Zen Cart Logo
Forums / General Questions / Specialized Catalog links for approved customers only?

Specialized Catalog links for approved customers only?

Locked

Views: 669

Results 1 to 3 of 3
This thread is locked. New replies are disabled.
3 Feb 2009, 4:39 PM
#1
jbhansen avatar

jbhansen

New Zenner

Join Date:
Dec 2006
Posts:
19
Plugin Contributions:
0

Specialized Catalog links for approved customers only?

We have a wholesale business, and all our customers must be preapproved before they're allowed to view our prices and purchase products. But once a customer has been approved, we provide them with a link to download our current inventory data - including prices - so they can import it into their own systems quickly and easily, whenever they need it.

The URL's for those links aren't published on the site anywhere for the public to see, but we're concerned that if those URLs somehow get out to noncustomers, we'll lose control over who can see our prices and who can't.

So here's the question: Is there a way we can password-protect those files? Here's what the page code looks like currently:

<code> <?php

header("Content-type: application/csv");
header("Content-Disposition: attachment; filename=filename_download.txt");
header("Pragma: no-cache");
header("Expires: 0");

if (file_exists('includes/configure.php')) {
/**
* load the main configure file.
*/
include('includes/configure.php');
} else {
header('location: zc_install/index.php');
}

$dbc = @mysql_connect(DB_SERVER,DB_SERVER_USERNAME,DB_SERVER_PASSWORD) OR die ('Could not connect to database: ' . mysql_error());

@mysql_select_db(DB_DATABASE) or die ('Could not select the database: ' . mysql_error());

$query="SELECT manufacturers_name AS manufacturer, products_model AS sku, products_quantity AS quantity, products_price AS price, products_msrp AS msrp, products_name AS name, products_salesperweek as salesperweek FROM products AS p, manufacturers AS m, products_description AS pd WHERE p.manufacturers_id = m.manufacturers_id AND pd.products_id = p.products_id ORDER BY manufacturer, sku";

$result=mysql_query($query);

$cr = "\n";
$tab = "\t";

if($result) {

$data = 'Manufacturer' . $tab . 'SKU' . $tab . 'Quantity' . $tab . 'Price' . $tab . 'MSRP' . $tab . 'Name' . $cr;

while ($row = mysql_fetch_array ($result, MYSQL_ASSOC))
{

$data .= $row['manufacturer'] . $tab . $row['sku'] . $tab . $row['quantity'] . $tab . number_format($row['price'],2) . $tab . number_format($row['msrp'],2) . $tab . $row['name'] . $cr;
}

mysql_free_result($result);

echo $data;

}
else {
echo '<p>The inventory list is currently unavailable. Sorry for the inconvenience. Please contact us to report this problem.</p>';
}
</code>

Thank you in advance!

3 Feb 2009, 6:50 PM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Specialized Catalog links for approved customers only?

You could write some custom code to do something like this:

a) put the link to that page on the My Account screen, and make it only show if the customer's authorization level is at the right value.
b) alter your script so that it checks that the customer is logged in with a valid ID, and also that their customer authorization level is right

4 Feb 2009, 3:40 AM
#3
jbhansen avatar

jbhansen

New Zenner

Join Date:
Dec 2006
Posts:
19
Plugin Contributions:
0

Re: Specialized Catalog links for approved customers only?

Ah ha. Thanks so much for the reply. That got me on the right track.