QUALITY PATCH

ACSD-61534: The design configuration can't be set using the bin/magento config:set command…

The design configuration can't be set using the bin/magento config:set command, and locked values can be altered through form manipulation. Quality patch ACSD-61534 for magento/module-theme applies to Magento Open Source and Adobe Commerce 2.4.7 to 2.4.7-p10.

Categories
Other
Components
magento/module-theme
Origin
adobe-commerce-support
Since QPT
1.1.55

Issue

The design configuration can't be set using the bin/magento config:set command, and locked values can be altered through form manipulation. With this patch, locked values set from the Command-line tool (CLI) with --lock-env or --lock-conf can't be updated.

Steps to reproduce

1. Lock a config value using a cloud environment variable, like CONFIG_WEBSITESBASEDESIGNHEAD_INCLUDES. 1. Go to the Admin panel. 1. Go to Content > Design > Configuration. 1. Click Edit near the Global/Main website in the second row. 1. Edit theme for a store view. 1. Open the HTML head. 1. Enable the disabled Scripts and Style Sheets field using developer tools. 1. Change the value and save it.

Adobe's page lists 2.4.7 - 2.4.7-p3 as compatible; the versions below are resolved from the current QPT constraints and are the ones the tool will offer.

Adobe scheduled the permanent fix for 2.4.8.

Install

Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply ACSD-61534. On Cloud, add ACSD-61534 under stage.build.QUALITY_PATCHES in .magento.env.yaml.

For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its ACSD-61534/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.

Patch files and compatible versions

Packages across compatible versions (1): magento/module-theme
Packages across compatible versions (1): magento/module-theme

magento/magento2-base >=2.4.7 <2.4.8

Magento Open Source
2.4.7-p10, 2.4.7-p9, 2.4.7-p8, 2.4.7-p7, 2.4.7-p6, 2.4.7-p5, 2.4.7-p4, 2.4.7-p3, 2.4.7-p2, 2.4.7-p1, 2.4.7
Adobe Commerce
2.4.7-p10, 2.4.7-p9, 2.4.7-p8, 2.4.7-p7, 2.4.7-p6, 2.4.7-p5, 2.4.7-p4, 2.4.7-p3, 2.4.7-p2, 2.4.7-p1, 2.4.7
Patch file
patches/os/ACSD-61534_2.4.7-p2.patch
  • vendor/magento/module-theme/Model/Config/PathValidator.php (added)
  • vendor/magento/module-theme/Model/Data/Design/ConfigFactory.php
  • vendor/magento/module-theme/Model/Design/Config/Validator.php
  • vendor/magento/module-theme/Plugin/DesignProcessorFacade.php (added)
  • vendor/magento/module-theme/etc/adminhtml/di.xml
  • vendor/magento/module-theme/etc/di.xml

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.