Zen Cart Logo
Forums / All Other Contributions/Addons / Ban Customers (by email address).

Ban Customers (by email address).

Locked

Views: 10,849

Results 21 to 40 of 53
This thread is locked. New replies are disabled.
24 May 2007, 4:07 PM
#21
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Ban Customers (by email address).

Since this particular problem is becoming larger, let's discard the zen_redirect module needs restructuring (as this was already reported in the past on the forum).

In your admin/ban_customers.php file,

find:

//----------------------------------------------------------------------------------
  //--- No customers are allowed (can't take any chances) ---
  //----------------------------------------------------------------------------------  
  if (!$_SESSION['admin_id']) {
      $messageStack->add_session(ENTRY_BANNED_CUSTOMERS_UNAUTHORIZED_ACCESS, 'warning');                 
      zen_redirect(zen_href_link(FILENAME_BAN_CUSTOMERS, '', 'NONSSL')); 
      } // End of if statement.

replace with:

//----------------------------------------------------------------------------------
  //--- No customers are allowed (can't take any chances) ---
  //----------------------------------------------------------------------------------  
  if (!$_SESSION['admin_id']) {
      $messageStack->add_session(ENTRY_BANNED_CUSTOMERS_UNAUTHORIZED_ACCESS, 'warning');                 
      ?>
      <script>window.location="<?php echo zen_href_link(FILENAME_BAN_CUSTOMERS, '', 'NONSSL'); ?>"</script>
      <?php
      } // End of if statement.

Will this fix this error message ?

24 May 2007, 4:09 PM
#22
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

however NO emails about banning are being sent

The reason of this particular behavior has been mentionned on my previous post. Perhaps you missed it while trying to evaluate other features on the MOD. :smile:

Again, I'm still investigating this problem. Let me know about the redirect fix.

24 May 2007, 4:13 PM
#23
merlinpa1969 avatar

merlinpa1969

Totally Zenned

Join Date:
Mar 2004
Posts:
13,031
Plugin Contributions:
4

Re: Ban Customers (by email address).

Yepp the redirect fixes

got that one,

as soon as we get this one nailed down I will work on the add fields mod

24 May 2007, 4:21 PM
#24
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

Merlinpa1969:

Yepp the redirect fixes

got that one,

as soon as we get this one nailed down I will work on the add fields mod

Outstanding. Since this seems to be a globalized problem, I will re-update my package immediately so that no one else encounters this problem in the future. Thanks for confirming this. :smile:

@DrByte:

You see ? There is a problem with the zen_redirect module (from the admin's end). It needs complete re-modulations from admin/includes/functions/general.php file since there are no preg_match validations for each browsers.

Again, here's the perfect example of what I mean:

@preg_match('/Microsoft|WebSTAR|Xitami/', getenv('SERVER_SOFTWARE')) ? 'Refresh: 0; URL=' : 'Location: ';

This methodology can either be used with header(refresh:) or header(location:) with all types of browsers without any headers already sent by . . . error messages since, right now, this problem only seems to grow larger.

24 May 2007, 4:28 PM
#25
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

Update: The file has been updated as well as the changelog documentation. For those who encountered this particular problem, simply replace your admin/ban_customers.php file as it should work nicely when loading back this MOD under the admin - > Ban Customers page.

24 May 2007, 4:43 PM
#26
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

Here's an alternative solution I recently discovered but seem to forgot about it.

In your admin/includes/functions/general.php file, if you make a backup first, then simply replace your zen_redirect's entire function with this one instead (and just the zen_redirect block - do NOT modify the others based on this instruction):

// Redirect to another page or site
  function zen_redirect($url) {
    global $logger;

// clean up URL before executing it
    while (strstr($url, '&&')) $url = str_replace('&&', '&', $url);
    while (strstr($url, '&&')) $url = str_replace('&&', '&', $url);
    // header locates should not have the & in the address it breaks things
    while (strstr($url, '&')) $url = str_replace('&', '&', $url);    
    echo '<script>window.location=\''.$url.'\'</script>';
    //header('Location: ' . $url);
    if (STORE_PAGE_PARSE_TIME == 'true') {
      if (!is_object($logger)) $logger = new logger;
      $logger->timer_stop();
    }    
    exit;
  }

