Skip to content

Enforce privileged LTI launch role for course linking and creation - #8130

Open
donny-wong wants to merge 4 commits into
MarkUsProject:masterfrom
donny-wong:canvas_prevent_non_instructor_course_creation
Open

Enforce privileged LTI launch role for course linking and creation#8130
donny-wong wants to merge 4 commits into
MarkUsProject:masterfrom
donny-wong:canvas_prevent_non_instructor_course_creation

Conversation

@donny-wong

Copy link
Copy Markdown
Contributor

Proposed Changes

(Describe your changes here. Also describe the motivation for your changes: what problem do they solve, or how do they improve the application or codebase? If this pull request fixes an open issue, use a keyword to link this pull request to the issue.)

Currently the Canvas role check only decides where to redirect after an LTI launch — it is not enforced on the pages themselves. This means any logged-in MarkUs user could go directly to the choose_course URL and create a course, even if they are a student on Canvas. This PR fixes that: a successful privileged launch is now recorded in the session, and choose_course/create_course return a 403 "Launch Required" page unless the user launched that deployment from the LMS with an instructor role. Also re-enables CSRF protection on create_course. Specs updated with tests for the forbidden cases.

Screenshots of your changes (if applicable)

Type of Change

(Write an X or a brief description next to the type or types that best describe your changes.)

Type Applies?
🚨 Breaking change (fix or feature that would cause existing functionality to change)
New feature (non-breaking change that adds functionality)
🐛 Bug fix (non-breaking change that fixes an issue) x
🎨 User interface change (change to user interface; provide screenshots)
♻️ Refactoring (internal change to codebase, without changing functionality)
🚦 Test update (change that only adds or modifies tests)
📦 Dependency update (change that updates a dependency)
📖 Documentation update (change that updates documentation)
🔧 Internal (change that only affects developers or continuous integration)

Checklist

(Complete each of the following items for your pull request. Indicate that you have completed an item by changing the [ ] into a [x] in the raw text, or by clicking on the checkbox in the rendered description on GitHub.)

Before opening your pull request:

  • I have performed a self-review of my changes.
    • Check that all changed files included in this pull request are intentional changes.
    • Check that all changes are relevant to the purpose of this pull request, as described above.
  • I have added tests for my changes, if applicable.
    • This is required for all bug fixes and new features.
  • I have updated the project documentation, if applicable.
    • This is required for new features.
  • If this is my first contribution, I have added myself to the list of contributors.

After opening your pull request:

  • I have updated the project Changelog (this is required for all changes).
  • I have verified that the pre-commit.ci checks have passed.
  • I have verified that the CI tests have passed.
  • I have reviewed the test coverage changes reported by Coveralls.
  • I have requested a review from a project maintainer.

Questions and Comments

(Include any questions or comments you have regarding your changes.)

@coveralls

coveralls commented Aug 17, 2026

Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 32064400081

Coverage increased (+0.006%) to 90.638%

Details

  • Coverage increased (+0.006%) from the base build.
  • Patch coverage: 53 of 53 lines across 2 files are fully covered (100%).
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 51815
Covered Lines: 47983
Line Coverage: 92.6%
Relevant Branches: 2491
Covered Branches: 1239
Branch Coverage: 49.74%
Branches in Coverage %: Yes
Coverage Strength: 129.65 hits per line

💛 - Coveralls

@donny-wong
donny-wong requested a review from Naragod August 17, 2026 20:24
@donny-wong donny-wong modified the milestones: v2.10.2, v2.10.3 Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants