Hi Guys.
I have been searching for a contribution for osCommerce that will prevent the session ID of a customer from being displayed in the website address bar i.e. osCsid=ecf475f31e57d735ec02821c1eff8a82 as I have discovered that if a user is logged in and send a link with the session attached to a friend, when the friend clicks on the link, it opens the site and logs him in as the user.
I have put in a temporary solution that detects if it is a different IP or browser and then asks you to log in again, but this is not ideal.
I see that Sybaritic uses some contribution that prevents the session ID from displaying.
Perhaps some of you know which contribution I should look for?
By the way, don't worry about site security ... the site is now secure again, but to be sure, if and when posting or e-mailing a link, be sure to remove the session ID.
I'm hoping one of you knows which contribution will work, I spent a couple hours searching the osCommerce contributions.
Regards
Itai
I have been searching for a contribution for osCommerce that will prevent the session ID of a customer from being displayed in the website address bar i.e. osCsid=ecf475f31e57d735ec02821c1eff8a82 as I have discovered that if a user is logged in and send a link with the session attached to a friend, when the friend clicks on the link, it opens the site and logs him in as the user.
I have put in a temporary solution that detects if it is a different IP or browser and then asks you to log in again, but this is not ideal.
I see that Sybaritic uses some contribution that prevents the session ID from displaying.
Perhaps some of you know which contribution I should look for?
By the way, don't worry about site security ... the site is now secure again, but to be sure, if and when posting or e-mailing a link, be sure to remove the session ID.
I'm hoping one of you knows which contribution will work, I spent a couple hours searching the osCommerce contributions.
Regards
Itai
Last edited: