Register

If this is your first visit, please click the Sign Up now button to begin the process of creating your account so you can begin posting on our forums! The Sign Up process will only take up about a minute of two of your time.

Results 1 to 6 of 6
  1. #1
    Senior Member RDesignista's Avatar
    Join Date
    Feb 2012
    Location
    Coconut Tree City
    Posts
    822
    Member #
    30921
    Liked
    123 times

    SSL is losing data during checkout (PHP cart)

    Hi everyone,

    I have the oddest problem right now.

    An online store I helped work on (Zen Cart) stopped working about 3 weeks back. What happens is that during the checkout process, when the SSL is initialized, the data is lost (the cart empties) and I get a "Page not found." I didn't touch anything, my client didn't touch anything, the webhosts say nothing changed, but the credit card companies did send my client a PCI compliance fine about the same time that this error showed (and if this was related, I'm not sure which is the chicken and egg...).

    Here's what I know:
    - The store was working fine for over a year prior to this.
    - When I turn off SSL, the checkout process is okay (meaning actual files are okay).
    - I'm not ruling out the possibility that something got hacked.
    - The admin, which is secured by SSL too, actually works just fine and the webhost support says the certificated (shared) is okay.
    - I just purchased a private SSL and will install it to see if it helps.
    - There's nothing relevant in the server error logs/store logs.
    - There are a lot of similar problems on forums, but none exactly as I explained.

    It's down for maintenance. You can take a look here.Just add an item to your cart, checkout, and on step 1/3 don't fill in anything, just press "CONTINUE CHECKOUT" and you'll see your cart empty and you're taken to a 404 page.

    Anyone have any idea?

  2.  

  3. #2
    Unpaid WDF Intern TheGAME1264's Avatar
    Join Date
    Dec 2002
    Location
    Not from USA
    Posts
    14,483
    Member #
    425
    Liked
    2783 times
    The SSL didn't expire, so that's not it.

    Personally, and I'm not sure if this relates to the PCI compliance fine you received, I'd start by installing the private SSL The reason I'm suggesting it relates to the clearing of the session variable as you're passed between aimaa.com and red.olm.net. If it's on its own SSL, it may not get cleared out, thus solving the problem.

    The other problem may be that the checkout page that it's looking for has been moved. Just because everyone says they didn't touch anything doesn't mean no one touched anything.

    Other than that, I've got nothing.
    If I've helped you out in any way, please pay it forward. My wife and I are walking for Autism Speaks. Please donate, and thanks.

    If someone helped you out, be sure to "Like" their post and/or help them in kind. The "Like" link is on the bottom right of each post, beside the "Share" link.

    My stuff (well, some of it): My bowling alley site | Canadian Postal Code Info (beta)

  4. #3
    Senior Member RDesignista's Avatar
    Join Date
    Feb 2012
    Location
    Coconut Tree City
    Posts
    822
    Member #
    30921
    Liked
    123 times
    I figured it was something to do with sessions and/or the SSL given. But again, thinking of the issue was like taking a sledgehammer to the johnson - nothing changed so how could things go wrong... web stuff isnt' like a car, which gets wear and tear and can suddenly stop working.

    This issue really reminded me that my PHP knowledge isn't really where it needs to be. I should really read up more on PHP since that's the only programming language that seems to help me get work.

    Thanks THEGAME. Will update. Or will surrender to Paypal checkout.

  5. #4
    Unpaid WDF Intern TheGAME1264's Avatar
    Join Date
    Dec 2002
    Location
    Not from USA
    Posts
    14,483
    Member #
    425
    Liked
    2783 times
    Well, there's never any harm in installing an SSL...assuming you do it properly.

    Since I don't know Zen Cart specifically, the only other thing I can suggest to look for is to see if there are any redirects to the "not found" page that would indicate any files that are missing and/or corrupted (0-byte files, for example).
    If I've helped you out in any way, please pay it forward. My wife and I are walking for Autism Speaks. Please donate, and thanks.

    If someone helped you out, be sure to "Like" their post and/or help them in kind. The "Like" link is on the bottom right of each post, beside the "Share" link.

    My stuff (well, some of it): My bowling alley site | Canadian Postal Code Info (beta)

  6. #5
    Senior Member RDesignista's Avatar
    Join Date
    Feb 2012
    Location
    Coconut Tree City
    Posts
    822
    Member #
    30921
    Liked
    123 times
    A new SSL worked. Still don't quite understand why or what the issue was. I guess I should've tried that from the start. Changing parts blindly is a bad and expensive method of fixing things when it comes to a car, but not so expensive when it comes to websites.

    And yes, I looked for a 0 byte file, but none was found. Happened to me once before. Really freaked me out, because I figured that files don't change unless someone touches them. Now I know better. Thanks.

  7. #6
    Unpaid WDF Intern TheGAME1264's Avatar
    Join Date
    Dec 2002
    Location
    Not from USA
    Posts
    14,483
    Member #
    425
    Liked
    2783 times
    Without having seen it, my guess is that the order session variable never got properly passed to the host's SSL. Since a session variable is domain-specific, installing an SSL would prevent that from occurring as the domain of the SSL matches the domain of the site.
    If I've helped you out in any way, please pay it forward. My wife and I are walking for Autism Speaks. Please donate, and thanks.

    If someone helped you out, be sure to "Like" their post and/or help them in kind. The "Like" link is on the bottom right of each post, beside the "Share" link.

    My stuff (well, some of it): My bowling alley site | Canadian Postal Code Info (beta)


Remove Ads

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
All times are GMT -6. The time now is 02:42 AM.
Powered by vBulletin® Version 4.2.3
Copyright © 2019 vBulletin Solutions, Inc. All rights reserved.
vBulletin Skin By: PurevB.com