UPSTREAM FIX

magento2-40032: Google Analytics being blocked by CSP when the Adwords module is disabled

Community fix magento2-40032 merged into magento/magento2 on 2026-01-16, released in 2.4.9; applies cleanly to 33 releases from 2.4.6 to 2.4.8-p5.

Fixes Google Analytics being blocked by CSP when the Adwords module is disabled edited

Pull request title
Added the scp allowlist for Analytics if you only use Google Analytics
Pull request
magento/magento2#40032
Issues
#40051 pr-derived
Author
@JeroenBoersma
Merged
2026-01-16
Fixed in
2.4.9
Reported on
—
Categories
—
Components
magento/module-google-analytics

Labels

Area
Analytics / Reporting
Component
GoogleAnalytics
Priority
P3
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Description

Having this module for the Analytics module makes this module work in work alone mode without the adwords module enabled.

Steps to reproduce

1. Disable the Magento_Adwords module
2. Enforce CSP (checkout) or manually
3. The GA code will not be loaded

Taken from the upstream pull request.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 75.8%. Probability it is security relevant: 38.2%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 61.1%, feature 35.6%, refactor 1.5%, docs_only 0.7%, tests_only 0.6%, dependency 0.5%40.1%
Areaotherother 38.8%, frontend 35.1%, checkout 8.9%19.0%
Reported versionunspecifiedunspecified 21.3%, 2.4.6 3.7%, 2.4.8 2.1%4.4%
Scope0.23 of 20 82.0%, 1 12.8%, 2 5.3%53.6%
Risk0.15 of 20 87.8%, 1 9.4%, 2 2.7%67.2%
Worth backporting1.50 of 22 62.0%, 1 26.5%, 0 11.6%20.1%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40032/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-google-analytics
Bundle README (what the ZIP ships)
# magento2-40032

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40032
Issue: https://github.com/magento/magento2/issues/40051
Author: @JeroenBoersma
Source commit: 0ea76627c5542048f28a10bdb3d8b4cf295b3e1c
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.