UPSTREAM FIX

magento2-38462: A failed address save blocking the customer from registering again

Community fix magento2-38462 merged into magento/magento2 on 2025-10-13, released in 2.4.9; applies cleanly to 33 releases from 2.4.6 to 2.4.8-p5.

Fixes a failed address save blocking the customer from registering again edited

Pull request title
Set isSecureArea before deleting customer
Pull request
magento/magento2#38462
Issues
#31540 pr-derived, #40211 pr-derived
Author
@DanieliMi
Merged
2025-10-13
Fixed in
2.4.9
Reported on
2.4.0
Categories
Customer
Components
magento/module-customer

Labels

Area
Account
Component
Customer
Priority
P2
Severity
S2
Reported on (labels)
2.4.0, 2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Description

When the address form is enabled in the registration and an required address field is missing the registration will fail with the message "Delete operation is forbidden for current area". This is because first the customer is created and then the address is saved. When the address cannot be saved due to validation errors the customer needs to be deleted which will fail in a non secure area. Then the customer cannot register again because the customer entity already exists. Deletion is not possible because isSecureArea is not set at this point. This PR sets isSecureArea for the deletion process.

Steps to reproduce

1. Enable address form in customer registration in customer_account_create.xml:
<referenceBlock name="customer_form_register">
    <arguments>
        <argument name="show_address_fields" xsi:type="boolean">true</argument>
    </arguments>
</referenceBlock>
3. Go to /customer/account/create/
4. Fill in the form
5. Remove an required address field
6. Send the form

Taken from the upstream pull request.

Error signatures

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 97.6%. Probability it is security relevant: 55.5%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 96.4%, refactor 1.5%, feature 0.7%, tests_only 0.6%, dependency 0.4%, docs_only 0.4%91.5%
Areacustomercustomer 91.6%, checkout 4.6%, admin 1.0%81.9%
Reported versionunspecifiedunspecified 35.0%, 2.4.0 1.7%, 2.4.9 1.6%11.8%
Scope0.96 of 21 59.2%, 0 22.6%, 2 18.3%15.2%
Risk0.92 of 20 38.9%, 1 30.5%, 2 30.5%0.7%
Worth backporting1.73 of 22 77.4%, 1 17.9%, 0 4.8%44.9%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-38462/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-customer
Bundle README (what the ZIP ships)
# magento2-38462

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/38462
Issue: https://github.com/magento/magento2/issues/31540
Issue: https://github.com/magento/magento2/issues/40211
Author: @DanieliMi
Source commit: 6002a523994a49c50fe9effdcf53e7582691576e
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.