Prestashop: Disabled products are visible with wrong token or no token at all

Created on 5 Feb 2020  路  5Comments  路  Source: PrestaShop/PrestaShop

Describe the bug
Disabled products are visible with wrong token or no token at all

To Reproduce
Steps to reproduce the behavior:

  1. Go to Catalog and disable a product
  2. Click on Preview
  3. Copy URL and open an Incognito window to make sure you're not logged in as admin and all cookies are cleared.
  4. Change the token in the URL to whatever, or even remove it, or remove all query parameteres and keep just ?preview=1. Refresh.
  5. The product is still visible, with no error message displayed

Screenshots
If applicable, add screenshots or screenrecords to help explain your problem.
With correct token:
image
Token removed:
image

Additional information
PrestaShop version: 1.7.5.2, 1.7.6, 1.7.7
PHP version: N/A

1.7.5.2 1.7.6.2 1.7.6.3 Bug FO Fixed PR available Products SEO & URLs

All 5 comments

Hi @rdy4ever,

Thanks for your report.
I manage to reproduce the issue with PS1.7.5.2 & PS1.7.6.2 & PS1.7.6.3 & the branch 1.7.7.x.
I鈥檒l add this to the debug roadmap so that it鈥檚 fixed. If you have already fixed it on your end or if you think you can do it, please do send us a pull request!
Thanks!

@PrestaShop/prestashop-product-team Hi, Is it the good behavior that a disabled product is accessible on the frontoffice from an anonymous user (but with a parameter in URL ?preview=1) ?

@PrestaShop/prestashop-product-team Hi, Is it the good behavior that a disabled product is accessible on the frontoffice from an anonymous user (but with a parameter in URL ?preview=1) ?

Hi @Progi1984
This is clearly a bug :)

I confirm a disabled product should never be accessible on front office, whatever type of "user" you are, except for preview which I guess is only usable with a specific token. Wdyt @Progi1984 ?

@colinegin Thanks for the answer.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

khouloudbelguith picture khouloudbelguith  路  3Comments

vincent-dp picture vincent-dp  路  3Comments

matks picture matks  路  3Comments

rGaillard picture rGaillard  路  3Comments

hiousi picture hiousi  路  3Comments