Skip to content

Fix missing sesskey validation on state-changing admin endpoints - #3377

Open
Patryk Mroczko (patmr7) wants to merge 1 commit into
MOODLE_500_STABLEfrom
wip-133982-m500
Open

Fix missing sesskey validation on state-changing admin endpoints#3377
Patryk Mroczko (patmr7) wants to merge 1 commit into
MOODLE_500_STABLEfrom
wip-133982-m500

Conversation

@patmr7

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the local_o365 admin UI by enforcing Moodle sesskey validation on state-changing endpoints to mitigate CSRF risks on admin actions.

Changes:

  • Added require_sesskey() to the cohort sync “delete mapping” action.
  • Added require_sesskey() to multiple ACP (Admin Control Panel) modes that perform mutations (queue clearing, maintenance actions, team connection actions, and user connection actions).
  • Updated generated admin/action URLs to include sesskey where needed (including adjusting URL output for the JS-driven POST in usermatch).

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

File Description
local/o365/cohortsync.php Requires sesskey for the delete action to prevent CSRF on cohort mapping deletion.
local/o365/classes/page/acp.php Enforces sesskey on multiple state-changing ACP modes and ensures corresponding action URLs include sesskey.
local/o365/classes/form/cohortsync.php Adds sesskey to the “delete mapping” URL so the new validation passes.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants