Skip to content

Releases: davidpesce/moodle-logstore_xapi

v5.1.0

Choose a tag to compare

@davidpesce davidpesce released this 21 Jul 03:32

v5.1.0

Adds Moodle 5.2 support, raises the minimum supported Moodle to 4.5, and
makes the Privacy API implementation functional.

Supported versions changed

Moodle 4.5 – 5.2 (previously 4.3 – 5.1).

Sites running Moodle 4.3 or 4.4 should stay on the 5.0.x line, which
includes the security fixes released in 5.0.3. Moodle 4.5 is the current
LTS.

Both ends of the new range are covered by CI across PostgreSQL and MariaDB.
Note that Moodle 5.2 itself requires PHP 8.3 and PostgreSQL 16 or MariaDB
10.11.

Privacy (GDPR) requests now include this plugin's data

The privacy provider previously declared that logstore_xapi_log and
logstore_xapi_failed_log hold personal data, but every export and deletion
method was an empty stub. In practice this meant:

  • a subject access (export) request returned nothing from these tables, and
  • a right-to-erasure request, or an ordinary user deletion, did not remove
    the user's rows.

Both are now implemented. Export and deletion cover both tables and run
through Moodle's standard log privacy handling in tool_log, the same path
logstore_standard uses.

If your site has processed erasure requests while running an earlier
version, rows for those users may still be present in these two tables.

They are not removed retroactively by upgrading. Re-running the deletion for
the affected users, or clearing the tables, is the way to reconcile that.

The declared metadata has also been corrected: it now lists the fields that
actually exist (userid, relateduserid, realuserid, ip, other) and
no longer names a moodleuserid field, which was never a column in either
table.

Fixed

  • Events no longer fail to transform when the standard log store's
    jsonformat setting is enabled.
    Transformers assumed the event other
    field was always PHP-serialized; with jsonformat on it is JSON, and
    historic events read from that table silently failed to convert. All
    decoding now handles both formats, matching how core reads the same field.

Changed

  • Deserialization of event data restricts allowed classes, matching the
    hardening core applies when reading the same field.
  • The report's filter column is validated against an allow-list before being
    used in a query. Both call sites already passed fixed values, so this
    closes a latent rather than live issue.
  • The route selection setting's "select all / deselect all" behaviour moved
    from an inline <script> to an AMD module, so the settings page works
    under a Content Security Policy that forbids inline script.

Upgrade notes

  • No database changes.
  • Requires Moodle 4.5 or later. Sites below that should remain on 5.0.3.
  • Review the privacy note above if your site has processed erasure requests.

Credits

Issues identified in an automated security review by
MDL Shield.

v5.0.3 — security release

Choose a tag to compare

@davidpesce davidpesce released this 20 Jul 22:48

v5.0.3 — security release

This is a security release. All sites should upgrade. There are no database
changes and no configuration is required after upgrading.

Security fixes

Failed-event report was readable without a capability. report.php gated
access inside a switch whose default branch performed no capability check,
so any authenticated user could read the failed-event log via
report.php?id=2&run=1, bypassing logstore/xapi:viewerrorlog. Unknown report
IDs are now rejected. The exposure was limited to operational metadata (event
names, error categories, timestamps) — no personal data and no ability to change
state.

TLS certificate verification is now enabled for the LRS connection. The
plugin previously sent statements with CURLOPT_SSL_VERIFYPEER disabled, so
anyone able to intercept traffic between Moodle and the LRS could read learner
data, capture the LRS username and password from the Basic auth header, and
tamper with the response. Verification is now on by default, including on
upgraded sites that have not yet visited the settings page.

Unescaped output in the admin reports. The LRS response body and, in the
historic report, the username were written into HTML table cells without
escaping. A malicious or compromised LRS could execute script in a manager's or
administrator's browser. Both are now escaped.

New settings

Two settings have been added under LRS Connection:

  • Verify the LRS TLS certificate — on by default. Leave it on.
  • Custom CA certificate bundle — the path to a PEM bundle. Use this when the
    LRS presents a certificate from a private or internal certificate authority.
    This is the preferred alternative to turning verification off, because the
    certificate is still checked.

If your LRS uses a private CA and you upgrade without setting one of these,
statements will fail to send and the failed-event report will show
cURL error: SSL certificate problem: .... Set the CA bundle path to resolve
it.

Turning verification off is supported but is a last resort. It disables both the
certificate and hostname checks, which is more permissive than the previous
behaviour, and it is reported as a warning in
Site administration → Reports → Security checks so it does not stay hidden.
The check reports "not applicable" while the xAPI logstore is disabled.

