{"data":{"id":"ACSD-60584","source":"qpt","sourceRef":"magento/quality-patches@1.1.84","title":"Fixes the issue where an access token created for the user on one website is allowed to access or change customer information on other websites.","categories":["GraphQL","Customer"],"components":["magento/module-customer-graph-ql"],"origin":"adobe-commerce-support","documentation":{"url":"https://experienceleague.adobe.com/en/docs/commerce-operations/tools/quality-patches-tool/patches-available-in-qpt/v1-1-53/acsd-60584-access-token-created-for-one-website-is-allowed-to-access-information-on-other-websites","path":"help/tools/quality-patches-tool/patches-available-in-qpt/v1-1-53/acsd-60584-access-token-created-for-one-website-is-allowed-to-access-information-on-other-websites.md","blobSha":"f354eee3224310d2bd2107ad7d1d1384b4b787a3","description":"The API token created for the user on one website allows you to access customer information, create a cart, and add products to the cart on other website views.","stepsToReproduce":"1. Ensure Share Customer Accounts configuration is set to Per Website. 1. Create additional website, store, and storeview. 1. Create two customers with the same email on the main website and the website from the previous step. 1. Generate a customer token via GraphQL on the main website. 1. Using the generated token, send a customer GraphQL query with the second website in the header to retrieve customer information. 1. Observe the returned result.","introducedInQpt":"1.1.53","createdFor":["2.4.6-p1"],"documentedRange":"2.4.5 - 2.4.6-p8","scheduledFixRelease":"2.4.8"},"files":[{"package":"magento/magento2-base","constraint":">=2.4.5 <2.4.5-p17 || >=2.4.6 <2.4.6-p15","path":"patches/os/ACSD-60584_2.4.6-p1.patch","blobSha":"eb3e2eff04695747e2b106c00aeed21e7ddf12a8","url":"https://raw.githubusercontent.com/magento/quality-patches/11d565bdde197b9c7bac859a5698e99098b48457/patches/os/ACSD-60584_2.4.6-p1.patch","thirdParty":false,"modifies":[{"path":"vendor/magento/module-customer-graph-ql/Model/Context/AddUserInfoToContext.php","change":"modified","package":"magento/module-customer-graph-ql"}],"packages":["magento/module-customer-graph-ql"],"hasTests":false,"applicableVersions":{"magento-community":["2.4.6-p14","2.4.6-p13","2.4.6-p12","2.4.6-p11","2.4.6-p10","2.4.6-p9","2.4.6-p8","2.4.6-p7","2.4.6-p6","2.4.6-p5","2.4.6-p4","2.4.6-p3","2.4.6-p2","2.4.6-p1","2.4.6","2.4.5-p16","2.4.5-p15","2.4.5-p14","2.4.5-p13","2.4.5-p12","2.4.5-p11","2.4.5-p10","2.4.5-p9","2.4.5-p8","2.4.5-p7","2.4.5-p6","2.4.5-p5","2.4.5-p4","2.4.5-p3","2.4.5-p2","2.4.5-p1","2.4.5"],"magento-commerce":["2.4.6-p14","2.4.6-p13","2.4.6-p12","2.4.6-p11","2.4.6-p10","2.4.6-p9","2.4.6-p8","2.4.6-p7","2.4.6-p6","2.4.6-p5","2.4.6-p4","2.4.6-p3","2.4.6-p2","2.4.6-p1","2.4.6","2.4.5-p16","2.4.5-p15","2.4.5-p14","2.4.5-p13","2.4.5-p12","2.4.5-p11","2.4.5-p10","2.4.5-p9","2.4.5-p8","2.4.5-p7","2.4.5-p6","2.4.5-p5","2.4.5-p4","2.4.5-p3","2.4.5-p2","2.4.5-p1","2.4.5"],"mage-os":[]},"unknownVersions":[],"requires":[],"replacedWith":null,"deprecated":false}],"applicableVersions":{"magento-community":["2.4.6-p14","2.4.6-p13","2.4.6-p12","2.4.6-p11","2.4.6-p10","2.4.6-p9","2.4.6-p8","2.4.6-p7","2.4.6-p6","2.4.6-p5","2.4.6-p4","2.4.6-p3","2.4.6-p2","2.4.6-p1","2.4.6","2.4.5-p16","2.4.5-p15","2.4.5-p14","2.4.5-p13","2.4.5-p12","2.4.5-p11","2.4.5-p10","2.4.5-p9","2.4.5-p8","2.4.5-p7","2.4.5-p6","2.4.5-p5","2.4.5-p4","2.4.5-p3","2.4.5-p2","2.4.5-p1","2.4.5"],"magento-commerce":["2.4.6-p14","2.4.6-p13","2.4.6-p12","2.4.6-p11","2.4.6-p10","2.4.6-p9","2.4.6-p8","2.4.6-p7","2.4.6-p6","2.4.6-p5","2.4.6-p4","2.4.6-p3","2.4.6-p2","2.4.6-p1","2.4.6","2.4.5-p16","2.4.5-p15","2.4.5-p14","2.4.5-p13","2.4.5-p12","2.4.5-p11","2.4.5-p10","2.4.5-p9","2.4.5-p8","2.4.5-p7","2.4.5-p6","2.4.5-p5","2.4.5-p4","2.4.5-p3","2.4.5-p2","2.4.5-p1","2.4.5"],"mage-os":[]},"conditions":null,"requirements":null},"_documentation":"https://magento.watch/api","_description":"Quality patch ACSD-60584 details"}