MDL-39090: Duplicate parameters in LTI launches
Removed endpoint query string params from body to prevent param duplication.
This commit is contained in:
committed by
Sam Hemelryk
parent
a2f561b6a7
commit
e1ff960c94
@@ -176,6 +176,19 @@ function lti_view($instance) {
|
||||
|
||||
if (!empty($key) && !empty($secret)) {
|
||||
$parms = lti_sign_parameters($requestparams, $endpoint, "POST", $key, $secret);
|
||||
|
||||
$endpointurl = new moodle_url($endpoint);
|
||||
$endpointparams = $endpointurl->params();
|
||||
|
||||
// Strip querystring params in endpoint url from $parms to avoid duplication.
|
||||
if (!empty($endpointparams) && !empty($parms)) {
|
||||
foreach (array_keys($endpointparams) as $paramname) {
|
||||
if (isset($parms[$paramname])) {
|
||||
unset($parms[$paramname]);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
} else {
|
||||
//If no key and secret, do the launch unsigned.
|
||||
$parms = $requestparams;
|
||||
|
||||
Reference in New Issue
Block a user