How Software Gets Done  


(No Login on Secured Page)

Custom Software Buyers
Request new bids
Search Coders
My Account
 
My Buyer 'To Do' List
 
My bid requests
  My escrow account
 
My General Info
 
Help for Buyers
Articles for Buyers
Latest News
 

Custom Software Coders

Newest open work
Browse all work
Search all work
My Account
 
My Coder 'To Do' List
 
My bids
 
My General Info
  My credit account
 
Help for Coders
Articles for Coders
Latest News
 

Affiliates

My account
 
My pipeline
 
My credit account
 
Help for Affiliates
Latest News
 
Newest Open Bid Requests.
Domain Specific WebSearch Engine
By StarSE on Jan 30
Max Bid: $250


simple tar
By CheatMode on Jan 30
Max Bid: $30

(Screen Shot)

Custom IE Toolbar
By ocibr on Jan 30
Max Bid: $20


web site logo
By Melni on Jan 30
Max Bid: $30

(Screen Shot)

DIAL TELEPHONE, RECORD RESPONSE
By C. Joseph Howard on Jan 30
Max Bid: Open to fair suggestions


Educational Index
By Mind Group Inc on Jan 30
Max Bid: Open to fair suggestions


Click here to put this ticker on your own site

Open Work Categories.
Database 
(137 open)
   Access 
(59 open)
   MySQL 
(68 open)
   Oracle 
(6 open)
   SQL Server 
(39 open)
   Other DB 
(17 open)
Documentation / Tech Writing 
(24 open)
Game Development 
(17 open)
Graphics / Art / Music 
(59 open)
   Graphics 
(55 open)
     3d Animation 
(16 open)
   Art (Misc.) 
(22 open)
   Music 
(9 open)
   3d Modeling 
(14 open)
Language Specific 
(106 open)
   ASP 
(59 open)
   C# 
(35 open)
   C++ / C 
(105 open)
   Cold Fusion 
(2 open)
   Delphi 
(27 open)
   Java 
(46 open)
   Perl 
(30 open)
   PHP 
(80 open)
   XML/XSL 
(24 open)
   Visual Basic 
(166 open)
   Visual Basic .Net 
(57 open)
   Other 
(46 open)
Misc 
(39 open)
   CAD 
(9 open)
MultiMedia 
(33 open)
Network 
(33 open)
   Network Design 
(9 open)
   Network Implementation 
(14 open)
Platforms 
(66 open)
   Windows 
(139 open)
     MS Exchange 
(5 open)
     MS Office 
(10 open)
     Other 
(10 open)
   Internet Browser 
(59 open)
   Linux 
(42 open)
   UNIX 
(26 open)
   Hand Held/PDA Programming 
(13 open)
Requirements 
(11 open)
Security 
(36 open)
Testing / Quality Assurance 
(14 open)
Web 
(129 open)
   Page Design 
(56 open)
   Flash 
(33 open)
   Web Services 
(57 open)
   Web (Other) 
(59 open)
Training 
(5 open)
   Computer Based 
(12 open)
 
Other
 
Other Sites

Download the free Rent A Coder IE toolbar!
 
Show Bid Request

ASP shopping cart add-ons
Bid Request Id: 28263
Bookmark in my 'To Do' list
Posted by: strfle (2 ratings)
(Software buyer rating 10)
Posted: Sep 21, 2002
8:31:39 PM EDT
Bidding Closes: Sep 28, 2002
10:13:13 PM EDT
Viewed (by coders): 303 times
Deadline: 10/4/2002
TIME EXPIRED
Phase:
100% of work was accepted by buyer. Coder account has been credited.
Max Accepted Bid: Bidding is closed
Project Type: Very Small Business Project: under $100 (USD)
Bidding Type: Open Auction
Categories: Windows, Database, Language Specific, Requirements, Platforms, ASP, Internet Browser, Misc, Security, Web Services
Enter chat room for this bid request
(0 active users at Jan 30, 2003 3:15:12 PM EDT)

Description:
#1 Problem: We want to use the candypress shopping cart on our website. By default, the shopping cart can support electronic payloads (downloads.)The shopping cart has a download script(sysDownload.asp) which does not reveal the true location of a file download and does not allow the product to be downloaded unless it has been payed for. The sysDownload.asp outputs a random link to a file located in a downloads folder(included on the program). The problem is that the download folder is not secure, anyone could index(find all of the pages) our site and find out/steal all of the files in the download folder. We could rename the downloads folder to an indescreate name but this still poses a security hazard.

1) What we need is for the download folder to be password protected somehow and the sysDownload.asp script to electronically type that password in when it needs to access a program from the download folder. This would prevent anyone from trying to access the download folder directly from the web without paying.


#2 Problem: There is also another problem in the script that we need to address. Once a paid order has been processed the sysDownload.asp gives the customer the ability to download the file. The only problem is the link can be shared with anyone who has not logged in.

2) What we need is for the link to only become active and downloadable once a user logs into the shopping cart, once they log out it becomes inactive. This would prevent a customer from telling another customer the download link.

Note To Bidder: In the zip I have included the email I recieved from sales explaining exactcally what I want and the candypress store front 1.8 free version. Information from me is in the NoteToBidder.doc. Please read the EmailFromTech.doc it contains important information.

Please give me comments if you know there is anything I can do to improve my request.

Thank you...

Deliverables:
1) Complete and fully-functional working program(s) in executable form as well as complete source code of all work done.

2) Installation package that will install the software (in ready-to-run condition) on the platform(s) specified in this bid request.

3) Complete ownership and distribution copyrights to all work purchased.

4) The alterations to the sysDownload.asp may not affect the original function of the script.
As in the original manufacture features, the time of day download, random link creation, the limit of downloads, and ip logging etc., still needs to work with the back-end (features in the email from technical support.)

5) Completed program must be in Asp work with the candypress shopping cart.

Platform:
Asp

Windows

All web browsers

Must work with candypress shopping cart.


Must be 100% finished and received by buyer on:

Oct 4, 2002 EDT
Deadline legal notes: All times are expressed in the time zone of the site EDT (UT - 5). If the buyer omitted a time, then the deadline is 11:59:59 PM EDT on the indicated date.

Additional Files:
This bid request includes IMPORTANT additional attached files. Please download and read fully before bidding.



Remember that contacting the other party outside of the site (by email, phone, etc.) on all business projects < $500 (before the buyer's money is escrowed) is a violation of both the software buyer and seller agreements. We monitor all site activity for such violations and can instantly expel transgressers on the spot, so we thank you in advance for your cooperation. If you notice a violation, you can report it to: abuse@rentacoder.com.
 
Bidding/Comments:
All monetary amounts on the site are in United States dollars.
Rent a Coder is a closed auction, so coders can only see their own bids and comments. Buyers can view every posting made on their bid requests.

See all rejected bids (and all comments)
Name   Bid Amount 
 
Date   Coder Rating  
maxxsoft
(7 ratings)
in Toronto, Ontario
Canada
 
$35 (USD) Sep 23, 2002
12:20:30 PM EDT
 9.71
(Excellent)
   
I have installed and tested the CandyPress software. It is not very well done but simple for the way it looks. The unique key generation is not really required. This is done probaly to identify duplicate order of the same product or for some other reason which I can not fugure out because the final thing that sysDownload.asp is doing is redirecting to already predifined download page (in admin section/utilities->download page relative to scripts folder). So basically no protection for any files on server side. Client loging is also not on security level (it is only used to identify custumer/order and status). So basically I would just add one more page that will require user to be loged in before downloading this file which will sit in Download folder which must be a folder set for scripting access and not folder for read access. Since everyting in this application is not scripting access you can safaly set the partent folder as folder for scripting access. Please note that doing this will disable Upload feature, whcih will not be usable any way if you decide to have user level access to this folder.

So it is doable this way, but I would go for CGI (exectuable program) that will manage downloads (send pages or files to web browser) or creating external solution (a separate web application to validate user name and password).
I will try to do the simplest thing to do (as you have requested) and that is to ask user to supply login credentials any time download is requested. So that would be most suitable. Expect later on today some fix from me, no matter if you select or reject my bid

Best regards,
 

maxxsoft
(7 ratings)
in Toronto, Ontario
Canada
 
N/A Sep 23, 2002
3:15:51 PM EDT
 9.71
(Excellent)
   
As promised earlier today. I have done log-in request before downloading the file. Please make backup of sysDownload.asp file in scripts directory and make sure you put the one in atachment.

Please let me know if this one is working for you. It worked on my local server.

Best regards
Attached File
 
 
 
 
  See 20 private reply(ies)
to/from maxxsoft.
 




Quick Search
 

 Advanced Search
Newest Open Work
Latest News

 
Credentials


 

 
Rent A Coder upholds the rigorous business practices required to be both a BBB member and Square Trade vendor.
  • All customer issues addressed within 2 days
  • Openly disclosed pricing and return policies
  • Participation in mediation at buyer request
  • Superior selling track record
This site is verified through its parent company, Exhedra Solutions, Inc.
 

Rent A Coder Top Coders.


Anuj Gakhar
Rated a 9.98 on 78 jobs 
Michael Sharp
Rated a 9.98 on 149 jobs 
Simon Price
Rated a 10 on 6 jobs 
RNA
Rated a 9.91 on 28 jobs 
Buddies
Rated a 9.82 on 52 jobs 
Securenext
Rated a 9.97 on 58 jobs 
Codman
Rated a 9.96 on 106 jobs 
markesh
Rated a 10 on 17 jobs 
Andrei Remenchuk
Rated a 10 on 9 jobs 
teleCODERS
Rated a 9.93 on 59 jobs 

See all top coders...

(What makes a top coder?)

Top Exam Scorers
 
Other
Rent A Coder is PayPal verified through it's parent company, Exhedra Solutions, Inc.

Created in partnership with:

 


Affiliate Sites



Latest News | About Us | Kudos | Feedback/Contact    Affiliates | Advertise    Privacy | Legal

Copyright © 2001, Exhedra Solutions, Inc. All rights reserved.
By using this site you agree to its Terms and Conditions.
"Rent A Coder" (tm), "Safe Project Escrow" (tm) and "How Software Gets Done" (tm)
are trademarks of Exhedra Solutions, Inc.