Quilgo Proctoring for Canvas
Quilgo Proctoring Canvas installation guideРуководство по установке в Canvas

Installing Quilgo Proctoring in Canvas

Quilgo Proctoring is installed once for your whole Canvas account. The setup has two parts: an LTI 1.3 app, and one proctoring snippet in your Canvas theme. Both are required.

For Canvas administrators ≈ 10 minutes LTI 1.3

Before you begin

Register the app

Quilgo supports Canvas automatic (dynamic) registration, so there is nothing to type by hand.

  1. In Canvas, go to Admin → Developer Keys → + Developer Key → LTI Registration.
    Developer Keys → + Developer Key → LTI Registration.
  2. Paste the registration address:
    https://quilgo-host/lti/register
    Paste your Quilgo registration address and click Continue. The address in the example points at a test server.
  3. A Quilgo page opens inside Canvas. Click Install.
    The Quilgo page inside the Canvas dialog — click Install.
  4. When Canvas shows its confirmation dialog, click the Enable & Close button.
    Canvas shows the permissions and placements it is about to create — click Enable & Close.

Turn the key on and make the app available

Canvas has now created the new key. Ensure it is ON and follow these steps to activate it:

  1. Go to Developer Keys, find Quilgo Proctoring and make sure its State is ON (switch it if it isn’t).
    The Quilgo Proctoring row in Developer Keys — State must be the green toggle.
  2. Open the key’s View in Canvas Apps link. Under Availability and Exceptions, click the edit (pencil) button, set the app to Available, and click Save.
    View in Canvas Apps sits in the key’s Details column.
    On the app page, open Availability and Exceptions and click the pencil button.
    Switch Not Available → Available, then Save.
  3. Reload the page — Quilgo Proctoring appears in the Admin sidebar.

Upload the proctoring snippet to your theme

  1. Download the snippet: in the Canvas left navigation open Admin → your account, then click Quilgo Proctoring in the account menu on the left (it appeared there after Step 2). On the page that opens, click Download Proctoring snippet — this saves quilgo-canvas.js to your computer.
    The account-level Quilgo Proctoring page, opened from the Admin sidebar.
    In Integration & Install Health, click Download proctoring snippet.
  2. Go to Admin → Themes, open your active theme in the Theme Editor and make sure the Upload tab is visible.
    Admin → Themes — hover your current theme and click Open in Theme Editor.
    The Upload tab with the JavaScript file slot.

    No Upload tab? Go to Admin → Settings, scroll to the bottom of the account settings page, tick Custom CSS/JavaScript overrides, save, then reopen the Theme Editor.

    Admin → Settings → Features: tick Custom CSS/JavaScript overrides.
  3. On the Upload tab, check whether a JavaScript file is already uploaded:
    • No file: nothing to combine — you will upload the downloaded quilgo-canvas.js as is.
      An empty JavaScript file slot — nothing to preserve, upload the snippet as is.
    • A file already exists: click the View File button next to the JavaScript file uploader and save the file to your computer. Open both files in a text editor and paste the snippet’s entire code at the very end of your existing file. Save the result with a .js extension and continue with the combined file.

      Important: add the snippet at the end of the file. Canvas allows only one JavaScript file per theme — uploading the snippet alone would replace your existing code.

  4. Upload the file in the JavaScript file slot on the Upload tab.
  5. Click Preview Your Changes, then Save theme and Apply theme.
    The file is attached — click Preview Your Changes, then Save theme in the green bar.

Activate your account

Until the account is activated, proctoring settings in quiz menus stay locked: teachers see “Please ask your administrator to activate the account to enable proctoring”, and administrators see the activation button right there.

  1. In the Admin sidebar, open Quilgo Proctoring and click Activate your account. The same button sits in two places on that page — at the bottom of Subscription Overview, and in the Activation account row of Integration & Install Health; either one opens the Quilgo dashboard on the sign-up page.
    Both entry points: the button under Subscription Overview and the link in the Activation account row.
  2. Create your Quilgo account there (or log in if you already have one) and confirm your email. The dashboard already knows which Canvas site you arrived from — create an organization (it holds billing, licences and team access) and click Connect site to finish the link.
    Sign up with an email address, or continue with Google.
    After confirming the email, click Log into my dashboard.
    The Canvas site is already identified; name the organization and click Connect site.
    Confirmation that proctoring is now active on the site.
  3. Back in Canvas, refresh the Quilgo Proctoring page — the Activation account row in Integration & Install Health should turn Active, and proctoring settings unlock for teachers.

Verify the installation

  1. In the Canvas Admin sidebar, open Quilgo Proctoring.
  2. Check the Integration & Install Health panel: Registration, Activation account and Proctoring integration should all read Active, and Theme file last seen should show a recent time (it refreshes within a few minutes of anyone viewing a Canvas page — reload a Canvas page, then refresh this panel).
    A finished installation: all three rows Active, a recent Theme file last seen, and the plan visible in Subscription Overview.
  3. Run a real test: open any quiz, choose Quilgo Proctoring from the quiz menu, tick Enable proctoring, pick the tracking methods and Save, then take the quiz as a test student. Open it with View as Student: before the attempt starts, a Start attempt dialog lists the tracking you switched on and asks for exactly those permissions — screen, camera, or both. Nothing is requested for methods you left off.
    The quiz ⋮ menu in Quizzes — Quilgo Proctoring is the last entry.
    Turn Enable Proctoring on, then pick the tracking methods and Save Settings.
    View as Student, top right of the course, opens Canvas as a test student.
    The student's Start attempt dialog — here only screen tracking was on, so it asks for screen access.

That’s the whole installation. From here teachers just tick Enable proctoring per quiz — no per-course setup is needed.

Where teachers find it

Troubleshooting

The registration window shows an error

The registration link Canvas issues is valid for one attempt only. Close the dialog and start again from Admin → Developer Keys → + Developer Key → LTI Registration.

No Upload tab (or no JavaScript slot) in the Theme Editor

Custom JavaScript uploads are disabled on your account. Go to Admin → Settings, scroll to the bottom of the account settings page, tick Custom CSS/JavaScript overrides, save, then reopen the Theme Editor — the Upload tab appears. On a self-hosted Canvas, if the tab is still missing after that, check item 2 of the self-hosted prerequisites.

“Theme file last seen: never”, or nothing is recorded

The theme file is missing or the theme was saved but not applied. Re-open the Theme Editor, confirm quilgo-canvas.js is uploaded under JavaScript, and click Apply theme. The panel updates within a few minutes of the first page view.

Browser console says “[Quilgo] this Canvas is not a known installation”

The theme file is in place, but your Canvas domain isn’t linked to a registration yet. Open Quilgo Proctoring from the Admin sidebar once (this links the domain automatically), or contact us if it persists.

“This app has been locked by an administrator and is not available for installation”

Appears on + App → By Client ID when your Canvas has the “Lock LTI Registrations” feature enabled and the app is marked as locked for client-ID deployment. Either unlock the app on its page in Canvas Apps (Admin → Apps → Manage), or skip the legacy install entirely and make the app available there via Availability and Exceptions — both paths end in the same installed state.

A student sees “Students are proctored through the quiz page, not this launch”

Expected — the student opened the tool link directly. They should simply take the quiz; proctoring starts there.

Anything else

Write to hello@quilgo.com — include your Canvas domain and a screenshot of the Integration & Install Health panel if you can.


Manual installation (fallback)

Use this only if automatic registration is unavailable on your Canvas instance — for example, if your institution has disabled dynamic registration.

  1. Go to Admin → Developer Keys → + Developer Key → + LTI Key.
  2. In Method, choose Enter URL and paste:
    https://quilgo-host/lti/canvas-config.json
    With Enter URL, your Canvas server fetches this address itself. If saving fails — common on self-hosted servers that block outbound traffic — open the URL in your browser, copy the JSON, and use the Paste JSON method instead.
  3. Set Key Name to Quilgo Proctoring and save. Switch the key’s State to ON.
  4. Copy the key’s Client ID — the long number shown in the Details column.
  5. Add the app to your account: Admin → Settings → Apps → View App Configurations → + App, set Configuration Type to By Client ID, paste the Client ID, then Submit → Install.
  6. Email the Client ID and your Canvas domain (for example canvas.school.edu) to hello@quilgo.com — we activate the installation on our side.

    Why this step exists: a manually created key is known only to Canvas — unlike automatic registration, nothing tells Quilgo about it. Your installation still connects itself the first time someone opens Quilgo Proctoring in Canvas, but until then the proctoring snippet in your theme has nothing to attach to. Sending us the Client ID and domain activates the installation ahead of that first launch, so recording works immediately. On a self-hosted Canvas this step is essential rather than optional: self-hosted instances issue non-unique Client IDs, and the domain (together with the issuer from the prerequisites) is what distinguishes your installation from another school’s.

  7. Continue with Step 3 (theme snippet), Step 4 (activation) and Step 5 (verification) above.

Self-hosted Canvas prerequisites

Quilgo works on any Canvas. Canvas Cloud (*.instructure.com) needs none of this — skip this section. A self-hosted Canvas must have the following configured. All of it is standard Canvas administration required by any LTI 1.3 tool, and every item can be verified in about ten minutes — before installing anything.

1 · LTI signing keys

Check: open this address in a browser:

https://your-canvas/api/lti/security/jwks

It must return one or more keys. {"keys":[]} means Canvas has nothing to sign launches with — every LTI 1.3 tool will fail.

Fix (Canvas server): generate three keys in the Rails console (bundle exec rails console) by running this three times:

key = OpenSSL::PKey::RSA.generate(2048); puts key.to_jwk(kid: Time.now.utc.iso8601).to_json

Place the three outputs in config/dynamic_settings.yml under store.canvas.lti-keys as jwk-past.json, jwk-present.json and jwk-future.json, then restart Canvas.

2 · Theme JavaScript delivery

Check: in Admin → Settings (bottom of the page) enable Custom CSS/JavaScript overrides — without it the Upload tab in the Theme Editor does not exist. Upload any JS file in the Theme Editor and apply the theme, then open any Canvas page, view its source, find the js_overrides script tag and open its URL. It must return the script, not an error page. A 4xx here means Canvas’s file storage cannot serve uploads.

Fix (Canvas server): file storage configuration in config/file_store.yml (local path and permissions, or S3 credentials); the exact failure is in the Canvas production logs for that download request.

3 · LTI 1.3 machinery

Check: in Admin → Developer Keys create any LTI key, then open any LTI placement. A “Something broke” error at either step appears before the external tool is contacted and indicates a Canvas configuration problem, not a tool problem.

Fix (Canvas server): the stack trace is in the Canvas error logs; typical causes are a missing or broken Rails cache (Redis) or an absent dynamic_settings.yml.

4 · Stable issuer

Check (Canvas server): run grep lti_iss config/security.yml and send us the value. Launches are validated against it, and changing it later invalidates the installation. The default is https://canvas.instructure.com, but self-hosted instances can change it.

5 · Environment basics

  • Recent Canvas version — run a current open-source release; old releases are an untested failure class.
  • HTTPS with a valid certificate on the Canvas domain — the tool runs in an iframe and browsers refuse mixed content.
  • Server clock synced via NTP — LTI launches are short-lived signed tokens; minutes of skew make every launch “expired”.
  • Outbound HTTPS from the Canvas server to your Quilgo server — Canvas fetches the tool configuration during registration and its JWKS when issuing service tokens.
  • Reverse proxy passes headers through — Quilgo identifies which Canvas a request came from by Origin/Referer; a proxy stripping them breaks identification. A restrictive Content-Security-Policy in front of Canvas must allow scripts from your Quilgo server’s domain.

Data and permissions

  • Quilgo receives the name and email of the user in each signed launch (Canvas privacy level “Public”).
  • The app requests exactly one LTI service: course membership, read-only (Names and Role Provisioning Service) — used to match attempts to students.
  • Quilgo never writes grades and requests no gradebook or Canvas API scopes.
  • Installing again (for example after re-running registration) does not create a second account — Canvas instances are recognised and merged automatically.

Technical reference

For change-management or security review. All URLs are on your Quilgo server.

ItemValue
Dynamic registration URLhttps://quilgo-host/lti/register
Manual JSON configurationhttps://quilgo-host/lti/canvas-config.json
OIDC login (initiation) URLhttps://quilgo-host/lti/login
Target link URI / redirect URIhttps://quilgo-host/lti/launch
Public JWK sethttps://quilgo-host/lti/jwks
Theme proctoring snippethttps://quilgo-host/loader/theme.js → quilgo-canvas.js
PlacementsAccount navigation, Quiz menu, Assignment menu — all titled “Quilgo Proctoring”
LTI scopeslti-nrps/scope/contextmembership.readonly only
Custom fields$Canvas.course.id, $Canvas.assignment.id, $Canvas.user.id, $Canvas.api.domain
SigningLTI 1.3 / OIDC, RS256, private_key_jwt

Appendix · Local development (Quilgo team)

Internal. Nothing in this appendix applies to customers — their Canvas and our server share one public domain, so none of these quirks exist for them. Remove this section from any copy shared outside the team.

The full stack

ServicePortHow to run
plasm API (Canvas build)8083pnpm start:dev-server in plasm (INTEGRATION_TYPE=canvas in .env)
plasm queue workers—pnpm start:dev-server:workers in plasm — without it (and the report worker) results show “report is not ready yet” forever
plasm report worker—pnpm start:dev-server:report-worker in plasm
plasm billing process8483pnpm start:dev-server:billing in plasm — the dashboard’s backend API (dev port = PORT + 400); without it the dashboard login shows a 404
Dashboard front-end3005dev server in plasm/front-end
Canvas LMS3000Docker compose in canvas-lms (canvas-lms-web-1)
Billing8181pnpm start:dev-server in billing
Media processor8686Docker container quilgo-media-processor
Pub/Sub emulator8681Docker container plasm-pubsub

Who resolves which URL

Canvas runs in Docker, the tool on the host — so localhost names two different machines. Browser-side URLs must stay localhost:8083; anything the Canvas server fetches needs host.docker.internal:8083.

URLDereferenced byUse
OIDC login, launch, /lti/register page, /loader/theme.jsBrowser (host)localhost:8083
“Enter URL” fetch of canvas-config.json, tool JWKS for NRPS tokensCanvas server (container)host.docker.internal:8083
  • Enter URL: paste http://host.docker.internal:8083/lti/canvas-config.json — or use Paste JSON with the config opened in the browser.
  • NRPS: after creating a manual key, edit its Public JWK URL to http://host.docker.internal:8083/lti/jwks — the container cannot reach localhost:8083 when validating our token requests.
  • Manual keys need our side too: pnpm lti:register-customer --client-id=<id> --domain=localhost:3000 --write (dry run without --write).
  • Emails: POSTMARK=POSTMARK_API_TEST — confirmation emails go to Postmark test mode; verify by send logs, no real inbox.

Reset to a from-scratch state

The wipe commands (our DB, keyed by domain = 'localhost:3000' so megasobaken survives, plus the Canvas-side cleanup) live in the repo: plasm/docs/local-canvas-dev.md.

Verify the clean state after running them (the theme file stays — it names no customer):

curl "http://localhost:8083/loader/identity?host=localhost:3000" -H "Origin: http://localhost:3000"
# → {}   (unknown installation — correct from-scratch state)

Установка Quilgo Proctoring в Canvas

Quilgo Proctoring устанавливается один раз на весь аккаунт Canvas. Установка состоит из двух частей: LTI 1.3-приложение и один сниппет прокторинга в теме Canvas. Нужны обе части.

Для администраторов Canvas ≈ 10 минут LTI 1.3

Перед началом

Зарегистрируйте приложение

Quilgo поддерживает автоматическую (динамическую) регистрацию Canvas — вручную ничего вводить не придётся.

  1. В Canvas откройте Admin → Developer Keys → + Developer Key → LTI Registration.
    Developer Keys → + Developer Key → LTI Registration.
  2. Вставьте адрес регистрации:
    https://quilgo-host/lti/register
    Вставьте адрес регистрации Quilgo и нажмите Continue. В примере показан тестовый сервер.
  3. Внутри Canvas откроется страница Quilgo. Нажмите Install (Установить).
    Страница Quilgo внутри диалога Canvas — нажмите Install.
  4. Когда Canvas покажет свой диалог подтверждения, нажмите кнопку Enable & Close.
    Canvas показывает разрешения и размещения, которые будут созданы — нажмите Enable & Close.

Включите ключ и откройте доступ к приложению

Canvas создал новый ключ. Убедитесь, что он включён (ON), и выполните следующие шаги, чтобы его активировать:

  1. Откройте Developer Keys, найдите Quilgo Proctoring и убедитесь, что State в положении ON (если нет — включите).
    Строка Quilgo Proctoring в Developer Keys — State должен быть зелёным.
  2. Откройте у ключа ссылку View in Canvas Apps. В разделе Availability and Exceptions нажмите кнопку редактирования (карандаш), установите Available и нажмите Save.
    Ссылка View in Canvas Apps — в колонке Details у ключа.
    На странице приложения откройте Availability and Exceptions и нажмите карандаш.
    Переключите Not Available → Available и нажмите Save.
  3. Перезагрузите страницу — в боковом меню Admin появится Quilgo Proctoring.

Загрузите сниппет прокторинга в тему Canvas

  1. Скачайте сниппет: в левой навигации Canvas откройте Admin → ваш аккаунт, затем в меню аккаунта слева нажмите Quilgo Proctoring (пункт появился там после шага 2). На открывшейся странице нажмите Download Proctoring snippet — файл quilgo-canvas.js сохранится на компьютер.
    Страница Quilgo Proctoring на уровне аккаунта, открытая из меню Admin.
    В блоке Integration & Install Health нажмите Download proctoring snippet.
  2. Откройте Admin → Themes, активную тему в Theme Editor и убедитесь, что видна вкладка Upload.
    Admin → Themes — наведите на текущую тему и нажмите Open in Theme Editor.
    Вкладка Upload с полем JavaScript file.

    Вкладки Upload нет? Откройте Admin → Settings, прокрутите страницу настроек аккаунта до конца, отметьте флажок Custom CSS/JavaScript overrides, сохраните и заново откройте Theme Editor.

    Admin → Settings → Features: отметьте Custom CSS/JavaScript overrides.
  3. На вкладке Upload проверьте, загружен ли уже JavaScript file:
    • Файла нет: объединять нечего — загрузите скачанный quilgo-canvas.js как есть.
      Поле JavaScript file пустое — сохранять нечего, загружайте сниппет как есть.
    • Файл уже есть: нажмите кнопку View File рядом с полем загрузки JavaScript-файла и сохраните файл на компьютер. Откройте оба файла в текстовом редакторе и вставьте весь код сниппета в самый конец вашего файла. Сохраните результат с расширением .js и дальше работайте с объединённым файлом.

      Важно: добавляйте сниппет именно в конец файла. Canvas допускает только один JavaScript-файл на тему — загрузка одного лишь сниппета заменила бы ваш существующий код.

  4. Загрузите файл в поле JavaScript file на вкладке Upload.
  5. Нажмите Preview Your Changes, затем Save theme и Apply theme.
    Файл прикреплён — нажмите Preview Your Changes, затем Save theme в зелёной полосе.

Активируйте аккаунт

Пока аккаунт не активирован, настройки прокторинга в меню тестов заблокированы: преподаватели видят «Please ask your administrator to activate the account to enable proctoring», а администраторы — кнопку активации прямо там.

  1. В боковом меню Admin откройте Quilgo Proctoring и нажмите Activate your account. На этой странице кнопка есть в двух местах — внизу блока Subscription Overview и в строке Activation account блока Integration & Install Health; любая из них откроет страницу регистрации в дашборде Quilgo.
    Обе точки входа: кнопка под Subscription Overview и ссылка в строке Activation account.
  2. Создайте там аккаунт Quilgo (или войдите в существующий) и подтвердите почту. Дашборд уже знает, с какого сайта Canvas вы пришли — создайте организацию (в ней живут биллинг, лицензии и доступ команды) и нажмите Connect site.
    Регистрация по email или через Google.
    После подтверждения почты нажмите Log into my dashboard.
    Сайт Canvas уже определён; назовите организацию и нажмите Connect site.
    Подтверждение: прокторинг на сайте активен.
  3. Вернитесь в Canvas и обновите страницу Quilgo Proctoring — строка Activation account в Integration & Install Health должна стать Active, а настройки прокторинга у преподавателей разблокируются.

Проверьте установку

  1. В боковом меню Admin в Canvas откройте Quilgo Proctoring.
  2. Проверьте панель Integration & Install Health: Registration, Activation account и Proctoring integration должны быть Active, а Theme file last seen — показывать недавнее время (обновляется за несколько минут после того, как кто-то откроет страницу Canvas — перезагрузите страницу Canvas и обновите панель).
    Завершённая установка: все три строки Active, свежее Theme file last seen и видный тариф в Subscription Overview.
  3. Проведите настоящий тест: откройте любой тест, выберите Quilgo Proctoring в меню теста, отметьте Enable proctoring, выберите методы отслеживания и нажмите Save, затем пройдите тест от имени тестового студента. Откройте его через View as Student: перед началом попытки появится диалог Start attempt: он перечисляет включённое отслеживание и запрашивает ровно те разрешения — экран, камеру или оба. Для выключенных методов ничего не запрашивается.
    Меню теста (⋮) в разделе Quizzes — Quilgo Proctoring в самом низу списка.
    Включите Enable Proctoring, выберите методы отслеживания и нажмите Save Settings.
    Кнопка View as Student справа вверху откроет курс от имени тестового студента.
    Диалог Start attempt у студента — здесь было включено только отслеживание экрана, поэтому запрашивается доступ к экрану.

На этом установка завершена. Дальше преподаватели просто включают прокторинг для нужных тестов — настройка по курсам не требуется.

Где инструмент видят преподаватели

Устранение неполадок

Окно регистрации показывает ошибку

Ссылка регистрации, которую выдаёт Canvas, действует только на одну попытку. Закройте окно и начните заново: Admin → Developer Keys → + Developer Key → LTI Registration.

В Theme Editor нет вкладки Upload (или поля для JavaScript)

На вашем аккаунте отключена загрузка пользовательского JavaScript. Откройте Admin → Settings, прокрутите страницу настроек аккаунта до конца, отметьте флажок Custom CSS/JavaScript overrides, сохраните и заново откройте Theme Editor — вкладка Upload появится. Если на self-hosted Canvas вкладки нет и после этого — проверьте пункт 2 предварительных требований для self-hosted.

«Theme file last seen: never» или запись не идёт

Файл темы не загружен, либо тема сохранена, но не применена. Откройте Theme Editor, убедитесь, что quilgo-canvas.js загружен в разделе JavaScript, и нажмите Apply theme. Панель обновится в течение нескольких минут после первого просмотра страницы.

В консоли браузера — «[Quilgo] this Canvas is not a known installation»

Файл темы на месте, но домен вашего Canvas ещё не привязан к регистрации. Один раз откройте Quilgo Proctoring из бокового меню Admin (домен привяжется автоматически). Если сообщение не исчезает — напишите нам.

«This app has been locked by an administrator and is not available for installation»

Появляется на шаге + App → By Client ID, если в вашем Canvas включена функция «Lock LTI Registrations» и приложение помечено как заблокированное для установки по Client ID. Либо снимите блокировку на странице приложения в Canvas Apps (Admin → Apps → Manage), либо вообще пропустите легаси-установку и откройте доступ к приложению там же через Availability and Exceptions — оба пути приводят к одному и тому же установленному состоянию.

Студент видит «Students are proctored through the quiz page, not this launch»

Это ожидаемо — студент открыл ссылку инструмента напрямую. Ему достаточно просто начать тест: прокторинг запустится на странице теста.

Другие вопросы

Напишите на hello@quilgo.com — по возможности укажите домен Canvas и приложите скриншот панели Integration & Install Health.


Ручная установка (запасной вариант)

Используйте её, только если автоматическая регистрация в вашем Canvas недоступна — например, динамическая регистрация отключена политикой организации.

  1. Откройте Admin → Developer Keys → + Developer Key → + LTI Key.
  2. В поле Method выберите Enter URL и вставьте:
    https://quilgo-host/lti/canvas-config.json
    При методе Enter URL сервер Canvas сам обращается по этому адресу. Если сохранение не срабатывает — частая ситуация на self-hosted серверах с закрытым исходящим трафиком — откройте адрес в браузере, скопируйте JSON и используйте метод Paste JSON.
  3. В поле Key Name укажите Quilgo Proctoring и сохраните. Переведите State ключа в ON.
  4. Скопируйте Client ID ключа — длинное число в колонке Details.
  5. Добавьте приложение в аккаунт: Admin → Settings → Apps → View App Configurations → + App, в поле Configuration Type выберите By Client ID, вставьте Client ID, затем Submit → Install.
  6. Отправьте Client ID и домен вашего Canvas (например, canvas.school.edu) на hello@quilgo.com — мы активируем установку со своей стороны.

