From 2fbf721f2782b7a97a436165f327c257dd0132cf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20S=CC=8Ckoda?= Date: Sun, 23 Jun 2013 12:22:31 +0200 Subject: [PATCH 1/2] MDL-40289 fix all badges capabilities 1/ contextlevel must be the lowest level where capability can be overriden 2/ coursecreator is for course creation only!!! 3/ do not mix user with other archetypes 4/ config risk is for admin actions only in standard install No upgrade cleanup, sorry, blame integrators... --- lib/db/access.php | 40 +++++++++++++++------------------------- 1 file changed, 15 insertions(+), 25 deletions(-) diff --git a/lib/db/access.php b/lib/db/access.php index c47725fcfb9..4514423392f 100644 --- a/lib/db/access.php +++ b/lib/db/access.php @@ -1892,19 +1892,17 @@ $capabilities = array( // View available badges without earning them. 'moodle/badges:viewbadges' => array( 'captype' => 'read', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( - 'manager' => CAP_ALLOW, 'user' => CAP_ALLOW, - 'student' => CAP_ALLOW ) ), // Manage badges on own private badges page. 'moodle/badges:manageownbadges' => array( - 'riskbitmap' => RISK_SPAM | RISK_PERSONAL, + 'riskbitmap' => RISK_SPAM, 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_USER, 'archetypes' => array( 'user' => CAP_ALLOW ) @@ -1923,69 +1921,62 @@ $capabilities = array( // Earn badge. 'moodle/badges:earnbadge' => array( 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'user' => CAP_ALLOW, - 'student' => CAP_ALLOW, ) ), // Create/duplicate badges. 'moodle/badges:createbadge' => array( - 'riskbitmask' => RISK_CONFIG | RISK_SPAM, + 'riskbitmask' => RISK_SPAM, 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'manager' => CAP_ALLOW, - 'coursecreator' => CAP_ALLOW, 'editingteacher' => CAP_ALLOW, ) ), // Delete badges. 'moodle/badges:deletebadge' => array( - 'riskbitmask' => RISK_CONFIG | RISK_DATALOSS, + 'riskbitmask' => RISK_DATALOSS, 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'manager' => CAP_ALLOW, - 'coursecreator' => CAP_ALLOW, 'editingteacher' => CAP_ALLOW, ) ), // Set up/edit badge details. 'moodle/badges:configuredetails' => array( - 'riskbitmask' => RISK_CONFIG, + 'riskbitmask' => RISK_SPAM, 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'manager' => CAP_ALLOW, - 'coursecreator' => CAP_ALLOW, 'editingteacher' => CAP_ALLOW, ) ), // Set up/edit criteria of earning a badge. 'moodle/badges:configurecriteria' => array( - 'riskbitmask' => RISK_CONFIG, 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'manager' => CAP_ALLOW, - 'coursecreator' => CAP_ALLOW, 'editingteacher' => CAP_ALLOW, ) ), // Configure badge messages. 'moodle/badges:configuremessages' => array( - 'riskbitmask' => RISK_CONFIG, + 'riskbitmask' => RISK_SPAM, 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'manager' => CAP_ALLOW, - 'coursecreator' => CAP_ALLOW, 'editingteacher' => CAP_ALLOW, ) ), @@ -1994,10 +1985,9 @@ $capabilities = array( 'moodle/badges:awardbadge' => array( 'riskbitmask' => RISK_SPAM, 'captype' => 'write', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'manager' => CAP_ALLOW, - 'coursecreator' => CAP_ALLOW, 'teacher' => CAP_ALLOW, 'editingteacher' => CAP_ALLOW, ) @@ -2007,7 +1997,7 @@ $capabilities = array( 'moodle/badges:viewawarded' => array( 'riskbitmask' => RISK_PERSONAL, 'captype' => 'read', - 'contextlevel' => CONTEXT_SYSTEM, + 'contextlevel' => CONTEXT_COURSE, 'archetypes' => array( 'manager' => CAP_ALLOW, 'teacher' => CAP_ALLOW, From f8bb8999e8c8fc4216030b15b5a925101e0b134f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20S=CC=8Ckoda?= Date: Sun, 23 Jun 2013 12:33:40 +0200 Subject: [PATCH 2/2] MDL-40289 fix block_badges capability defaults --- blocks/badges/db/access.php | 8 ++++---- blocks/badges/version.php | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/blocks/badges/db/access.php b/blocks/badges/db/access.php index 3470f53f8b5..5804558ff37 100644 --- a/blocks/badges/db/access.php +++ b/blocks/badges/db/access.php @@ -26,11 +26,11 @@ $capabilities = array( 'block/badges:addinstance' => array( - 'riskbitmask' => RISK_PERSONAL, 'captype' => 'read', - 'contextlevel' => CONTEXT_SYSTEM, - 'archetypes' => array( - 'user' => CAP_ALLOW, + 'contextlevel' => CONTEXT_BLOCK, + 'archetypes' => array( + 'editingteacher' => CAP_ALLOW, + 'manager' => CAP_ALLOW ), 'clonepermissionsfrom' => 'moodle/site:manageblocks' ), diff --git a/blocks/badges/version.php b/blocks/badges/version.php index 4b9e10d0389..2dfca1c6708 100644 --- a/blocks/badges/version.php +++ b/blocks/badges/version.php @@ -25,6 +25,6 @@ defined('MOODLE_INTERNAL') || die(); -$plugin->version = 2013050100; // The current plugin version (Date: YYYYMMDDXX). +$plugin->version = 2013050101; // The current plugin version (Date: YYYYMMDDXX). $plugin->requires = 2013050100; // Requires this Moodle version. $plugin->component = 'block_badges'; \ No newline at end of file