Uploaded image for project: 'Sakai'
  1. Sakai
  2. SAK-2141

Possibility of student modifying their assignment grades

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: CLOSED
    • Priority: Blocker
    • Resolution: Fixed
    • Affects Version/s: 2.0, 2.0.1
    • Fix Version/s: 2.1.0
    • Component/s: Assignments
    • Labels:
      None

      Description

      There is a way that a student can access their instructor's 'grade' view and modify grades, or modify an assignment. It is an obscure way, but nevertheless possible.

      What I did is to right-click on an assignment and chose 'send link'. This gave me the entire URL of the assignment. This is an example:
      https://testctools.ds.itd.umich.edu/portal/tool/7652851f-3781-49d5-80a3-e7195ca8849e?sakai_action=doView_submission&panel=Main&assignmentReference=/assignment/a/260472a9-6bd4-4da6-00e5-685465274d24/d520ffaf-55cb-4b00-0025-6af47e886712

      I logged in as the instructor of that same site and opened up the URL for the 'grade' link of that same assignment. This is the link I got:
      https://testctools.ds.itd.umich.edu/portal/tool/7652851f-3781-49d5-80a3-e7195ca8849e?sakai_action=doGrade_assignment&panel=Main&assignmentId=/assignment/a/260472a9-6bd4-4da6-00e5-685465274d24/d520ffaf-55cb-4b00-0025-6af47e886712

      If you are a student in the class and type in the last URL, then you get the same access as the instructor's grade option. You can change grades and such.

      There isn't a lot of differences between the two links above:
      change doView_submission to doGrade_assignment and Reference to Id

      Student might learn of the structure of the links by creating a site themselves, viewing the links and trying it themselves.

        Gliffy Diagrams

          Zeplin

            Attachments

              Activity

                People

                Assignee:
                Unassigned Unassigned
                Reporter:
                mcuriel Moises Curiel (Inactive)
                Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                  Dates

                  Created:
                  Updated:
                  Resolved:

                    Git Integration