VirtueMart Forum

VirtueMart 2 + 3 + 4 => General Questions => Topic started by: Ohanys on November 10, 2017, 12:53:10 PM

Title: Order detail premission
Post by: Ohanys on November 10, 2017, 12:53:10 PM
Hi,

I have big security problem.

If I login to my account, I can see orders history. I can click on orders and I can see detail. Url:

xxx.xx/order?order_number=1000

But If I rewrite url to any random exist order number, I can see it too! I can see all orders that was create without registration - THIS IS PROBLEM, I see users informations. If order created registered and loged user, access is denied - CORRECT.

Can you help me, how set order history? Every user must see only his orders.

Thank you very much.
Title: Re: Order detail premission
Post by: AH on November 10, 2017, 18:46:30 PM
VM version etc
Title: Re: Order detail premission
Post by: Ohanys on November 11, 2017, 20:10:04 PM
Joomla 3.8.2, VirtueMart 3.0.18
Title: Re: Order detail premission
Post by: Ventsi Genchev on November 12, 2017, 07:26:18 AM
Every user sees only his orders, but the administrator can see everyone. I do not see what a problem that can be.