[Date Prev][Date Next][Thread Prev][Thread Next][Minivend by date
][Minivend by thread
]
Re: [mv] Minivend 4.04 loses session id with forms?
****** message to minivend-users from Hans-Joachim Leidinger <jojo@buchonline.net> ******
Sakari Ailus schrieb:
>
> ****** message to minivend-users from Sakari Ailus <sakari.ailus@nic.fi> ******
>
> Hi!
>
> I'm migrating catalogs for Minivend 3.x to use them with new 4.x series.
> To me it seems that new Minivend 4.04 loses session id when submitting
> forms, first this caused a problem because I use scratch variables to
> implement administrator user authentication which, of course, failed
> since scratch variables are lost. This doesn't happen on Minivend 3.14
> or on Minivend 4.04 with browser supporting cookies, but without cookie
> support it does (on Minivend 4.04).
>
> In last case forms still work if I specify mv_session_id manually (<form
> ACTION="[process-target secure=1]" METHOD=POST>...<input type=hidden
> name=mv_session_id value="[data session arg]">...</form>) but, as the
> FAQ file says, this should be necessary only with GET forms.
I can confirm that. But I'm not able to carry the same session id with
<input type=hidden name=mv_session_id value="[data session arg]">
This was my test:
- server and secure server has the same domain name
- using browser with cookie disable
- order some items into the basket
- basket has items in both case as a normal basket and as a secure
basket
- log in as an user test -> losing items and getting new session id
- call the basket with the former session id and I get the items, but
I'm not log in as an user test
(MV 4.04, FreeBSD 3.4-STABLE, Apache)
Another test with WIN98, Sambar Server V4.2, MV 3.14-5, Active State 5.6
and no secure server didn't lost any items.
I've get a confirmation about this behavior with Linux.
Any comments or confirmations?
Regards,
Joachim
--
-------------Hans-Joachim Leidinger---------------------
-
To unsubscribe from the list, DO NOT REPLY to this message. Instead, send
email with 'UNSUBSCRIBE minivend-users' in the body to Majordomo@minivend.com.
Archive of past messages: http://www.minivend.com/minivend/minivend-list