Skip to content

Enforce privileged LTI launch role for course linking and creation - #8130

Merged
david-yz-liu merged 4 commits into
MarkUsProject:masterfrom
donny-wong:canvas_prevent_non_instructor_course_creation
Sep 9, 2026
Merged

Enforce privileged LTI launch role for course linking and creation#8130
david-yz-liu merged 4 commits into
MarkUsProject:masterfrom
donny-wong:canvas_prevent_non_instructor_course_creation

Conversation

@donny-wong

Copy link
Copy Markdown
Contributor

Proposed Changes

(Describe your changes here. Also describe the motivation for your changes: what problem do they solve, or how do they improve the application or codebase? If this pull request fixes an open issue, use a keyword to link this pull request to the issue.)

Currently the Canvas role check only decides where to redirect after an LTI launch — it is not enforced on the pages themselves. This means any logged-in MarkUs user could go directly to the choose_course URL and create a course, even if they are a student on Canvas. This PR fixes that: a successful privileged launch is now recorded in the session, and choose_course/create_course return a 403 "Launch Required" page unless the user launched that deployment from the LMS with an instructor role. Also re-enables CSRF protection on create_course. Specs updated with tests for the forbidden cases.

Screenshots of your changes (if applicable)

Type of Change

(Write an X or a brief description next to the type or types that best describe your changes.)

Type Applies?
🚨 Breaking change (fix or feature that would cause existing functionality to change)
New feature (non-breaking change that adds functionality)
🐛 Bug fix (non-breaking change that fixes an issue) x
🎨 User interface change (change to user interface; provide screenshots)
♻️ Refactoring (internal change to codebase, without changing functionality)
🚦 Test update (change that only adds or modifies tests)
📦 Dependency update (change that updates a dependency)
📖 Documentation update (change that updates documentation)
🔧 Internal (change that only affects developers or continuous integration)

Checklist

(Complete each of the following items for your pull request. Indicate that you have completed an item by changing the [ ] into a [x] in the raw text, or by clicking on the checkbox in the rendered description on GitHub.)

Before opening your pull request:

  • I have performed a self-review of my changes.
    • Check that all changed files included in this pull request are intentional changes.
    • Check that all changes are relevant to the purpose of this pull request, as described above.
  • I have added tests for my changes, if applicable.
    • This is required for all bug fixes and new features.
  • I have updated the project documentation, if applicable.
    • This is required for new features.
  • If this is my first contribution, I have added myself to the list of contributors.

After opening your pull request:

  • I have updated the project Changelog (this is required for all changes).
  • I have verified that the pre-commit.ci checks have passed.
  • I have verified that the CI tests have passed.
  • I have reviewed the test coverage changes reported by Coveralls.
  • I have requested a review from a project maintainer.

Questions and Comments

(Include any questions or comments you have regarding your changes.)

@coveralls

coveralls commented Aug 17, 2026

Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 34267318387

Coverage increased (+0.006%) to 90.684%

Details

  • Coverage increased (+0.006%) from the base build.
  • Patch coverage: 53 of 53 lines across 2 files are fully covered (100%).
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 52423
Covered Lines: 48570
Line Coverage: 92.65%
Relevant Branches: 2517
Covered Branches: 1252
Branch Coverage: 49.74%
Branches in Coverage %: Yes
Coverage Strength: 128.74 hits per line

💛 - Coveralls

@donny-wong
donny-wong requested a review from Naragod August 17, 2026 20:24
@donny-wong donny-wong modified the milestones: v2.10.2, v2.10.3 Aug 18, 2026
@donny-wong
donny-wong force-pushed the canvas_prevent_non_instructor_course_creation branch from c5aa0ed to ef87752 Compare September 1, 2026 13:32

@Naragod Naragod left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Update the changelog and you are good to go.

@Naragod
Naragod requested a review from david-yz-liu September 8, 2026 17:45
@donny-wong
donny-wong force-pushed the canvas_prevent_non_instructor_course_creation branch from ef87752 to ff60fd3 Compare September 8, 2026 19:09

@david-yz-liu david-yz-liu left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work, @donny-wong!

@david-yz-liu
david-yz-liu merged commit 60a442b into MarkUsProject:master Sep 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants