x

HELP!!! Big Security Issue - Review emails give access to password protected pages

I created password protected pages that allow me to send free products to my customers.  However, the email that's requesting a review of the product provides a link back to the password protected page, bypassing any login.  Thus, anyone with that email can access those pages and purchase free items!

HELP!!!!!

3,387 Views
Message 1 of 7
Report
6 REPLIES 6
Square

That should only happen if you're opening the link in a browser in which you'd already entered the password. For example, try this:

1. Quit any browser your have open on your computer

2. Click a link in the email that goes to a password protected page

That should prompt you again to enter a password.

3,373 Views
Message 8 of 7
Report

Adam,

Nope.  I forwarded the email to my wife, who opened it in her mobile phone without having access to that page.

3,360 Views
Message 8 of 7
Report
Square

Oh, I see what you mean. Try this:

1. Create a new page of your site and choose the product option

2. Connect that to your product and set the visilbity to password protected

3. Add another page to your site and hide it from your navigation, then drag the product page your just made under it so these are all hidden from your site navigation.

4. Repeat steps 1 & 2 for any products you don't want public

That should make it so the link also prompts for a site password.

3,355 Views
Message 8 of 7
Report

Thanks for the suggestion, @Adam.

I already have it set up that way, except the page below the hidden page is a category page, with all the free products in that category.

However, I don't want them to have to enter a password in order to leave a review.

3,336 Views
Message 8 of 7
Report

@Adam, any other thoughts?

3,329 Views
Message 8 of 7
Report
Square

Hmm... I can't think of another way right now short of making changes on our end. You could post that to our Vote on Features board if you have a moment.

3,327 Views
Message 8 of 7
Report