DF-Wiki and Username (serious bug)

DF-Wiki and Username (serious bug)

by N Hansen -
Number of replies: 1
I really like DF-Wiki and want to use it right away in one of my courses. But there is a serious flaw in it that I consider unacceptable because it not only poses a security risk for my students but could cause all kinds of problems in the long run. That is the fact that the person who creates or edits a page is stored by their username, rather than their userid. Username is something that can change at any time. Also, displaying a user's user name, rather than their real name, puts their account at risk.

Userid is fixed and is what is used by every other module in Moodle to identify a user. So why doesn't DF-Wiki use it?
Average of ratings: -
In reply to N Hansen

Re: DF-Wiki and Username (serious bug)

by Martin Dougiamas -
Picture of Core developers Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
Absolutely, only the user id should be stored, and wiki display should use that to get the name. Even the old wiki module does that.