Add-on DragonByte eCommerce 1.3.4.1 [XenForo]

DragonByte eCommerce
DragonByte eCommerce is a highly advanced digital retailer for XenForo, containing advanced features such as multiple pricing tiers, coupons and automatic sales.

Fully integrated with XenForo 2, DragonByte eCommerce takes advantage of all built-in XenForo 2 functionality like the new Payment Profile system which allows you to accept payments from different payment processors.

Overview Feature list Copyright info System Requirements Releases (103) Reviews (7) Discussion

DragonByte Technologies

Company Information
Staff member
Company Info
A new update is available for DragonByte eCommerce by DragonByte Technologies.


DragonByte eCommerce 1.3.4.1

Update highlights

This is a re-release of v1.3.4 (which has also been patched) to fix an issue that could lead to data loss.

Given following scenario:
  • Another user's order is pending
  • The current viewing user is the owner of a product in the other user's cart (and thus can't purchase it)
  • The current viewing user visits the order log in the Admin control panel
In the above scenario, any order items whose products are owned by the current viewing user would be silently removed from the other user's cart.

The reason this occurred is that every time the order total is calculated for pending orders, the order items are validated to ensure that the user has the permission to buy the item in question.
This permission check did not ensure it was taking the buyer's permissions into account, so permissions were checked incorrectly.

The problem only revealed itself because of the Order log in the AdminCP, which is currently the only way it is possible to view another user's current pending order.

To clarify: The existing v1.3.4 release has also been patched, so if your eCommerce license has expired since the release of v1.3.4, you can re-download that version to obtain the fix.


Complete Change Log

Fix: Fix a race condition where viewing another user's pending order could remove their items from cart


Read more about this product...
 

Product Information

XenForo 2.0.6+ XenForo 2.1.x XenForo 2.2.x XenForo 2.3.x
Seller
DragonByte Technologies
Release date
Last update
97.2% 4.86 star(s) 7 ratings

Pricing information

1 Month
€29.95
Renewal cost
€19.95
1 Year
€74.95
Renewal cost
€54.95

Branding Free

Lifetime
€70.00

Professional Installation

1 Day
€29.95
Back
Top