Control Panel Usability Enhancements

#2
Not really a usability enhancement as such, but any user can view anyone elses invoice in the control panel once they're logged in.

Just changing the invoice number when viewing one of you own allows you to see invoices for other random users. Clicking on the transaction reference id in the invoice gives you an error, saying that it does not belong to you, so you cannot see payment details, but I was expecting to get that error when just trying to view the invoice itself.

Can this check be added to the invoice page as well as the payment reference page?
 

Mark Jeftovic (#fb)

Administrator
Staff member
#3
Not really a usability enhancement as such, but any user can view anyone elses invoice in the control panel once they're logged in.

Just changing the invoice number when viewing one of you own allows you to see invoices for other random users. Clicking on the transaction reference id in the invoice gives you an error, saying that it does not belong to you, so you cannot see payment details, but I was expecting to get that error when just trying to view the invoice itself.

Can this check be added to the invoice page as well as the payment reference page?
Sorry for the delay, I just saw this post now - this issue was fixed. THx.
 
Top