View Issue Details

IDProjectCategoryView StatusLast Update
0005285OXID eShop (all versions)1.05. Userspublic2015-03-12 16:40
Reportertomas.lygutas 
PrioritynormalSeverityfeatureReproducibilityalways
Status closedResolutionsuspended 
Product Version 
Target Version4.9.0_5.2.0_RC1Fixed in Version 
Summary0005285: Shop should check if user owns email when user creates shop account
DescriptionIf you have a shop-side user account and use Paypal Express without being logged in (Email-Address in Shop matches Email-Address in Paypal) and select a different delivery address, you are greeted with Error-Message after being redirected back to shop. Message asks user to login and go through checkout again, it is related with possible security issues, as emails are note validated (confirmation mail should be sent).
If email would be always validated, shop could trust shipping address from PayPal.
TagsNo tags attached.
ThemeAll
BrowserAll
PHP Versionany
Database Versionany

Relationships

related to 0004796 resolvedtomas.lygutas module PayPal Transfer of shipping address from paypal to Shop only works when user is logged in 
related to 0005713 resolvedsaulius.stasiukaitis OXID eShop (all versions) New TLDs are not accepted by oxinputvalidator 

Activities

svetlana

2014-03-28 09:59

reporter   ~0009699

waiting for the PO decision.

leofonic

2014-06-19 14:30

reporter   ~0009981

Why do you have to go through pp-Express checkout again? With pp-Express, user is sent to order overwiew from pp, why not ask for password when user is sent back to shop and then directly show order overview?
Other possible solution: make guest orders with existing mail addresses possible.

QA

2015-03-12 16:40

administrator   ~0010788

Last edited: 2015-03-18 10:05

View 2 revisions

moved to backlog