[SOLVED] in CBSubs with special promotion a bug makes password saved in plain text on registration

8 years 1 month ago #280562 by beat
<answer class="friendly">
We are looking into the issue you are describing :)
Thanks for your patience! :)
</answer>

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info
The following user(s) said Thank You: lousyfool

Please Log in to join the conversation.

8 years 1 month ago #280564 by beat
I am unable to reproduce your issue with exact same settings as described.

So I doubt that CBSubs or CB themselves are solely responsible for that cleartext password storage you describe.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

8 years 1 month ago #280565 by beat
You may want to disable all other CB plugins on a clone of the site. Then check the issue stops, and re-enable one by one until it happens again...

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

8 years 1 month ago - 8 years 1 month ago #280575 by lousyfool

beat wrote: I am unable to reproduce your issue with exact same settings as described.

So I doubt that CBSubs or CB themselves are solely responsible for that cleartext password storage you describe.


Oh, it's simple for you to reproduce it!

I am now PM'ing you a link where you can download an Akeeba backed-up package (incl Kickstart) of my "clean test environment".
It has only J! 3.5.1, CB and CBSubs, and Akeeba Backup, nothing else. Just install (5 minutes), launch frontend and pick "Test Plan 3" (it's marked as the one with negative fixed promotion, etc. Register and go through the dummy payment gateway, then check the PW field for the new user in the database. Bingo!


Meanwhile I'll do as you advised and play with disabling plugins...

Please Log in to join the conversation.

8 years 1 month ago #280578 by lousyfool

beat wrote: You may want to disable all other CB plugins on a clone of the site. Then check the issue stops...


Done. See attached screenshot for all plugins not required being disabled in my clean test site.

But the issue doesn't stop. Still, the PW saves in plain text under the mentioned conditions.

Well, see my post here above and the PM I sent you. You have all to reproduce it. ;)

Thanks for staying put and fixing it soon. My client's deadline for 'going live' is now very near...
Attachments:

Please Log in to join the conversation.

8 years 4 weeks ago #280595 by krileon
Please PM backend login credentials for a clone of your site on the same hosting environment as the site having issues. Alternatively you can provide login credentials for the site experiencing issues, but note we will be toggling extensions/features on/off and enabling debugging.

We are unable to confirm your issue on local clean installs across several test environments. We've also had no other reports (that I am aware of) regarding this issue. It appears isolate to your install.

We do not unpack unfamiliar sources (including Akeeba Kickstarts), sorry. We do not have the time to setup clean environments off-site everytime someone needs an install review. You will have to provide the clone your self on your existing hosting environment (ideal as it allows us to also factor in possible server issues) or login to your site it self (please backup if you do).


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.587 seconds

Facebook Twitter LinkedIn