MDL-32239 question bank: wrong cap checks editing/viewing quesitions
authorTim Hunt <T.J.Hunt@open.ac.uk>
Wed, 28 Mar 2012 11:09:12 +0000 (12:09 +0100)
committerTim Hunt <T.J.Hunt@open.ac.uk>
Thu, 29 Mar 2012 13:14:10 +0000 (14:14 +0100)
commit51c5e6057c67687f5d872f8a228cfea275abf576
treecf7b788ca456ebabc99aea6e47c243141354fa14
parenta2800781977c053db84a90ee059495a715183b86
MDL-32239 question bank: wrong cap checks editing/viewing quesitions

None of these problems affect the default roles. They only occur when
the permissions have been edited to allow restricted subsets of the
question capabilities.

In some cases, things that the restriced subset of capabilities should
have allowed were blocked by errors. In other cases, users were allowed
to do more than they should bave been due to failures to check the
right capabilities in the right places.

For full details, see the bug report.

Two of the bugs were previously reported separately as MDL-26395 and
MDL-27232.
question/editlib.php
question/question.php
question/type/edit_question_form.php