Security enhancements

This release includes the same security fixes and platform security improvements that are included in Adobe Commerce 2.4.6-p5, 2.4.5-p7, and 2.4.4-p8. See Adobe Security Bulletin for the latest discussion of these fixed issues.

No confirmed attacks related to these issues have occurred to date. However, certain vulnerabilities can potentially be exploited to access customer information or take over administrator sessions. Most of these issues require that an attacker first obtains access to the Admin. As a result, we remind you to take all necessary steps to protect your Admin, including but not limited to these efforts:

Additional security enhancements

Security improvements for this release improve compliance with the latest security best practices.

  • Changes to the behavior of non-generated cache keys:

    • Non-generated cache keys for blocks now include prefixes that differ from prefixes for keys that are generated automatically. (Non-generated cache keys are keys that are set through template directive syntax or the setCacheKey or setData methods.)
    • Non-generated cache keys for blocks now must contain only letters, digits, hyphens (-), and underscore characters (_).
  • Limitations on the number of auto-generated coupon codes. Magento Open Source now limits the number of coupon codes that are automatically generated. The default maximum is 250,000. Merchants can use the new Code Quantity Limit configuration option (Stores > Settings:Configuration > Customers > Promotions) to prevent potentially overwhelming the system with many coupons.

  • Optimization of the default Admin URL generation process. The generation of the default Admin URL has been optimized for increased randomness, which makes generated URLs less predictable.

  • A new full-page cache configuration setting can help to mitigate the risks associated with the HTTP {BASE-URL}/page_cache/block/esi endpoint. This endpoint supports unrestricted, dynamically loaded content fragments from Commerce layout handles and block structures. The new Handles params size configuration setting sets the value of this endpoint’s handles parameter, which determines the maximum allowed number of handles per API. The default value of this property is 100. Merchants can change this value from the Admin (Stores > Settings:Configuration > System > Full Page Cache > Handles params size). See Configure the Commerce application to use Varnish.

  • Added Subresource Integrity (SRI) support to comply with PCI 4.0 requirements for verification of script integrity on payment pages. Subresource Integrity (SRI) support provides integrity hashes for all JavaScript assets residing in the local filesystem. The default SRI feature is implemented only on the payment pages for the Admin and storefront areas. However, merchants can extend the default configuration to other pages. See Subresource Integrity in the Commerce PHP Developer Guide.

  • Changes to Content Security Policy (CSP)—Configuration updates and enhancements to Adobe Commerce Content Security Policies (CSPs) to comply with PCI 4.0 requirements. For details, see Content Security Policies in the Commerce PHP Developer Guide.

    • The default CSP configuration for payment pages for Commerce Admin and storefront areas is now restrict mode. For all other pages, the default configuration is report-only mode. In releases prior to 2.4.7, CSP was configured in report-only mode for all pages.

    • Added a nonce provider to allow execution of inline scripts in a CSP. The nonce provider facilitates the generation of unique nonce strings for each request. The strings are then attached to the CSP header.

    • Added options to configure custom URIs to report CSP violations for the Create Order page in the Admin and the Checkout page in the storefront. You can add the configuration from the Admin or by adding the URI to the config.xml file.

      NOTE
      Updating the CSP configuration to restrict mode might block existing inline scripts on the payment pages in the Admin and storefront, which causes the following browser error when a page loads: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src. Fix these errors by updating the whitelist configuration to allow required scripts. See Troubleshooting in the Commerce PHP Developer Guide.
  • Native rate limiting for payment information transmitted through REST and GraphQL APIs. Merchants can now configure rate limiting for the payment information transmitted using REST and GraphQL. This added layer of protection supports prevention of carding attacks and potentially decreases the volume of carding attacks that test many credit card numbers at once. This is a change in the default behavior of an existing REST endpoint. See Rate limiting.

  • The default behavior of the isEmailAvailable GraphQL query and the (V1/customers/isEmailAvailable) REST endpoint has changed. By default, the APIs now always return true. Merchants can enable the original behavior by setting the Enable Guest Checkout Login option in the Admin to yes, but doing so can expose customer information to unauthenticated users.

Platform enhancements

Platform upgrades for this release improve compliance with the latest security best practices.

Magento Open Source 2.4.7 includes the following platform upgrades:

  • PHP 8.3 compatibility. This release introduces support for PHP 8.3. Magento Open Source now supports both PHP 8.3 and 8.2. PHP 8.2 will be supported until its End of Service (EOS) date in December 2025. After December 2025, all merchants running 2.4.7 deployments should migrate to PHP 8.3.

