Promoodle - an open letter

Re: Promoodle - an open letter

by Chardelle Busch -
Number of replies: 0
Picture of Core developers
http://promoodle.com/center/course/view.php?id=9

I wouldn't call this an integration, really. All it does is provide seamless logging in and out of, and account registration/password retrieval, for Joomla/Moodle users. There are two Joomla components. The first one when a link is created to it in Joomla and then clicked, passes the username and password (hashed of course) from Joomla to Moodle login via a form. The other replaces the Moodle login page--logging in users to Joomla first, then passing the info through the aforementioned component to the Moodle page that was trying to be accessed--it also includes a loginas guest link.

I'm certainly no security expert--so if anyone knows if this is an unsecure way to do it--let us know. Of course, any Joomla addon component used with Register Globals on is not going to be secure--which is why it is the recommended setting for Joomla and should be turned off.