QUALITY PATCH

ACSD-61895: GraphQL responses for guest customers (using a public shared catalog with all allowed…

GraphQL responses for guest customers (using a public shared catalog with all allowed categories) do not return any categories when a private shared catalog with restrictions is created for the same categories. Quality patch ACSD-61895 for magento/module-catalog-permissions-graph-ql applies to Magento Open Source and Adobe Commerce 2.4.4 to 2.4.7-p10.

Categories
GraphQL, Catalog/Product
Components
magento/module-catalog-permissions-graph-ql
Origin
adobe-commerce-support
Since QPT
1.1.57

Issue

GraphQL responses for guest customers (using a public shared catalog with all allowed categories) do not return any categories when a private shared catalog with restrictions is created for the same categories.

Steps to reproduce

1. Install Adobe Commerce with B2B and sample data. 1. Ensure that B2B features are enabled. 1. Create two shared catalogs: one public and one private. * Public Shared Catalog: * Assign all categories to the public catalog. * Private Shared Catalog: * Assign only the Gear category and its child categories to the private catalog. * Assign the private catalog to a test company. 1. Create a company user: * Create a user associated with the test company linked to the private shared catalog. * Ensure that the user is only able to access the Gear category and its child categories on the frontend when logged in. 1. Query categories via API: * Use API client to execute the following GraphQL query without a customer token: query Categories { categories { items { children_count children { uid name children_count children { uid name } } } } } 1. Observe the response and verify if the Gear category and other categories are returned. 1. Now query categories with a customer token: * Log in as the test company user. * Execute the same GraphQL category query, but include the customer token for the logged-in user. * Observe the response and check if only the Gear category and its child categories are returned.

Adobe's page lists 2.4.4 - 2.4.7-p3 as compatible; the versions below are resolved from the current QPT constraints and are the ones the tool will offer.

Adobe scheduled the permanent fix for 2.4.8.

Install

Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply ACSD-61895. On Cloud, add ACSD-61895 under stage.build.QUALITY_PATCHES in .magento.env.yaml.

For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its ACSD-61895/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.

Patch files and compatible versions

Packages across compatible versions (1): magento/module-catalog-permissions-graph-ql

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.