UPSTREAM FIX

magento2-39103: A logged-out customer keeps a login-only cart price rule

Community fix magento2-39103 merged into magento/magento2 on 2024-12-13, released in 2.4.8; applies cleanly to 27 releases from 2.4.6 to 2.4.7-p10.

Fixes the issue where a logged-out customer keeps a login-only cart price rule edited

Pull request title
Cart price rule created for logged in user incorrectly gets applied for not logged in user
Pull request
magento/magento2#39103
Issues
#38944 human
Author
@rogerdz
Merged
2024-12-13
Fixed in
2.4.8
Reported on
—
Categories
Shopping Cart
Components
magento/module-persistent

Labels

Area
Cart & Checkout
Component
UiComponents
Priority
P1
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Description

Here user is logged out but still we can see the product in the cart and cart price rule is still applied.

Steps to reproduce

1. In Marketing -> Cart Price Rules add rule for log in customers (select general customer group), for example 5% discount.(Shown in Screenshot - 1)
3. In Stores -> Configuration ->Customers -> Persistent Shopping Cart -> set the following configuration: Enable Persistence - Yes , Clear Persistence on Sign Out – Yes (Shown in Screenshot - 2)
4. In Stores -> Configuration -> General -> Web ->Default Cookie Settings ->Cookie Lifetime (For example 60 seconds) (Shown in Screenshot - 3)
5. In the shop, create a customer account and add a product to the cart. At this time, the cart price rule will be applied, and the user will get a discount on the product.
6. After that user will be log out according to the cookie lifetime (step – 3)
7. Open the shop, at this time user is not log in into the shop, but user can still see the product into the cart with applied discount.(Shown in Screenshot - 4)

Expected result

When user is logged out cart price rule should not applied and cart should be empty.

Actual result

Here user is logged out but still we can see the product in the cart and cart price rule is still applied.

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: passes before and after (test does not cover the fix)unit: passes before and after
2.4.8
2.4.8 conflictcontains the fix 2.4.8-p1 conflictcontains the fix 2.4.8-p2 conflictcontains the fix 2.4.8-p3 conflictcontains the fix 2.4.8-p4 conflictcontains the fix 2.4.8-p5 conflictcontains the fix
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 98.2%. Probability it is security relevant: 82.5%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 96.8%, refactor 1.3%, tests_only 0.6%, feature 0.6%, dependency 0.4%, docs_only 0.3%92.5%
Areacheckoutcheckout 81.2%, customer 9.4%, other 3.3%62.4%
Reported versionunspecifiedunspecified 36.3%, 2.4.7-p4 1.6%, 2.4.8-p2 1.5%12.7%
Scope0.96 of 21 49.8%, 0 26.9%, 2 23.3%6.2%
Risk1.42 of 22 61.0%, 1 20.1%, 0 18.9%17.3%
Worth backporting1.55 of 22 63.7%, 1 27.8%, 0 8.5%23.6%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-39103/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-persistent
Bundle README (what the ZIP ships)
# magento2-39103

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/39103
Issue: https://github.com/magento/magento2/issues/38944
Author: @rogerdz
Source commit: 3943f79e335f17f7aa2a91b687198b38fd2f9aa6
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.