Permalink
Browse files

ensure user has_capability('mod/hotpot:attempt', $module) when viewin…

…g a HotPot or submitting results
  • Loading branch information...
1 parent 9218ade commit f50ea0419e8c7fb21176b403cd62b7ac0a5b5cd7 @gbateson gbateson committed Nov 9, 2009
Showing with 5 additions and 1 deletion.
  1. +3 −1 mod/hotpot/attempt.php
  2. +2 −0 mod/hotpot/view.php
View
@@ -21,8 +21,10 @@
error("Course Module ID is incorrect");
}
- // make sure this user is enrolled in this course
+ // make sure this user is enrolled in this course and can access this HotPot
require_login($course);
+ $context = get_context_instance(CONTEXT_MODULE, $cm->id);
+ require_capability('mod/hotpot:attempt', $context);
$next_url = "$CFG->wwwroot/course/view.php?id=$course->id";
$time = time();
View
@@ -34,8 +34,10 @@
}
}
+ // make sure this user is enrolled in this course and can access this HotPot
require_login($course);
$context = get_context_instance(CONTEXT_MODULE, $cm->id);
+ require_capability('mod/hotpot:attempt', $context);
}
// set nextpage (for error messages)
$nextpage = "$CFG->wwwroot/course/view.php?id=$course->id";

0 comments on commit f50ea04

Please sign in to comment.