UPSTREAM FIX

magento2-36354: REST attribute creation silently replacing a wrong backend_type

Community fix magento2-36354 merged into magento/magento2 on 2026-01-06, released in 2.4.9; applies cleanly to 33 releases from 2.4.6 to 2.4.8-p5.

Fixes REST attribute creation silently replacing a wrong backend_type edited

Pull request title
Different validation between attribute creation and update via REST API
Pull request
magento/magento2#36354
Issues
#36327 human
Author
@rogerdz
Merged
2026-01-06
Fixed in
2.4.9
Reported on
2.4.4
Categories
Web API
Components
magento/module-catalog

Labels

Area
APIs
Component
Api
Priority
P2
Severity
—
Reported on (labels)
2.4.4

Issue

Title and steps come from the upstream issue and pull request.

Description

Wrong backend type is set on attribute

Steps to reproduce

Issue a request following these criteria
- Request method: POST
- Endpoint: /rest/V1/products/attributes
- example Body:
{
"attribute": {
"is*wysiwyg*enabled": false,
"is*html_allowed_on*front": false,
"used*for_sort*by": false,
"is_filterable": true,
"is*filterable_in*search": true,
"is*used_in*grid": true,
"is*visible_in*grid": false,
"is*filterable_in*grid": true,
"position": 0,
"apply_to": <],
"is_searchable": "1",
"is*visible_in_advanced*search": "1",
"is_comparable": "1",
"is*used_for_promo*rules": "0",
"is*visible_on*front": "0",
"used*in_product*listing": "1",
"is_visible": true,
"scope": "global",
"attribute_code": "brand",
"frontend_input": "select",
"entity*type*id": "4",
"is_required": false,
"options": [
{
"label": "test1"
},
{
"label": "test2"
},
{
"label": "test3"
}
],
"is*user*defined": true,
"default*frontend*label": "Brand",
"frontend_labels": null,
"backend_type": "decimal",
"source_model": "Magento%5C%5CEav%5C%5CModel%5C%5CEntity%5C%5CAttribute%5C%5CSource%5C%5CTable",
"default_value": "",
"is_unique": "0"
}
}
-> attribute will be created, but with BE type text (due to getBackendTypeByInput() function)

Expected result

Correct backend*type will be created if valid in body, or throw exception if wrong backend_type provided or fallback to current behavior if backend*type not mentioned.

Actual result

Wrong backend type is set on attribute


[img width="950" alt="Screenshot 2022-10-21 at 4 56 44 PM" src="https://user-images.githubusercontent.com/51680745/197205328-2a519ab7-3208-48d0-a30b-9d3e79bf68f8.png"]

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: test files do not apply to this releaseunit: could not run before, could not run after · integration: could not run before, could not run after
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: test files do not apply to this releaseunit: could not run before, could not run after · integration: could not run before, could not run after
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 97.1%. Probability it is security relevant: 0.6%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 95.9%, refactor 1.6%, tests_only 1.0%, feature 0.8%, dependency 0.3%, docs_only 0.3%90.5%
Areacatalogcatalog 63.6%, graphql_api 31.2%, admin 2.6%43.1%
Reported version2.4.42.4.4 55.5%, unspecified 4.4%, 2.4.4-p1 2.7%30.5%
Scope1.10 of 21 49.4%, 2 30.5%, 0 20.1%6.6%
Risk0.54 of 20 55.1%, 1 35.6%, 2 9.3%15.9%
Worth backporting1.51 of 22 60.9%, 1 29.1%, 0 10.1%19.8%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-36354/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-catalog
Bundle README (what the ZIP ships)
# magento2-36354

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/36354
Issue: https://github.com/magento/magento2/issues/36327
Author: @rogerdz
Source commit: 398f7b3ea355b9ee2a9104389b57f7c2701a93b5
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.