关于Articulate Storyline 360整合adlnet/xAPIWrapper发起xAPI课程的咨询
Great question—passing sensitive xAPI parameters like auth, actor, or endpoint directly in the URL is a major security risk (they’re stored in browser history, server logs, and can be intercepted), so let’s break down how to fix this and integrate the ADL libraries properly.
First, let’s eliminate the need to expose sensitive data in the URL entirely. Here are two reliable approaches:
Server-Side Launch Proxy Page
Create a dedicated launch endpoint in your LMS that uses a short-lived, unique token instead of raw xAPI parameters. For example, the user clicks a link likehttp://my.lms.com/launch-course?token=abc123xyz. Your LMS validates this token, pulls the user’s xAPI config (endpoint, auth, actor, etc.) from a server-side session or database, then dynamically loads the Storyline course while injecting these parameters into the page context (not the URL).Override Storyline’s xAPI Config via Global Variables
Storyline 360 supports overriding its default xAPI settings using a global JavaScript variable before the course loads. On your launch page, define the config first, then loadstory.html:// Define xAPI config globally before loading Storyline window.tinCanApiConfig = { endpoint: "http://my.lms.com/lrs/endpoint/", auth: "Basic OjFjMGY4NTYxNzUwOGI4YWY0NjFkNzU5MWUxMzE1ZGQ1", actor: {"name": ["First Last"], "mbox": ["mailto:firstlast@mycompany.com"]}, activityId: "61XkSYC1ht2_course_id", registration: "760e3480-ba55-4991-94b0-01820dbd23a2" }; // Load Storyline's course page window.location.href = "http://my.lms.com/TCActivityProvider/story.html";Storyline will automatically detect this global variable and use it to initialize xAPI, no URL parameters required.
Let’s clarify what each library does and how to weave them into your LMS workflow:
- xapi-launch: Handles secure, standardized xAPI course launches per ADL’s specification. It replaces URL parameters with session-based or POST-based parameter passing, ensuring sensitive data never hits the browser’s address bar.
- xAPIWrapper: Simplifies xAPI statement creation, sending, and LRS interactions (a more user-friendly alternative to raw XMLHttpRequest calls).
Integration Steps
Set Up xapi-launch on the LMS
Implement the xapi-launch endpoint in your LMS. When a user starts a course:- Your LMS stores the user’s xAPI config in a server-side session.
- Redirect the user to xapi-launch’s launch page, or embed its startup script in your custom launch page. The library will handle securely passing the config to the course via
postMessageor a hidden POST form.
Replace Storyline’s Default xAPI Implementation with xAPIWrapper
Storyline uses its own built-in xAPI handler, but you can override it with xAPIWrapper:- Add
xAPIWrapper.min.jsto your Storyline published folder (e.g.,story_content/js/). - Edit
story.htmlor add a custom script to load the wrapper and override Storyline’sTinCanobject:// Load xAPIWrapper const wrapperScript = document.createElement('script'); wrapperScript.src = 'story_content/js/xAPIWrapper.min.js'; wrapperScript.onload = function() { // Initialize wrapper with your secure config ADL.XAPIWrapper.changeConfig({ endpoint: window.tinCanApiConfig.endpoint, auth: window.tinCanApiConfig.auth, actor: window.tinCanApiConfig.actor }); // Replace Storyline's default TinCan object with the wrapper window.TinCan = ADL.XAPIWrapper; }; document.head.appendChild(wrapperScript);
Now all xAPI statements from Storyline will be sent via xAPIWrapper.
- Add
Articulate doesn’t officially list xAPIWrapper as a supported library, but it’s fully compatible with minor customization:
- Storyline exposes a global
TinCanobject for all xAPI operations. By replacing this object with xAPIWrapper (as shown above), Storyline will use the wrapper seamlessly for its default statement sending. - You can also use Storyline’s Execute JavaScript trigger to call xAPIWrapper functions directly, allowing you to send custom xAPI statements beyond Storyline’s built-in behavior.
- Always serve your LMS, LRS, and course content over HTTPS to encrypt all data in transit.
- Use short-lived, session-bound tokens instead of static Basic auth credentials to reduce exposure risk if a token is compromised.
- Validate all incoming xAPI requests on your LRS to ensure they’re from authorized users and follow xAPI formatting rules.
内容的提问来源于stack exchange,提问作者Chinmay Waghmare

