MiniVend Akopia Services

[Date Prev][Date Next][Thread Prev][Thread Next][Minivend by date ][Minivend by thread ]

Re: userdb/AOL/CyberCash problems



>     Greetings:   Everything had been working great for several  months
>(minivend 3.12) until we found that at least one AOL user was being
>presented with another AOL user's personal info INCLUDING CC number when
>she  tried to log in to the checkout page.  I think it has something to do
>with  AOL caching, but that's weird since its through the https server. 
>About  the same time, CyberCash transactions stopped working AND my ISP
>upgraded their  PERL.   In any event, I'm working on a rebuild of the
>site with minivend 3.14.    I previously needed a patch to Order.pm for
>CyberCash 3.2 to work.  Is that needed now?   Can anyone tell me how to
>avoid the AOL problem  and or correct it if needed?   Thanks

Hello,

please turn off HTML formatting when posting to this list.

That one AOL users information is presented to another AOL user is probably
caused by the DomainTail configuration directive (default on) in
minivend.cfg. This is known to be problematic, but still a sad necessity
for some browsers.

That the CC info is presented to another user means you have must have
changed some configuration as minivend will not store the CC number by
default. It requires some effort to do this and is certainly not
recommended. Export your userdb to ascii and check whether you actually
store this information in the userdb.  From what I know Mike went to some
effort to avoid storing CC info at all, this certainly is not default
behaviour.

If Cybercash stopped working at the same time perl was upgraded, I would
check whether a needed module is missing. AFAIK Cybercash 3.2 works with
3.14. With the AOL problem (esp the CC# problem), make sure you use the
minivend variable names for payment, this should prevent the cc-number
problem.

Frank

--
Frank Miedreich
Max-Planck-Institut fuer psychologische  Forschung
Leopoldstr. 24   80802 Muenchen   +49 89 38602-237




Search for: Match: Format: Sort by: