Page 1 of 2 12 LastLast
Results 1 to 10 of 16
  1. #1
    Join Date
    Aug 2009
    Posts
    12
    Plugin Contributions
    0

    Default Session lost when clicking on pages from https to http under IE

    Hi all,

    I have just found that, under IE, when I log in (https page), if I click on any page which is http one, then the session is lost, and the status shows that I am not logged in yet. So now if I click on any https page, it asks me to login again..

    There is no problem when change between https pages.
    And there is no problem under Firefox and Chrome. The problem is only under IE. I have checked on IE6, IE7 and IE8, also checked on XP, Vista and WIN7, all the same, the session will be lost when redirecting pages from https to http.

    Is this a common problem? or just happen to me because of any file of zen-cart I have modified wrongly?

    Could anyone please advise why this happen and how to fix it?
    Many Thanks!!!

    There is a Security Warning popping up when I log in (I am not sure if this is related to the lost session or not), as shown below:

  2. #2
    Join Date
    Aug 2009
    Posts
    12
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    (don't know how to edit my thread above, so I add something here)

    Just found that, the problem might not come from SSL or HTTPS to HTTP. Something wrong within my login/register pages.
    I have tested that, when SSL is disabled, I can not either login as a user or regsiter a user account under IE...

    I tried to remove my CUSTOM_TEMPLATE, but still no luck...

  3. #3
    Join Date
    Jun 2003
    Posts
    33,720
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    Your URL?
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  4. #4
    Join Date
    Aug 2009
    Posts
    12
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    Hi Kim, my url is t i v o n a . c o m . a u

    I have tested a lot trying to see what differences between HTTPS pages and HTTP pages, and what consequences would happen.
    I think my previous description isn't accurate enough. The session seems like not lost, but two different sessions for HTTPS and HTTP.

    What I have found are:

    (All done under IE, and all tested on the first time to open the site (it means the session must be cleared before trying again)

    1.
    When the site is opened, there is a zenid generated, eg. zenid=c66d48a24712cf0c74269f03d11414c4.
    After clicking on a HTTPS page, eg. Login page, zenid is the same, c66d48a24712cf0c74269f03d11414c4.
    After logged in, zenid changes to a different one, eg. zenid=080bbc7121e22366aeb6db7ce51f19a3. But when I checked request['zenid'] now, the request['zenid'] is the first one c66d48a24712cf0c74269f03d11414c4. (When I tested by using Firefox/Chrome, the request['zenid'] this time should be the same as zenid which is the one generated after directly logged in). So now, if you click on any HTTP page, then it shows you not logged in yet...

    2.
    When the site is opened, then you click on a HTTP page first, after that, click on a HTTPS page, eg. Login page, and this time, you can't even login.

    3.
    If copy the login page address, eg. http://domain/index.php?main_page=login directly on IE and log in, then no problem at all changing pages from HTTPS to HTTP, or HTTP to HTTPS. zenid and requst['zenid'] this time, they are the same all the way.

    4.
    If I don't enable SSL in the configure.php, "define('ENABLE_SSL', 'false');", then I can not even login under IE.
    (but there was once I did log in successfully, only one time, and I could changing pages without any problem, still stay logged in. However, no matter how many times I try now, can not log in anymore, really weird....)

    Please help! This is really annoying me and it's been a couple of days trying to figure it out and still can't.
    Now it seems like even I disable SSL, still have problem to login..
    Thanks in advance.

  5. #5
    Join Date
    Jun 2003
    Posts
    33,720
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    You are using one of the quick checkout addons?
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  6. #6
    Join Date
    Sep 2009
    Location
    Liverpool
    Posts
    96
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    I had exactly the same problem but with IE, FF, Chrome and Safari. For some weird reason, it corrected itself today.

  7. #7
    Join Date
    Aug 2009
    Posts
    12
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    Quote Originally Posted by Kim View Post
    You are using one of the quick checkout addons?
    Kim, I am not using any quick checkout addon.

    The addons I am using are:
    1. all_sub_cats_products
    2. column_layout_grid_for_product_listing
    I think so far I have just used those two.
    And I modified some files and changed Admin Settings to make Registration process shorter. Does this cause the problem? I tried to remove my custom template, but the problem still remains. So I reckon it is not about what I modifed, it might be something related to SSL, HTTPS, HTTP kind of thing..

  8. #8
    Join Date
    Aug 2009
    Posts
    12
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    anyone can help with this pls?

  9. #9
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: Session lost when clicking on pages from https to http under IE

    Did you put in all the Chinese characters into your code that you can see in a view source?

    If not, you best see if your site is hacked ...



    You have a few issues ...

    In FireFox, if you click on the Login, you will see the broken lock ... click it, and click on Media and fix the issues with images that are not secure ...

    Next, there appears to be a problem on the edit account ...

    You will find if you create that initial email and password by clicking on the Login, that if you go to Checkout it wants the missing data ... that doesn't appear to work correctly or it is getting hung up ...

    First get the code working with:

    Hit the site ...

    Add to Cart ...

    Click Login ...

    Go to Product (anything just to get off secure page) ...

    Go to My Account ...

    Edit Address ...

    Once you have that working ... then move on to the next step ...
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

  10. #10
    Join Date
    Aug 2009
    Posts
    12
    Plugin Contributions
    0

    Default Re: Session lost when clicking on pages from https to http under IE

    Hi Ajeh, thanks for you reply.

    Yeah, I did put all Chinese characters into my code as references to reminder me. It is not hacked.

    I am not sure what you mean "the broken lock"? I have tried it in Firefox and can't see what the broken lock is? and also where is "Media" can be clicked on? is that possible to show me any screenshot or more details pls?

    There is a problem in User address book which hasn't been fixed yet. But I reckon it shouldn't be related to the HTTPS/HTTP and SSL problem under IE?

    For the rest problem you mentioned, were they under IE or FF?
    thanks again.

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Replies: 7
    Last Post: 31 Dec 2014, 04:58 PM
  2. HTTP vs HTTPS pages - as designed?
    By Brian1234 in forum General Questions
    Replies: 3
    Last Post: 13 Jun 2011, 03:41 AM
  3. From http:// to https://
    By Phoebus in forum General Questions
    Replies: 2
    Last Post: 9 Jan 2010, 12:07 AM
  4. Many http links in https pages
    By Brian1234 in forum General Questions
    Replies: 4
    Last Post: 11 Mar 2008, 03:18 AM
  5. Admin pages jumps from https to http
    By fontgarden in forum Customization from the Admin
    Replies: 9
    Last Post: 6 Apr 2007, 10:45 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg