Results 1 to 3 of 3
  1. #1
    Join Date
    Feb 2004
    Location
    portsmouth, nh us
    Posts
    119
    Plugin Contributions
    4

    Default Customer Logs in and sees another customers account

    I had a weird problem that I can't seem to track down. A customer logged into their account and saw another customer's information. Has anyone else ever had this problem? Could this be a session problem?

    This is a 1.2.6 install with wholesale/dual pricing installed.
    "You must be the change you wish to see in the world" - Ghandi

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Customer Logs in and sees another customers account

    Yes - it's likely a session problem .... but more specifically it's an advertising problem.
    If the customer is coming to your site via a link that contains a zenid parameter, then *everyone* who comes to that link will share their information.

    The key is to *NOT* post links that contain the zenid parameter. This means emails, advertising, everything.

    In the newer versions of Zen Cart there have been some improvements to the Session Recreate logic which will dump the existing zenid during login and build a new one. You could try flipping that switch on in your current version, but I have no idea if it will help much or not. I suggest upgrading either way.
    Admin->Configuration->Sessions->"Session Recreate" --- set to True.
    Don't touch anything else in there.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Feb 2004
    Location
    portsmouth, nh us
    Posts
    119
    Plugin Contributions
    4

    Default Re: Customer Logs in and sees another customers account

    Thanks,

    I will make sure that we don't send out any links containing the session id.

    An upgrade is in progress, but it takes a while to get through everything and test it
    "You must be the change you wish to see in the world" - Ghandi

 

 

Similar Threads

  1. There exist any forum plugin (so customers don't need another account)?
    By DArnaez in forum All Other Contributions/Addons
    Replies: 4
    Last Post: 1 Nov 2014, 01:12 AM
  2. Prices disappear during checkout OR when a customer logs into thier account
    By donhorn in forum Setting Up Specials and SaleMaker
    Replies: 4
    Last Post: 7 Sep 2014, 08:11 PM
  3. Want to add another e-mail address field to customer account
    By MelodyW in forum Managing Customers and Orders
    Replies: 1
    Last Post: 27 Feb 2013, 03:34 PM
  4. Everyone Sees Account Info
    By staedtler in forum General Questions
    Replies: 10
    Last Post: 11 Jun 2008, 11:28 PM
  5. Replies: 4
    Last Post: 18 Jan 2008, 08:14 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR