Book Image

Building Online Stores with osCommerce: Beginner Edition

By : David Mercer
Book Image

Building Online Stores with osCommerce: Beginner Edition

By: David Mercer

Overview of this book

Using an easy-to-read and engaging style, this book introduces the fundamentals of osCommerce, and helps you build your first online store. It covers the out-of-the-box features of osCommerce, but it also shows you how to customize the application to your own needs. The book starts with the basics of downloading and installing osCommerce, or simply how to enable it on your Internet domain using the tools provided by your host. All of the most important configuration issues are explained, with clear instructions and advice to help you make the right choices. Once osCommerce is installed and configured, you will take a good look at how to work with your store's data including product information as well as other data which is responsible for keeping your site healthy. The all important topic of customization is also dealt with comprehensively. You will see how to develop attractive sites that will make your store a pleasure to browse and your products a pleasure to buy! Of course, no discussion on osCommerce would be complete without a look at how to obtain and treat payments. Using the modules provided with osCommerce you will be collecting money from your happy customers in no time! Once the reader has a fully fledged, and operational site it is time to look at deployment? an important topic for discussion if development has taken place on a development machine. The appendix will add a few tools to your armory and shed some light as to what is going on behind the scenes in case things go awry.
Table of Contents (13 chapters)

Securing the Administration Tool


Without a doubt, one of the major potential security threats comes from using the administration tool over the Internet. Should someone gain access to this tool on your live site, they could cause untold mischief, and much wailing and gnashing of teeth will ensue. As a result, we are going to enforce the use of a username and password in order to gain access to the admin folder, as well as ensure that the admin folder is only available over a secure server (which uses SSL to encrypt communications).

Note

You might also wish to change the name of the admin folder to something random, which will add a small amount of security in that it may not be immediately obvious to a potential hacker where this web-based tool is housed. If you do so you will need to edit config.php to reflect these changes as none of your file paths should contain the word admin anymore.

Before we do go ahead and secure the admin tool, it is worth considering that forcing communications...