QUALITY PATCH

ACSD-58054: Inactive customer token generation via API

Inactive customer token generation via API. Quality patch ACSD-58054 for magento/module-company applies to Magento Open Source and Adobe Commerce 2.4.4 to 2.4.5-p11.

Categories
B2B, Web API, Customer
Components
magento/module-company, magento/module-company-graph-ql, magento/module-negotiable-quote-graph-ql
Origin
adobe-commerce-support
Since QPT
1.1.49

Issue

Inactive customer token generation via API.

Steps to reproduce

1. Create a customer account. 1. Create a customer token using API. 1. Navigate to the backend and disable the customer account. 1. Try to generate a customer token again.

Adobe's page lists 2.4.4 - 2.4.5-p9 as compatible; the versions below are resolved from the current QPT constraints and are the ones the tool will offer.

Install

Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply ACSD-58054. On Cloud, add ACSD-58054 under stage.build.QUALITY_PATCHES in .magento.env.yaml.

For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its ACSD-58054/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.

Patch files and compatible versions

Packages across compatible versions (3): magento/module-company, magento/module-company-graph-ql, magento/module-negotiable-quote-graph-ql

magento/magento2-b2b-base >=1.3.3 <1.3.3-p13 || >=1.3.4 <1.3.4-p12

Magento Open Source
—
Adobe Commerce
2.4.5-p11, 2.4.5-p10, 2.4.5-p9, 2.4.5-p8, 2.4.5-p7, 2.4.5-p6, 2.4.5-p5, 2.4.5-p4, 2.4.5-p3, 2.4.5-p2, 2.4.5-p1, 2.4.5, 2.4.4-p12, 2.4.4-p11, 2.4.4-p10, 2.4.4-p9, 2.4.4-p8, 2.4.4-p7, 2.4.4-p6, 2.4.4-p5, 2.4.4-p4, 2.4.4-p3, 2.4.4-p2, 2.4.4-p1, 2.4.4
Patch file
patches/commerce/ACSD-58054_1.3.4-p5.patch
  • vendor/magento/module-company/Model/Customer/Permission.php
  • vendor/magento/module-company/Plugin/Customer/Model/Authentication.php (added)
  • vendor/magento/module-company/Plugin/Quote/Api/CartManagementInterfacePlugin.php
  • vendor/magento/module-company/Plugin/Quote/Api/CartRepositoryInterfacePlugin.php (added)
  • vendor/magento/module-company/etc/webapi_rest/di.xml
  • vendor/magento/module-company/etc/webapi_soap/di.xml
  • vendor/magento/module-company-graph-ql/Model/Company/Role/ValidateRole.php
  • vendor/magento/module-company-graph-ql/etc/graphql/di.xml
  • vendor/magento/module-negotiable-quote-graph-ql/Model/NegotiableQuote/RequestNegotiableQuoteForUser.php
  • vendor/magento/module-negotiable-quote-graph-ql/Model/Resolver/PlaceNegotiableQuoteOrder.php
  • vendor/magento/module-negotiable-quote-graph-ql/Model/Resolver/RequestNegotiableQuote.php
  • vendor/magento/module-negotiable-quote-graph-ql/i18n/en_US.csv (added)

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.