Results 1 to 3 of 3
  1. #1
    Join Date
    Jun 2019
    Location
    Austin TX
    Posts
    65
    Plugin Contributions
    0

    Default How should 'customers_secret' be handled in upgrade?

    I'm moving a 1.5.6b database into a fresh install of 1.5.8 and everything has been working well so far but I noticed that 'customers_secret' was not a column in the old database and that it is not nullable in the new database. I was able to properly import the old data without issue but I was wondering if that was creating a security issue since every customer's secret is just an empty varchar(64). Does that mean customer accounts are at risk of unauthorized password resets if someone tries to enter a blank secret to reset an account's password?

  2. #2
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    13,318
    Plugin Contributions
    94

    Default Re: How should 'customers_secret' be handled in upgrade?

    Quote Originally Posted by clam_man View Post
    I'm moving a 1.5.6b database into a fresh install of 1.5.8 and everything has been working well so far but I noticed that 'customers_secret' was not a column in the old database and that it is not nullable in the new database. I was able to properly import the old data without issue but I was wondering if that was creating a security issue since every customer's secret is just an empty varchar(64). Does that mean customer accounts are at risk of unauthorized password resets if someone tries to enter a blank secret to reset an account's password?
    That new field is used only when using the admin-login-as-customer feature introduced in zc157.

  3. #3
    Join Date
    Jun 2019
    Location
    Austin TX
    Posts
    65
    Plugin Contributions
    0

    Default Re: How should 'customers_secret' be handled in upgrade?

    Thank you for the reply. I appreciate you clearing that up for me. I was worried and wanted to make sure before making the new site live. Looks like nothing at all to worry about then!

 

 

Similar Threads

  1. How soon should I upgrade?
    By jonnyboy22 in forum General Questions
    Replies: 3
    Last Post: 2 Jan 2012, 11:52 PM
  2. How long on the average should it take to upgrade?
    By richk58 in forum Upgrading from 1.3.x to 1.3.9
    Replies: 3
    Last Post: 24 Feb 2011, 11:40 PM
  3. How is downloadable content handled?
    By aliasjanedoe in forum General Questions
    Replies: 1
    Last Post: 19 Aug 2009, 01:33 AM
  4. How to handled delayed charges?
    By Cunk in forum General Questions
    Replies: 4
    Last Post: 25 Aug 2008, 06:19 PM
  5. How are backorders handled?
    By GrayOne in forum Built-in Shipping and Payment Modules
    Replies: 1
    Last Post: 19 Mar 2008, 07:05 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR