Bildungsportal / moodle-local_table_sql

GNU General Public License v3.0
1 stars 0 forks source link

Security guidelines #7

Closed lostrogit closed 5 months ago

lostrogit commented 5 months ago

I would suggest avoid directly accessing to $_POST in this method, in order to comply with the security policy https://moodledev.io/general/development/policies/security#dont-trust-any-input-from-users

rschrenk commented 5 months ago

I have found no other solution, but the Post-Vars are validated later using the Moodle mechanics. They are only put into another structure to comply with the Moodle standards, after they have been packed by a Javascript in