YET ANOTHER EasyStore Issue: Customer Order View is STILL BROKEN - Question | JoomShaper
SP Page Builder 6 is Here! Learn More →

YET ANOTHER EasyStore Issue: Customer Order View is STILL BROKEN

SC

Stuart Clark

EasyStore 1 year ago

I've updated to EasyStore 1.2.1 - which apparently fixes a method for GUEST accounts to view their orders... Only it doesn't!

The Option is there on the confirmation page (see: https://prnt.sc/bRYw6XNXphLr), but the significant fxxx up is that this links to /shop/myorders which IMMEDIATELY redirects to the Joomla login screen!

How exactly is a GUEST meant to log in to Joomla????

0
6 Answers
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 1 year ago #163633

Hello Stuart Clark

I have created a test order as a guest user. Here is the order view.

prnt.sc/fgAsKizxAN1l

It looks fine. Please check it again.

Best regards

-1
SC
Stuart Clark
Accepted Answer
1 year ago #163676

This is ABSOLUTELY NOT FIXED

  1. The link on the page I showed you in the above screenshot is to /shop/my-orders - that link REQUIRES LOGIN
  2. If, however, I add an order number to the end of that URL - e.g. /shop/my-orders/37 - then I can view the order without logging in. HOWEVER, I CAN ALSO VIEW ANY OTHER GUEST ORDER BY SIMPLY TYPING A DIFFERENT ORDER ID

**YOU HAVE NOW ENGINEERED A PRIVACY ISSUE - ANYONE CAN FIND OUT PERSONALLY IDENTIFIABLE INFORMATION ABOUT ANY ORDER BY SIMPLY PHISHING ORDER IDs.

YOU NEED TO FIX THIS IMMEDIATELY

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 1 year ago #163683

I got your point. I have talked to the team. They are working for a better solution that does not hamper privacy.

0
SC
Stuart Clark
Accepted Answer
1 year ago #163697

It shouldn't require a customer to point this out!

I'm SERIOUSLY loosing faith in JoomShaper's ability to deliver robust products!

0
SC
Stuart Clark
Accepted Answer
1 year ago #163777

??? There is a SERIOUS SECURITY FLAW in EasyStore at the moment, caused by JoomShaper's lax development.

RESOLVING THIS SHOULD BE YOUR FIRST PRIORITY

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 1 year ago #163805

Yes, the team is working on it. I will update you when I get the fix.

0