MantisBT - ATutor
View Issue Details
0003300ATutorTests/Surveyspublic2008-01-24 01:012008-08-21 08:54
IndieRect 
harris 
normalminoralways
closedfixed 
1.6 
1.6.1 
SVN
0003300: Test intro page is available when a test is not
ATutor version: 1.6 RC1

Even if students cannot take some test because of its expiry or used up attempts, they can view tools/test_intro.php for that test. It can be done by typing in the correct URL.
Not a big problem, but since it is supposed to be protected (as I can say from the code), then it needs to be.

I suggest a refactoring approach to fixing this and improving the overall readability of authentication code in the test area: http://www.atutor.ca/view/12/12652/1.html. [^]
No tags attached.
Issue History
2008-01-24 01:01IndieRectNew Issue
2008-01-24 01:01IndieRectAffects version => SVN
2008-04-30 06:39cindyStatusnew => assigned
2008-04-30 06:39cindyAssigned To => harris
2008-05-14 09:33harrisNote Added: 0002916
2008-05-14 09:34harrisStatusassigned => resolved
2008-05-14 09:34harrisFixed in Version => 1.6.1
2008-05-14 09:34harrisResolutionopen => fixed
2008-05-14 09:34harrisNote Added: 0002917
2008-08-21 08:54gregStatusresolved => closed

Notes
(0002916)
harris   
2008-05-14 09:33   
Perform a similar check like take_test.php
(0002917)
harris   
2008-05-14 09:34   
7530