News:

AbanteCart v1.4.2 is released.

Main Menu

Do you like AbanteCart? Please rate AbanteCart or share your experience with other eCommerce entrepreneurs. Go to Softaculous rating page to add your rating or write a review

There are download security issues !

Started by Storyresources, June 03, 2013, 07:09:20 AM

Previous topic - Next topic

Storyresources

 :o
Very sadly i have set up my cart and most things seem to be working, BUT i have just run through a test purchase and found that there are some serious concerns for those of us selling digital delivery items  :o

Here what i found:
logged in as a client in storefront and made a test purchase
Went to the download area to get my purchases, and found that you can download and save the purchased file - which I don't want clients to be able to do - I only want them to be able to print the file
, BUT BUT BUT ....
the real issues is that if you simply right click on the DOWNLOAD button you can open the file, and the your order is not updated to indicate this, so in fact your can open and save the file as many times as you like simply using the right click feature


So  it would seen at this stage that AbanteCart is not suitably secure for digital product delivery, unless you don't mind how many times the file is downloaded
This is a real shame is I was starting to really like this program

I'd be very keen to hear what the developing comments are on this and if there is any plan to secure digital delivery

Carolyn


abolabo

"No one is useless in this world who lightens the burdens of another."
― Charles Dickens

Storyresources

No i have my downloads set to 1

If you run a test purchase through my store exactly like a client would see at www dot storyresources.co.nz/index.php?rt=account/download

its till in test mode... so your welcome to give it a try and see what you find
I'd love to hear you can fix this issue, otherwise I have to go back to my old cart

Carolyn

Storyresources

I screen shot is attached for you
Carolyn


Storyresources

OK AbanteCart.com you win, I've given up waiting to hear from you, so will look for another shopping cart option. :-\
Carolyn

Basara

Quote from: abolabo on June 03, 2013, 07:18:47 AM
is it?
I can confirm the bug. "Total Downloads Allowed" not work (AbanTeCart v1.1.5). If set it to 1, customer able to download more than 1 time.

abolabo

bug fix is replacing of file public_html/storefront/controller/pages/account/download.php by attached
"No one is useless in this world who lightens the burdens of another."
― Charles Dickens

Storyresources

AWESOME thank you, the systems no longer allows multiple downlands

Could I suggest, that if you guys are working towards solution for anything, that you post a reply to let us know your looking into it, otherwise we're not sure if a reply is coming. Especially when i see a number of other posts on the forum that don't get replies.
Perhaps sometime when you have hours of free time  ;) someone could add comments to some of these topics that gets looks of views, as obviously some of us do try and look for solutions here before asking for your help.

Carolyn




abantecart

Be mindful, this is a forum and not individual support.  Members get to this as they can. There are no promises or deliverable dates.
Please  rate your experience or leave your review
We need your help to build better free open source ecommerce platform for everyone. See how you can help

Forum Rules Code of conduct
AbanteCart.com 2010 -