Zen Cart Logo
Forums / All Other Contributions/Addons / sessionWatcher (better handling of session timeouts)

sessionWatcher (better handling of session timeouts)

Locked

Views: 9,932

Results 41 to 50 of 50
This thread is locked. New replies are disabled.
3 Sep 2010, 6:24 PM
#41
s_mack avatar

s_mack

Totally Zenned

Join Date:
Jun 2005
Location:
Kelowna, BC Canada
Posts:
1,033
Plugin Contributions:
4

sessionWatcher (better handling of session timeouts)

I know I should have looked at it way back when... but I'm only now updating my zen an reinstalling my mod here... and I have to say, the "errors" that were "fixed" above, I have to question. Unless you have a source to say otherwise, I think the use of isset is just semantics and hardly fixes an error. And without further support, you introduce an error with your ENABLE_SESSION_WATCHER check (where's that constant come from?)

I'm pretty sure the file was good as-was.

  • Steven
3 Sep 2010, 6:37 PM
#42
s_mack avatar

s_mack

Totally Zenned

Join Date:
Jun 2005
Location:
Kelowna, BC Canada
Posts:
1,033
Plugin Contributions:
4

Re: sessionWatcher (better handling of session timeouts)

FYI, the package works as-is for v1.3.9f

I still think this is one of my best, most useful, and under-appreciated mods :) several years later, only a couple thousand downloads!

One thing I perhaps never made clear is that you can enjoy the benefits of the return-where-they-were features even if you don't want to bother with the pre-fill-their-form feature. The site I'm installing it on right now, for example, doesn't use reviews or any forms really where the customer might take > 20 minutes to type up. So I'm not bothering with all the template edits. But the core functionality of it still sends a customer to the page they were on when they login. FAR more intuitive.

  • Steven
4 Sep 2010, 1:39 AM
#43
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: sessionWatcher (better handling of session timeouts)

Um ... if this addon is installed and someone is on the checkout-payment screen and enters credit card details and encounters a timeout, does this addon store the credit card number in the database?
If so, then this is a very dangerous addon, and makes the store fail PCI compliance.
I submit that this addon should be disabled on checkout_* pages.

4 Sep 2010, 1:55 AM
#44
s_mack avatar

s_mack

Totally Zenned

Join Date:
Jun 2005
Location:
Kelowna, BC Canada
Posts:
1,033
Plugin Contributions:
4

Re: sessionWatcher (better handling of session timeouts)

We had a back-and-forth on this a couple years ago when I first submitted it :)

Short answer, "no". It is not unsafe at all. Because no forms/fields are included by default. Check out the readme. The shopkeeper has to deliberately add code to a form to include it. It is intended for long items, such as reviews. Imagine the frustration of a customer who takes the time to help the shop but takes "too long" and loses their work?

Nobody takes 25 minutes to type in 16 numbers for checkout. So no shopkeeper is going to bother adding the function to that form. I believe it is in the readme to NOT include it with any form relating to sensitive data.

4 Sep 2010, 2:05 AM
#45
s_mack avatar

s_mack

Totally Zenned

Join Date:
Jun 2005
Location:
Kelowna, BC Canada
Posts:
1,033
Plugin Contributions:
4

Re: sessionWatcher (better handling of session timeouts)

From the first post of this thread:

s_mack:

sessionWatcher provides serves the following purposes:

  1. To return a user to the page they were on after they log in using the "log in" links (but doesn't interfere with pages that have built-in history). This is more intuitive for the user.
  1. To allow a user to not have to re-type data when submitting a form after their session has timed out. This can apply to the Contact Us page, the Write a Review page, or any page that a user is required to be logged in to submit, and could conceivably take longer than 24 minutes to complete (24 minutes is the default session time-out). For example, if they are a slow typer or they get distracted. Save your customers unnecessary work and frustration!

I may have highlighted item 2 with red, but the first item is the primary feature in my opinion, and the one I still strongly believe you guys should include in the core code! Absolutely no security holes with that one (or #2 unless a shopkeeper did so) and it makes the shop login process worlds more intuitive for the end user.

I've always thought it absurd that you go to the store, add a product, go to checkout, login, and are sent back to the product. huh? You should obviously be sent back to the checkout where you were! With the first feature of this mod that happens. No matter where the customer is when they login they are sent back there. it just makes sense.

  • Steven
4 Sep 2010, 2:14 AM
#46
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: sessionWatcher (better handling of session timeouts)

s_mack:

Check out the readme. The shopkeeper has to deliberately add code to a form to include it. It is intended for long items, such as reviews.

Okay. Noted. Clearly I scanned the readme too quickly. :blush:

In it you state: "except you probably want to leave the account creation and the checkout processes alone (just in case)".

I submit that you should still explicitly prevent it from working on checkout_* pages since that data should never be stored unencrypted, even if the merchant decides they want to shoot themselves in the foot.
Then again, PCI compliance is always up to the merchant's choices anyway. We can't spoon-feed them forever.

4 Sep 2010, 2:17 AM
#47
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: sessionWatcher (better handling of session timeouts)

s_mack:

I've always thought it absurd that you go to the store, add a product, go to checkout, login, and are sent back to the product. huh? You should obviously be sent back to the checkout where you were!
Yes, I agree. That would be absurd.
That's why a clean new install of Zen Cart works exactly like this:

  • add to cart
  • go to checkout
  • login or create account
  • return to checkout
    Just as one would expect
4 Sep 2010, 2:22 AM
#48
s_mack avatar

s_mack

Totally Zenned

Join Date:
Jun 2005
Location:
Kelowna, BC Canada
Posts:
1,033
Plugin Contributions:
4

Re: sessionWatcher (better handling of session timeouts)

Hmmmm...

HMMM....

Hmmm?

OK well now I have to figure out why mine doesn't.

Tell me this. When you go to a page, say to write a review (something that requires login), and while you're on that page you realize you're not logged in. So you click "login" and do so... where does that take you?

  • Steven
4 Sep 2010, 2:36 AM
#49
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: sessionWatcher (better handling of session timeouts)

I just tried it with a brand new install with demo data. I clicked on a product, clicked on Write a Review, it took me to login, I logged in, and it took me directly back to the Write a Review screen for that product.

4 Sep 2010, 2:49 AM
#50
s_mack avatar

s_mack

Totally Zenned

Join Date:
Jun 2005
Location:
Kelowna, BC Canada
Posts:
1,033
Plugin Contributions:
4

Re: sessionWatcher (better handling of session timeouts)

Well doesn't that just smoke the donkey...

appears I wrote a mod to fix a problem I introduced at some point. And only took a couple years to figure it out.

Odd thing though... I've used this on dozens of shops to fix that same problem. So if I can figure out what the common thread is, there might be something useful in all this.