Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Sign in to follow this  
lorax

Purchase without Account - why check for pwd?

Recommended Posts

I was tracking down a problem I'm having with this contribution and discovered that the Order_Info_Process.php file has a section for analyzing passwords.

 

Since the contribution was designed to forego passwords I wondered why this is even in there? Might someone be able to explain?


Apathy is a dominant gene - mutate.

Share this post


Link to post
Share on other sites

I thnk one problem that might happen is if the order_info doesn't check for a password, it would be possible for a purchase/w/o/acocunt user to create a 'temporary' account with the same email address as someone else... then if that temporary account weren't cleared from the database, say because of someone exiting the shop before checkout was finished, then you'd have two accounts with the same email address - thus potentially making it impossible for the 'real' account to log in.

 

If someone can tell me why this wouldn't be an issue, then there would be no sense in keeping the password check.

 

What would be ideal is if all the customer information were stored in a cookie instead of stored to the database... that would finally clear up the last of the problems with the PWA mod.


-D. M. 8)

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×