UPSTREAM FIX

magento2-39188: Varnish configs do not strip common marketing parameters

Community fix magento2-39188 merged into magento/magento2 on 2024-11-01, released in 2.4.8.

Fixes the issue where Varnish configs do not strip common marketing parameters edited

Pull request title
The Varnish configs do not strip Klaviyo marketing parameter
Pull request
magento/magento2#39188
Issues
#35227 human, #38298 human
Author
@sprankhub
Merged
2024-11-01
Fixed in
2.4.8
Reported on
2.4.6-p3
Categories
Cache
Components
magento/module-page-cache

Labels

Area
Framework
Component
Cache
Priority
P2
Severity
—
Reported on (labels)
2.4.6-p3

Issue

Title and steps come from the upstream issue and pull request.

Description

1. Varnish does not strip the parameter, and since the value is unique per visitor, those requests will not match any hashes in Varnish's cache.
2. This also results in additional PHP load due to the request needing to be processed by Magento.

Steps to reproduce

1. Use a VCL that is included with Magento.
2. Send a marketing email via Klaviyo.
3. Watch varnishlog.
4. Visit the site using a link that is included in a Klaviyo-generated email.
5. Visit the site using a similar link that does not include the _kx query parameter.
6. Compare the results shown by varnishlog.

Expected result

1. The _kx parameter should be stripped, ensuring that visitors using links with the _kx parameter are served the cached version of the requested page.

Actual result

1. Varnish does not strip the parameter, and since the value is unique per visitor, those requests will not match any hashes in Varnish's cache.
2. This also results in additional PHP load due to the request needing to be processed by Magento.

---
Please provide [Severity](https://devdocs.magento.com/guides/v2.4/contributor-guide/contributing.html#backlog) assessment for the Issue as Reporter. This information will help during Confirmation and Issue triage processes.

- [ ] Severity: S0 _- Affects critical data or functionality and leaves users without workaround._
- [ ] Severity: S1 _- Affects critical data or functionality and forces users to employ a workaround._
- [X] Severity: S2 _- Affects non-critical data or functionality and forces users to employ a workaround._
- [ ] Severity: S3 _- Affects non-critical data or functionality and does not force users to employ a workaround._
- [ ] Severity: S4 _- Affects aesthetics, professional look and feel, “quality” or “usability”._

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 file-missing 2.4.6-p1 file-missing 2.4.6-p2 file-missing 2.4.6-p3 file-missing 2.4.6-p4 file-missing 2.4.6-p5 file-missing 2.4.6-p6 file-missing 2.4.6-p7 file-missing 2.4.6-p8 file-missing 2.4.6-p9 file-missing 2.4.6-p10 file-missing 2.4.6-p11 file-missing 2.4.6-p12 file-missing 2.4.6-p13 file-missing 2.4.6-p14 file-missing 2.4.6-p15 file-missing
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 file-missing 2.4.7-p1 file-missing 2.4.7-p2 file-missing 2.4.7-p3 file-missing 2.4.7-p4 file-missing 2.4.7-p5 file-missing 2.4.7-p6 file-missing 2.4.7-p7 file-missing 2.4.7-p8 file-missing 2.4.7-p9 file-missing 2.4.7-p10 file-missing
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 conflictcontains the fix 2.4.8-p1 conflictcontains the fix 2.4.8-p2 conflictcontains the fix 2.4.8-p3 conflictcontains the fix 2.4.8-p4 conflictcontains the fix 2.4.8-p5 conflictcontains the fix
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 93.0%. Probability it is security relevant: 0.7%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 87.3%, feature 8.5%, refactor 1.6%, dependency 0.9%, docs_only 0.9%, tests_only 0.8%72.5%
Areaframeworkframework 94.3%, admin 1.5%, frontend 1.1%87.4%
Reported version2.4.6-p32.4.6-p3 52.9%, 2.4.6 13.6%, unspecified 2.2%29.2%
Scope0.44 of 20 63.5%, 1 29.2%, 2 7.3%24.0%
Risk0.23 of 20 80.1%, 1 16.6%, 2 3.3%50.6%
Worth backporting1.61 of 22 69.9%, 1 21.4%, 0 8.8%31.2%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-39188/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

No checked release lacks this fix with a clean code match, so no bundle is offered.

Bundle README (what the ZIP ships)
# magento2-39188

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/39188
Issue: https://github.com/magento/magento2/issues/35227
Issue: https://github.com/magento/magento2/issues/38298
Author: @sprankhub
Source commit: b9690e97908fab31b67425a670e629263f9fff77
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.