Compare commits

..
2 Commits
Author SHA1 Message Date
cameron1729 a55678d2cb Merge pull request #412 from sarahjcotton/WR489688-security-fix-39
WR489688: Security fix #30
2026-07-13 21:12:31 +08:00
Sarah Cotton be740fd139 WR489688: Security fix #30 2026-06-25 15:15:22 +01:00
2 changed files with 6 additions and 2 deletions
+4
View File
@@ -267,6 +267,10 @@ class outagelib {
// single-quotes (and double for the sake of it) are present otherwise it would break the code.
$allowedips = addslashes($allowedips);
// Escape the access key before substitution into the PHP literal to prevent
// code injection via a maliciously crafted access key value.
$accesskey = addslashes((string)$accesskey);
$cookiesecure = is_moodle_cookie_secure();
// Since Moodle 4.3 cookiehttponly is default to true and this CFG is not set.
+2 -2
View File
@@ -28,8 +28,8 @@
defined('MOODLE_INTERNAL') || die();
$plugin->component = "auth_outage";
$plugin->version = 2024081905; // The current plugin version (Date: YYYYMMDDXX).
$plugin->release = 2024081905; // Human-readable release information.
$plugin->version = 2024081906; // The current plugin version (Date: YYYYMMDDXX).
$plugin->release = 2024081906; // Human-readable release information.
$plugin->requires = 2017111309; // 2017111309 = T13, but this really requires 3.9 and higher.
$plugin->maturity = MATURITY_STABLE; // Suitable for PRODUCTION environments!
$plugin->supported = [39, 405]; // A range of branch numbers of supported moodle versions.