Forums / Addon Payment Modules / Ensuring SSL only access to the cart

Ensuring SSL only access to the cart

Locked

Views: 1,061

Results 1 to 3 of 3
This thread is locked. New replies are disabled.
13 Jul 2010, 10:55 AM
#1
feef avatar

feef

New Zenner

Join Date:
May 2010
Posts:
6
Plugin Contributions:
0

Ensuring SSL only access to the cart

I've installed an SSL cert, reconfigured the site to use SSL and https access works when clicking thru the payment process.

However, if you remove the "s" form https when in the cart (or enter the cart URL manually over http) and load the page that way, you are still able to see, and submit card and personal data over http.

Is there a way of ensuring ALL access to the pages index.php?main_page=checkout_[XXX] are redirected to their SSL conterparts?

Thanks

a

13 Jul 2010, 2:21 PM
#2
Kim avatar

Kim

Obaa-san

Join Date:
Jun 2003
Location:
West Coast, North America
Posts:
26,667
Plugin Contributions:
0

Re: Ensuring SSL only access to the cart

However, if you remove the "s" form https when in the cart (or enter the cart URL manually over http) and load the page that way, you are still able to see, and submit card and personal data over http

Not exactly - All of the form information is still sent via https as long as your cart and certificate are configured correctly.

Please do not PM for support issues: a private solution doesn't benefit the community.

Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

13 Jul 2010, 2:51 PM
#3
feef avatar

feef

New Zenner

Join Date:
May 2010
Posts:
6
Plugin Contributions:
0

Re: Ensuring SSL only access to the cart

Kim:

Not exactly - All of the form information is still sent via https as long as your cart and certificate are configured correctly.

I recognise that, but I'd rather have it so that any page where you're entering creditcard numbers has been served over SSL.

I've worked it out using mod_rewrite in a .htaccess file.

RewriteEngine On
RewriteCond %{QUERY_STRING} ^main_page=checkout_(.*)$
RewriteCond %{SERVER_PORT} !443
RewriteRule (.*) https://%{server_name}/$1 [R]

i.e.
Turn on the rewrite ening
Match cases where the query string has checkout_[foo] (where foo could be "confirmation", "shipping" or "payment")
Then check if you're not using port 443
and if not then rewrite to https://