security in resources

by Martin Dougiamas -
Number of replies: 0
Picture of Core developers Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
Javascript yes, but PHP, no. It's too much of a security hole - anyone who got into a teacher account could potentially do a lot of damage to Moodle and the server it's running on.

There was some talk a while back about a new resource type called "PHP code" which WOULD parse the documents for PHP. I think this could be a good idea as long as it was an option controlled by the admin.
Average of ratings: Useful (1)