Enforce valid lis_outcome_service_url

Recently, a new institution joined CodeOcean and used a relative URL. This won't work, so that we are rejecting non-absolute URLs by now.
This commit is contained in:
Sebastian Serth
2024-04-26 09:31:41 +02:00
committed by Dominic Sauer
parent fa856adcf0
commit 96f5f1f8d7
5 changed files with 23 additions and 2 deletions

View File

@ -4,7 +4,8 @@ class SessionsController < ApplicationController
include Lti
%i[require_oauth_parameters require_valid_consumer_key require_valid_oauth_signature require_unique_oauth_nonce
set_current_user require_valid_exercise_token set_study_group_membership set_embedding_options].each do |method_name|
require_valid_lis_outcome_service_url set_current_user require_valid_exercise_token set_study_group_membership
set_embedding_options].each do |method_name|
before_action(method_name, only: :create_through_lti)
end