Jump to content
jimlongo

shopping_cart.php accessible to non logged-in user

Recommended Posts

I just noticed this by chance today.

I am running bootstrap version of OSCv2.3.4

I can visit the shopping_cart.php when not logged in.  Of course the cart is empty.

Any other pages i try to visit will redirect me to the login page, but not this one.

Is this intentional or some misconfiguration?

Share this post


Link to post
Share on other sites

Intentional. 

You can add products to the shopping cart before logging in.  Logging in merges your current carts. 

On someone's first visit to the site, the intended flow is

1.  Browse and find products that you want to buy. 

2.  Add them to the cart.

3.  Click the check out button. 

4.  Create an account. 

5.  Pick checkout options. 

6.  Confirm options and check out. 

It would be possible to add a message on that page that says something like "You are currently not logged in.  If you would like to see saved items, please log in." 


Always back up before making changes.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×