Results 1 to 3 of 3
  1. #1
    Join Date
    Apr 2005
    Posts
    13
    Plugin Contributions
    0

    Default Is there ANY way to fix the zenid problems ONCE AND FOR ALL?

    I am getting quite frustrated with the zen-id issue that allows one customer unknowingly to log in as another customer. We have problems every so often with this in our store, and today especially had a problem, where one customer received about 10 order confirmations that she did not ORDER!

    I've done a search on this and seen SO many other sites have had this problem. Usually they are told not to post a link with the "zen-id" in it. This is fine & dandy, but how in the world do you inform everyone who visits your store that they have to be extremely careful in posting links to your store anywhere? We have lots of customers who like our stuff, then post at other places about it, and may include a zen-id without even knowing about the problem.

    Is there some sort of fix for this that will take care of the problem once and forever? Some add-on we can add that automatically deletes a 'zen-id' part of a link when it comes through?

    Does the newest version of zen-cart still have this problem (we have the version just before this recent change)?

    Please help.

  2. #2
    Join Date
    Mar 2005
    Posts
    555
    Plugin Contributions
    4

    Default Re: Is there ANY way to fix the zenid problems ONCE AND FOR ALL?

    go to the code suggestion forum and find a post by Jeff D about DWNOs mod that will solve this.

    Please consider the code in that post to be very BETA and it wont work if your using a shared SSL.
    My humble contributions....
    Info at a Glance Admin, Alternative Header & Improved Whos Online + Currently working on the next!
    If you have to think..... your obviously looking at the admin :)

  3. #3
    Join Date
    Jul 2005
    Posts
    120
    Plugin Contributions
    0

    Default Re: Is there ANY way to fix the zenid problems ONCE AND FOR ALL?

    1.3.0.2 still has this issue. You can turn on 'recreate session id' in Admin->Config->Sessions

    It'll take care of the case where the zenid is copied before a customer logs in.

    The only exception to your problem is if the user copies the URL with the zenid after logging in and posts it somewhere. Until someone logs out using that session id or it times out...every connection using that zenid will be able to see that original users address, order history, etc.

 

 

Similar Threads

  1. Attributes to all products at once- surely there must be a way to do it?
    By zan_dude in forum Setting Up Categories, Products, Attributes
    Replies: 3
    Last Post: 26 Oct 2012, 12:11 PM
  2. Replies: 0
    Last Post: 27 Oct 2011, 11:38 PM
  3. How would I move the template all the way to the right and fix an image to the
    By pityocamptes in forum Templates, Stylesheets, Page Layout
    Replies: 10
    Last Post: 15 Sep 2010, 05:45 AM
  4. Is there a way to edit all attributes at once?
    By badboy in forum Setting Up Categories, Products, Attributes
    Replies: 2
    Last Post: 16 Apr 2010, 04:08 AM
  5. Replies: 10
    Last Post: 26 Oct 2006, 11:07 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR