Register for InstructureCon25 • Passes include access to all sessions, the expo hall, entertainment and networking events, meals, and extraterrestrial encounters.
Found this content helpful? Log in or sign up to leave a like!
Hi,
We've identified a potential security and privacy issue with SCORM packages uploaded via the SCORM LTI tool in Canvas. When a SCORM package is embedded or added as an assignment, the content is hosted on a public domain (e.g. https://dub.scorm.canvaslms.com
) and can be accessed without authentication if someone has the direct link.
This is easy to replicate — for example, a student can right-click on a menu item or embedded SCORM player, copy the link address, and share it. The content then loads outside of Canvas, with no login or tracking required.
We came across the setting ApiUseSignedLaunchLinks=true
However, we’re unsure what modifications are required in the SCORM package itself to support this.
Could someone clarify:
What steps are needed to make a SCORM package compatible with signed launch links in Canvas?
Is this feature officially supported, and is there any technical documentation available?
Is the SCORM player hosted by Rustici, and if so, does it support or require specific setup for this feature?
We’re looking for a more secure workflow to protect SCORM-based content and assessment materials. Any guidance would be greatly appreciated.
Thanks!
Hi @GarethLogan,
I do not have an answer for you but have you reported this concern to directly to Canvas Support or to your Canvas CSM?
For this type of situation, it (probably) is not possible for someone (e.g. an LMS admin or LMS user) to work around Canvas' implementation of SCORM.
-Doug
thanks for the reply @dbrace yes we have reached out to both now and awaiting a reply.
You are welcome, @GarethLogan, and thank you for doing that.
-Doug
@GarethLogan, did you hear anything back from Canvas Support.
-Doug
This seems like an oversight from Canvas. Allowing any an all content to be accessible on public links when uploaded as SCORM would surely be a bit of a problem for any institution that cares about their content and IP.
Even ancient Blackboard 8 managed it better than this.
To interact with Panda Bot in the Instructure Community, you need to sign up or log in:
Sign In