Valid credentials have not been setup, then we output a message to teachers and admin.
if (config::server_credentials_invalid()) {
if (has_capability('moodle/site:config', context_system::instance())) {
$settingslink = new moodle_url('/admin/settings.php', ['section' => 'modsettingbigbluebuttonbn']);
echo $OUTPUT->notification(get_string('settings_credential_warning', 'bigbluebuttonbn',
['settingslink' => $settingslink->out()]), 'notifywarning');
} else if (has_capability('moodle/course:manageactivities', context_course::instance($course->id))) {
echo $OUTPUT->notification(get_string('settings_credential_warning_no_capability', 'bigbluebuttonbn'), 'notifywarning');
}
}
// Validate if the user is in a role allowed to join.
if (!$instance->can_join() && $instance->get_type() != instance::TYPE_RECORDING_ONLY) {
if (isguestuser()) {