Configurable Reports

Maintained by Sara Arjona, Juan Leyva
This block is a Moodle custom reports builder. You can create custom reports without SQL knowledge. It's a tool suitable for admins or teachers.
Price option: Free

Supports Moodle 1.9-5.2 See all versions
Latest release: 2 months ago
Installations: 16046
Downloads (last 90 days): 3421

Frankenstyle name: block_configurable_reports
Blocks

Comments

Comments are no longer open for new posts. Existing comments remain available to read.

That was my mistake, where is the AI when you need it?... but I can also say I was planning for the future smile
I'll have to leave it like this to avoid breaking people that already updated
Hi Juan and Sarah,
Did you mean to do a release number 2027050401 (2027 is next year)?
Best regards,
Michael
Hi — I want to report a critical vulnerability in this plugin. Impact: any teacher account on a site with this block enabled can escalate to full database read access (admin password hashes, all user data) and ultimately to RCE as www-data by self-granting managesqlreports, creating a SQL-type report, and uploading a malicious plugin once the admin hash is cracked. The plugin's per-instance safe-override UI (block/instances/edit.php + permissions.php) lets any editingteacher self-grant block/configurable_reports:managesqlreports, after which reports/sql/report.class.php:execute_sql() runs attacker-supplied SELECT directly against the Moodle DB (PT-confirmed live: SELECT @@version returned MySQL 8.0.42 from production). 4 additional student-reachable unparameterised SQL sinks live in reports/sql/report.class.php and 3 of the filter plugins. Fix: restrict managesqlreports to the site-administrator archetype only (remove it from safe-override entirely), and parameterise every $DB->execute() / get_records_sql() call via placeholders.
This plugin has become a bit buggy when running on Moodle 4.5.8, with some deprecated function error messages appearing. Do you think you will be releasing a newer version anytime soon? Thank you.
When will there be an update to Moodle 5.1?
Any chance of upgradeing this plugin to Moodle 5.x any time soon?
Olá tudo bem? este plugin funciona no Moodle 5.+ ?
@John, you haven't specified HOW you are applying the filter in your sql query, so we don't have much to go on... But try this:
SELECT grc.description AS Rubric_Description,
asg2.name AS Assignment_Name
FROM ...
WHERE ...
%%FILTER_SEARCHTEXT:CONCAT(grc.description,' ',asg2.name):~%%
Each of the columns that you want to be searchable must be included in the %%FILTER_SEARCHTEXT:...:~%% filter parameter.
You should use the Configurable Reports FORUM for questions like this. See https://moodle.org/mod/forum/view.php?id=7979
We use Totara (built off of Moodle) and had Configurable Reports installed. However, the search only appears to work on the first field in the SQL query. Can you change the Configurable Reports to search on all fields in the Reports you create.
Here is the start of the SQL:
SELECT grc.description AS Rubric_Description,
asg2.name AS Assignment_Name
The search is NOT working on Assignment_Name, only on Rubric_Description in this example.
Thank you for your time.
Hi, will you be supporting Moodle 5?
Hi
I hope you are well, it's been ages. Block Reports appears to work on Moodle 5. Could you update the supported extension on your end to Moodle 5 so that it installs automatically each week when we update our Moodle instance? It saves us so much time. Cheers.
Hi,
In moodle 4.5 in RTL languages it's hard to move the mouse inside the SQL editing zone.
The cursor can be moved by using keyboard arrows but not the mouse itself.
Hi Team,
We are using Moodle version 4.5.4+ (Build: 20250502) with plugin version 2024051300, and we’ve noticed that the plugin uses the deprecated function get_all_user_name_fields() in multiple places.
As of recent Moodle versions, it seems this function has been deprecated and removed from core. It should be replaced maybe with: \core_user\fields::get_name_fields().
Regards
Question: why statement
%%FILTER_SEARCHTEXT_lastname:uu.lastname:~%%
works, but case insensitive does not ?
%%FILTER_SEARCHTEXT_lastname:uu.lastname:~*%%
it is error or by design ?
Absolutely Zoran. To load results after applying filters or parameters is what is missing in this plugin. It would be perfect with it.