Shop module

Author Message

Lars Eirik R

Wednesday 17 March 2010 6:06:13 am

Hi we are working with a client and have set upt the webshop functionality locally.

I have some important questions which i would like you to answer.

One of the main problems we are facing is the fact that i may easily view other users orders.. If i am not logged in(anonymous) , i may still view all orders placed in the system by going to the url /shop/orderview/<number>

This has to be incorrect ?

Are there any smart solutions i should apply or is this related to accesscontrol?

Any help is greatly appreciated.

Jean-Luc Nguyen

Wednesday 17 March 2010 7:27:53 am

Hello,

Does you anonymous user have specific role ?

http://www.acidre.com

Lars Eirik R

Wednesday 17 March 2010 9:50:52 am

hm.. i guess assigning shop -> all functions is not the best for the shop module.. Will take a look at this later.

Thanks for getting back to me.

Lars Eirik R

Wednesday 17 March 2010 10:20:17 am

Hm. Only assigning the function buy does not help.

I have to add i have only tested this with accessing different orderview/<number> from the same computer.

But it seems strange that i can access another users orders.

Also.. i am not caching the website, all cache for templates and content is off.

Any ideas?

Lars Eirik R

Thursday 18 March 2010 12:08:30 pm

ignore this, as it seems the user was logged in..

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 29 2025 23:45:31
Script start
Timing: Jan 29 2025 23:45:31
Module start 'layout'
Timing: Jan 29 2025 23:45:31
Module start 'content'
Timing: Jan 29 2025 23:45:31
Module end 'content'
Timing: Jan 29 2025 23:45:31
Script end

Main resources:

Total runtime0.0139 sec
Peak memory usage2,048.0000 KB
Database Queries3

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0043 588.0078151.1953
Module start 'layout' 0.00430.0025 739.203136.6094
Module start 'content' 0.00680.0056 775.812594.0078
Module end 'content' 0.01230.0016 869.820333.9922
Script end 0.0139  903.8125 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.002316.4627140.0002
Check MTime0.00107.0391140.0001
Mysql Total
Database connection0.00064.517810.0006
Mysqli_queries0.002014.131130.0007
Looping result0.00000.071810.0000
Template Total0.00139.110.0013
Template load0.00096.430510.0009
Template processing0.00042.587910.0004
Override
Cache load0.00064.487010.0006
General
dbfile0.00106.813480.0001
String conversion0.00000.049640.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs