Roles in Student Roles FAQ breach on Front Page?

Roles in Student Roles FAQ breach on Front Page?

by Sandy Warner -
Number of replies: 3

Hi

I have been trying to get Students and Authenticated users to read All of front page, including forum.  I am using 9.1  I did what the Manual FAQ suggested (tried all of them) and when clicking Student as the default role for the Front Page, it ALLOWS ALL STUDENTS into the Admin panel to change all the Front Page settings!

I discovered when logged in as a student, there is a tiny Site Administration box on the Front Page and if you click on it, it shows Front Page.  Then CLick on it, and all of the following are available for student to edit!

Site Administration

Front Page

Front Page settings

Front Page roles

Front Page backup

Front Page restore

Front Page questions

Site files

Either the new 9.1 comment in the FAQ is incomplete, or there is a breach.

Either:

  1. Access Site Administration > Front Page > Front Page roles
  2. Follow the "Override permissions" link
  3. Click on "Authenticated User"
  4. Scroll down to Forum
  5. Change the capability mod/forum:viewdiscussion to allow
  6. Click the "Save changes" button at the bottom of the page

Or, in Moodle 1.9 onwards:

  1. Access Site Administration > Front Page > Front Page settings
  2. Set the default front page role to student.

 

FROM FAQ:  http://docs.moodle.org/en/Roles_FAQ
Average of ratings: -
In reply to Sandy Warner

Re: Roles in Student Roles FAQ breach on Front Page?

by Tim Hunt -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers
I cannot reproduce this. Here is what I did in my 1.9.3 test site:
  1. Log in as admin.
  2. Access Site Administration > Front Page > Front Page settings
  3. Set the default front page role to student.
  4. Log out.
  5. Log in as to an account that only has student permissions on a few courses.
  6. Go to the front page.
I do not see the site administration block, as expected.

Are you sure you do not have any other roles settings that might be affecting this? For example are there any role assignments or overrides in the front page course? And do the Authenticated user and Student role have any permissions in addition to the default ones?
In reply to Sandy Warner

Re: Roles in Student Roles FAQ breach on Front Page?

by Michael Penney -
Check the role settings for your student role - see if they match the defaults -the darker gray bars.
In reply to Michael Penney

Re: Roles in Student Roles FAQ breach on Front Page?

by ben reynolds -
We just discovered this when someone changed the front page settings. evil

The problem was that another someone had changed the default front page role to administrator, thus allowing students to see the site admin block for front page.