-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enhancing Plugin Security and Authorization: Important Suggestions for Consideration #23
Comments
Hi @Thefieldman , many thanks for taking the time to write your thoughts about this plugin down.
Well, I would like to point out that this plugin is called 'password', but it's main design principle was to allow teachers to protect individual course activities with additional secrets - in addition to a course enrolment secret.
If you could give clear steps to reproduce for this situation, I would be grateful.
I fully understand your expectations. But this plugin is a community project. If you have such a large audience / clientele, please feel encouraged to spend some more time to explain your needs and, ideally, contribute code to fulfil the needs in the end. Cheers, |
Hello Alex, thank you for your quick response. I really appreciate your work on this plugin and don't want to do you any injustice. I understand that you developed the plugin for a specific purpose and think that the use case I described is very specific and may be rare. In my opinion, the plugin is very successful and, among other things, makes a successful contribution to gamification! Cheers |
Dear @abias and @lucaboesch,
I hope this message finds you well. I'd like to share a suggestion for further enhancing the plugin in a more concrete manner:
I've noticed that there might be room for improvement in the authorization concept of the plugin. It would be great if we could enhance it to ensure better security. It's crucial to approach the design, description, and implementation of security-related features with utmost care since users tend to rely on them.
Currently, there seems to be an issue where teachers who don't have authorization can still remove the password for others, which ideally shouldn't be the case. Moreover, the lack of logging for these actions makes it difficult to trace any unauthorized changes.
Given our target audience, consisting of several thousand schools in Germany, these adjustments are vital for us to be able to fully utilize the plugin.
We genuinely appreciate your consideration of these suggestions. Thank you in advance for your attention and support.
The text was updated successfully, but these errors were encountered: