Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Admin .htaccess security bypasses login.php


Guest

Recommended Posts

Posted

This is interesting. I've always used the .htpasswd_oscommerce extra security, and I've always had to log in on both the .htpasswd_oscommerce popup box, then again on /admindir/login.php. A few days ago it stopped directing me to /login.php.

 

Previously if there was no action in the admin section for 30 mins I had to log in again at login.php.

 

Now none of this is happening, I only have to log in once, and I can leave the browser open all day without logging in again.

 

I'd like things to go back to how they were, any ideas?

 

Thanks!

Posted

Obvious check: did someone (you, hacker, host) modify your .htaccess and related files? Has your host modified anything to disable certain functions (you'll probably have to open a support ticket and ask them)?

Posted

Not that I know of. I just reset the .htpasswd to see if it helped but it still seems the same.

 

What would you suggest I ask the host in a support ticket?

 

Thanks a lot.

 

Obvious check: did someone (you, hacker, host) modify your .htaccess and related files? Has your host modified anything to disable certain functions (you'll probably have to open a support ticket and ask them)?

Posted

Actually its now working as its supposed to. There is only the pop-up login and the osc login is done automatically.

Posted

Oh, ok. I just felt a lot safer having to log in twice.

 

If I close the tab without logging out, then open admin again I'm not prompted to log in again, I'm just let straight in. That seems incredibly unsafe! Also in the past if there was no action in (I think) 30 mins you had to log in again, this no longer happens. Can I turn all these security features back on somehow??

 

Thanks

 

Actually its now working as its supposed to. There is only the pop-up login and the osc login is done automatically.

Posted

Did anyone have any thoughts on making the admin automatically log out after inactivity or closing a tab?

Posted

Remember the login like that is a browser function. The code in the shop doesn't know you are closing the browser so the session would stay active. You could try clearing cookies in the browser.

Support Links:

For Hire: Contact me for anything you need help with for your shop: upgrading, hosting, repairs, code written, etc.

All of My Addons

Get the latest versions of my addons

Recommended SEO Addons

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...