JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/07/2020 : 12:47:46
One of my clients has been having this issue, but it was only on one computer, so we thought it was something with his computer since I could not recreate it on my end. They are now working with another company to upload some products for them and this new company is have similar issues. It seems that when they try to download a CSV of current products or when they try to upload or import anything to the site, they are prompted (by pop up) to log in again.
I know someone would have to be logged in to check on this. Could someone (Marlene or Vince or someone) reply to this and let me know if they'd be willing to work on this issue with me? I'll then contact you and send you the login details.
If anyone else has had anything similar to this happen, I'd love to hear any solutions or suggestions.
Thanks!
|
Vince
Administrator
42874 Posts |
Posted - 05/07/2020 : 13:23:14
|
Vince
Administrator
42874 Posts |
Posted - 05/08/2020 : 02:54:47
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/08/2020 : 08:39:09
Sent to your email address.
Thanks!
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/08/2020 : 08:40:17
The issue has happened a few different ways - trying to download a csv file, trying to upload a file, and trying to edit a product and change the image within that product.
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/08/2020 : 08:44:00
One other thing to look at is the address in the URL - I have no idea why, when the client accesses this site from their system it shows as not secure. It shows as secure on my end and my host says there is no problem with the SSL certificate.
Any ideas on that?
|
Marshall
Ecommerce Template Guru
USA
1916 Posts |
Posted - 05/08/2020 : 09:04:11
Is the store URL and SSL URL both the same in the main settings?
Marshall CENLYT Productions - ms designs Affordable Web Design Custom Ecommerce Designs Responsive Websites Cenlyt.com
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/08/2020 : 09:09:00
Yes, both say https:
|
Phil
ECT Moderator
United Kingdom
7715 Posts |
Posted - 05/08/2020 : 10:02:45
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/08/2020 : 10:40:36
Phil - the URL is: alkydigger.net
Is there anything else you need?
|
1818charlie
ECT Moderator
United Kingdom
1198 Posts |
Posted - 05/08/2020 : 16:12:36
Running the domain alkydigger.net through a https check, these are the results that I am getting
SSL Certificate is Valid No Insecure Social Links No Insecure Sitemap(s) Found No Insecure Redirects Found
Insecure forms have been found 29 Active Mixed/Insecure Content Found (+ 861 Duplicates) 82 Passive Mixed/Insecure Content Found (+ 53 Duplicates) 11 Insecure Canonical links found 243 Insecure Links to the Same Domain Found (+ 1824 Duplicates)
Your website is not currently using the "strict-transport-security" header, which can leave you open to man-in-the-middle attacks with tools like SSLStrip This is one aspect of SSL that I consistently find is not implemented.
Steve Manchester England
Remember - Any edits to the ectcart.css file will be overwritten by updater's. ALL edits to ectcart.css rules should be placed in your style.css file
|
Vince
Administrator
42874 Posts |
Posted - 05/09/2020 : 03:35:23
Hi JustDucky The main admin pages will check the login cookie but scripts like the CSV download, image upload etc will just assume you are logged in and this seems where the problem is. If you leave the page idle long enough and then click on say the image upload then the page will refresh to the admin login page. So what I've done is added code to those scripts to also check the cookies like the main pages. I've added the changes to the v7.2 updater (if you are using v7.1 then please let me know), so if you download the updater and copy these files it should sort this out... vsadmin/doupload.php vsadmin/dumporders.php vsadmin/popupemail.php Vince Click Here for Shopping Cart SoftwareClick Here to sign up for our newsletterClick Here for the latest updater
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/11/2020 : 12:56:15
Hi Vince - yes, we are using v 7.1.9 -- what should we do?
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/12/2020 : 09:23:14
So...what should I do here since I'm using 7.1? Should I just update to the newest version? I need to get back to my client and let him know if I have a solution for this.
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/12/2020 : 10:43:53
More issues. Now this is happening at times: https://www.alkydigger.net/2020%20Screenshot/6722.jpeg
Also, as you can see, the URL is still showing non secure. However; on my system I cannot recreate this at all. Every page I visit is showing as secure.
Can someone help me, please?
|
Phil
ECT Moderator
United Kingdom
7715 Posts |
Posted - 05/12/2020 : 11:05:59
Edited by - Phil on 05/12/2020 11:10:09
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/12/2020 : 11:24:41
Actually the image only shows "www.alkydigger.net" along with the padlock with the line through it.
The other issue in that image is that it keeps popping up like that showing "Error couldn't find cart".
|
Vince
Administrator
42874 Posts |
Posted - 05/13/2020 : 02:13:44
|
JustDucky923
Ecommerce Template Guru
USA
1333 Posts |
Posted - 05/13/2020 : 08:27:48
So do I simply apply the 7.1 updater again? Would it be better to apply the newest 7.2 updater? I'm a little confused.
|
Vince
Administrator
42874 Posts |
Posted - 05/13/2020 : 09:52:41
|
|
|