QUALITY PATCH

MDVA-25602: PayPal Payflow Pro payment method and treating cookies as SameSite=Lax by default…

PayPal Payflow Pro payment method and treating cookies as SameSite=Lax by default in the Chrome 80 browser and API response redirect to customer login page. Quality patch MDVA-25602 for magento/framework applies to Magento Open Source and Adobe Commerce 2.3.0 to 2.3.4-p2.

Categories
Payments
Components
magento/framework, magento/module-payment, magento/module-paypal, magento/module-website-restriction
Origin
adobe-commerce-support

No Adobe documentation page exists for this patch.

Install

Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply MDVA-25602. On Cloud, add MDVA-25602 under stage.build.QUALITY_PATCHES in .magento.env.yaml.

For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its MDVA-25602/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.

Patch files and compatible versions

Packages across compatible versions (3): magento/module-payment, magento/module-paypal, magento/framework
Packages across compatible versions (4): magento/module-payment, magento/module-paypal, magento/framework, magento/module-website-restriction

magento/magento2-base 2.3.0

Magento Open Source
2.3.0
Adobe Commerce
2.3.0
Patch file
patches/os/MDVA-25602_2.3.0.patch
  • vendor/magento/module-payment/Block/Transparent/Redirect.php (added)
  • vendor/magento/module-payment/view/adminhtml/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-payment/view/frontend/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-paypal/Controller/Adminhtml/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Controller/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Model/Payflow/Service/Request/SecureToken.php
  • vendor/magento/module-paypal/Model/Payflow/Service/Response/Transaction.php
  • vendor/magento/module-paypal/Plugin/TransparentSessionChecker.php (added)
  • vendor/magento/module-paypal/etc/di.xml
  • vendor/magento/module-paypal/etc/frontend/page_types.xml
  • vendor/magento/module-paypal/view/adminhtml/layout/transparent_payment_redirect.xml (added)
  • vendor/magento/module-paypal/view/frontend/layout/transparent_payment_redirect.xml (added)
  • vendor/magento/module-payment/view/adminhtml/web/js/transparent.js (renamed)
  • vendor/magento/framework/Session/SessionManager.php
  • vendor/magento/framework/Session/SessionStartChecker.php (added)

magento/magento2-base >=2.3.1 <2.3.2

Magento Open Source
2.3.1
Adobe Commerce
2.3.1
Patch file
patches/os/MDVA-25602_2.3.1.patch
  • vendor/magento/module-payment/Block/Transparent/Redirect.php (added)
  • vendor/magento/module-payment/view/adminhtml/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-payment/view/frontend/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-paypal/Controller/Adminhtml/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Controller/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Model/Payflow/Service/Request/SecureToken.php
  • vendor/magento/module-paypal/Model/Payflow/Service/Response/Transaction.php
  • vendor/magento/module-paypal/Plugin/TransparentSessionChecker.php (added)
  • vendor/magento/module-paypal/etc/di.xml
  • vendor/magento/module-paypal/etc/frontend/page_types.xml
  • vendor/magento/module-paypal/view/adminhtml/layout/transparent_payment_redirect.xml (added)
  • vendor/magento/module-paypal/view/frontend/layout/transparent_payment_redirect.xml (added)

magento/magento2-base >=2.3.2 <2.3.3

Magento Open Source
2.3.2-p2, 2.3.2-p1, 2.3.2
Adobe Commerce
2.3.2-p2, 2.3.2-p1, 2.3.2
Patch file
patches/os/MDVA-25602_2.3.2.patch
  • vendor/magento/module-payment/Block/Transparent/Redirect.php (added)
  • vendor/magento/module-payment/view/adminhtml/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-payment/view/frontend/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-paypal/Controller/Adminhtml/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Controller/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Model/Payflow/Service/Request/SecureToken.php
  • vendor/magento/module-paypal/Model/Payflow/Service/Response/Transaction.php
  • vendor/magento/module-paypal/Plugin/TransparentSessionChecker.php (added)
  • vendor/magento/module-paypal/etc/di.xml
  • vendor/magento/module-paypal/etc/frontend/page_types.xml
  • vendor/magento/module-paypal/view/adminhtml/layout/transparent_payment_redirect.xml (added)
  • vendor/magento/module-paypal/view/frontend/layout/transparent_payment_redirect.xml (added)

magento/magento2-base >=2.3.3 <2.3.5

Magento Open Source
2.3.4-p2, 2.3.4-p1, 2.3.4, 2.3.3-p2, 2.3.3
Adobe Commerce
2.3.4-p2, 2.3.4-p1, 2.3.4, 2.3.3-p2, 2.3.3
Patch file
patches/os/MDVA-25602_2.3.4.patch
  • vendor/magento/module-payment/Block/Transparent/Redirect.php (added)
  • vendor/magento/module-payment/view/adminhtml/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-payment/view/frontend/templates/transparent/redirect.phtml (added)
  • vendor/magento/module-paypal/Controller/Adminhtml/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Controller/Transparent/Redirect.php (added)
  • vendor/magento/module-paypal/Model/Payflow/Service/Request/SecureToken.php
  • vendor/magento/module-paypal/Model/Payflow/Service/Response/Transaction.php
  • vendor/magento/module-paypal/Plugin/TransparentSessionChecker.php (added)
  • vendor/magento/module-paypal/etc/di.xml
  • vendor/magento/module-paypal/etc/frontend/page_types.xml
  • vendor/magento/module-paypal/view/adminhtml/layout/transparent_payment_redirect.xml (added)
  • vendor/magento/module-paypal/view/frontend/layout/transparent_payment_redirect.xml (added)

magento/magento2-ee-base >=2.3.0 <2.3.5

Magento Open Source
—
Adobe Commerce
2.3.4-p2, 2.3.4-p1, 2.3.4, 2.3.3-p2, 2.3.3, 2.3.2-p2, 2.3.2-p1, 2.3.2, 2.3.1, 2.3.0
Patch file
patches/commerce/MDVA-25602_2.3.4.patch
  • vendor/magento/module-website-restriction/etc/webrestrictions.xml

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.