Magento Open Source 2.4.7 is still compatible with PHP 8.1 for upgrade purposes only. PHP 8.1 is not supported and not recommended. Magento Open Source 2.4.7 core code, all bundled extensions, and all Adobe-owned extensions and SaaS services are compatible with PHP 8.3.

  • RabbitMQ 3.13 support. This release is compatible with the latest version of RabbitMQ 3.13. Compatibility remains with RabbitMQ 3.11 and 3.12, which is supported through August 2024 and December 2024 respectively, but Adobe recommended using Magento Open Source 2.4.7 only with RabbitMQ 3.13.

  • Composer 2.7.x. Compatibility with Composer 2.2.x remains.

  • Varnish cache 7.4 support. This release is compatible with the latest version of Varnish Cache 7.4. Compatibility remains with the 6.0.x and 7.2.x versions, but we recommended using Magento Open Source 2.4.7 only with Varnish Cache version 7.4 or version 6.0 LTS.

  • Elasticsearch 8.11 compatibility

  • OpenSearch 2.12 and OpenSearch 1.3 support

  • Redis 7.2

  • The extjs library has been replaced with the latest version of jsTree.

  • jquery/fileUpload library has been removed.

All JavaScript libraries and NPM dependencies in Magento Open Source core code have been updated to the latest available versions. All Laminas library dependencies have been updated to the latest version that are compatible with PHP 8.3.

Additional upgrades

  • The Commerce UPS XML API gateway has been migrated to the new Commerce UPS REST API to support updates that UPS is making to their API security model. (UPS is implementing an OAuth 2.0 security model (bearer tokens) for all APIs.) All previous Commerce UPS XML APIs have been removed from the Magento Open Source 2.4.7 code base.

  • The Magento Open Source integration with FedEx has been migrated from legacy FedEx WSDL Web Services to the latest FedEx RESTful APIs. FedEx Web Services Tracking, Address Validation, and Validate Postal Codes WSDLS will be retired in May 2024.

  • Added support for the new USPS Ground Advantage shipping method. This is an out-of-box integration with USPS’s new shipping method, USPS Ground Advantage, which was released July 2023. This new integration can be used to retrieve shipping rates and schedule deliveries and returns through the USPS shipping service. The USPS Ground Advantage shipping method replaces these shipping methods, which were retired when the USPS Ground Advantage shipping method was released:

    • USPS Retail Ground
    • First-Class Package Service
    • Parcel Select Ground
  • Temando shipping modules have been removed from the core Magento Open Source code base. This feature was deprecated in Magento Open Source 2.4.4.

Performance and scalability enhancements

Magento Open Source 2.4.7 includes the following enhancements to Magento Open Source performance and scalability:

  • Enhanced indexer management. The new indexer:set-status command supports the dynamic management of indexer status. Admin users can use this command to change indexer status to suspended, invalid, or valid. This feature is particularly useful for managing system performance during extensive bulk operations, such as product imports or updates, by allowing control over when indexers are automatically triggered by the system’s cron jobs. See Manage the indexers.

  • Product listing page for complex products with many options. Load time has improved for product listing pages that include complex products with over 100 options. The performance of GraphQL requests to list products by category has also improved.

  • Sales rule performance improvements. Improved performance of enterprise deployments with many (approximately 100,000) active sales rules. Enterprise deployments that heavily implement promotions often deploy many active cart rules. These types of enterprise deployments running Magento Open Source 2.4.7 will not see any performance degradation related to the number of configured cart price rules during checkout operations.

  • Faster save operations of store-level configurations for deployments with many stores. Saving configuration settings in deployments with more than 500 stores can be time-consuming. The new Async Config module enables asynchronous configuration save operations by running a cron job that uses a consumer to process the save operation in a message queue. AsyncConfig is disabled by default.

  • Faster generation of the config cache for large configurations. The bin/magento cache:clean config command now pre-warms the config cache when the config cache is enabled. This reduces the downtime required to generate the config cache for large configurations. Configuration save operations no longer clean the config_scopes cache before writing data to the cache, which also reduces the time that other requests are locked out while config data is being written.

