Zen Cart Logo
Forums / Installing on a Linux/Unix Server / .htaccess and Admin Area Problem

.htaccess and Admin Area Problem

Views: 3,560

Results 1 to 12 of 12
15 Mar 2013, 2:00 AM
#1
sanguinarius avatar

sanguinarius

New Zenner

Join Date:
Feb 2013
Location:
Green Valley, Arizona, United States
Posts:
21
Plugin Contributions:
0

.htaccess and Admin Area Problem

I'm using ZC 1.5.0. new install from my hosting company cPanel. I have SSL and all that.

I wanted to make the following urls all automatically forward to https://www.sanguinarius.org/store/ :

http://www.sanguinarius.org/store/
http://sanguinarius.org/store/
https:/sanguinarius.org/store/

I contacted my hosting company and they told me to use a .htaccess file with this in it:

[B]RewriteEngine On
    RewriteCond %{SERVER_PORT} 80
    RewriteRule ^(.*)$ https://www.sanguinarius.org/store/$1 [R=301,L][/B]

and upload it to my store directory. (That is so the rest of my website doesn't get forwarded to https://;blahblahblah.

OK, fine. I did that. Then I went to edit a product and submit it to the database and I get the pink strip at the top that says:

Error ERROR: The data you submitted was found to be empty. YOUR CHANGES HAVE NOT BEEN SAVED. You may have a problem with your browser or your internet connection.

=====

What did I do wrong and how do I make it right short of removing the .htaccess file and having people going to http://www.sanguinarius.org/store/ and it not being secure? Or do I remove the file and do something else that you ZC guys here know about but my webhost's tech support doesn't?

15 Mar 2013, 2:12 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: .htaccess and Admin Area Problem

What's so sensitive about your site that you need it to serve everything over SSL?

To do it, it would be a whole lot simpler if you simply deleted that .htaccess change and merely set all the URLs in your configure.php files to point to https:// instead of a mix of http:// and https://

15 Mar 2013, 10:26 AM
#3
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: .htaccess and Admin Area Problem

Sanguinarius:

I contacted my hosting company and they told me ...

I would cancel my hosting account IMMEDIATELY, and move the installation to a crowd that knows eCommerce and zencart in particular.

The minute a host indicates that they have little idea about how important platforms and systems work should be a clear signal to go find one that knows what they are doing.

15 Mar 2013, 11:54 PM
#4
sanguinarius avatar

sanguinarius

New Zenner

Join Date:
Feb 2013
Location:
Green Valley, Arizona, United States
Posts:
21
Plugin Contributions:
0

Re: .htaccess and Admin Area Problem

schoolboy:

I would cancel my hosting account IMMEDIATELY, and move the installation to a crowd that knows eCommerce and zencart in particular.

The minute a host indicates that they have little idea about how important platforms and systems work should be a clear signal to go find one that knows what they are doing.

I canceled my old host immediately and moverd to my current one BECAUSE they DID support Zen Cart. I've paid for a year: hosting, dedicated IP and SSL certificate and I can't afford to move at this point. I'm on a fixed income but hoping to eventualy break out of the cycle by becoming a webepreneur. :) Anyway, I like them. I think I just got a hold of one that was a dummy.

16 Mar 2013, 12:04 AM
#6
sanguinarius avatar

sanguinarius

New Zenner

Join Date:
Feb 2013
Location:
Green Valley, Arizona, United States
Posts:
21
Plugin Contributions:
0

Re: .htaccess and Admin Area Problem

This is what I have in my catalog/includes/configure.php folder:

// Define the webserver and path parameters
  // HTTP_SERVER is your Main webserver: eg-http://www.your_domain.com
  // HTTPS_SERVER is your Secure webserver: eg-https://www.your_domain.com
  define('HTTP_SERVER', 'http://sanguinarius.org');
  define('HTTPS_SERVER', 'https://sanguinarius.org');

  // Use secure webserver for checkout procedure?
  define('ENABLE_SSL', 'false');

// NOTE: be sure to leave the trailing '/' at the end of these lines if you make changes!
// * DIR_WS_* = Webserver directories (virtual/URL)
  // these paths are relative to top of your webspace ... (ie: under the public_html or httpdocs folder)
  define('DIR_WS_CATALOG', '/store/');
  define('DIR_WS_HTTPS_CATALOG', '/store/');

Shouldn't this following snippet of code be set to "true"? WOuld that alone solve my problem?:

// Use secure webserver for checkout procedure?
define('ENABLE_SSL', 'false');

This is what I have in my admin/includes/configure.php file:

/**
 * WE RECOMMEND THAT YOU USE SSL PROTECTION FOR YOUR ENTIRE ADMIN:
 * To do that, make sure you use a "https:" URL for BOTH the HTTP_SERVER and HTTPS_SERVER entries:
 */
  define('HTTP_SERVER', 'http://sanguinarius.org');
  define('HTTPS_SERVER', 'https://sanguinarius.org');
  define('HTTP_CATALOG_SERVER', 'http://sanguinarius.org');
  define('HTTPS_CATALOG_SERVER', 'https://sanguinarius.org');

  // secure webserver for admin?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_ADMIN', 'true');

  // secure webserver for storefront?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_CATALOG', 'true');
16 Mar 2013, 12:26 AM
#7
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: .htaccess and Admin Area Problem

