diff --git a/classes/local/controllers/infopage.php b/classes/local/controllers/infopage.php index acfe126..8e646bc 100644 --- a/classes/local/controllers/infopage.php +++ b/classes/local/controllers/infopage.php @@ -53,10 +53,14 @@ public function __construct(?array $params = null) { $CFG->svgicons = true; if (is_null($params)) { + $id = optional_param('id', null, PARAM_INT); $params = [ - 'id' => optional_param('id', null, PARAM_INT), + 'id' => $id, 'outage' => null, - 'static' => optional_param('static', false, PARAM_BOOL), + 'static' => !is_null($id) && hash_equals( + self::statickey($id), + optional_param('statickey', '', PARAM_ALPHANUM) + ), ]; } else { $defaults = [ @@ -152,4 +156,21 @@ private function set_parameters(array $params) { $this->outage = $params['outage']; $this->static = $params['static']; } + + /** + * Computes the secret token that proves a request to view an outage's static + * rendering came from this plugin's own static-page generator, not an external + * client forging the request. Used to gate the 'static' flag (see constructor). + * + * @param int $outageid + * @return string + */ + public static function statickey($outageid) { + $secret = get_config('auth_outage', 'staticsecret'); + if (empty($secret)) { + $secret = random_string(64); + set_config('staticsecret', $secret, 'auth_outage'); + } + return hash_hmac('sha256', (string)$outageid, $secret); + } } diff --git a/classes/local/controllers/maintenance_static_page.php b/classes/local/controllers/maintenance_static_page.php index 4a6896d..644bdf1 100644 --- a/classes/local/controllers/maintenance_static_page.php +++ b/classes/local/controllers/maintenance_static_page.php @@ -56,7 +56,8 @@ public static function create_from_outage($outage) { header('X-Outage-EndTime: ' . $outage->stoptime); } $data = maintenance_static_page_io::file_get_data( - $CFG->wwwroot . '/auth/outage/info.php?auth_outage_hide_warning=1&static=1&id=' . $outage->id + $CFG->wwwroot . '/auth/outage/info.php?auth_outage_hide_warning=1&id=' . $outage->id + . '&statickey=' . infopage::statickey($outage->id) ); $html = $data['contents']; } diff --git a/preview.php b/preview.php index f2c2508..9a1d5a1 100644 --- a/preview.php +++ b/preview.php @@ -30,7 +30,11 @@ // @codingStandardsIgnoreStart require_once(__DIR__.'/../../config.php'); +require_once($CFG->libdir . '/adminlib.php'); // @codingStandardsIgnoreEnd + +admin_externalpage_setup('auth_outage_manage'); + $id = optional_param('id', null, PARAM_INT); $outage = is_null($id) ? outagedb::get_next_starting() : outagedb::get_by_id($id); if (is_null($outage)) { diff --git a/version.php b/version.php index df16521..a1ed2ed 100644 --- a/version.php +++ b/version.php @@ -28,8 +28,8 @@ defined('MOODLE_INTERNAL') || die(); $plugin->component = "auth_outage"; -$plugin->version = 2024081906; // The current plugin version (Date: YYYYMMDDXX). -$plugin->release = 2024081906; // Human-readable release information. +$plugin->version = 2024081907; // The current plugin version (Date: YYYYMMDDXX). +$plugin->release = 2024081907; // Human-readable release information. $plugin->requires = 2017111309; // 2017111309 = T13, but this really requires 3.9 and higher. $plugin->maturity = MATURITY_STABLE; // Suitable for PRODUCTION environments! $plugin->supported = [39, 405]; // A range of branch numbers of supported moodle versions. diff --git a/views/info/content.php b/views/info/content.php index 8a01cef..1345c0a 100644 --- a/views/info/content.php +++ b/views/info/content.php @@ -39,7 +39,15 @@ stoptime, get_string('datetimeformat', 'auth_outage')); ?> -
get_description(); ?>
+
+ get_description(), + FORMAT_HTML, + ['context' => context_system::instance()] + ); + ?> +