easy entry to a course from admin course - #3103
Conversation
c318c9b to
25a31e2
Compare
|
This is now retargeted to |
914c17f to
a7d9a03
Compare
|
Develop is now up to date. So you can rebase onto it now. |
25a31e2 to
734f08d
Compare
|
Rebased and pushed. |
drgrice1
left a comment
There was a problem hiding this comment.
These are just code suggestions. I am still working on analyzing the effect of this on other authentication modules.
I have created a pull request to this branch with these suggested code changes.
|
So as far as the other authentication modules go, here is my assessment.
So probably for now, you could just add comments in the documentation stating that this does not work with Saml2 and Shibbolith. Perhaps later, if there is demand, this could be extended to work for those. |
See my review of openwebwork#3103 for details on the changes.
b929da1 to
f876832
Compare
See my review of openwebwork#3103 for details on the changes.
Co-authored-by: Claude <noreply@anthropic.com>
See my review of openwebwork#3103 for details on the changes.
f876832 to
f1e033f
Compare
|
Thanks for your review of this. I merged your PR and updated the comments in defaults.config and localOverrides.conf.dist. I wrote that it won't work for Sam2, Shibboleth, or CAS. But maybe I should not mention CAS? |
This is marked draft. Even though I'm targeting WeBWorK-2.21 right now, that is only so that the diff is clearly visible in GitHub. Later this will be re-targeted to develop, following the 2.21 release.
This (optional feature, off by default) makes it so that if you are using cookies for session management (not keys) and if you have a valid active session in the admin course, then that will smoothly grant you access into any other course. Some conditions are needed, of course:
create_and_delete_courses).The main feature here (from my perspective) is that you can click links in the admin course and just be granted a session in the course you clicked on. This even works if that other course only allows users to enter through an LMS. You can also just click any link to any course, like say one in a student help email, and gain a session cookie. And you won't need to type a password.
All of this still requires 2FA for the course you are entering, assuming 2FA is enabled for that course, for a user of your level. That's actually something I would prefer not to have to do if I'm already authenticated in the admin course. But that could be changed later if this PR is not too objectionable.
Technical note: just because your user in the admin course and user in some other course have the same password, they would still have different password hashes if passwords were set independently. This really only works if the user in the other course were added to that other course as an admin user at the time the other course was initialized.