forked from moodle/moodle
-
Notifications
You must be signed in to change notification settings - Fork 1
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
MDL-80836 auth_lti: take user through login instead of sesspiggyback
Browsers are phasing out 3rd party cookies. Those which can be set are partitioned to the top level embedding site, so piggybacking is prevented. This will break the account linking process. This fix swaps the piggyback for a login round trip, as originally intended, which resolves the issue.
- Loading branch information
Showing
3 changed files
with
10 additions
and
21 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -32,7 +32,6 @@ | |
* info - a notification describing the first launch options | ||
* cancreateaccounts - whether or not the user is allowed to create auth_lti accounts | ||
* accountinfo - information about the user, importantly whether they are logged in or not. | ||
* noauthnotice - a notification telling the user they must be authenticated to link accounts. Only relevant when not logged in. | ||
Example context (json): | ||
{ | ||
|
@@ -46,19 +45,12 @@ | |
"issuccess": true | ||
}, | ||
"cancreateaccounts": true, | ||
"isloggedin": true, | ||
"accountinfo": { | ||
"isloggedin": true, | ||
"firstname": "John", | ||
"lastname": "Smith", | ||
"email": "[email protected]", | ||
"picturehtml": "<img src=\"http://site.example.com/pluginfile.php/5/user/icon/boost/f2?rev=99\" class=\"round\" alt=\"\" width=\"35\" height=\"35\">" | ||
}, | ||
"noauthnotice": { | ||
"message": "To link your existing account you must be logged in to the site...", | ||
"extraclasses": "", | ||
"announce": false, | ||
"closebutton": false, | ||
"iswarning": true | ||
} | ||
} | ||
}} | ||
|
@@ -79,8 +71,8 @@ | |
<div class="card-body text-center d-flex flex-column"> | ||
<i class="fa fa-user-circle-o fa-2x link"></i> | ||
<h4 class="card-title">{{#str}} useexistingaccount, auth_lti {{/str}}</h4> | ||
{{#accountinfo}} | ||
{{#isloggedin}} | ||
{{#accountinfo}} | ||
<p class="card-text mt-2"> | ||
<span class="text-muted"> | ||
{{#str}} currentlyloggedinas, auth_lti {{/str}} | ||
|
@@ -90,14 +82,12 @@ | |
{{firstname}} {{lastname}} ({{email}}) | ||
</p> | ||
<input type="submit" class="btn btn-primary mt-auto" name="existing_account" value="{{#str}} linkthisaccount, auth_lti {{/str}}"> | ||
{{/accountinfo}} | ||
{{/isloggedin}} | ||
{{^isloggedin}} | ||
<p class="card-text text-muted">{{#str}} mustbeloggedin, auth_lti {{/str}}</p> | ||
{{#noauthnotice}} | ||
{{> core/notification}} | ||
{{/noauthnotice}} | ||
<input type="submit" class="btn btn-primary mt-auto" name="existing_account" value="{{#str}} login, moodle {{/str}}"> | ||
{{/isloggedin}} | ||
{{/accountinfo}} | ||
</div> | ||
</div> | ||
</div> | ||
|