UPSTREAM FIX

magento2-38268: Placing a GraphQL order succeeds with a shipping method disabled in the admin

Community fix magento2-38268 merged into magento/magento2 on 2025-10-29, released in 2.4.9; applies cleanly to 33 releases from 2.4.6 to 2.4.8-p5.

Placing a GraphQL order succeeds with a shipping method disabled in the admin edited

Pull request title
AC-10472 Validate shipping method placing an order in GraphQL
Pull request
magento/magento2#38268
Issues
#38273 pr-derived
Author
@emartinpalomas
Merged
2025-10-29
Fixed in
2.4.9
Reported on
—
Categories
—
Components
magento/module-quote

Labels

Area
—
Component
—
Priority
P2
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Description

Validate shipping method before placing an order in GraphQL

Steps to reproduce

1. Create a cart
2. Add item to cart
3. Set cart address
4. Select an available shipping method
5. Go into the admin and disable the selected shipping method
6. Place the order using GraphQL

Without validation GraphQL succeeds and converts the cart into an order, with this validation GraphQL returns an error pointing out that the selected shipping method is not available

Taken from the upstream pull request.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: test files do not apply to this releaseapi-functional: could not run before, could not run after
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: test files do not apply to this releaseapi-functional: could not run before, could not run after
2.4.9
2.4.9 cleancontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 89.0%. Probability it is security relevant: 3.3%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 85.1%, feature 8.5%, refactor 2.1%, cleanup 1.8%, tests_only 1.6%, dependency 0.5%, docs_only 0.4%68.8%
Areagraphql_apigraphql_api 60.6%, checkout 36.8%, customer 0.5%43.2%
Reported versionunspecifiedunspecified 28.9%, 2.4.6 2.9%, 2.4.8 2.1%8.1%
Scope0.49 of 20 61.4%, 1 28.0%, 2 10.6%20.0%
Risk0.90 of 20 48.8%, 2 38.6%, 1 12.5%10.5%
Worth backporting1.56 of 22 65.7%, 1 25.1%, 0 9.2%25.4%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-38268/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-quote
Bundle README (what the ZIP ships)
# magento2-38268

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/38268
Issue: https://github.com/magento/magento2/issues/38273
Author: @emartinpalomas
Source commit: a0a5d991611e302a941bfab132332c4c195d3a66
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.