-
-
Notifications
You must be signed in to change notification settings - Fork 27
LMS Competency Tests Developer Guide
3.0.0 Β· user guide: Competency tests
The questions are kept in a bank, tests are built from the bank, and each candidate sits a frozen snapshot of one test through a token link. This page covers where everything lives and the rules that must not be broken.
| File | What it is | |
|---|---|---|
| βοΈ | includes/lms/competency_tests.php |
every rule - validation, scoring, snapshot, token, clock, retention, the AI prompt and its parser |
| π₯οΈ | api/lms/tests.php |
the analyst API - tests, bank, candidates, settings. All behind Cap::LMS_TESTS
|
| π | api/lms/test_public.php |
the candidate's API - start, save, submit. No session; the token is the credential |
| π | lms/test.php |
the candidate's page (public, i18n_guarded, self-contained CSS, works on a phone) |
| π₯οΈ |
lms/tests/index.php, edit.php, result.php, _page.php
|
the analyst pages; _page.php holds the gates and the <head>
|
| π¨ |
assets/js/lms-tests.js, assets/css/lms-tests.css
|
one script for the three pages, chosen by <body data-ct-page>
|
| π |
includes/capabilities.php, lms/settings/manifest.php
|
Cap::LMS_TESTS = 'lms.competency_tests', claimed by the settings tab tests (sensitive) |
| βοΈ | lms/settings/index.php |
the Competency tests tab; the page now opens for LMS_MANAGE or LMS_TESTS, each seeing its own tabs |
| ποΈ |
database/freeitsm.sql, includes/db_verify_schema.php, includes/db_verify_indexes.php, api/system/db_verify.php
|
five tables, seven indexes, four FKs |
| π‘οΈ | includes/csrf.php |
api/lms/test_public.php is on CSRF_EXEMPT_PATHS
|
| π§ͺ | tests/lms-competency-tests.php |
53 checks, the candidate endpoint over HTTP included |
| Table | Holds |
|---|---|
lms_ct_questions |
the bank. answers_json = [{"text","marks"}]; status draft / approved / hidden; source ai / manual; role_context (searchable) |
lms_ct_tests |
title, role description, time limit, pass mark, is_archived
|
lms_ct_test_skills |
the skill rows: skill, difficulty, format, question_count, sort_order |
lms_ct_test_questions |
which bank questions are on a test, in order. Unique (test, question) |
lms_ct_sittings |
one candidate's attempt: token_hash, snapshot_json, responses_json, the clock columns, score_percent, skills_json, notes |
FKs: skills and test-questions cascade with their test; a test-question cascades with its bank question. A sitting's test_id is ON DELETE SET NULL, because a sitting never needs its test (see the snapshot rule). Deleting a test that has sittings archives it instead, so that the Candidates list can still name it.
The AI only ever writes status = 'draft'. lmsCtBuildSnapshot() refuses a test holding any draft or hidden question, and refuses an empty test. Everything that sends goes through it. lmsCtValidateQuestion() is the one validator for the editor and the AI. It drops, never "fixes", a multiple-choice question with two right answers, because that is a bad question rather than a labelling slip.
create_sitting writes lmsCtBuildSnapshot() into snapshot_json: question text, answers in a shuffled order (Fisher-Yates over random_int), marks and max. From then on the sitting reads only its snapshot:
- the candidate's page renders from it
- scoring reads it
- the result page shows it
Editing, hiding or deleting a bank question, or deleting the test, changes nothing about a sent paper. Don't add a code path that joins a sitting back to lms_ct_questions.
lms/test.php prints question and answer text only: no marks, no max, no explanation, and no JSON of the snapshot. save takes {q, a} indexes into the snapshot and validates them against it. The test suite asserts that the page HTML contains none of these.
lmsCtNewToken() returns 32 random bytes as hex, and the SHA-256 of that is stored. lmsCtFindSitting() rejects anything that isn't 64 lowercase hex before it touches the database. Because the raw link exists only in the create_sitting / new_link response, the UI says it is shown once. new_link works only before Start.
lms/test.php sends Referrer-Policy: no-referrer, Cache-Control: no-store and X-Robots-Tag: noindex, because the token is in its URL. The candidate API reads the token from the body. An unknown token and a cancelled one get the same 404 invalid.
api/lms/test_public.php is on the CSRF exempt list (like the web chat): it has no session to forge, and it carries its own credential. It is also an exemption in tests/module-access-coverage.php, for the same reason.
