<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>ProductCart Shopping Cart Software Forums : Registration E-Mail with Non-Secure Link</title>
  <link>https://forum.productcart.com/</link>
  <description><![CDATA[This is an XML content feed of; ProductCart Shopping Cart Software Forums : Using ProductCart : Registration E-Mail with Non-Secure Link]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sun, 12 Apr 2026 09:04:42 +0000</pubDate>
  <lastBuildDate>Wed, 13 Jul 2011 19:06:20 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forum.productcart.com/RSS_post_feed.asp?TID=4608</WebWizForums:feedURL>
  <image>
   <title><![CDATA[ProductCart Shopping Cart Software Forums]]></title>
   <url>https://forum.productcart.com/forum_images/pc_logo_50.png</url>
   <link>https://forum.productcart.com/</link>
  </image>
  <item>
   <title><![CDATA[Registration E-Mail with Non-Secure Link : Actually, it&amp;#039;s a security...]]></title>
   <link>https://forum.productcart.com/registration-email-with-nonsecure-link_topic4608_post17958.html#17958</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=2305">SBW</a><br /><strong>Subject:</strong> 4608<br /><strong>Posted:</strong> 13-July-2011 at 7:06pm<br /><br />Actually, it's a security issue simply by the fact that data is being submitted in a non-encrypted matter. That's the only issue I'm concerned about. &nbsp;It has nothing to do with someone else coming by and getting into their session.]]>
   </description>
   <pubDate>Wed, 13 Jul 2011 19:06:20 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/registration-email-with-nonsecure-link_topic4608_post17958.html#17958</guid>
  </item> 
  <item>
   <title><![CDATA[Registration E-Mail with Non-Secure Link : The login works on a session variable...]]></title>
   <link>https://forum.productcart.com/registration-email-with-nonsecure-link_topic4608_post17954.html#17954</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=190">intour</a><br /><strong>Subject:</strong> 4608<br /><strong>Posted:</strong> 13-July-2011 at 5:05pm<br /><br />The login works on a session variable so they stay logged in during that browser session only though it will time out eventually.<DIV>&nbsp;</DIV><DIV>For the situation you described to become a securtity issue the person would have to leave his/her computer logged into his/her email and be still logged into the prodcutcart browser session and someone else would have to come along and click the link before it timed out.</DIV><DIV>&nbsp;</DIV><DIV>Nigel</DIV>]]>
   </description>
   <pubDate>Wed, 13 Jul 2011 17:05:10 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/registration-email-with-nonsecure-link_topic4608_post17954.html#17954</guid>
  </item> 
  <item>
   <title><![CDATA[Registration E-Mail with Non-Secure Link :      Hi,I noticed that when...]]></title>
   <link>https://forum.productcart.com/registration-email-with-nonsecure-link_topic4608_post17943.html#17943</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=2305">SBW</a><br /><strong>Subject:</strong> 4608<br /><strong>Posted:</strong> 09-July-2011 at 10:37am<br /><br />Hi,<div><br></div><div>I noticed that when a customer registers, a welcome e-mail is sent out to the person and it has a non-secure link to the page that allows edits to the customer profile:</div><div><br></div><div><span apple-style-span="Apple-style-span" style="font-family: Helvetica; line-height: normal; font-size: medium; "><a href="http://" target="_blank" rel="nofollow">http://www.mycompany.com/productcart/pc/custPref.asp</a></span></div><div><br></div><div><span apple-style-span="Apple-style-span" style="font-family: Helvetica; line-height: normal; font-size: medium; "><a href="http://store.st&#111;newellbodies.com/productcart/pc/custPref.asp" target="_blank" rel="nofollow"></a></span>Now, if the person is not logged in already, then this link actually takes the person to a secure login page first. &nbsp;After logging in, they can proceed to the profile page which is also secure.</div><div><br></div><div>However, if they are already logged in and they click the non-secure e-mail link, then they are taken to the profile page which remains non-secure.</div><div><br></div><div>I know this would be a rare event, but if someone does click the link for convenience after they are already logged in, then they would be submitting personal information in a non-secure manner. &nbsp;Is there any way to change this?</div><div><br></div><div>I could change the scStoreURL in the storeconstants.asp file, to use https instead of http, but that would affect other things as well. &nbsp;I'm told this could cause mixed content errors.</div><div><br></div><div>By the way, I'm sorry to not list the version of ProductCart I'm using. &nbsp;I'm just taking over a site and am not too familiar with it. &nbsp;I can't seem to find anything that tells me where the version number is listed. Any suggestions?</div><div><br></div><div>Thanks.</div><span style="font-size:10px"><br /><br />Edited by SBW - 14-July-2011 at 10:34am</span>]]>
   </description>
   <pubDate>Sat, 09 Jul 2011 10:37:00 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/registration-email-with-nonsecure-link_topic4608_post17943.html#17943</guid>
  </item> 
 </channel>
</rss>