Braintree

  • Vaulted PayPal and Pay Later Changes—Logged-in customers who have previously vaulted/stored their PayPal account have the option to pay with:

    • Pay Now (without having to log into their PayPal account, the user can pay with their default card)
    • Pay with a different funding source
    • Pay with a different account
    • PayPal Pay Later or PayPal Credit button
  • 3DS support for Google Pay—Included 3DS verification support for the Google Pay non-tokenized cards. See the Braintree documentation for more information.

  • Vault Apple Pay Payments—Allow logged-in customers to vault/store their Apple Pay payments to their Commerce store account to use on future transactions. This reduces the number of steps on checkout and creates a faster checkout experience for the returning customer.

  • Vault Google Pay Payments—Allow logged-in customers to vault/store their Google Pay payments to their Commerce store account to use on future transactions. This reduces the number of steps on checkout and creates a faster checkout experience for the returning customer.

  • Vault Venmo Payments—Allow logged-in customers to vault/store their Venmo accounts to their Commerce store account to use on future transactions. This reduces the number of steps on checkout and creates a faster checkout experience for the returning customer.

  • Vault ACH Payments—Allow logged-in customers to vault/store their ACH payments to their Commerce store account to use on future transactions. This reduces the number of steps on checkout and creates a faster checkout experience for the returning customer.

  • Express Payment buttons at the top of checkout—To encourage a faster checkout experience, we’ve introduced Express Payment options at the beginning of the checkout. Customers can now pay by PayPal, PayPal Pay Later, Apple Pay, and Google Pay Express payments.

  • Braintree release notes and Support links within the Admin Configuration—Merchants can now directly link from the Commerce Admin to Braintree support and release notes online.

  • GraphQL support for all Braintree payment methods except Venmo—More configurations are exposed in the GraphQL API. This is particularly useful for headless applications.

  • Vaulting payments in account area—Logged-in customers can now vault/store new credit/debit cards and PayPal accounts in the Customer account area. Previously, customers could only vault/store when saving their payments for later use when completing a transaction on the checkout, now they can vault new credit/debit cards and PayPal accounts without needing to create a new transaction.

  • Frictionless Transactions—Frictionless transactions accelerate the payment process by reducing the number of customer clicks/steps to complete an online credit/debit card transaction. Previously (when 3DS was enabled), every customer was 3DS challenged. With the new Frictionless Transactions feature, customers are only challenged for 3DS when the bank requests it. This reduces cart abandonment, increases conversion rates, and leads to more sales.

  • Dispute webhooks—When a customer disputes a transaction in Braintree, the dispute status is now passed on to Commerce. It is searchable in the Sales > Order grid and attached to each order.

GraphQL

Magento Open Source 2.4.7 includes enhanced GraphQL caching abilities, GraphQL schema support for custom attributes, support for headless order cancellation, and improved resolver caching.

  • More flexible cart management. The clearCart mutation now clears the contents of a specified shopping cart in a single action. It replaces the clearCustomerCart mutation, which has been deprecated.

  • Improvements in create cart mutations. The createGuestCart mutation has been added to replace the deprecated createEmptyCart mutation. Previously, if you used createEmptyCart, you could not determine whether the cart was for a guest or logged-in customer.

  • Order items now include product images. OrderItemInterface exposes product images, which permits images to be associated with ordered products and load more efficiently. GitHub-32369

  • Expanded support for resolver caching. The following GraphQL query resolvers are now cacheable in the GraphQL Resolver Results cache, which improves performance when queries are submitted with POST requests:

    • Magento\CustomerGraphQl\Model\Resolver\Customer::resolve
    • Magento\CustomerGraphQl\Model\Resolver\CustomerAddress::resolve
    • Magento\CustomerGraphQl\Model\Resolver\IsSubscribed::resolve
    • Magento\CatalogGraphQl\Model\Resolver\Product\MediaGallery::resolve
  • Support for order cancellation. The cancelOrder mutation allows a customer to cancel an order, passing its identifier and a cancellation reason.

  • Enhanced support for custom attributes. GraphQL custom attribute support has been enhanced by enriching API data to support all attribute types. The GraphQL EAV attributes schema now supports extending customer attributes and customer address objects in the Admin and retrieving them using GraphQL. Specific areas of enhancement include:

    • extended/added custom attributes support to specific areas such as customer and customer address
    • added caching for custom attributes
    • enhanced existing custom attributes support for products
  • Enhanced GraphQL caching capabilities improve page load speed. Caching capability has been added to these queries, improving the speed of page load time for most PWA pages:

  • Improved GraphQL parser performance. GraphQL parser performance has been improved by reducing the number of times the parse method is called per request. It is now called once. Previously, the parser was called at least three times.