-
started_datetimeis set once (WHERE started_datetime IS NULL). - The deadline is
started + time_limit_minutes. An untimed sitting still closes afterLMS_CT_UNTIMED_HOURS(24), so nothing stays open for ever. -
saveis accepted until the deadline plusLMS_CT_GRACE_SECONDS(60), which allows for a click already in flight. - After that, any request closes the sitting with
finish_reason = 'time_up'andsubmitted_datetime= the deadline (not the moment it was noticed), scoring what was saved. -
lmsCtFinaliseOverdue()does the same for sittings nobody touches. It runs whenever the Candidates list or a result is read. - The page's countdown is the server's remaining seconds against
performance.now(), so changing the device clock changes nothing.
save uses JSON_SET(..., CAST(? AS UNSIGNED)) in one statement, so two quick clicks on different questions can't overwrite each other.
For each question, the score is the marks for the chosen answer divided by the best marks on offer. Unanswered scores 0. The overall percentage is the mean of those fractions, and so is the per-skill percentage (grouped by skill + difficulty). A graded question worth 0-5 therefore counts no more than a 0-1 multiple-choice one. score_percent and skills_json are stored at close, so the list doesn't recompute them.
lmsCtPurge(), at most once a day (lms_ct_last_purge) and run from the Candidates list, deletes sittings older than lms_ct_retention_days (default 180; 0 = never) that are over: submitted, cancelled, or never started with the link out of date. A sitting started and never finished is closed by rule 5 first, and only then aged out.
lmsCtGenerate() makes one call per skill (at most 20 questions per call), using the LMS AI config (aiSettingsLoad($conn, 'lms_ai')). The prompt carries:
- the role description and the skill
- a description of what the difficulty level means
- up to 40 existing question texts on that skill, so it doesn't repeat itself
- a rule that every answer must be similar in length and detail. A live run showed the right answer was always the longest; shuffling hides its position, not its length.
Graded questions come back as four strings, best first, and get the install's marks in that order. lmsCtParseDrafts() is separate from the call, so the parsing is tested against sample replies (fenced JSON, a question with two right answers, a graded question with three answers, a prose refusal) without spending anything.
generate (the API) fills a skill's shortfall: what the test already holds for that skill + difficulty + format counts first. Then come approved bank questions (ORDER BY RAND(), not already on the test, unless use_bank is off), and only then the AI.
| Who | Can |
|---|---|
Cap::LMS_TESTS (Competency tests, sensitive) |
everything on this page: LMS β Tests, and the Settings tab |
Cap::LMS_MANAGE |
nothing here - course management only |
| admin | everything, as always |
The LMS header shows Tests to LMS_TESTS holders, and Settings to holders of either grant. Every analyst page calls requireModuleAccess('lms') and requireCapability(Cap::LMS_TESTS); the API calls requireModuleAccessJson and requireCapabilityJson.
lms_ct_link_days (7), lms_ct_time_limit (45), lms_ct_graded_marks (5,3,1,0), lms_ct_retention_days (180), lms_ct_show_score (0), lms_ct_last_purge. They are written by api/lms/tests.php (save_settings), not by the generic settings writer, so the manifest tab has no setting_keys.
The analyst pages' strings are in lang/en/lms.php under tests, and the candidate page's under candidate. Every call site passes its English (lt() in PHP, L() β window.tf in JS, tr() on the public page), so an untranslated key shows English, never a key.
FREEITSM_URL=https://your-install/ php tests/lms-competency-tests.php
The suite creates its own questions, test and sittings (tagged), and deletes them in finally. It puts the purge's last-run day back. It skips the retention checks if the install already has old candidates of its own, because a test must never delete someone's real results.
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96