Quote Originally Posted by Ajeh View Post
......

Granted you have to really want to get in there and are not a "good" customer ... so, this might not be worth the hassel to try to fix ... otherwise, somewhere you may need one more check that evil is not being committed ...
Had another thought on this point:

A customer needs to know the products_id before they can apply this "trick". They first need to be (manually) privileged by the store owner to actually get the products_id

If they are already approved (=privileged) then there is no point for them to try this hack.

In the demo store the privileged login credentials are openly displayed for demo / testing purposes, in a real store that is not the case.

Still, for this mod to be picture perfect it needs to be watertight. So ..... v2.1 it will be

Need to find a test where the products_id is checked against the array CATEGORY_RESTRICTION_LOGIN_CATEGORY which is configured via admin ...