Was the ability to pass the quiz password in the URL query string removed?

Re: Was the ability to pass the quiz password in the URL query string removed?

by Tim Hunt -
Number of replies: 0
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

Yes, things have changes in a way that probably does break this. (What you were doing uses exactly the same mechanism as 'cross-site request forgery' (XSRF) security vulnerabilites, and so the Moodle forms library makes it difficult to do, and the code changed from using random HTML to using a real Moodle form.

However, if you try a bit harder you can probalby still fake the correct request.

Alternatively, there are now (in 2.2) things called Quiz access rule plugins (http://docs.moodle.org/dev/Quiz_access_rules) and with a new plugin like this you could probably bring back the old behaviour, but in a more secure way.