Activity Feed
- Posted Re: Mobile Session Expiration on The Product Blog. 11-10-2022 06:03 AM
- Posted Re: Log Off all Devices on Idea Conversations. 11-10-2022 05:58 AM
- Got a Kudo for Re: Mobile Session Expiration. 08-17-2022 11:04 AM
- Got a Kudo for Re: Mobile Session Expiration. 07-25-2022 06:54 AM
- Posted Re: Printable course roster on Canvas Ideas. 07-22-2022 10:45 AM
- Posted Re: Mobile Session Expiration on The Product Blog. 07-22-2022 10:40 AM
- Kudoed Re: Mobile Session Expiration for rake_9. 07-22-2022 10:40 AM
- Kudoed Mobile Session Expiration for jozsefdavid. 07-22-2022 10:24 AM
- Posted Re: Log Off all Devices on Idea Conversations. 12-03-2021 02:18 PM
- Got a Kudo for Re: Default expiration date for access tokens?. 09-15-2021 04:09 PM
- Got a Kudo for Re: My Calender view changed, is there any way to change it back to the old calendar? . 08-06-2020 02:03 AM
- Got a Kudo for Re: Can anyone tell me how Power School works with Canvas?. 08-06-2020 01:59 AM
- Kudoed Ability to View HEIC files in SpeedGrader Preview for jlmckown. 04-27-2020 11:56 AM
- Got a Kudo for Re: My Calender view changed, is there any way to change it back to the old calendar? . 04-21-2020 05:24 PM
- Posted Re: My Calender view changed, is there any way to change it back to the old calendar? on Canvas Question Forum. 04-21-2020 11:33 AM
- Kudoed Re: Canvas Release Notes (2020-03-21) for venitk. 02-20-2020 06:27 AM
- Posted Re: Log Off all Devices on Idea Conversations. 01-13-2020 10:46 AM
- Posted Re: Log Off all Devices on Idea Conversations. 03-27-2019 09:09 AM
- Posted Re: Log Off all Devices on Idea Conversations. 03-27-2019 09:07 AM
- Kudoed Re: Default expiration date for access tokens? for ben_hudson. 03-26-2019 11:06 AM
My Posts
Post Details | Date Published | Views | Kudos |
---|
11-10-2022
06:03 AM
@jozsefdavid Do we have any updates on the implementation of this "feature"?
... View more
11-10-2022
05:58 AM
@danielcktan Yes... this is exactly the problem with not having some sort of functionality that allows Admin access to reset and expire all tokens.
You can contact Instructure Support to get them all expired and locked out... and a button would be better.
Been asking about forever tokens for about 7 years. Sorry to hear this...
... View more
07-22-2022
10:40 AM
3 Kudos
Great to see this... two additional features that would be fantastic would be "kick this user now" and "kick all users now" from the back end... The use case for this (that's not listed above) is that many colleges (and we K-12 institutions) use external authentication methods (in our case, LDAPS via AD). When we have a kid that withdraws from the school, we disable their account in Active Directory. Regrettably, that student still has access to their Canvas courses via the App. We currently have to contact Support to force expire all tokens to kick them from the app. Typically, we would use this option at password change time when we *really* want students to update their passwords... we can communicate a time for this to happen and not worry about students that may be doing something because they've been warned. thanks, Jamie
... View more
12-03-2021
02:18 PM
OMG. Thank you @Stef_retired . You literally just made my year. Now if we can just get it done before California only sells electric cars...
smiles,
Jamie
... View more
04-21-2020
11:33 AM
1 Kudo
Hi Stefanie, Admin here... Sophie is using an iPad. I'm guessing that the last update to the Canvas app changed the way that calendars work. No custom work on our end... and any custom work wouldn't affect the iPad app in any case. Also no toggle... I'll let her know. smiles, Jamie
... View more
01-13-2020
10:46 AM
The Student App NEVER logs out, so there's no need for that button on the iOS app. Forever tokens means "forever"... smiles, Jamie
... View more
03-27-2019
09:09 AM
Also agreed... since our CMS is able to ask engineering to do this, it's scriptable at some level. I'd love to see "nuke one" and "nuke all" commands for Admins. And I LOVE LOVE LOVE the idea behind "disallow mobile access"... with all of the issue with the mobile versions of Canvas, this would *force* students to use the full, web version (which would log them out after 15 minutes of inactivity, but I digress...)