Other changes

  • logstore/xapi:manageerrors and logstore/xapi:managehistoric are now
    declared as write capabilities, which reflects that they authorise
    requeueing events. Existing role assignments and overrides are unaffected.
  • Removed cli/testdataseeder.php, a development-only fixture generator that
    shipped in the release and could not run (it referenced $CFG before loading
    config.php).
  • Removed src/loader/lrs.php, an unused duplicate of the active LRS loader.
  • Transport-level failures now report the underlying cURL error instead of
    storing an empty message in the failed-event log.
  • The failed-notification email template no longer uses unescaped output for
    event names and counts.

Upgrade notes

  • No database changes.
  • Sites whose LRS uses a valid publicly-trusted certificate need no action.
  • Sites whose LRS uses a private CA should set the CA certificate bundle path.
  • Moodle 4.3 – 5.1 remain supported.

Credits

Issues identified in an automated security review by
MDL Shield.

v5.0.2

Choose a tag to compare

@davidpesce davidpesce released this 20 Jul 23:10

v5.0.2

Removed

JISC support has been removed (#889). The Adds JISC data to statements
(send_jisc_data) setting, the JISC statement extension, and its tests are
gone. The JISC platform has been discontinued, so this was dead code. No
action is required.

Fixed

  • Settings page could take over 10 minutes to load on sites with many
    cohorts
    (#842, #887). The cohort notification setting is now an AJAX
    search selector rather than a checkbox list rendering every cohort.
  • Null and empty responses in matching questions no longer cause errors
    (#891, #893). Affects the match, gapselect and randomsamatch question
    transformers, with tests added.

Changed

  • Admin settings UX improvements: settings are grouped under headings with
    clearer descriptions (#888).
  • Added SECURITY.md and GitHub issue templates for bug reports and feature
    requests.
  • Added plugin directory listing metadata, screenshots, and canonical
    repository links.

Upgrade notes

  • No database changes.
  • Moodle 4.3 – 5.1 supported.

v5.0.1

Choose a tag to compare

@davidpesce davidpesce released this 23 Feb 21:41

What's Changed

Full Changelog: v5.0.0...v5.0.1

v5.0.0

Choose a tag to compare

@davidpesce davidpesce released this 17 Feb 23:15
1fc1646

What's Changed

Full Changelog: v4.9.0...v5.0.0

v4.9.0

Choose a tag to compare

@davidpesce davidpesce released this 17 Feb 21:30

What's Changed

  • docs(composer.lock): Updates author details by @ryasmi in #859
  • resolves issue #865 by @davidpesce in #866
  • Fix all warnings for PHPCS by @davidpesce in #867
  • ISSUE-878: Unsupport operand types by @sharpchi in #880
  • correctly fetch a subchapters parent (#776) & refactor TestRepository::read_records() method by @ScottVerbeek in #849
  • Import type not defined by @sharpchi in #875
  • fix src\transformer\utils\quiz_question\get_numerical_answer when ans… by @renaudlemaire in #869
  • ISSUE-868: Cannot transform lesson by @sharpchi in #870
  • replace issue for event by @sharpchi in #874
  • FIX:876 - Remove test definitions that conflict with core Moodle tests by @davidpesce in #882
  • Fix877 - question_manually_graded exception divide by zero by @davidpesce in #883
  • switch to isset rather than empty by @davidpesce in #884

New Contributors

Full Changelog: v4.8.0...v4.9.0

v4.8.0

Choose a tag to compare

@davidpesce davidpesce released this 11 Feb 16:07
967aa19

This again contains significant changes to the plugin. That said, existing installations (in supported versions of Moodle) can feel safe in updating.

Changes:

  • YetAnalytics contribution of many core Moodle events and optimization of existing events.

v4.7.0

Choose a tag to compare

@davidpesce davidpesce released this 19 Oct 19:13
416b92c

A large number of changes have been added to this release, but none of them are breaking changes. Existing installations (in supported versions of Moodle) can feel safe in updating.

Changes:

  • Merge of further developed branch (master-jisc) into master. This branch includes new functionality with showing failed statements, historical processing of events, and retrying events.
  • Convert from Travis to Github Actions
  • Utilize the moodle-plugin-ci and moodle-release workflows
  • PHPdocs have been added throughout
  • Significant codechecker fixes

v4.6.0

Choose a tag to compare

@HT2Bot HT2Bot released this 28 Mar 14:18
e5be1b7

4.6.0 (2020-03-28)

Features

  • bigbluebutton: Adds event support for BigBlueButton plugin. (e5be1b7)

v4.5.0

Choose a tag to compare

@HT2Bot HT2Bot released this 28 Jan 15:42

4.5.0 (2020-01-28)

Features

  • Settings: Attempts to reduce confusion in LRS configuration. (a467f00)