hypothesis / hypothesis/lms

Gather requirements for the LTI 1.1 Security Update

Open
#876 2 comments 0 reactions 0 assignees View on GitHub
Spike
Dominant language
Python
Stars
53
Forks
16
Avg merge
14d 5h
Merged PRs (30d)
14

Description

From #850.

In order for us to pursue IMS certification after 31st December 2019, we need to implement either LTI 1.3 or a ["Security Update" to LTI 1.1](https://www.imsglobal.org/spec/lti/security-update/v1p0).

The security update may be a small-enough amount of work compared to LTI 1.3 that it would be worth doing before we come to LTI 1.3. This also involves investigating the support for this change with the various major LMSes.

The "Security Update" does not explain what issue exactly is mitigated, but it mentions an XSRF attack. A detailed explanation with worked example of the security issue can be found here: https://community.brightspace.com/s/article/Update-on-LTI-Vulnerability-LTI-Launch-with-New-Security-Requirements.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.