Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential concern of users viewing ltijs as an LTI "shim" #215

Open
danny-does-stuff opened this issue Mar 6, 2024 · 0 comments
Open

Potential concern of users viewing ltijs as an LTI "shim" #215

danny-does-stuff opened this issue Mar 6, 2024 · 0 comments
Assignees
Labels
enhancement New feature or request

Comments

@danny-does-stuff
Copy link
Contributor

I am very grateful for your work with ltijs and providing great open source software! I wanted to bring this to your attention in case it may be something you would like to be aware of.

I came across this document put out by 1EdTech advising against the use of what they call "LTI shims". It defines a shim as "an intermediary piece of software that bridges the connection between two systems". It goes on to explain that a "platform-hosted" or "tool-hosted" shim is ok, but that "Third Party" shims pose various security risks and should be avoided by educational tools.

I believe that ltijs fits their definition of a "shim", and that it falls squarely into the "tool-hosted shim" category. This means that it is not the type of software that 1EdTech is advising against, but potential users may still be wary of any type of shim, and therefore be more wary of ltijs.

There's nothing really actionable here, this is simply something that I came across today and thought it may be valuable for you to know as well! The document goes on to say that "In 2024, the certification process will be strengthened to add additional checks to ensure the LTI 1.3 connection for a tool is direct to the tool and not via 3rd party providers." I hope you find this information useful, and thanks again for this great open source solution!

@danny-does-stuff danny-does-stuff added the enhancement New feature or request label Mar 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants