logo
Welcome to our new AbleCommerce forums. As a guest, you may view the information here. To post to this forum, you must have a registered account with us, either as a new user evaluating AbleCommerce or an existing user of the application. For all questions related to the older version of Gold and earlier, please go to AbleCommerce Gold forum. Please use your AbleCommerce username and password to Login. New Registrations are disabled.

Notification

Icon
Error

Options
Go to last post Go to first unread
Joe Payne2  
#1 Posted : Thursday, March 11, 2021 3:26:03 AM(UTC)
Joe Payne2

Rank: Advanced Member

Groups: HelpDesk, Developers
Joined: 11/9/2018(UTC)
Posts: 564

Thanks: 122 times
Was thanked: 26 time(s) in 25 post(s)
When using the export products, you are given the option to export all products or selected products.

If you choose 'selected products', the Manage Products view is rendered. This works, however choosing some products and clicking the 'Update' dropdown offers a choice of 'Assign Groups'.

Assigning user groups to products at this stage should not be available. The user arrived here via export-products and user group assignment is not relevant.

Wanna join the discussion?! Login to your AbleCommerce Forums forum account. New Registrations are disabled.

Joe Payne2  
#2 Posted : Thursday, March 11, 2021 3:27:08 AM(UTC)
Joe Payne2

Rank: Advanced Member

Groups: HelpDesk, Developers
Joined: 11/9/2018(UTC)
Posts: 564

Thanks: 122 times
Was thanked: 26 time(s) in 25 post(s)
You can also delete selected products here. Very bad time to have that choice.
shaharyartiwana25816656  
#3 Posted : Friday, March 12, 2021 2:00:57 AM(UTC)
shaharyar

Rank: Advanced Member

Groups: Admin, Developers, Registered, HelpDesk, Authorized User
Joined: 10/5/2018(UTC)
Posts: 704

Thanks: 5 times
Was thanked: 113 time(s) in 112 post(s)
Hi Joe,

Yes, we are just redirecting to the Manage Products page for selected products export with default functionalities. Even if you navigate to this page from the admin menu you will see the export option in the default implementation.

Can you please elaborate what are the drawbacks of having all options available when navigated from the products export page?

Thanks
Joe Payne2  
#4 Posted : Friday, March 12, 2021 9:23:27 AM(UTC)
Joe Payne2

Rank: Advanced Member

Groups: HelpDesk, Developers
Joined: 11/9/2018(UTC)
Posts: 564

Thanks: 122 times
Was thanked: 26 time(s) in 25 post(s)
The drawback is a user experience that permits unrelated behaviors to occur on the same page. In this case, the user is attempting to export products. Yet they arrive to a page where the entire store catalog can be deleted.

The two actions have nothing to do with each other. Offering the ability to delete products, or even the entire store catalog, during the product export process is poor design.





ray22901031  
#5 Posted : Friday, March 12, 2021 9:35:01 AM(UTC)
ray22901031

Rank: Advanced Member

Groups: Authorized User, Developers
Joined: 2/17/2019(UTC)
Posts: 909

Thanks: 3 times
Was thanked: 15 time(s) in 15 post(s)
"Can you please elaborate what are the drawbacks of having all options available when navigated from the products export page?"

SECURITY SECURITY SECURITY !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

A division of power, you don't want somebody who wants to export products either by mistake or a deliberate action be in a position to delete products. The insertion of products is extremely time-consuming, deleting all of them or portion of them only take seconds.

I really love this product but when it comes to security, it is the weakest I have ever seen, certain people should have certain responsibilities and it is extremely difficult when the foundation is so weak when it comes to security.

I react to this comment has an owner of a company who has been in business for over 30 years who have had employees with mischief intent, the system currently barely works (when it comes to security) and as stated many times before is still riddled with bugs that lets people with even the least restriction do maximum damage.

A more granule approach is necessary, I believe this has been stated in the past, if something is for export, it should be kept within that scope, anything else is just plain dangerous.

I'm pretty sure Joe has his opinions, but please, revisit the security portion of the software which really drags it down.

I am pretty sure that a lot of us would appreciate your attention on this matter.

Thank You,
-Ray
Users browsing this topic
Guest
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.