Loaded Commerce Community

Banner


Board index » Loaded Commerce Support » Security Issues

All times are UTC - 5 hours




Post new topic Reply to topic  [ 10 posts ] 
Author Message
 Post subject: Search box by-passes Account login access?
PostPosted: Wed Mar 18, 2009 5:06 pm 
Offline
CRE Newbie
User avatar

Joined: Tue Mar 17, 2009 12:37 pm
Posts: 4
If a customer does a search for a product that is not viewable in the Guest Preview area then they can by-pass the Account login and access information that is normally seen after a login. Surely this is a security issue. Is there any way around it? It is possible to show the search only on selected pages? Any advice would be grateful. Thanks in advance. Jaddey

PS: This was a problem with 6.2 B2B and appears to still be a problem in 6.3!
(The site is for a wholesale business).

_________________
You're only as good as your last piece of work!


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Wed Mar 18, 2009 8:29 pm 
Offline
CRE Legend
User avatar

Joined: Fri Jan 13, 2006 1:00 am
Posts: 11084
Location: Nappanee Indiana
I don't think it is a creloaded issue but your template..

have you tried this in a default template?
the logic is there to only search products that are in the retail/guest unless logged in

_________________
Jason Miller
https://www.creloadedexpert.com
CRE Loaded Expert Team
CRE Loaded Support
Home of the FIRST 100% tableless CRE Loaded template


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Wed Mar 18, 2009 8:59 pm 
Offline
CRE Newbie
User avatar

Joined: Tue Mar 17, 2009 12:37 pm
Posts: 4
Thank you for your reply. As far as I know it is a customised template based on the original B2B. The search goes to all the products on the web site but omits the prices. Shown as a zero. The description and images can be seen, plus any extra items from the related products which can then lead to other exclusive items. However, the user cannot navigate to other areas from the menu bar as previously with 6.2 - this is now restricted with 6.3.

I may have to design separate pages just for the Guest preview away from the catalogue altogether to remove this. But I was wondering if it was possible to remove the search just for the preview within the CRELoaded software.

I am testing the search facility as I am updating the site - the search has to cater for logical items the user may expect to find, but then there is always the possibility of a search for something they may wish to find that is not available in the preview - and it is human nature to run a search for that desired item irrespective. I am testing it for all possibilities.

_________________
You're only as good as your last piece of work!


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Wed Mar 18, 2009 9:59 pm 
Offline
CRE Legend
User avatar

Joined: Fri Jan 13, 2006 1:00 am
Posts: 11084
Location: Nappanee Indiana
the logic is already in a default template to show only products assigned to retail/guest/group user account

if your template is not doing that, then you need to work out those issues with the template

switch to one of the default b2b template to see if the issue remains.. if not, then you know its within the templates pages/files

_________________
Jason Miller
https://www.creloadedexpert.com
CRE Loaded Expert Team
CRE Loaded Support
Home of the FIRST 100% tableless CRE Loaded template


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Wed Mar 18, 2009 11:09 pm 
Offline
CRE Newbie
User avatar

Joined: Tue Mar 17, 2009 12:37 pm
Posts: 4
Thanks, Jason, for your feedback. I will try to work around it with the template files.

_________________
You're only as good as your last piece of work!


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Wed Mar 18, 2009 11:15 pm 
Offline
CRE Legend
User avatar

Joined: Fri Jan 13, 2006 1:00 am
Posts: 11084
Location: Nappanee Indiana
if it is on the search pages only

replace your templates/your template name/content/advanced***.tpl.php with the default files located in

templates/content/

_________________
Jason Miller
https://www.creloadedexpert.com
CRE Loaded Expert Team
CRE Loaded Support
Home of the FIRST 100% tableless CRE Loaded template


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Wed Mar 18, 2009 11:31 pm 
Offline
CRE Newbie
User avatar

Joined: Tue Mar 17, 2009 12:37 pm
Posts: 4
Thanks again, for pointing me to the directory. I am grateful. I will let you if it works, cheers.

Jaddey

_________________
You're only as good as your last piece of work!


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Tue Jul 14, 2009 9:09 pm 
Offline
CRE Newbie

Joined: Thu Jul 09, 2009 8:02 pm
Posts: 11
View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

_________________
For some useful modules to creloaded
http://www.commercexp.com/products/creloaded-modules/?


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Tue Jul 14, 2009 9:16 pm 
Offline
CRE Talented

Joined: Thu Dec 25, 2008 5:09 pm
Posts: 489
Location: CO
supportjason wrote:
View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.


Ummmm.... What the heck are you talking about? Free trail for what? Are you going to provide an answer to this problem or not? If yes, just post the thing.


Top
 Profile  
 
 Post subject: Re: Search box by-passes Account login access?
PostPosted: Tue Jul 14, 2009 10:18 pm 
Offline
CRE Legend
User avatar

Joined: Fri Jan 13, 2006 1:00 am
Posts: 11084
Location: Nappanee Indiana
he is a spammer trying to promote their new site.. with 100% unrelated links

_________________
Jason Miller
https://www.creloadedexpert.com
CRE Loaded Expert Team
CRE Loaded Support
Home of the FIRST 100% tableless CRE Loaded template


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 10 posts ] 

Board index » Loaded Commerce Support » Security Issues

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
It is currently Thu May 24, 2012 8:30 am
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group

Login

Forums Latest Activity

Top Listing

1. Cart2Cart - Shopping...
    Category: Shopping Cart Database Conversion Scripts
    
2. Points & Rewards PLUS!...
    Category: Add-Ons
    
3. Configuration Server...
    Category: Fixes
    
4. Credit Card with CCV
    Category: Payment Modules
    
5. CC7333_ATS
    Category: Templates
    
Show more...

© CRE Loaded is a product of Chain Reaction Ecommerce, Inc. Usage & Privacy Policy