Renewals / New Purchases link in members area

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Reeve of Shinra
    Senior Member
    • Sep 2001
    • 4325
    • 4.0.0

    Renewals / New Purchases link in members area

    I understand a new members area might be in the works... if it is, I'd like to suggest a change for the Renewals / New Purchases link..


    I almost copy/pasted it into a thread but it has my username and password to the members area in it. I don't think that should be required since we already logged in.

    /order/?customerid=#############&password=############################
    Plan, Do, Check, Act!
  • Knightmane
    Member
    • Mar 2007
    • 35
    • 4.2.X

    #2
    I was told that renewals couldn't be made months in advance anymore. You had to wait until your license was within 2 months of expiring before you could renew your licenses.

    Comment

    • Fusion
      Senior Member
      • Aug 2001
      • 4346
      • 3.8.x

      #3
      Originally posted by Knightmane
      I was told that renewals couldn't be made months in advance anymore. You had to wait until your license was within 2 months of expiring before you could renew your licenses.
      This is true, but it is not related to what the OP is pointing out.
      Toddler from Hell

      Comment

      • Ryan Ashbrook
        Senior Member
        • May 2003
        • 1967

        #4
        Originally posted by Reeve of Shinra
        I understand a new members area might be in the works... if it is, I'd like to suggest a change for the Renewals / New Purchases link..


        I almost copy/pasted it into a thread but it has my username and password to the members area in it. I don't think that should be required since we already logged in.

        /order/?customerid=#############&password=############################
        I'm pretty sure it is required because the actual order script isn't contained in the same location we log in at, so it needs to know which customer you are and that you're authorized to make purchases for that customer id.
        Ryan Ashbrook - My Blog - My Twitter

        Comment

        • David Grove
          Senior Member
          • Apr 2008
          • 3507
          • 5.5.x

          #5
          It's still a bad idea, since that URL is logged on the server (probably) and in the user's browser and the password could be accidentally divulged because of this.
          ~~~~~

          Comment

          • Ryan Ashbrook
            Senior Member
            • May 2003
            • 1967

            #6
            Originally posted by sockwater
            It's still a bad idea, since that URL is logged on the server (probably) and in the user's browser and the password could be accidentally divulged because of this.
            I didn't say it was good, just that that's probably the reason.
            Ryan Ashbrook - My Blog - My Twitter

            Comment

            • Colin F
              Senior Member
              • May 2004
              • 17689

              #7
              As has been said, the reason is to verify the user, as the order script isn't inside the members area.

              The password that's transmitted in that link isn't your actual members area password, so there shouldn't be any worries about someone getting in to your members area. If someone did somehow get a hold of that link, they'd be able to see what licenses you had and order licenses for you.

              This hasn't been an issue so far, so we likely won't change it for the time being. Nonetheless, thanks for voicing your concern!
              Best Regards
              Colin Frei

              Please don't contact me per PM.

              Comment

              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
              Working...