Releases: davidpesce/moodle-logstore_xapi
Release list
v5.1.0
v5.1.0
Adds Moodle 5.2 support, raises the minimum supported Moodle to 4.5, and
makes the Privacy API implementation functional.
Supported versions changed
Moodle 4.5 – 5.2 (previously 4.3 – 5.1).
Sites running Moodle 4.3 or 4.4 should stay on the 5.0.x line, which
includes the security fixes released in 5.0.3. Moodle 4.5 is the current
LTS.
Both ends of the new range are covered by CI across PostgreSQL and MariaDB.
Note that Moodle 5.2 itself requires PHP 8.3 and PostgreSQL 16 or MariaDB
10.11.
Privacy (GDPR) requests now include this plugin's data
The privacy provider previously declared that logstore_xapi_log and
logstore_xapi_failed_log hold personal data, but every export and deletion
method was an empty stub. In practice this meant:
- a subject access (export) request returned nothing from these tables, and
- a right-to-erasure request, or an ordinary user deletion, did not remove
the user's rows.
Both are now implemented. Export and deletion cover both tables and run
through Moodle's standard log privacy handling in tool_log, the same path
logstore_standard uses.
If your site has processed erasure requests while running an earlier
version, rows for those users may still be present in these two tables.
They are not removed retroactively by upgrading. Re-running the deletion for
the affected users, or clearing the tables, is the way to reconcile that.
The declared metadata has also been corrected: it now lists the fields that
actually exist (userid, relateduserid, realuserid, ip, other) and
no longer names a moodleuserid field, which was never a column in either
table.
Fixed
- Events no longer fail to transform when the standard log store's
jsonformatsetting is enabled. Transformers assumed the eventother
field was always PHP-serialized; withjsonformaton it is JSON, and
historic events read from that table silently failed to convert. All
decoding now handles both formats, matching how core reads the same field.
Changed
- Deserialization of event data restricts allowed classes, matching the
hardening core applies when reading the same field. - The report's filter column is validated against an allow-list before being
used in a query. Both call sites already passed fixed values, so this
closes a latent rather than live issue. - The route selection setting's "select all / deselect all" behaviour moved
from an inline<script>to an AMD module, so the settings page works
under a Content Security Policy that forbids inline script.
Upgrade notes
- No database changes.
- Requires Moodle 4.5 or later. Sites below that should remain on 5.0.3.
- Review the privacy note above if your site has processed erasure requests.
Credits
Issues identified in an automated security review by
MDL Shield.
v5.0.3 — security release
v5.0.3 — security release
This is a security release. All sites should upgrade. There are no database
changes and no configuration is required after upgrading.
Security fixes
Failed-event report was readable without a capability. report.php gated
access inside a switch whose default branch performed no capability check,
so any authenticated user could read the failed-event log via
report.php?id=2&run=1, bypassing logstore/xapi:viewerrorlog. Unknown report
IDs are now rejected. The exposure was limited to operational metadata (event
names, error categories, timestamps) — no personal data and no ability to change
state.
TLS certificate verification is now enabled for the LRS connection. The
plugin previously sent statements with CURLOPT_SSL_VERIFYPEER disabled, so
anyone able to intercept traffic between Moodle and the LRS could read learner
data, capture the LRS username and password from the Basic auth header, and
tamper with the response. Verification is now on by default, including on
upgraded sites that have not yet visited the settings page.
Unescaped output in the admin reports. The LRS response body and, in the
historic report, the username were written into HTML table cells without
escaping. A malicious or compromised LRS could execute script in a manager's or
administrator's browser. Both are now escaped.
New settings
Two settings have been added under LRS Connection:
- Verify the LRS TLS certificate — on by default. Leave it on.
- Custom CA certificate bundle — the path to a PEM bundle. Use this when the
LRS presents a certificate from a private or internal certificate authority.
This is the preferred alternative to turning verification off, because the
certificate is still checked.
If your LRS uses a private CA and you upgrade without setting one of these,
statements will fail to send and the failed-event report will show
cURL error: SSL certificate problem: .... Set the CA bundle path to resolve
it.
