QUALITY PATCH

MDVA-37748: GraphQL query returns products not assigned to a shared catalog

GraphQL query returns products not assigned to a shared catalog. Quality patch MDVA-37748 for app/code applies to Magento Open Source and Adobe Commerce 2.4.2 to 2.4.2-p2.

Categories
B2B, GraphQL
Components
app/code, magento/module-catalog-permissions-graph-ql, magento/module-customer-segment, magento/module-shared-catalog-graph-ql
Origin
adobe-commerce-support
Since QPT
1.1.5

Issue

GraphQL query returns products not assigned to a shared catalog.

Steps to reproduce

1. Create two products and assign them to a category: * Product 1 - Public * Product 2 1. Assign "Product 1 - Public" to the "Default (General)" shared catalog. 1. Create an additional custom shared catalog and assign it to "Product 2." 1. Create a new company and assign it to the additional shared catalog created in step three. 1. After cron execution/reindex, on the frontend, validate that you can see "Product 1 - Public" if you are not logged in. 1. Log in as the admin of the company created in step four, and validate that you only see "Product 2." 1. Request an Authorization Token using the following GraphQL query: mutation { generateCustomerToken( email: "company.admin@exapmle.test" password: "password" ) { token } } 1. Add header Authorization Bearer value-of-the-token and execute the following GraphQL query: { products( filter: {}, pageSize: 100, currentPage: 1 sort: {} ) { total_count page_info { page_size current_page } aggregations { attribute_code count label options { label value count } } items { name sku created_at updated_at stock_status description {html} short_description {html} url_key url_path price_tiers{ final_price{ value currency } discount{ amount_off percent_off } quantity } price_range { maximum_price { regular_price { value } final_price { value } } minimum_price { regular_price { value } final_price { value } } } image { url } thumbnail { url } small_image { url } media_gallery { url } ... on ConfigurableProduct { configurable_options { id label position use_default attribute_code values { value_index label swatch_data { value } } product_id } variants { product { id name sku #margin #margin_percentage image { url } small_image { url } thumbnail { url } media_gallery{ url } attribute_set_id ... on PhysicalProductInterface { weight } price_range { minimum_price { regular_price { value currency } } } } attributes { label code value_index } } } } } }

Adobe's page lists 2.4.2 - 2.4.2-p2 as compatible; the versions below are resolved from the current QPT constraints and are the ones the tool will offer.

Adobe scheduled the permanent fix for 2.4.4.

Install

Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply MDVA-37748. On Cloud, add MDVA-37748 under stage.build.QUALITY_PATCHES in .magento.env.yaml.

For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its MDVA-37748/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.

Patch files and compatible versions

Packages across compatible versions (4): magento/module-banner-graph-ql, magento/module-catalog-permissions-graph-ql, magento/module-customer-segment, magento/module-shared-catalog-graph-ql

magento/magento2-ee-base >=2.4.2 <2.4.3

Magento Open Source
—
Adobe Commerce
2.4.2-p2, 2.4.2-p1, 2.4.2
Patch file
patches/commerce/MDVA-37748_2.4.2_v3.patch
  • app/code/Magento/BannerGraphQl/Model/DynamicBlockFormatter.php (added)
  • app/code/Magento/BannerGraphQl/Model/DynamicBlocks.php (added)
  • app/code/Magento/BannerGraphQl/Model/Resolver/DynamicBlocks.php (added)
  • app/code/Magento/BannerGraphQl/Plugin/Block/Widget/Banner.php (added)
  • app/code/Magento/BannerGraphQl/README.md (added)
  • app/code/Magento/BannerGraphQl/composer.json (added)
  • app/code/Magento/BannerGraphQl/etc/graphql/di.xml (added)
  • app/code/Magento/BannerGraphQl/etc/module.xml (added)
  • app/code/Magento/BannerGraphQl/etc/schema.graphqls (added)
  • app/code/Magento/BannerGraphQl/etc/widget.xml (added)
  • app/code/Magento/BannerGraphQl/registration.php (added)
  • vendor/magento/module-catalog-permissions-graph-ql/Model/Customer/GroupProcessor.php
  • vendor/magento/module-catalog-permissions-graph-ql/Plugin/CatalogGraphQl/ProductSearchCriteriaFilter.php (added)
  • vendor/magento/module-catalog-permissions-graph-ql/etc/di.xml
  • vendor/magento/module-catalog-permissions-graph-ql/etc/search_request.xml (added)
  • vendor/magento/module-customer-segment/Model/CustomerSegmentsProvider.php (added)

magento/magento2-b2b-base >=1.3.1 <1.3.2

Magento Open Source
—
Adobe Commerce
2.4.2-p2, 2.4.2-p1, 2.4.2
Patch file
patches/commerce/MDVA-37748_1.3.1_v3.patch
  • vendor/magento/module-shared-catalog-graph-ql/Model/Resolver/Products/DataProvider/Product/CollectionProcessor/ApplyCategoryPermissionsOnProductProcessor.php (added)
  • vendor/magento/module-shared-catalog-graph-ql/etc/di.xml (added)
  • vendor/magento/module-shared-catalog-graph-ql/etc/module.xml

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.