Posting in the Magento forums has been disabled pending the implementation of a new and improved forum solution which should better serve the community.

For new questions please post at magento.stackexchange.com, the community-run support site for the Magento community. We will be providing updates on the new forum solution soon. For questions or concerns please email community@magento.com.

Magento Forum

Is this a security bug? 
 
stereotomy
Jr. Member
 
Total Posts:  28
Joined:  2008-02-10
 

after adding some items to my cart, i navigate to the “mysite/checkout/onepage/success” page and it says the order is complete. i see the order at the admin panel. question

am i missing something??????

 
Magento Community Magento Community
Magento Community
Magento Community
 
mzentrale1
Guru
 
Total Posts:  731
Joined:  2007-12-06
Stuttgart, Germany
 

Hi,

which version are you using? Are you logged i or guest? I cant confirm this.

cheers

stefan

 
Magento Community Magento Community
Magento Community
Magento Community
 
stereotomy
Jr. Member
 
Total Posts:  28
Joined:  2008-02-10
 

hi stefan,

- i am using 1.1.1.
- shopping as guest

as said, the issue is very obvious.

my site is at http://www.xxxxxxx.com/english (pm me please)

you may want to see for yourself too. i am confused.

thanks.

 
Magento Community Magento Community
Magento Community
Magento Community
 
mzentrale1
Guru
 
Total Posts:  731
Joined:  2007-12-06
Stuttgart, Germany
 

Hi,

i can confirm this behavior in shop /english, in your default shop (without english) there is no problem, so it seems its a really hard bug in multistore funkction of magento! Please write a bug report!

Cheers

Stefan

 
Magento Community Magento Community
Magento Community
Magento Community
 
stereotomy
Jr. Member
 
Total Posts:  28
Joined:  2008-02-10
 

thanks, I will.

and actually i have edited my original post, I dont want people to place phantom orders at my website smile

 
Magento Community Magento Community
Magento Community
Magento Community
 
Michael_1
Enthusiast
 
Total Posts:  826
Joined:  2007-08-31
 

Hi guys,

I’m not able to get the order placed on the site (I know the real link).
Can you please describe the detailed steps how to reproduce this ?

Thank you,
Michael

 
Magento Community Magento Community
Magento Community
Magento Community
 
mzentrale1
Guru
 
Total Posts:  731
Joined:  2007-12-06
Stuttgart, Germany
 

Hi,

in shop http://www.foo.de/english:

i add a product to the cart - in store “english” - and than i called http://www.foo.de/english/onepage/checkout/succes without checkout process. I was redirected to the empty cart. Done as guest.

in shop http://www.foo.de (i think its default), i also added a product to cart and called http://www.foo.de/onepage/checkout/success without checkout process and was redirected to normal card which contains the added product.

Its not my shop, i only tested it.

Hope that helps, maybe its useful to have access to adminpanel to check configuration.

Cheers

Stefan

 
Magento Community Magento Community
Magento Community
Magento Community
 
CreedFeed
Member
 
Total Posts:  74
Joined:  2007-08-31
Milwaukee, WI
 

I tried duplicating this on an install of 1.1.1 I have and going directly to the checkout/onepage/success simply redirected me to checkout/cart with the items in my cart displaying.

 
Magento Community Magento Community
Magento Community
Magento Community
 
Michael_1
Enthusiast
 
Total Posts:  826
Joined:  2007-08-31
 

i also added a product to cart and called http://www.foo.de/onepage/checkout/success without checkout process and was redirected to normal card which contains the added product.

I don’t see any bug here. It should redirect to shopping cart if no valid data was submitted to this page, and it does redirect.
Did I miss anything ?

 
Magento Community Magento Community
Magento Community
Magento Community
 
mzentrale1
Guru
 
Total Posts:  731
Joined:  2007-12-06
Stuttgart, Germany
 

Hi,

can you pm me the url?

Cheers

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
Back to top