{"data":{"id":"magento2-38462","source":"github-pr","sourceRef":"magento/magento2#38462","title":"Set isSecureArea before deleting customer","pr":{"number":38462,"url":"https://github.com/magento/magento2/pull/38462","author":"DanieliMi","mergedAt":"2025-10-13T06:00:41Z","mergeCommit":"22e91fb57330751e3405ad2b598380b2e04a7b0e","headCommit":"6002a523994a49c50fe9effdcf53e7582691576e","baseRef":"2.4-develop","diffSha256":"686d8fb580417ea5802f321d640649cd2d102dba0ea3b898b7d76fc36c98e098"},"issues":[{"number":31540,"url":"https://github.com/magento/magento2/issues/31540","title":"[Issue] Fixed 'Delete operation is forbidden for current area' error.","labels":["Component: Customer","Issue: Confirmed","Priority: P2","Progress: PR in progress","Reported on 2.4.0","Reproduced on 2.4.x","Severity: S2"],"kind":"pr-derived"},{"number":40211,"url":"https://github.com/magento/magento2/issues/40211","title":"[Issue] Set isSecureArea before deleting customer","labels":["Area: Account","Component: Customer","Issue: Confirmed","Priority: P1","Progress: done","Reported on 2.4.x","Reproduced on 2.4.x"],"kind":"pr-derived"}],"fixedIn":"2.4.9","containingTags":["2.4.9"],"reportedOn":"2.4.0","codeMatch":{"2.4.6":"clean","2.4.6-p1":"clean","2.4.6-p2":"clean","2.4.6-p3":"clean","2.4.6-p4":"clean","2.4.6-p5":"clean","2.4.6-p6":"clean","2.4.6-p7":"clean","2.4.6-p8":"clean","2.4.6-p9":"clean","2.4.6-p10":"clean","2.4.6-p11":"clean","2.4.6-p12":"clean","2.4.6-p13":"clean","2.4.6-p14":"clean","2.4.6-p15":"clean","2.4.7":"clean","2.4.7-p1":"clean","2.4.7-p2":"clean","2.4.7-p3":"clean","2.4.7-p4":"clean","2.4.7-p5":"clean","2.4.7-p6":"clean","2.4.7-p7":"clean","2.4.7-p8":"clean","2.4.7-p9":"clean","2.4.7-p10":"clean","2.4.8":"clean","2.4.8-p1":"clean","2.4.8-p2":"clean","2.4.8-p3":"clean","2.4.8-p4":"clean","2.4.8-p5":"clean","2.4.9":"conflict"},"affectedVersions":["2.4.6","2.4.6-p1","2.4.6-p2","2.4.6-p3","2.4.6-p4","2.4.6-p5","2.4.6-p6","2.4.6-p7","2.4.6-p8","2.4.6-p9","2.4.6-p10","2.4.6-p11","2.4.6-p12","2.4.6-p13","2.4.6-p14","2.4.6-p15","2.4.7","2.4.7-p1","2.4.7-p2","2.4.7-p3","2.4.7-p4","2.4.7-p5","2.4.7-p6","2.4.7-p7","2.4.7-p8","2.4.7-p9","2.4.7-p10","2.4.8","2.4.8-p1","2.4.8-p2","2.4.8-p3","2.4.8-p4","2.4.8-p5"],"components":["magento/module-customer"],"files":[{"path":"app/code/Magento/Customer/Model/AccountManagement.php","change":"modified","package":"magento/module-customer"}],"stripped":{"tests":[],"docs":[],"outsideCode":[]},"linesChanged":22,"mergeBatched":false,"excluded":null,"sections":{"description":"When the address form is enabled in the registration and an required address field is missing the registration will fail with the message \"Delete operation is forbidden for current area\". This is because first the customer is created and then the address is saved. When the address cannot be saved due to validation errors the customer needs to be deleted which will fail in a non secure area. Then the customer cannot register again because the customer entity already exists. Deletion is not possible because isSecureArea is not set at this point. This PR sets isSecureArea for the deletion process.","stepsToReproduce":"1. Enable address form in customer registration in customer_account_create.xml:\n```\n<referenceBlock name=\"customer_form_register\">\n    <arguments>\n        <argument name=\"show_address_fields\" xsi:type=\"boolean\">true</argument>\n    </arguments>\n</referenceBlock>\n```\n3. Go to /customer/account/create/\n4. Fill in the form\n5. Remove an required address field\n6. Send the form","expectedResult":null,"actualResult":null,"source":"pr"},"signatures":["} catch (InputException $e) {","2. Change them as shown below (Emulate InputException from addressRepository->save method):","throw new InputException(__(\"Test\")); <-- this line was added"],"labels":{"area":["Account"],"component":["Customer"],"priority":"P2","severity":"S2","reportedOn":["2.4.0","2.4.x"]},"categories":["Customer"],"triage":{"model":"@cf/cloudflare/clef","requestHash":"64dd3307f251886611c30dba75fdc1a6a64552c9cea1652c43af940699aae401","isBugfix":0.9763,"changeKind":{"choice":"bugfix","probabilities":{"bugfix":0.9637,"feature":0.0074,"refactor":0.0148,"tests_only":0.0059,"docs_only":0.0039,"dependency":0.0043},"confidence":0.9148},"scope":{"score":0.9571,"probabilities":{"0":0.2255,"1":0.592,"2":0.1825},"confidence":0.152},"risk":{"score":0.9162,"probabilities":{"0":0.3892,"1":0.3054,"2":0.3054},"confidence":0.007},"area":{"choice":"customer","probabilities":{"catalog":0.0036,"checkout":0.0456,"customer":0.9162,"admin":0.0097,"graphql_api":0.0039,"framework":0.0089,"frontend":0.0071,"other":0.005},"confidence":0.8192},"securityRelevant":0.5548,"reportedVersion":{"choice":"unspecified","probabilities":{"2.4.0":0.0166,"2.4.0-p1":0.0089,"2.4.1":0.0082,"2.4.1-p1":0.0063,"2.4.2":0.0102,"2.4.2-p1":0.0077,"2.4.2-p2":0.0084,"2.4.3":0.0085,"2.4.3-p1":0.0091,"2.4.3-p2":0.0092,"2.4.3-p3":0.0059,"2.4.4":0.0114,"2.4.4-p1":0.0064,"2.4.4-p10":0.0047,"2.4.4-p11":0.0061,"2.4.4-p12":0.0051,"2.4.4-p13":0.0053,"2.4.4-p14":0.006,"2.4.4-p15":0.0047,"2.4.4-p16":0.0052,"2.4.4-p17":0.0043,"2.4.4-p18":0.0044,"2.4.4-p2":0.003,"2.4.4-p3":0.0031,"2.4.4-p4":0.0039,"2.4.4-p5":0.0037,"2.4.4-p6":0.0046,"2.4.4-p7":0.004,"2.4.4-p8":0.0038,"2.4.4-p9":0.0037,"2.4.5":0.0119,"2.4.5-p1":0.0083,"2.4.5-p10":0.0057,"2.4.5-p11":0.0089,"2.4.5-p12":0.0077,"2.4.5-p13":0.0076,"2.4.5-p14":0.0076,"2.4.5-p15":0.0064,"2.4.5-p16":0.0071,"2.4.5-p17":0.0062,"2.4.5-p2":0.0034,"2.4.5-p3":0.0048,"2.4.5-p4":0.005,"2.4.5-p5":0.0048,"2.4.5-p6":0.0059,"2.4.5-p7":0.0052,"2.4.5-p8":0.0054,"2.4.5-p9":0.0044,"2.4.6":0.0145,"2.4.6-p1":0.011,"2.4.6-p10":0.0079,"2.4.6-p11":0.0098,"2.4.6-p12":0.0078,"2.4.6-p13":0.0094,"2.4.6-p14":0.0085,"2.4.6-p15":0.0072,"2.4.6-p2":0.0048,"2.4.6-p3":0.0077,"2.4.6-p4":0.0084,"2.4.6-p5":0.0071,"2.4.6-p6":0.0082,"2.4.6-p7":0.009,"2.4.6-p8":0.0063,"2.4.6-p9":0.0051,"2.4.7":0.0144,"2.4.7-p1":0.0101,"2.4.7-p10":0.0077,"2.4.7-p2":0.0081,"2.4.7-p3":0.0117,"2.4.7-p4":0.014,"2.4.7-p5":0.0111,"2.4.7-p6":0.0156,"2.4.7-p7":0.0118,"2.4.7-p8":0.0094,"2.4.7-p9":0.0062,"2.4.8":0.0144,"2.4.8-p1":0.0098,"2.4.8-p2":0.0126,"2.4.8-p3":0.0128,"2.4.8-p4":0.0126,"2.4.8-p5":0.0103,"2.4.9":0.0158,"unspecified":0.3502},"confidence":0.118},"backportWorthy":{"score":1.7258,"probabilities":{"0":0.0477,"1":0.1787,"2":0.7736},"confidence":0.4489}},"curated":{"title":"Fixes a failed address save blocking the customer from registering again","description":"When the address form is enabled in the registration and a required address field is missing, the registration fails with the message \"Delete operation is forbidden for current area\". The customer is created first and the address saved afterwards; deletion fails because isSecureArea is not set, so the customer cannot register again. The change sets isSecureArea for the deletion process.","categories":["Customer"],"author":"claude-code/opus-5.5","date":"2026-10-06","reviewedBy":null},"tests":null},"_documentation":"https://magento.watch/api","_description":"Upstream fix magento2-38462 details"}