Diferencia entre revisiones de «Riesgos»

De MoodleDocs
mSin resumen de edición
Línea 1: Línea 1:
{{Roles}}
{{Roles}}
{{Moodle 1.7}}
{{Pendiente de traducir}}
{{Pendiente de traducir}}
Esta página describe los riesgos que puede tener cada permiso. (Esta página está incompleta y es necesario añadir más información.)


Careful consideration should be given to the risks involved in allowing different capabilities.
==Configuración==
==Configuración==
Los usuarios podrían cambiar la configuración y el comportamiento del sitio
Certain capabilities, such as [[Capabilities/moodle/site:doanything|moodle/site:doanything]] are intended for administrators only, as they enable users to change the site configuration and behaviour.


==XSS ('''Scripting''' a través del sitio)==
==XSS (Cross-Site Scripting)==
Los usuarios podrían agregar archivos y textos que permiten '''scripting''' a través del sitio (XXS).
Certain capabilities enable users to add non-checked files and HTML code containing JavaScript etc. This may be misused for cross-site scripting (XSS) purposes, with the potential to gain full admin access. These capabilities are intended for administrators and teachers only.


==Privacidad==
==Privacy==
Los usuarios podrían acceder a información privada de otros usuarios
Certain capabilities enable users to gain access to private information of other users, for example non-public information in a user's profile. These capabilities are intended for administrators and teachers only.


==Spam==
==Spam==
Línea 22: Línea 21:
* Teacher - certain capabilities with XSS and privacy risks are allowed
* Teacher - certain capabilities with XSS and privacy risks are allowed
* Administrator - all capabilities are allowed
* Administrator - all capabilities are allowed
==See also==
* [[Development:Hardening new Roles system]]
* [[Capabilities/moodle/site:trustcontent]]


[[Category:Administrador]]
[[Category:Administrador]]

Revisión del 06:29 12 jul 2009


Nota: Pendiente de Traducir. ¡Anímese a traducir esta página!.     ( y otras páginas pendientes)


Careful consideration should be given to the risks involved in allowing different capabilities.

Configuración

Certain capabilities, such as moodle/site:doanything are intended for administrators only, as they enable users to change the site configuration and behaviour.

XSS (Cross-Site Scripting)

Certain capabilities enable users to add non-checked files and HTML code containing JavaScript etc. This may be misused for cross-site scripting (XSS) purposes, with the potential to gain full admin access. These capabilities are intended for administrators and teachers only.

Privacy

Certain capabilities enable users to gain access to private information of other users, for example non-public information in a user's profile. These capabilities are intended for administrators and teachers only.

Spam

Certain capabilities enable users to add content to site, for example forum posts, account creation, and send messages to other users. These capabilities may be misused for spamming purposes.

Risks for predefined roles

  • Guest - only capabilities without any risks are allowed
  • Student - certain capabilities with spam risks are allowed
  • Teacher - certain capabilities with XSS and privacy risks are allowed
  • Administrator - all capabilities are allowed

See also