yep.
Hosting a customer that has a Magento shopping cart. I was helping them with something and couldn't find the login button. Moved onto something else, which got me logged in another way, then couldn't find the logout button.
I ask and I'm told it's for security.... Let's remove the login/logout button from the header template because it invites people to mess with the system. Let's tell users that they have to add /login or /logout to do that.
I tried to explain that it destroys the user experience and that if a site is so insecure that petty things like hiding a login/logout button are required, it shouldn't be online.
oh wtf.
Hosting a customer that has a Magento shopping cart. I was helping them with something and couldn't find the login button. Moved onto something else, which got me logged in another way, then couldn't find the logout button.
I ask and I'm told it's for security.... Let's remove the login/logout button from the header template because it invites people to mess with the system. Let's tell users that they have to add /login or /logout to do that.
I tried to explain that it destroys the user experience and that if a site is so insecure that petty things like hiding a login/logout button are required, it shouldn't be online.
oh wtf.