Jump to content



Latest News: (loading..)

- - - - -

v2.3.1 - Sessions - Customers without payment issue.


  • Please log in to reply
9 replies to this topic

#1   AnthonyAU

AnthonyAU
  • Members
  • 12 posts
  • Real Name:Antony C

Posted 26 June 2012 - 08:35 AM

Hello everyone

if customers in ‘Order Confirmation user interface’ copy and paste or hand typing to modify the URL from “mystore.com/checkout_confirmation.php” to “mystore.com/checkout_process.php” this can be successfully place order without payment.

This is our store admin user interface “Sessions” current setting

Host server: Linux
------------------------------------------------------------------------------------------------------------
Session Directory     /home/mystore/public_html/includes/work/

Force Cookie Use     False   (Try in ‘Trun’ status still have issue)

Check SSL Session ID        False

Check User Agent      False

Check IP Address     False

Prevent Spider Sessions   True

Recreate Session True
------------------------------------------------------------------------------------------------------------
I using FireFox 13.0.1 to test this issue

Is this a session issue? Any setting I miss it?

Anyone know what happen and how to fix it?

#2   14steve14

14steve14

    STORE OWNER NOT CODER

  • Members
  • 3,073 posts
  • Real Name:Steve
  • Gender:Male
  • Location:Dorset UK

Posted 26 June 2012 - 10:17 AM

What version of oscommerce are you using.
REMEMBER BACKUP, BACKUP AND BACKUP
I am not a coder, so dont bother sending PMs asking for help as you wont get any.  

OSC has a steep learning curve, but in general the program does work.  If it doesnt work, the chances are it is something you have done.

#3   AnthonyAU

AnthonyAU
  • Members
  • 12 posts
  • Real Name:Antony C

Posted 26 June 2012 - 11:43 PM

Hi Steve

i check in 'Admin user interface' is showing

--------------------------------------------------------------------------------------

Version Checker

Installed Version: osCommerce Online Merchant v2.3.1

You are running the latest version of osCommerce Online Merchant.

----------------------------------------------------------------------------------------

#4   DunWeb

DunWeb
  • Members
  • 12,713 posts
  • Real Name:Chris
  • Gender:Male
  • Location:Ontario, Canada

Posted 26 June 2012 - 11:55 PM

@AnthonyAU


I believe the checkout order is:

shopping_cart.php
checkout_shipping.php
checkout_payment.php
  - this leads to the online payment processor and then returns the customer to the checkout_process.php (hidden file)
checkout_confirmation.php


checkout_process.php IS NEVER called up.  It is a file used to track the process only.


I tested this on my v2.3.1 store and could not alter the checkout process.  I received this error when trying to replicate your issue:

https://www.xxxxxx.com/shopping_cart.php?error_message=Express%20Checkout%20token%20is%20missing.

"Checkout Token is Missing"


Any further information you can share ?


Chris
:|: Was this post helpful ? Click the LIKE THIS button :|:

See my Profile (click here)  for more information and to contact me for professional osCommerce support that includes custom templates, add ons as well as cart leasing and support plans.

#5 ONLINE   multimixer

multimixer

    Lemons or Melons ?

  • Partner
  • 4,377 posts
  • Real Name:George Zarkadas
  • Gender:Male
  • Location:Greece

Posted 27 June 2012 - 06:12 AM

@AnthonyAU

what payment module did you use to do this?

#6   AnthonyAU

AnthonyAU
  • Members
  • 12 posts
  • Real Name:Antony C

Posted 27 June 2012 - 09:31 AM

Hi Chris and George


---------------------------------------------------------------------------------------------
For the Payment module:

Our store only to use - 'PayPal Website Payments Standard' (Version 1.0)

--------------------------------------------------------------------------------------------
Add-On:

- QTpro4.6.1

- Easy Meta Tags 1.8

-------------------------------------------------------------------------------------------

Attached - Order_without_payment.JPG
Attached File  Order_without_payment.JPG   96.72K   25 downloads

#7   AnthonyAU

AnthonyAU
  • Members
  • 12 posts
  • Real Name:Antony C

Posted 13 July 2012 - 07:56 AM

Hi everyone

Any new suggestion for this issue?

Am i setting worng? or i shounldn't setting like that?

#8   frankjohnson8

frankjohnson8
  • Members
  • 1 posts

Posted 13 July 2012 - 09:26 AM

What version of oscommerce are you using.

Edited by frankjohnson8, 13 July 2012 - 09:34 AM.


#9   AnthonyAU

AnthonyAU
  • Members
  • 12 posts
  • Real Name:Antony C

Posted 16 July 2012 - 12:33 AM

Hi Frank

i Installed Version 2.3.1

#10   DunWeb

DunWeb
  • Members
  • 12,713 posts
  • Real Name:Chris
  • Gender:Male
  • Location:Ontario, Canada

Posted 16 July 2012 - 12:43 AM

@AnthonyAU

Refer to the Closing PayPal Exploit thread



Chris
:|: Was this post helpful ? Click the LIKE THIS button :|:

See my Profile (click here)  for more information and to contact me for professional osCommerce support that includes custom templates, add ons as well as cart leasing and support plans.