Rank: Advanced Member
Groups: HelpDesk, Developers Joined: 11/9/2018(UTC) Posts: 564
Thanks: 122 times Was thanked: 26 time(s) in 25 post(s)
|
When using the export products, you are given the option to export all products or selected products.
If you choose 'selected products', the Manage Products view is rendered. This works, however choosing some products and clicking the 'Update' dropdown offers a choice of 'Assign Groups'.
Assigning user groups to products at this stage should not be available. The user arrived here via export-products and user group assignment is not relevant.
|
|
|
|
Rank: Advanced Member
Groups: HelpDesk, Developers Joined: 11/9/2018(UTC) Posts: 564
Thanks: 122 times Was thanked: 26 time(s) in 25 post(s)
|
You can also delete selected products here. Very bad time to have that choice.
|
|
|
|
Rank: Advanced Member
Groups: Admin, Developers, Registered, HelpDesk, Authorized User Joined: 10/5/2018(UTC) Posts: 704
Thanks: 5 times Was thanked: 113 time(s) in 112 post(s)
|
Hi Joe,
Yes, we are just redirecting to the Manage Products page for selected products export with default functionalities. Even if you navigate to this page from the admin menu you will see the export option in the default implementation.
Can you please elaborate what are the drawbacks of having all options available when navigated from the products export page?
Thanks
|
|
|
|
Rank: Advanced Member
Groups: HelpDesk, Developers Joined: 11/9/2018(UTC) Posts: 564
Thanks: 122 times Was thanked: 26 time(s) in 25 post(s)
|
The drawback is a user experience that permits unrelated behaviors to occur on the same page. In this case, the user is attempting to export products. Yet they arrive to a page where the entire store catalog can be deleted.
The two actions have nothing to do with each other. Offering the ability to delete products, or even the entire store catalog, during the product export process is poor design.
|
|
|
|
Rank: Advanced Member
Groups: Authorized User, Developers Joined: 2/17/2019(UTC) Posts: 909
Thanks: 3 times Was thanked: 15 time(s) in 15 post(s)
|
"Can you please elaborate what are the drawbacks of having all options available when navigated from the products export page?"
SECURITY SECURITY SECURITY !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
A division of power, you don't want somebody who wants to export products either by mistake or a deliberate action be in a position to delete products. The insertion of products is extremely time-consuming, deleting all of them or portion of them only take seconds.
I really love this product but when it comes to security, it is the weakest I have ever seen, certain people should have certain responsibilities and it is extremely difficult when the foundation is so weak when it comes to security.
I react to this comment has an owner of a company who has been in business for over 30 years who have had employees with mischief intent, the system currently barely works (when it comes to security) and as stated many times before is still riddled with bugs that lets people with even the least restriction do maximum damage.
A more granule approach is necessary, I believe this has been stated in the past, if something is for export, it should be kept within that scope, anything else is just plain dangerous.
I'm pretty sure Joe has his opinions, but please, revisit the security portion of the software which really drags it down.
I am pretty sure that a lot of us would appreciate your attention on this matter.
Thank You, -Ray
|
|
|
|
Forum Jump
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.
Important Information:
The AbleCommerce Forums uses cookies. By continuing to browse this site, you are agreeing to our use of cookies.
More Details
Close