Two changes, highlighted and bolded in red:

Sanguinarius:

catalog/includes/configure.php:

// Define the webserver and path parameters
// HTTP_SERVER is your Main webserver: eg-http://www.your_domain.com
// HTTPS_SERVER is your Secure webserver: eg-https://www.your_domain.com
define('HTTP_SERVER', 'http://sanguinarius.org');
define('HTTPS_SERVER', 'https://sanguinarius.org');

// Use secure webserver for checkout procedure?
define('ENABLE_SSL', '[B]true[/B]');

// NOTE: be sure to leave the trailing '/' at the end of these lines if you make changes!
// * DIR_WS_* = Webserver directories (virtual/URL)
// these paths are relative to top of your webspace ... (ie: under the public_html or httpdocs folder)
define('DIR_WS_CATALOG', '/store/');
define('DIR_WS_HTTPS_CATALOG', '/store/');

> 
> 
> This is what I have in my admin/includes/configure.php file:
> 
> ```
/**
 * WE RECOMMEND THAT YOU USE SSL PROTECTION FOR YOUR ENTIRE ADMIN:
 * To do that, make sure you use a "https:" URL for BOTH the HTTP_SERVER and HTTPS_SERVER entries:
 */
  define('HTTP_SERVER', 'http[B]s[/B]://sanguinarius.org');
  define('HTTPS_SERVER', 'https://sanguinarius.org');
  define('HTTP_CATALOG_SERVER', 'http://sanguinarius.org');
  define('HTTPS_CATALOG_SERVER', 'https://sanguinarius.org');

  // secure webserver for admin?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_ADMIN', 'true');

  // secure webserver for storefront?  Valid choices are 'true' or 'false' (including quotes).
  define('ENABLE_SSL_CATALOG', 'true');
16 Mar 2013, 2:45 AM
#8
sanguinarius avatar

sanguinarius

New Zenner

Join Date:
Feb 2013
Location:
Green Valley, Arizona, United States
Posts:
21
Plugin Contributions:
0

Re: .htaccess and Admin Area Problem

In the admin configure, won't this line of code (below) make my whole domain SSL?

define('HTTP_SERVER', 'https://sanguinarius.org');

Do I need my whole domain to be secure? Is that something I should have enabled anyway or not? Does it make it safer from hackers?

16 Mar 2013, 2:54 AM
#9
sanguinarius avatar

sanguinarius

New Zenner

Join Date:
Feb 2013
Location:
Green Valley, Arizona, United States
Posts:
21
Plugin Contributions:
0

Re: .htaccess and Admin Area Problem

Well, you're the Sensei, DrByte. It works, so I'm not going to question that. I can continue with my customizing and adding products. Thank you.

16 Mar 2013, 4:22 AM
#10
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: .htaccess and Admin Area Problem

NOTE: You quoted your catalog AND admin configure.php files, and I told you to put the "s" in ONLY on the admin one. Not the other one. Heed that.

16 Mar 2013, 5:21 AM
#11
sanguinarius avatar

sanguinarius

New Zenner

Join Date:
Feb 2013
Location:
Green Valley, Arizona, United States
Posts:
21
Plugin Contributions:
0

Re: .htaccess and Admin Area Problem

I did put it only in that one.

16 Mar 2013, 10:45 PM
#12
lhungil avatar

lhungil

Totally Zenned

Join Date:
Feb 2012
Location:
mostly harmless
Posts:
1,818
Plugin Contributions:
4

Re: .htaccess and Admin Area Problem

Glad you were able to get things sorted. I just stumbled across this thread... One of the major problems you were encountering is because the RewriteRule your hosting provider gave you causes a 301 redirect even if POST data is present.

This is one of many mistakes people make when working with 301 redirects. Issuing a 301 redirect for a request containing POST data will result in loss of the POST data. This is why you were seeing "ERROR: The data you submitted was found to be empty. YOUR CHANGES HAVE NOT BEEN SAVED. You may have a problem with your browser or your internet connection".

As other people on here already mentioned, the correct fix is to change the configure.php files so Zen Cart generates links starting with the protocol, server name, and other information correctly the first time - with no 301 redirects needed.

If you must redirect the first request to your website in case someone does not type the "www."... The following would be better:

RewriteEngine On
RewriteCond %{SERVER_PORT} 80
RewriteCond %{HTTP_HOST} ^sanguinarius\.org$ [NC]
RewriteCond %{REQUEST_METHOD} !POST
RewriteRule ^.*$ http://www\.%{HTTP_HOST}%{REQUEST_URI} [R=301,QSA,L]

RewriteCond %{SERVER_PORT} 443
RewriteCond %{HTTP_HOST} ^sanguinarius\.org$ [NC]
RewriteCond %{REQUEST_METHOD} !POST
RewriteRule ^.*$ https://www\.%{HTTP_HOST}%{REQUEST_URI} [R=301,QSA,L]

In most cases only the first block will be the only block needed. Keep in mind as well not all servers support checking %{SERVER_PORT}. Again, this would only be needed to catch the first page (as the links would contain what is in your configure.php files) when someone manually typed in your address - or - links from another site (adwords, search engines, etc) did not have the "www." prefix.