Forums / Bug Reports / [Done v1.5.0] Small bug found on Authorize.net AIM refund page

[Done v1.5.0] Small bug found on Authorize.net AIM refund page

Locked

Views: 2,677

Results 1 to 5 of 5
This thread is locked. New replies are disabled.
6 Feb 2011, 8:48 PM
#1
buzzworm2 avatar

buzzworm2

New Zenner

Join Date:
Nov 2008
Posts:
16
Plugin Contributions:
0

[Done v1.5.0] Small bug found on Authorize.net AIM refund page

I found a small bug on the refund page for Authorize.net.

In Admin>customers>orders you can edit an order and void a transaction that hasn't settled.

The input box on the right says "enter auth ID" but that didn't work; I got a "transaction not found" error message.

So I tried the transaction ID instead and that worked.

The file is /public_html/includes/modules/payment/authorizenet/authorizenet_admin_notification.php

and line 76 (or 77?) is

Line #76 : $outputVoid .= MODULE_PAYMENT_AUTHORIZENET_AIM_ENTRY_VOID . '<br />' . zen_draw_input_field('voidauthid', 'enter auth ID', 'length="32"');

but should be this to avoid confusion:
Line #76 : $outputVoid .= MODULE_PAYMENT_AUTHORIZENET_AIM_ENTRY_VOID . '<br />' . zen_draw_input_field('voidauthid', 'enter transaction ID', 'length="32"');

8 Feb 2011, 3:18 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.5.0] Small bug found on Authorize.net AIM refund page

Well, calling it a transaction ID would be equally incorrect if you were wanting to cancel an Authorize-Only authorization, ie: something that hasn't been captured yet, since there's no transaction ID associated with an Auth-only event until it is captured.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

8 Feb 2011, 8:35 AM
#3
buzzworm2 avatar

buzzworm2

New Zenner

Join Date:
Nov 2008
Posts:
16
Plugin Contributions:
0

Re: [Done v1.5.0] Small bug found on Authorize.net AIM refund page

I have the AIM payment module set to auth+capture and I immediately got an authID and a transID. But only the transID worked in that field to void the transaction. Are you saying that if I had set AIM to "auth-only", I wouldn't have received a transID? And in that case, do you think an authID would've voided the transaction?

12 Feb 2011, 11:44 PM
#4
ibuttons avatar

ibuttons

New Zenner

Join Date:
Nov 2008
Posts:
51
Plugin Contributions:
0

Re: [Done v1.5.0] Small bug found on Authorize.net AIM refund page

Boy, thanks buzzworm2 for posting that. We interpreted the label the same way you did, and we thought the screen just did not work. We tried a lot of different things, but just did not think of using the transaction key.

Dr. Byte, is there anyway that you could make the wording clearer? I am sure more people than us have been bitten by this one. And I must confess, I am not sure what you meant by your answer.

Meanwhile, since we authorize and capture simultaneously, I am going to just change the wording as suggested by buzzworm2, since that is clear for us.

Thanks again, buzzworm2, for posting that.

16 Feb 2011, 3:12 AM
#5
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.5.0] Small bug found on Authorize.net AIM refund page

I suppose clearer wording of the text above that box would be:> You may void a transaction which has not yet been settled, or an authorization which has not been captured.

Enter the unsettled Trans ID or the uncaptured Auth ID:

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.