Support

Admin Tools

#22927 PayPal order confirmation

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Tuesday, 07 July 2015 13:09 CDT

wicko
 We are using iSubscription by iJoobi but we are having issues with our payments completing. Once a payment is made within PayPal then the site automatically activated the account. But since we installed Admin Tool this has stopped working. If we turn it off then everything works fine.

But we don't want to turn off Admin Tools and need to find out how to stop Admin Tools stopping this process.

I have contacted iJoobi and they have pointed out the culprit with the completion being AdminTools. When asked what file or directory they used so I could make a exception in Admin Tools they came back with this.

We do not use files for the confirmation, instead we use the standard Joomla link so we have a URL.

Sample for jStore: index.php?option=com_jstore&controller=payment&task=confirmation....

For jSubscription would be like this:

index.php?option=com_jsubscription&controller=payment&task=confirmation....

Out site is Proficiency Post

Kind regard

David

Web design and development in Reading and Oxfordshire UK.

Wicko Web design

dlb
David,

That is the correct way to call the program, through the index.php file. Since their php file is not being called directly, Admin Tools would not block it for that reason. This is probably a false positive XSS attack or something similar. Please trigger the error in iSubscription then check your Security Exceptions log to see why it was blocked. Please post the exception and we'll figure out how to set up the exception.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

wicko
The problem is that iSubscription don't come up with an error it just never completes a purchase once complete at PayPal.
Would there be anything blocking the site connecting PayPal or getting a PayPal api?
regards
David

Web design and development in Reading and Oxfordshire UK.

Wicko Web design

dlb
Yes, it is possible that the return message from PayPal was blocked. But there should be a record of why it was blocked.

I'm referring to the Security Exceptions Log in Admin Tools under Web Application Firewall, not one of the server logs.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

wicko
Just checked the security exceptions firewall and there is nothing there. Even if I set a date of over 1 month.
Does this need to be turned on first? If so where?
I have also checked the WAF configuration and see that XSS shirld is not on.
image
How do I need to set this to collect the data you need?
regards

David

Web design and development in Reading and Oxfordshire UK.

Wicko Web design

dlb
The log should be turned on by default, but you set that under Web Application Firewall, Configure WAF, on the Logging and Reporting tab, Log Security Exceptions should be set to Yes. Also, on the same tab, the Do not log these reasons should be set to Geo Block only.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!