    Зачем этот шаг: ключ, созданный вручную, известен только Canvas — в отличие от автоматической регистрации, Quilgo о нём ничего не узнаёт. Установка всё равно подключится сама при первом открытии Quilgo Proctoring в Canvas, но до этого момента сниппету прокторинга в вашей теме не к чему привязаться. Прислав нам Client ID и домен, вы активируете установку заранее — запись работает сразу. Для self-hosted Canvas этот шаг не опциональный, а обязательный: такие инстансы выдают неуникальные Client ID, и именно домен (вместе с issuer из предварительных требований) отличает вашу установку от установки другой организации.

  7. Затем выполните шаг 3 (сниппет темы), шаг 4 (активация) и шаг 5 (проверка).

Предварительные требования для self-hosted Canvas

Quilgo работает с любым Canvas. Canvas Cloud (*.instructure.com) ничего из этого не требует — пропустите раздел. На self-hosted Canvas должно быть настроено следующее. Всё это — стандартное администрирование Canvas, необходимое любому инструменту LTI 1.3, и каждый пункт можно проверить примерно за десять минут — ещё до установки.

1 · Ключи подписи LTI

Проверка: откройте в браузере адрес:

https://ваш-canvas/api/lti/security/jwks

Должен вернуться хотя бы один ключ. Ответ {"keys":[]} означает, что Canvas нечем подписывать запуски — не будет работать ни один инструмент LTI 1.3.

Исправление (сервер Canvas): сгенерируйте три ключа в консоли Rails (bundle exec rails console), выполнив эту команду три раза:

key = OpenSSL::PKey::RSA.generate(2048); puts key.to_jwk(kid: Time.now.utc.iso8601).to_json

Поместите три результата в config/dynamic_settings.yml в раздел store.canvas.lti-keys как jwk-past.json, jwk-present.json и jwk-future.json, затем перезапустите Canvas.

2 · Доставка JavaScript темы

Проверка: в Admin → Settings (внизу страницы) включите Custom CSS/JavaScript overrides — без этого в Theme Editor нет вкладки Upload. Загрузите в Theme Editor любой JS-файл и примените тему, затем откройте любую страницу Canvas, посмотрите её исходный код, найдите тег скрипта js_overrides и откройте его адрес. Должен вернуться сам скрипт, а не страница ошибки. Ответ 4xx означает, что файловое хранилище Canvas не может отдавать загруженные файлы.

Исправление (сервер Canvas): настройка файлового хранилища в config/file_store.yml (локальный путь и права доступа либо учётные данные S3); точная причина сбоя — в production-логах Canvas для этого запроса на скачивание.

3 · Механика LTI 1.3

Проверка: в Admin → Developer Keys создайте любой LTI-ключ и откройте любое LTI-размещение. Ошибка «Something broke» на любом из шагов возникает до обращения к внешнему инструменту и указывает на проблему конфигурации Canvas, а не инструмента.

Исправление (сервер Canvas): стек-трейс — в логах ошибок Canvas; типичные причины — отсутствующий или неисправный кеш Rails (Redis) либо отсутствующий dynamic_settings.yml.

4 · Стабильный issuer

Проверка (сервер Canvas): выполните grep lti_iss config/security.yml и сообщите нам значение. Запуски проверяются по нему, и его изменение позже сделает установку недействительной. По умолчанию это https://canvas.instructure.com, но self-hosted инстансы могут его менять.

5 · Базовые требования к окружению

  • Актуальная версия Canvas — используйте свежий open-source-релиз; старые версии — непроверенный класс отказов.
  • HTTPS с действительным сертификатом на домене Canvas — инструмент работает в iframe, и браузеры блокируют смешанный контент.
  • Часы сервера синхронизированы по NTP — LTI-запуски являются короткоживущими подписанными токенами; расхождение в несколько минут делает каждый запуск «просроченным».
  • Исходящий HTTPS с сервера Canvas к вашему серверу Quilgo — Canvas запрашивает конфигурацию инструмента при регистрации и его JWKS при выдаче сервисных токенов.
  • Обратный прокси пропускает заголовки — Quilgo определяет, с какого Canvas пришёл запрос, по Origin/Referer; прокси, срезающий их, ломает идентификацию. Ограничивающая Content-Security-Policy перед Canvas должна разрешать скрипты с домена вашего сервера Quilgo.

