Skip to content

Commit 8036401

Browse files
committed
Add the hidden authentication fields to the LTI update form.
The content generator `hidden_authen_fields` method should be called in all page forms, but was not added ot the form in the LTI update page. As a result if you are acting as a student, go to that page, and click "Update Grades", then the acting ceases. Even worse, if `session_management_via` is set to "key", and you click "Update Grades", then you are sent to the login page, and have to login again in order for the form to submit. I missed this when this page was created. @somiaj observed the issue when acting as another user on the page.
1 parent a00a004 commit 8036401

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

templates/ContentGenerator/Instructor/LTIUpdate.html.ep

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@
4747
%
4848
<h2><%= maketext('Start LTI Grade Update') %></h2>
4949
<%= form_for current_route, method => 'POST', id => 'updateLTIForm', name => 'updateLTIForm', begin =%>
50+
<%= $c->hidden_authen_fields =%>
5051
<div class="row mb-3">
5152
<%= label_for updateUserID => maketext('Update user:'), class => 'col-auto col-form-label fw-bold' =%>
5253
<div class="col-auto">

0 commit comments

Comments
 (0)