| ||||||||||
Shopping cart software Solutions for online shops and malls | ||||||||||
|
X-Cart Home | FAQ | Forum rules | Calendar | User manuals | Login |
Get rid of provider & quantity lines | |||
|
|
Thread Tools | Search this Thread |
#1
|
|||||||
|
|||||||
Get rid of provider & quantity lines
Almost ready to go live and noticed that when a customer checks their order history, there is a line that says provider (a.k.a. the user name of the person that entered the product in the database):
Quote:
Now, obviously it looks silly to have the word master written on the product description but it'll look far sillier when someone buys something that my daughter entered and says "sissy" or one that one of my other helpers entered that says "idontcare" because he couldn't think of a user name. Can someone tell me where/how to remove that line totally? I'd also like to remove the line that says Quantity 1 item(s). ~Beth
__________________
X-Cart version 3.5.6 PHP 4.3.4 MySQL server 3.23.56 MySQL client 3.23.49 Web server Apache/1.3.31 (Unix) Operation system Linux Perl 5.008 |
|||||||
#2
|
|||||||||
|
|||||||||
Thats done in the /skin1/main/order_info.tpl file, and you are absolutely right about showing that info, not because it looks silly, its because it is using the direct username for the provider which gives a hint to a possible hacker.
Just take these lines out: Code:
__________________
It doesn\'t matter what is done... it is how it is done. ============================= XCart Version: 3.5.3 -> Dmcigars.com XCart Version: 4.1.3.... |
|||||||||
#3
|
|||||||
|
|||||||
Thanks! Yes, I thought about the security issue but one of the things on my checklist of "to dos" before opening is to delete all the temp admin accounts I made during setup so none of them would have been valid anyway. Given that, I guess the aesthetics were all I was thinking about.
Wonder why this is included in the file? Seems an odd thing to post to the customer's side (the admin user name, that is). ~Beth
__________________
X-Cart version 3.5.6 PHP 4.3.4 MySQL server 3.23.56 MySQL client 3.23.49 Web server Apache/1.3.31 (Unix) Operation system Linux Perl 5.008 |
|||||||
#4
|
|||||||||
|
|||||||||
I agree, it should have an Admin conditional IF A then show. Or at least have the provider name, not login.
__________________
It doesn\'t matter what is done... it is how it is done. ============================= XCart Version: 3.5.3 -> Dmcigars.com XCart Version: 4.1.3.... |
|||||||||
|
|||
X-Cart forums © 2001-2020
|