Close the gaps an audit of courses, tasks, files and grades turned up
Every area — courses, rooms, boards, topics, tasks, files, quizzes, teams,
groups, submissions, grades — was checked for data the instance has and the
tools did not show.
Grades and feedback. A teacher's /homework page is a different page from a
student's: grade and comment live in the grading form, one block per
submission, so a teacher account reported every graded submission as having
neither. parseTeacherGrading reads the form, and list_submissions can now
include the written feedback and who handed the work in.
Names. /api/v1 is partly served: courses, users and classes survive in the
deployment's ingress table, and users/{id} is the only route from an id to a
name. Submitters, file creators and course teachers resolve through it, and
degrade to "not visible to this account" where a student may not read them.
Courses, rooms and classes. get_course adds the description, teachers,
member count and weekly timetable from /api/v1/courses. list_classes is new.
get_room reports what the account may do — allowedOperations is an object of
booleans, not the list it was typed as — and applicants and invitation links
where it may manage them.
Board and topic content. Link descriptions, image alt text, drawing and
video-conference titles, the ids behind external tools and H5P content (the
only thing resembling a quiz), and what a deleted element used to be. Topic
Etherpad pads are read like board pads, and htmlToText keeps table columns
apart and drops template indentation.
Files. A scan with no text layer falls back to the preview endpoint, whose
width and outputFormat are undocumented enums, so Claude gets a picture of
the page; list_files reports counts and sizes. Teams stay documented as
unreadable at any API version; their files come later.
What the crawl missed. Tasks attached to topics (18 of 60 on the live
account), each course's own file area, and — behind INDEX_PERSONAL_FILES —
personal files and submissions with their grade comments, so search and
what_changed cover grading. A submission hit points at get_task.
The local instance's preview profile gets an ImageMagick policy that allows
the coders its 7.1.2 build needs; the image's own denies them all.
110 tests.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -252,6 +252,17 @@ plain HTTP locally.
|
||||
|
||||
**A file uploads but will not download.** See the `av` note above.
|
||||
|
||||
**Previews never appear, and `/api/v3/file/preview/...` answers 404
|
||||
PREVIEW_NOT_POSSIBLE.** Two causes, both local. First, with no virus scanner
|
||||
(see the `av` note) every upload stays `securityCheck.status=pending`, and a
|
||||
record that has not been scanned reports `previewStatus: awaiting_scan_status`
|
||||
— previews are gated on the scan. Second, the `file-preview` image ships an
|
||||
ImageMagick policy written for an older ImageMagick than the 7.1.2 it actually
|
||||
contains, so every coder it needs is denied and each attempt fails with
|
||||
*"attempt to perform an operation not authorized by the security policy"* —
|
||||
which the API surfaces as a 404. `file-preview/policy.xml` is mounted over the
|
||||
image's own to fix the second; the first is inherent to running without `av`.
|
||||
|
||||
**H5P element stays empty.** `docker compose --profile tools run --rm
|
||||
h5p-libraries` and watch it finish; the editor has nothing to offer until the
|
||||
content types are in the bucket.
|
||||
|
||||
Reference in New Issue
Block a user