ProductCart E-Commerce Solutions Homepage
Forum Home Forum Home > ProductCart > Using ProductCart
  New Posts New Posts RSS Feed - Registration E-Mail with Non-Secure Link
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Registration E-Mail with Non-Secure Link

 Post Reply Post Reply
Author
Message
SBW View Drop Down
Newbie
Newbie


Joined: 09-July-2011
Status: Offline
Points: 0
Post Options Post Options   Thanks (0) Thanks(0)   Quote SBW Quote  Post ReplyReply Direct Link To This Post Topic: Registration E-Mail with Non-Secure Link
    Posted: 09-July-2011 at 10:37am
Hi,

I noticed that when a customer registers, a welcome e-mail is sent out to the person and it has a non-secure link to the page that allows edits to the customer profile:


Now, if the person is not logged in already, then this link actually takes the person to a secure login page first.  After logging in, they can proceed to the profile page which is also secure.

However, if they are already logged in and they click the non-secure e-mail link, then they are taken to the profile page which remains non-secure.

I know this would be a rare event, but if someone does click the link for convenience after they are already logged in, then they would be submitting personal information in a non-secure manner.  Is there any way to change this?

I could change the scStoreURL in the storeconstants.asp file, to use https instead of http, but that would affect other things as well.  I'm told this could cause mixed content errors.

By the way, I'm sorry to not list the version of ProductCart I'm using.  I'm just taking over a site and am not too familiar with it.  I can't seem to find anything that tells me where the version number is listed. Any suggestions?

Thanks.


Edited by SBW - 14-July-2011 at 10:34am
Back to Top
intour View Drop Down
Senior Member
Senior Member


Joined: 30-June-2006
Location: United Kingdom
Status: Offline
Points: 0
Post Options Post Options   Thanks (0) Thanks(0)   Quote intour Quote  Post ReplyReply Direct Link To This Post Posted: 13-July-2011 at 5:05pm
The login works on a session variable so they stay logged in during that browser session only though it will time out eventually.
 
For the situation you described to become a securtity issue the person would have to leave his/her computer logged into his/her email and be still logged into the prodcutcart browser session and someone else would have to come along and click the link before it timed out.
 
Nigel
Innerview
Productcart Platinum Reseller
Web Design/Hosting/Virtual Tours
Back to Top
SBW View Drop Down
Newbie
Newbie


Joined: 09-July-2011
Status: Offline
Points: 0
Post Options Post Options   Thanks (0) Thanks(0)   Quote SBW Quote  Post ReplyReply Direct Link To This Post Posted: 13-July-2011 at 7:06pm
Actually, it's a security issue simply by the fact that data is being submitted in a non-encrypted matter. That's the only issue I'm concerned about.  It has nothing to do with someone else coming by and getting into their session.
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.078 seconds.