VirtueMart Forum

VirtueMart 2 + 3 + 4 => Virtuemart Development and bug reports => Topic started by: safemode on October 27, 2011, 15:55:45 PM

Title: [Fixed]Password displayed plain at the order form.
Post by: safemode on October 27, 2011, 15:55:45 PM
Hi,
I have concern about adding/editing bill to data with register option. On the confirmation page password provided as hidden in form, shows plain after submit.
I think for security reason it should be hidden there also.
Regards.
T.

[attachment cleanup by admin]
Title: Re: Password displayed plain at the order form.
Post by: Milbo on October 27, 2011, 19:44:05 PM
Hehe, your name is program.

Please provide your complete links that I understand what you are doing.

Okey I think I was able to reproduce the bug. It is afaik not security related, because it happens only, when you enter your password, but then checkout as guest. This means this passwords are not used, because they are only used, when you use register and checkout.
Title: Re: Password displayed plain at the order form.
Post by: safemode on October 27, 2011, 20:16:56 PM
Here are the steps:

I am starting on the cart page and click on the "Add/Edit billing address information" button as Anonymous.
Then after input all information on edit page I use  "Register And Checkout" button and have page like this one. Now there is a bigger picture of it.
Regards.

[attachment cleanup by admin]
Title: Re: Password displayed plain at the order form.
Post by: Milbo on October 27, 2011, 22:34:55 PM
Because you want that the people must first use a registration link.... hmm in fact it is not good todo it that way. But I should find a possibility to remove it.
Title: Re: Password displayed plain at the order form.
Post by: alatak on November 04, 2011, 18:18:58 PM
Hi,

Fixed and Solved.
Title: Re: [Fixed]Password displayed plain at the order form.
Post by: Aliciah85 on November 09, 2011, 00:08:05 AM
how did you fix this- it is still happening with my cart. All that should be siplayed there is the address, not all the other stuff.

Is there any way to go back to the multi page checkout? i feel that this is confusing as the user may not know they have to enter a billing address first. Is it not possible to have a cart summary show and then when they proceed to checkout for it to ask them to register or checkout as a guest?
Title: Re: [Fixed]Password displayed plain at the order form.
Post by: Milbo on November 09, 2011, 03:30:04 AM
It is done exactly that way.
Title: Re: [Fixed]Password displayed plain at the order form.
Post by: Aliciah85 on November 09, 2011, 03:38:49 AM
hmm- not on my site it isnt! its all on the one page :(

http://203.123.59.45/~bootleg/index.php/component/virtuemart/cart