Данные и права доступа

  • При каждом подписанном запуске Quilgo получает имя и email пользователя (уровень приватности Canvas — «Public»).
  • Приложение запрашивает ровно один LTI-сервис: список участников курса, только чтение (Names and Role Provisioning Service) — чтобы сопоставлять попытки со студентами.
  • Quilgo никогда не выставляет оценки и не запрашивает доступ к журналу оценок или Canvas API.
  • Повторная установка (например, после повторной регистрации) не создаёт второй аккаунт — инстансы Canvas распознаются и объединяются автоматически.

Техническая справка

Для согласования изменений и проверки безопасности. Все адреса — на вашем сервере Quilgo.

ПараметрЗначение
Адрес динамической регистрацииhttps://quilgo-host/lti/register
JSON-конфигурация для ручной установкиhttps://quilgo-host/lti/canvas-config.json
OIDC login (initiation) URLhttps://quilgo-host/lti/login
Target link URI / redirect URIhttps://quilgo-host/lti/launch
Публичный набор ключей (JWK)https://quilgo-host/lti/jwks
Сниппет прокторинга для темыhttps://quilgo-host/loader/theme.js → quilgo-canvas.js
Размещения (placements)Account navigation, Quiz menu, Assignment menu — везде «Quilgo Proctoring»
LTI-разрешения (scopes)только lti-nrps/scope/contextmembership.readonly
Пользовательские поля$Canvas.course.id, $Canvas.assignment.id, $Canvas.user.id, $Canvas.api.domain
ПодписьLTI 1.3 / OIDC, RS256, private_key_jwt

Приложение · Локальная разработка (команда Quilgo)

Внутреннее. Ничего из этого приложения не касается клиентов — у них Canvas и наш сервер живут на одном публичном домене, и этих особенностей просто не существует. Удалите раздел из любой копии, которая уходит за пределы команды.

Полный стек

СервисПортКак запустить
plasm API (сборка Canvas)8083pnpm start:dev-server в plasm (INTEGRATION_TYPE=canvas в .env)
plasm воркеры очередей—pnpm start:dev-server:workers в plasm — без него (и report-воркера) результаты вечно показывают «report is not ready yet»
plasm report-воркер—pnpm start:dev-server:report-worker в plasm
plasm биллинг-процесс8483pnpm start:dev-server:billing в plasm — backend API дашборда (dev-порт = PORT + 400); без него логин дашборда показывает 404
Дашборд (front-end)3005dev-сервер в plasm/front-end
Canvas LMS3000Docker compose в canvas-lms (canvas-lms-web-1)
Биллинг8181pnpm start:dev-server в billing
Media processor8686Docker-контейнер quilgo-media-processor
Эмулятор Pub/Sub8681Docker-контейнер plasm-pubsub

Кто разыменовывает какой URL

Canvas работает в Docker, инструмент — на хосте, поэтому localhost означает две разные машины. Браузерные URL остаются localhost:8083; всё, что запрашивает сервер Canvas, требует host.docker.internal:8083.

URLРазыменовываетИспользовать
OIDC login, launch, страница /lti/register, /loader/theme.jsБраузер (хост)localhost:8083
Загрузка canvas-config.json через «Enter URL», JWKS инструмента для токенов NRPSСервер Canvas (контейнер)host.docker.internal:8083
  • Enter URL: вставляйте http://host.docker.internal:8083/lti/canvas-config.json — либо используйте Paste JSON с конфигом, открытым в браузере.
  • NRPS: после создания ручного ключа поменяйте его Public JWK URL на http://host.docker.internal:8083/lti/jwks — контейнер не достучится до localhost:8083, когда будет проверять наши запросы токенов.
  • Ручные ключи требуют и нашей стороны: pnpm lti:register-customer --client-id=<id> --domain=localhost:3000 --write (без --write — сухой прогон).
  • Письма: POSTMARK=POSTMARK_API_TEST — письма подтверждения уходят в тестовый режим Postmark; проверяйте по логам отправки, реального ящика нет.

Сброс к состоянию «с нуля»

Команды очистки (наша БД — по domain = 'localhost:3000', так что megasobaken сохраняется, — плюс чистка на стороне Canvas) лежат в репозитории: plasm/docs/local-canvas-dev.md.

Проверка чистого состояния после их выполнения (файл темы остаётся — он не привязан к клиенту):

curl "http://localhost:8083/loader/identity?host=localhost:3000" -H "Origin: http://localhost:3000"
# → {}   (неизвестная установка — правильное состояние «с нуля»)