    Kristina Hoeppner
      Bug 1793943: Review new language strings · b125a378
      Kristina Hoeppner and Robert Lyon
      Go over new language strings since 18.04
      and fix them up where necessary. Those that
      only have impact on English do not receive a
      new language ID.
    Gregor Anzelj
      Bug 1743870: Moderate portfolios of regular users · 4e5e0aae
      Gregor Anzelj and Robert Lyon
      Allow institution admins and site admins to immediately remove all
      sharing options from a page (or collection if the page is within
      a collection) that is deemed objectionable.
    Mark Webster
      Bug 1771362: Fix timezone issues. · bc25beec
      Mark Webster and Robert Lyon
      Adds timezone dropdown the site settings. If no timezone selected
      it uses site settings country to determine correct timezone and sets
      that in the database.
      PHP and DB session timezones will then assume this setting for all times.
      This makes setting $cfg->dbtimezone obsolete - there is a warning to
      admins to update their timezone setting on admin dashboard.
      - A timezone or country MUST be selected in site options.
      - Will not correct existing incorrect times, as no timezone info was
      stored in the DB for dates/times, so it's impossible to determine what timezone
      was used when saving.
      - Changing the timezone will not adjust the display of existing times, for the
      same reason.
    Rebecca Blundell
      Bug 1765674: Make registration revokable and data always visible · 50a14e7a
      Rebecca Blundell and Robert Lyon
      - changed some lang strings to make them work whether registered or not.
      - made Registration box always visible
      - added functionality to remove registration
      - removed option to change email setting. Registration means sending
      - added registration_firstsent field to use for telling the admin how
        long their site has been regiestered.
      - removed switch for "Send weekly updates" from "Site options" page as
        it seemed confusing to have it in 2 places with different wording.
      - updated failing behat tests
    Robert Lyon
      Bug 1760767: Create a cli script to allow for bulk delete of users from commandline · 2dbbe1fb
      Robert Lyon authored
      To allow a server admin to clean up a site
      The script should be able to:
      - delete all users that have never logged in (created by admin)
      - and/or delete all users that have not logged in since a certain date
      - and/or delete only those users from a certain institution
      The script has a 'dryrun' flag set to false by default to allow one to
      check how many users will be deleted before actually doing the deletion
      - do more checks
    Robert Lyon
      Bug 1748782: Fix clash of 'active' values in user search results · 6b8396d6
      Robert Lyon and Kristina Hoeppner
      We were confusing user active with auth active values from db call
      So changed the auth 'active' to 'authactive'
      Also add warning message to top of admin/users/edit.php page to
      indicate that user has expired (similar to when user is suspended)
    Gregor Anzelj
      Bug 845263: Password policy · 9c26c145
      Gregor Anzelj and Robert Lyon
      Improve the password policy enforcement and configuration in Mahara.
      Have a pre-defined password policy of a minimum of 8 characters with
      type "alphanumeric mixed case + symbols".
      Also allow site administrators to set the desired password policy in
      Site Options > Security Settings. In all locations where password
      is set, the password input should also include a password strength
    Cecilia Vela Gurovic
      Bug 1734178: allow user to delete own account · 9837f182
      Cecilia Vela Gurovic and Robert Lyon
      added settings
      - institution level: reviewselfdeletion
          0 if the institution does not require approval
            from an admin to delete an account
          1 if the institution requires an admin to approve
            account deletion requests from users
          if not set, it takes the value from the site's
      - site level: defaultreviewselfdeletion
        (Site options->User Settings -> Review account before self-deletion)
          1 if the site's default is requiring approval
          null otherwise
      Account deletion by a user
      when a user accesses to the account settings, a
      'Delete account' button is displayed.
      This will:
      - If the user belongs to an institution that requires
        approval (or does not have the settings but the site
        requires approval by default)
          then a notification will be sent to the admins
          of the institutions that require approval that
          the user belongs to
      - if the user belongs to institutions and none of them
        require approval (or does not have the setting
        but the site does not require approval by default)
          then the account is deleted
      - if the user does not belong to any institution
          then the action will depend on the setting of
          the 'mahara' institution or sites default if
          'mahara' doesn't have the setting
      Approval by institution admins
      An institution admin can see the pending deletion
      requests in Admin menu-> Institution -> Pending deletions
      After approving/denying a request, the user
      that requested the account deletion will receive
      a notification
    Maria Sorica
      Bug 1734174: Add the after login privacy page · 44a6284e
      Maria Sorica authored
      Upon login, if the user has not yet agreed to the most
      recent Privacy statement versions, he will be redirected
      to this page.
      On install admin user accepts default privacy
    Cecilia Vela Gurovic
      Bug 1739688: 'Strict privacy switch' · ae6c3fd9
      Cecilia Vela Gurovic authored
      Created switch in site options. When set to 'yes',
      it disables the multiple institution per user switch.
      To do: When set to 'yes', force user to accept T&C
      and privacy statement. Will be resolved in another
      bug report #1741799
