Forums | Mahara Community

Support /
Canvas Admins can access to Mahara's users account


19 December 2019, 13:03

Hi,

I have recently integrated Mahara into one of the Canvas courses. Canvas admins can act as a user and when they click on Mahara integration link while they are acting as a user they can access Mahara's account for this user, even when they don't have admin access to Mahara.

That's mean any Canvas admin will be able to access to all Mahara users' content without permission.

Mahara ver: 19.04.1

Is there a way to prevent this?

Kristina Hoeppner's profile picture
Posts: 4729

23 December 2019, 15:37

Hi Mays,

It is correct that at the moment someone masquerading as a person in the LMS can go through to the portfolio and end up in the same account. I don't know if there is an existing function to prevent that for LTI accounts or not. Does that also happen when you use other LTI services?

When we used MNet with Moodle, Moodle prevented the masquerading. So I'm wondering if it is something that the LMS would need to implement rather than Mahara.

I created an item on our tracker where we can gather info when someone investigates this.

Thanks

Kristina

2 results