- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
HELP!!! Big Security Issue - Review emails give access to password protected pages
I created password protected pages that allow me to send free products to my customers. However, the email that's requesting a review of the product provides a link back to the password protected page, bypassing any login. Thus, anyone with that email can access those pages and purchase free items!
HELP!!!!!
- Labels:
-
password protection
-
reviews
-
Security
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
That should only happen if you're opening the link in a browser in which you'd already entered the password. For example, try this:
1. Quit any browser your have open on your computer
2. Click a link in the email that goes to a password protected page
That should prompt you again to enter a password.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
Adam,
Nope. I forwarded the email to my wife, who opened it in her mobile phone without having access to that page.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
Oh, I see what you mean. Try this:
1. Create a new page of your site and choose the product option
2. Connect that to your product and set the visilbity to password protected
3. Add another page to your site and hide it from your navigation, then drag the product page your just made under it so these are all hidden from your site navigation.
4. Repeat steps 1 & 2 for any products you don't want public
That should make it so the link also prompts for a site password.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
Thanks for the suggestion, @Adam.
I already have it set up that way, except the page below the hidden page is a category page, with all the free products in that category.
However, I don't want them to have to enter a password in order to leave a review.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
@Adam, any other thoughts?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content
Hmm... I can't think of another way right now short of making changes on our end. You could post that to our Vote on Features board if you have a moment.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report Inappropriate Content