Then, from there, you can replace:

//----------------------------------------------------------------------------------
  //--- No customers are allowed (can't take any chances) ---
  //----------------------------------------------------------------------------------  
  if (!$_SESSION['admin_id']) {
      $messageStack->add_session(ENTRY_BANNED_CUSTOMERS_UNAUTHORIZED_ACCESS, 'warning');                       
      ?>
      <script>window.location="<?php echo zen_href_link(FILENAME_BAN_CUSTOMERS, '', 'NONSSL'); ?>"</script>
      <?php
      } // End of if statement.

back to:

//----------------------------------------------------------------------------------
  //--- No customers are allowed (can't take any chances) ---
  //----------------------------------------------------------------------------------  
  if (!$_SESSION['admin_id']) {
      $messageStack->add_session(ENTRY_BANNED_CUSTOMERS_UNAUTHORIZED_ACCESS, 'warning');                 
      zen_redirect(zen_href_link(FILENAME_BAN_CUSTOMERS, '', 'NONSSL'));      
      } // End of if statement.

P.S: This should work entirely for all your admin pages from now on. :cool:

Before I remake modifications on the admin/ban_customers.php file, I'll be waiting for inputs on this.

24 May 2007, 5:00 PM
#27
paulm avatar

paulm

Totally Zenned

Join Date:
Nov 2003
Posts:
1,878
Plugin Contributions:
5

Re: Ban Customers (by email address).

Hi, I was wondering what this part of the (posted) code is (or was) supposed to do:

//----------------------------------------------------------------------------------
  //--- No customers are allowed (can't take any chances) ---
  //----------------------------------------------------------------------------------  
  if (!$_SESSION['admin_id']) {
      $messageStack->add_session(ENTRY_BANNED_CUSTOMERS_UNAUTHORIZED_ACCESS, 'warning');                 
      ?>
      <script>window.location="<?php echo zen_href_link(FILENAME_BAN_CUSTOMERS, '', 'NONSSL'); ?>"</script>
      <?php
      } // End of if statement.
```?

It looks like it is supposed to secure something, but it doesn't. So I assume I missing the whole point.
24 May 2007, 5:10 PM
#28
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

It looks like it is supposed to secure something, but it doesn't. So I assume I missing the whole point.

Indeed. You're missing the point. :D

The reason why this was required to be replaced is due to the increase error messages of: Headers already sent by .... This fix will avoid bad redirection, currently handled from the zen_redirect function as, in fact, my post above, shows how to respectively replace the old zen_redirect function with the new one so that it will, from now on, redirect properly under all admin pages. :wink2:

24 May 2007, 5:27 PM
#29
paulm avatar

paulm

Totally Zenned

Join Date:
Nov 2003
Posts:
1,878
Plugin Contributions:
5

Re: Ban Customers (by email address).

Reading your reply I think I am not missing the point after all. If you get a "headers already sent message" after a header redirect it usually means that the headers are already sent. A header redirect is supposed to be executed before any headers are sent.

Replacing the zen_redirect() code by the code you posted looks like a potential security risk to me. I assume the zen admin protection does not (fully) rely on the zen_redirect function, but the change you suggest allows anyone to visit any admin page (not that they will probably be able to see/do anything, but still...).

24 May 2007, 5:43 PM
#30
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

but the change you suggest allows anyone to visit any admin page (not that they will probably be able to see/do anything, but still...).

A good point here. Althought, the specific reason why I added that is due to the hacking section on this forum regarding vulnerability that might be encountered in the admin section. Supposing there's already a protection involved from the admin's header, and hackers gets through anyway, don't you think they will gain access to all admin files on anyhow ? :wink2:

At least, from my end, as stated on the uncommented paragraph of that block, I'd rather not take any chances by not putting this validation.

24 May 2007, 5:44 PM
#31
samad64 avatar

samad64

Totally Zenned

Join Date:
May 2006
Location:
Texas
Posts:
554
Plugin Contributions:
2

Re: Ban Customers (by email address).

TheOracle:

Sorry, I don't quite understand what you mean by that. The red and green switch works perfectly fine. When enabling (green) the banning feature, the customer gets notified. When the red button is checked, it means that the customer is not banned but, to make sure that other admins to not report this customer twice, the master admin(s) already are aware of their customer's situation. Which is why, reasons are an obligation to be stated when a regular admin wishes to report customers regarding issues they might of had noticed.

I meant without the mod installed :).. the person was just wondering what the mod does so I was describing normal, without mod behavior compared to this one

24 May 2007, 5:49 PM
#32
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

I meant without the mod installed :).. the person was just wondering what the mod does so I was describing normal, without mod behavior compared to this one

Currently, this MOD is not built-in within Zen-Cart. Meaning, without this MOD, a regular admin could not report a specific customer to one of the webmasters level.
The customer could still visit as many pages as she / he wants without (or limited) restrictions from the admin section.

This MOD allows you to amplify restrictions as banned customers are also notified regarding their account status (and, that, from each modulated pages you will add this function). :wink2:

Althought, for instance, since the email-a-friend page also tolerates guests to get in, it would be quite difficult to ban the customer since the admin's configuration would be useless at this point.

26 May 2007, 1:22 PM
#33
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

Update:

A new update of this MOD has just been released. Email functionality should now operate as expected. More info under the changelog.txt file. For those who upgrades from a previous release, simply follow the upgrade.txt file's instruction.

26 May 2007, 5:15 PM
#34
peekay avatar

peekay

Zen Follower

Join Date:
Jun 2006
Location:
U.K.
Posts:
103
Plugin Contributions:
0

Re: Ban Customers (by email address).

I'll take another look ASAP :smile:

27 May 2007, 11:11 PM
#35
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

What is the status on this topic ? Does it work as expected ? :lookaroun

4 Jun 2007, 4:55 PM
#36
charmedbytina2 avatar

charmedbytina2

Totally Zenned

Join Date:
Mar 2007
Location:
AZ
Posts:
1,890
Plugin Contributions:
0

Re: Ban Customers (by email address).

I would really like to install this mod for my site, but when I tried, I couldn't log into my admin.:oops:

I'm sure I messed up somewhere, but am not sure what I did wrong!
I guess I got lost following the install instructions.

Any help is appreciated.

Thanks!

4 Jun 2007, 7:25 PM
#37
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

Hi Tina,

are you sure this is happening since you installed the MOD ?

If so, which version of PHP, mySQL and Zen-Cart version are you using ?

If you accidentally banned yourself (don't really know how if you do have a test account), simply go to your phpmyadmin and empty your banned table customers (by using the 'empty' link). This should definitely fix the issue.

4 Jun 2007, 7:55 PM
#38
charmedbytina2 avatar

charmedbytina2

Totally Zenned

Join Date:
Mar 2007
Location:
AZ
Posts:
1,890
Plugin Contributions:
0

Re: Ban Customers (by email address).

Oracle! Thanks for the quick response!

I probably banned myself (and rightfully so, lol).

Zen version most recent from the downloads.
php I think is 5. something
mysql is 4.0 or 4.1 (I thinks!)

4 Jun 2007, 8:30 PM
#39
theoracle avatar

theoracle

Suspended

Join Date:
Aug 2004
Posts:
3,180
Plugin Contributions:
1

Re: Ban Customers (by email address).

Hum ... tested with PHP 4. In the mean time, I did not see any reports issues with PHP 5 regarding this MOD yet. Let's assume you applied my steps (perhaps correctly / uncorrectly), if you empty your banned customers table from phpmyadmin and try to re-login again, will it work ?

10 Jun 2007, 4:26 AM
#40
kimsonvu avatar

kimsonvu

Zen Follower

Join Date:
Aug 2006
Location:
HCMC
Posts:
263
Plugin Contributions:
0

Re: Ban Customers (by email address).

I can not download this modules!Can someone help me?

Thanks you so much!