QUALITY PATCH

LYNX-839: Remove customer group/segments/promo rules information exposure through the GraphQL

Remove customer group/segments/promo rules information exposure through the GraphQL. Quality patch LYNX-839 for magento/module-catalog-rule applies to Magento Open Source and Adobe Commerce 2.4.8.

Categories
GraphQL
Components
magento/module-catalog-rule, magento/module-catalog-rule-graph-ql, magento/module-customer, magento/module-customer-graph-ql, magento/module-sales-rule, magento/module-sales-rule-graph-ql, magento/module-customer-segment, magento/module-customer-segment-graph-ql
Origin
adobe-commerce-support

No Adobe documentation page exists for this patch.

Install

Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply LYNX-839. On Cloud, add LYNX-839 under stage.build.QUALITY_PATCHES in .magento.env.yaml.

For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its LYNX-839/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.

Patch files and compatible versions

Packages across compatible versions (6): magento/module-catalog-rule, magento/module-catalog-rule-graph-ql, magento/module-customer, magento/module-customer-graph-ql, magento/module-sales-rule, magento/module-sales-rule-graph-ql
Packages across compatible versions (8): magento/module-catalog-rule, magento/module-catalog-rule-graph-ql, magento/module-customer, magento/module-customer-graph-ql, magento/module-sales-rule, magento/module-sales-rule-graph-ql, magento/module-customer-segment, magento/module-customer-segment-graph-ql

magento/magento2-base 2.4.8

Magento Open Source
2.4.8
Adobe Commerce
2.4.8
Patch file
patches/os/LYNX-839_CE_2.4.8.patch
  • vendor/magento/module-catalog-rule/Model/Config/CatalogRule.php (deleted)
  • vendor/magento/module-catalog-rule/Model/ResourceModel/GetAllCatalogRules.php (deleted)
  • vendor/magento/module-catalog-rule/Model/ResourceModel/GetAppliedCatalogRules.php (deleted)
  • vendor/magento/module-catalog-rule/etc/adminhtml/system.xml (deleted)
  • vendor/magento/module-catalog-rule/etc/config.xml (deleted)
  • vendor/magento/module-catalog-rule-graph-ql/Model/Resolver/AllCatalogRules.php (deleted)
  • vendor/magento/module-catalog-rule-graph-ql/Model/Resolver/AppliedCatalogRules.php (deleted)
  • vendor/magento/module-catalog-rule-graph-ql/etc/graphql/di.xml
  • vendor/magento/module-catalog-rule-graph-ql/etc/schema.graphqls (deleted)
  • vendor/magento/module-customer/Model/Config/AccountInformation.php (deleted)
  • vendor/magento/module-customer/etc/adminhtml/system.xml
  • vendor/magento/module-customer/etc/config.xml
  • vendor/magento/module-customer-graph-ql/Model/Resolver/AllCustomerGroups.php (deleted)
  • vendor/magento/module-customer-graph-ql/Model/Resolver/CustomerGroup.php (deleted)
  • vendor/magento/module-customer-graph-ql/Model/Resolver/GetCustomerGroup.php (deleted)
  • vendor/magento/module-customer-graph-ql/etc/graphql/di.xml
  • vendor/magento/module-customer-graph-ql/etc/schema.graphqls
  • vendor/magento/module-sales-rule/Model/Config/Coupon.php (deleted)
  • vendor/magento/module-sales-rule/Model/ResourceModel/GetAllCartRules.php (deleted)
  • vendor/magento/module-sales-rule/Model/ResourceModel/GetAppliedCartRules.php (deleted)
  • vendor/magento/module-sales-rule/etc/adminhtml/system.xml
  • vendor/magento/module-sales-rule/etc/config.xml
  • vendor/magento/module-sales-rule-graph-ql/Model/Resolver/AllCartRules.php (deleted)
  • vendor/magento/module-sales-rule-graph-ql/Model/Resolver/AppliedCartRules.php (deleted)
  • vendor/magento/module-sales-rule-graph-ql/etc/graphql/di.xml (deleted)
  • vendor/magento/module-sales-rule-graph-ql/etc/schema.graphqls

magento/magento2-ee-base 2.4.8

Magento Open Source
—
Adobe Commerce
2.4.8
Patch file
patches/commerce/LYNX-839_EE_2.4.8.patch
  • vendor/magento/module-customer-segment/Model/Config.php (deleted)
  • vendor/magento/module-customer-segment/etc/adminhtml/system.xml
  • vendor/magento/module-customer-segment/etc/config.xml
  • vendor/magento/module-customer-segment-graph-ql/Model/Resolver/CustomerSegments.php (deleted)
  • vendor/magento/module-customer-segment-graph-ql/Model/Resolver/SegmentsList.php (deleted)
  • vendor/magento/module-customer-segment-graph-ql/Model/Resolver/VisitorSegments.php (deleted)
  • vendor/magento/module-customer-segment-graph-ql/etc/graphql/di.xml (deleted)
  • vendor/magento/module-customer-segment-graph-ql/etc/schema.graphqls

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.