{"data":{"id":"ACSD-54472","source":"qpt","sourceRef":"magento/quality-patches@1.1.84","title":"Fixes the issue where customers of a rejected company can still authenticate, and customers of a blocked and a rejected company can still place orders, added additional validation for GraphQL endpoints.","categories":["B2B","GraphQL"],"components":["magento/module-company","magento/module-company-graph-ql","magento/module-negotiable-quote-graph-ql"],"origin":"adobe-commerce-support","documentation":{"url":"https://experienceleague.adobe.com/en/docs/commerce-operations/tools/quality-patches-tool/patches-available-in-qpt/v1-1-40/acsd-54472-customers-of-rejected-company-can-still-authenticate-and-place-orders","path":"help/tools/quality-patches-tool/patches-available-in-qpt/v1-1-40/acsd-54472-customers-of-rejected-company-can-still-authenticate-and-place-orders.md","blobSha":"de2731e1f10f51addc55a64b85e0a8bc89c485a4","description":"The customers of a rejected company can still authenticate, and customers of a blocked and rejected company can still place orders.","stepsToReproduce":"1. Create a company. 1. Add products to the cart via GraphQL. 1. Change the company status to Blocked. 1. Send a GraphQL request to place the order and to create a negotiable quote. 1. Change the company status to Rejected. 1. Send a GraphQL request to obtain the company's user authorization token. 1. Set customer status to Inactive. 1. Send a GraphQL request to obtain the company's user authorization token.","introducedInQpt":"1.1.40","createdFor":["2.4.6"],"documentedRange":"2.4.6 - 2.4.6-p3","scheduledFixRelease":"2.4.7"},"files":[{"package":"magento/magento2-b2b-base","constraint":">=1.3.5 <1.3.6","path":"patches/commerce/ACSD-54472_1.3.5_v2.patch","blobSha":"d3774bd74789164efc1b880b238bea587eb1b0f1","url":"https://raw.githubusercontent.com/magento/quality-patches/11d565bdde197b9c7bac859a5698e99098b48457/patches/commerce/ACSD-54472_1.3.5_v2.patch","thirdParty":false,"modifies":[{"path":"vendor/magento/module-company/Model/Customer/Permission.php","change":"modified","package":"magento/module-company"},{"path":"vendor/magento/module-company/Plugin/Customer/Model/Authentication.php","change":"added","package":"magento/module-company"},{"path":"vendor/magento/module-company/Plugin/Quote/Api/CartManagementInterfacePlugin.php","change":"modified","package":"magento/module-company"},{"path":"vendor/magento/module-company/Plugin/Quote/Api/CartRepositoryInterfacePlugin.php","change":"added","package":"magento/module-company"},{"path":"vendor/magento/module-company/etc/di.xml","change":"modified","package":"magento/module-company"},{"path":"vendor/magento/module-company-graph-ql/etc/graphql/di.xml","change":"modified","package":"magento/module-company-graph-ql"},{"path":"vendor/magento/module-negotiable-quote-graph-ql/Model/NegotiableQuote/RequestNegotiableQuoteForUser.php","change":"modified","package":"magento/module-negotiable-quote-graph-ql"},{"path":"vendor/magento/module-negotiable-quote-graph-ql/Model/Resolver/RequestNegotiableQuote.php","change":"modified","package":"magento/module-negotiable-quote-graph-ql"}],"packages":["magento/module-company","magento/module-company-graph-ql","magento/module-negotiable-quote-graph-ql"],"hasTests":false,"applicableVersions":{"magento-community":[],"magento-commerce":["2.4.6-p7","2.4.6-p6","2.4.6-p5","2.4.6-p4","2.4.6-p3","2.4.6-p2","2.4.6-p1","2.4.6"],"mage-os":[]},"unknownVersions":[],"requires":[],"replacedWith":null,"deprecated":false}],"applicableVersions":{"magento-community":[],"magento-commerce":["2.4.6-p7","2.4.6-p6","2.4.6-p5","2.4.6-p4","2.4.6-p3","2.4.6-p2","2.4.6-p1","2.4.6"],"mage-os":[]},"conditions":{"and":[{"type":"config","path":"btob/website_configuration/company_active","match":"1"}]},"requirements":null},"_documentation":"https://magento.watch/api","_description":"Quality patch ACSD-54472 details"}