... View more
03-27-2019
09:07 AM
Agreed... no need for hours, just add option for "Now", "Every XX" days, and "Yearly on XX date". I don't see the issue with forcing all users to reauthenticate into the app... they enter their password to get on the wireless, check their e-mail, and access grades in our SIS... why not on our LMS?
... View more
03-26-2019
11:01 AM
1 Kudo
Hi Ben, I've been yelling about this for years... but with the way that ideas work around this place, it may be another 4 years before we get any motion on this issue. Looks like the only way we'll get any traction on this basic security issue is to ask our student bodies to up vote the issue. I tried some time ago, but it got squashed. https://community.canvaslms.com/ideas/6628 As a side note, you can request all tokens to get expired from your CSM. We have to do this twice yearly when passwords change, but I'm completely uncomfortable with student's grades being accessible from a device when their account has been expired in AD. Ugh. Welcome to the nightmare... smiles, Jamie
... View more
03-26-2019
10:55 AM
Hi Susan, This is how "other apps" handle the "forever token" issue (they log out of all devices by default when passwords are changed). When I originally brought this up with our CSM, the answer back from Product Development/Engineering was "Well, everyone does it this way."... so I tested it. Facebook does it this way as did most of the other apps that "remembered" logins. In checking around, I also found out that Schoology follows Canvas with their mobile app with the forever token. Doesn't Instructure want to be able to tell folks that they have better security than Schoology? Looks like it's time to sic everyone on this one. smiles, Jamie
... View more
01-31-2018
02:13 PM
I had previously requested that Instructure get off their collective tails and implement a fix for this to match the security of the website, but they've made it very clear that iPads will always be second class citizens on this platform. Short version: Website: 15 minutes of no activity = logoff iPad app: forever tokens = never log off ever for anything even if someone's account is disabled, password changed or other actions. It's just not acceptable and may be in violation of other regulations that require systems to protect student information by logging out after some timeout period. I'm going to ask all of our faculty to vote on this one to see if we can get their attention. BTW You can request an "everyone logout" from your CSM to expire all accounts on some date or time. For now, it has to go through engineering to happen... thus the need for contacting your cheerleader um... CSM for help. thanks, Jamie
... View more
01-31-2018
11:43 AM
Hi Renee, Thank you for confirming that security is off topic for Instructure. Yes, I did submit this as a feature idea... and as a support ticket. No traction at all... and this confirms it. smiles, Jamie
... View more
01-31-2018
11:34 AM
4 Kudos
During this security meeting, was there any talk about making the security on the iOS app match the website? Website = log out after 15 minutes of no activity iOS app = NEVER LOG OUT EVER EVEN IF PASSWORD IS CHANGED I'd argue that this is a much larger issue than the security issues surrounding Javascript... smiles, Jamie
... View more
12-01-2016
10:48 AM
2 Kudos
Not 100% sure why Todd is looking at Clever (although I have some ideas), but you don't need an additional package for the integration to "work". Honestly, it's so simple that you'll overthink it (like I did) and do a few days of database work to set up Canvas. Not necessary... here's how it works: 1. Set up your schedules/courses/attendees in PowerSchool 2. Let your CSM know that the new year is in and that it's time for a new year in Canvas. 3. Open Canvas the next day and *pow* it's done. Canvas automagically sets up: Teacher accounts Student accounts Sections Courses Student and teacher assignments to sections and courses It also, as Todd mentions above, updates based on changes on the PowerSchool side... so you just need to move Sally from Algebra 1, first period to Algebra 1, 3rd period in PowerSchool and she will move overnight. One of the reasons Todd may be looking at Clever has to do with how GPB works with grades that are entered in PowerSchool... that is, they NEVER get back to Canvas. This is not a criticism (that's the way it's supposed to work), but his situation may require a full set of grades in Canvas *and* in PowerSchool. In our case, we do not allow parent access to Canvas and tell students and parents that the only grades that count are the ones they see in PowerSchool. Of course, right now there are some issues with Canvas and PowerTeacher Pro that are holding up our move to PowerSchool 10 (the current version), so you may want to speak with Instructure about how critical that function is for you before jumping in... :smileyconfused:
... View more