CiviCRM Community Forums (archive)

*

News:

Have a question about CiviCRM?
Get it answered quickly at the new
CiviCRM Stack Exchange Q+A site

This forum was archived on 25 November 2017. Learn more.
How to get involved.
What to do if you think you've found a bug.



  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Using CiviCRM »
  • Using Core CiviCRM Functions (Moderator: Yashodha Chaku) »
  • Using Checksums for Profile is revealing other contacts info or overwriting
Pages: [1]

Author Topic: Using Checksums for Profile is revealing other contacts info or overwriting  (Read 846 times)

petednz

  • Forum Godess / God
  • I’m (like) Lobo ;)
  • *****
  • Posts: 4899
  • Karma: 193
    • Fuzion
  • CiviCRM version: 3.x - 4.x
  • CMS version: Drupal 6 and 7
Using Checksums for Profile is revealing other contacts info or overwriting
September 16, 2010, 01:55:42 pm
Hi - can anyone shed any light on likely causes of the following.

Client sends out email with civicrm/profile/edit?reset=1&gid=28&id={contact.contact_id}&{contact.checksum}

Contact A clicks on link fills in info and saves, Contact B uses their link and ends up overwriting Contact A's data (resulting in two Contacts in DB with same name)

Contact C clicks on link, fills in form, saves, reclicks on link to check their data has been saved, sees Contact D's information.

Another contractor on this project had earlier made a comment that "After submission of intake form in ie it was not working some time. It was because of javascript error on website but that has been fixed now. And also i cleared the cache this is also the cause some time. cache should be clear weekly."

Does any of the above suggest the problem and/or solution?

I have tried to replicate the above by doing the following: grab 3 contacts (all with fuzion email addresses) - send an email using same content with checksum as used for others. Used each checksum link in a different browser, made changes and saved each in turn, and then reopened the form - in no cases did I observe any data other than that belonging to the correct person.

Given the data involved includes very confidential information we need to sort this.
Sign up to StackExchange and get free expert advice: https://civicrm.org/blogs/colemanw/get-exclusive-access-free-expert-help

pete davis : www.fuzion.co.nz : connect + campaign + communicate

Pages: [1]
  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Using CiviCRM »
  • Using Core CiviCRM Functions (Moderator: Yashodha Chaku) »
  • Using Checksums for Profile is revealing other contacts info or overwriting

This forum was archived on 2017-11-26.