Turning verification off is supported but is a last resort. It disables both the
certificate and hostname checks, which is more permissive than the previous
behaviour, and it is reported as a warning in
Site administration → Reports → Security checks so it does not stay hidden.
The check reports "not applicable" while the xAPI logstore is disabled.
Other changes
logstore/xapi:manageerrorsandlogstore/xapi:managehistoricare now
declared aswritecapabilities, which reflects that they authorise
requeueing events. Existing role assignments and overrides are unaffected.- Removed
cli/testdataseeder.php, a development-only fixture generator that
shipped in the release and could not run (it referenced$CFGbefore loading
config.php). - Removed
src/loader/lrs.php, an unused duplicate of the active LRS loader. - Transport-level failures now report the underlying cURL error instead of
storing an empty message in the failed-event log. - The failed-notification email template no longer uses unescaped output for
event names and counts.
Upgrade notes
- No database changes.
- Sites whose LRS uses a valid publicly-trusted certificate need no action.
- Sites whose LRS uses a private CA should set the CA certificate bundle path.
- Moodle 4.3 – 5.1 remain supported.
Credits
Issues identified in an automated security review by
MDL Shield.
v5.0.2
v5.0.2
Removed
JISC support has been removed (#889). The Adds JISC data to statements
(send_jisc_data) setting, the JISC statement extension, and its tests are
gone. The JISC platform has been discontinued, so this was dead code. No
action is required.
Fixed
- Settings page could take over 10 minutes to load on sites with many
cohorts (#842, #887). The cohort notification setting is now an AJAX
search selector rather than a checkbox list rendering every cohort. - Null and empty responses in matching questions no longer cause errors
(#891, #893). Affects thematch,gapselectandrandomsamatchquestion
transformers, with tests added.
Changed
- Admin settings UX improvements: settings are grouped under headings with
clearer descriptions (#888). - Added
SECURITY.mdand GitHub issue templates for bug reports and feature
requests. - Added plugin directory listing metadata, screenshots, and canonical
repository links.
Upgrade notes
- No database changes.
- Moodle 4.3 – 5.1 supported.
v5.0.1
v5.0.0
What's Changed
- Fix 853 by @davidpesce in #885
- moodle-plugin-ci tweaks to play nice
Full Changelog: v4.9.0...v5.0.0
v4.9.0
What's Changed
- docs(composer.lock): Updates author details by @ryasmi in #859
- resolves issue #865 by @davidpesce in #866
- Fix all warnings for PHPCS by @davidpesce in #867
- ISSUE-878: Unsupport operand types by @sharpchi in #880
- correctly fetch a subchapters parent (#776) & refactor TestRepository::read_records() method by @ScottVerbeek in #849
- Import type not defined by @sharpchi in #875
- fix src\transformer\utils\quiz_question\get_numerical_answer when ans… by @renaudlemaire in #869
- ISSUE-868: Cannot transform lesson by @sharpchi in #870
- replace issue for event by @sharpchi in #874
- FIX:876 - Remove test definitions that conflict with core Moodle tests by @davidpesce in #882
- Fix877 - question_manually_graded exception divide by zero by @davidpesce in #883
- switch to isset rather than empty by @davidpesce in #884
New Contributors
- @sharpchi made their first contribution in #880
- @ScottVerbeek made their first contribution in #849
- @renaudlemaire made their first contribution in #869
Full Changelog: v4.8.0...v4.9.0
v4.8.0
This again contains significant changes to the plugin. That said, existing installations (in supported versions of Moodle) can feel safe in updating.
Changes:
- YetAnalytics contribution of many core Moodle events and optimization of existing events.
v4.7.0
A large number of changes have been added to this release, but none of them are breaking changes. Existing installations (in supported versions of Moodle) can feel safe in updating.
Changes:
- Merge of further developed branch (master-jisc) into master. This branch includes new functionality with showing failed statements, historical processing of events, and retrying events.
- Convert from Travis to Github Actions
- Utilize the moodle-plugin-ci and moodle-release workflows
- PHPdocs have been added throughout
- Significant codechecker fixes