MDL-82365 mod_lesson: stricter equality checks of activity password.
This commit is contained in:
committed by
Ilya Tregubov
parent
08e8db984c
commit
bb83d2d84f
@@ -2887,15 +2887,17 @@ class lesson extends lesson_base {
|
||||
|
||||
if ($this->properties->usepassword && empty($USER->lessonloggedin[$this->id])) {
|
||||
$correctpass = false;
|
||||
if (!empty($userpassword) &&
|
||||
(($this->properties->password == md5(trim($userpassword))) || ($this->properties->password == trim($userpassword)))) {
|
||||
|
||||
$userpassword = trim((string) $userpassword);
|
||||
if ($userpassword !== '' &&
|
||||
($this->properties->password === md5($userpassword) || $this->properties->password === $userpassword)) {
|
||||
// With or without md5 for backward compatibility (MDL-11090).
|
||||
$correctpass = true;
|
||||
$USER->lessonloggedin[$this->id] = true;
|
||||
} else if (isset($this->properties->extrapasswords)) {
|
||||
// Group overrides may have additional passwords.
|
||||
foreach ($this->properties->extrapasswords as $password) {
|
||||
if (strcmp($password, md5(trim($userpassword))) === 0 || strcmp($password, trim($userpassword)) === 0) {
|
||||
if ($password === md5($userpassword) || $password === $userpassword) {
|
||||
$correctpass = true;
|
||||
$USER->lessonloggedin[$this->id] = true;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user