New fields for existing mutations

  • Added the quickorder_active field to the storeConfig and availableStores queries. This field indicates whether the quick order feature is enabled.

  • Added the following fields to the setBillingAddressOnCart and setShippingAddressesOnCart mutations:

    • fax
    • middlename
    • prefix
    • suffix

New queries and mutations

Deprecated queries and mutations

Inventory Management

Inventory Management (v1.2.7) provides tools to manage product inventory. This community-developed feature is bundled with Adobe Commerce and Magento Open Source core code.

Magento Open Source Extension metapackage

This release includes the Magento Open Source Extension metapackage v1.0.0, which automatically bundles select Magento Open Source extensions with this core release. The version of this extension that is included in this metapackage is installed when composer update is run, simplifying the process of upgrading the extension when upgrading to the latest core release. This extension maintains an independent release schedule.

The Magento Open Source Extension metapackage for Magento Open Source 2.4.7 includes these extensions:

Future versions of this extension metapackage will contain additional extensions.

PWA Studio

PWA Studio v14.0 is compatible with Magento Open Source 2.4.7-beta1. It includes multiple enhancements to improve accessibility. For information about bug fixes, see PWA Studio releases. See Version compatibility for a list of PWA Studio versions and their compatible Magento Open Source core versions.

Web API framework

This release introduces two new REST endpoints that provide a workaround for a limitation with the REST API GET and POST V1/products/attributes endpoints. These endpoints return the same value for the is_filterable attribute for both the Filterable(with results) and Filterable(no results) options of the Use in Layered Navigation option. (The is_filterable attribute property is of type Boolean, which does not permit setting this property to Filterable(no results).)

Two new REST endpoints have been implemented as a workaround:

  • PUT /V1/products/attributes/{attributeCode}/is-filterable/{isFilterable}. Path parameters: attributeCode (String) and isFilterable (int values are: 0 is No; 1 is Filterable (with results); 2 is Filterable (no results)).
  • GET /V1/products/attributes/{attributeCode}/is-filterable. Path parameters: attributeCode (String).

Fixed issues

We have fixed hundreds of issues in the Magento Open Source 2.4.7 core code. A subset of the fixed issues included in this release is described below.

Installation, upgrade, deployment

  • Unnecessary cache manipulation has been removed from the set-up process. Previously, Magento Open Source wrote its configuration to disk unnecessarily when bin/magento setup:db-data:upgrade or bin/magento setup:upgrade was run, which caused issues with som modules during setup. GitHub-38124
  • Deployment issues due to insufficient memory and large tables have been resolved. The bin/magento setup:upgrade command no longer fails due to memory-exceeded errors that are related to large MySQL tables.
  • bin/magento setup:install now completes successfully after app/etc/config.php has been deleted. Previously, the missing file was not regenerated during installation, and Magento Open Source threw an error. GitHub-37805
  • bin/magento setup:upgrade has been refactored to run successfully when installing a new module that installs both tables and associated mview indexers. GitHub-37304
  • Database restoration no longer fails due a delimiter error. Previously, Magento Open Source threw this error when bin/magento setup:rollback --db was executed: Syntax error or access violation: 1064 You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near 'delimiter' at line 1, query was: delimiter ;;.
  • The bin/magento setup:upgrade command no longer fails with this type of MySQL memory limit-related error: PHP Fatal error: Allowed memory size of 4294967296 bytes exhausted (tried to allocate 20480 bytes). Multi-select attribute migration has been optimized to consume less memory during setup:upgrade.
  • Generating a database backup now works as expected from both the Admin and command line. Previously, Magento Open Source threw this error: Syntax error or access violation: 1064 You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near 'delimiter' at line 1, query was: delimiter ;;.
  • Running setup:config:set without specifying the --lock-db-prefix parameter no longer erases the current value from the env.php file.
  • Varnish configuration has been updated to prevent guest users from accessing cached content related to other customer groups.
  • bin/magento setup:upgrade now completes successfully when installing a new module that installs both tables and associated mview indexers.
  • bin/magento setup:upgrade now displays a more informative error message when a message queue topic does not include a topic name. GitHub-34246
  • bin/magento setup:upgrade now displays a more informative error message when merged XML files are invalid. The error message now includes the filename.

Admin UI

  • Charts are now successfully disabled by default on the dashboard. GitHub-38430
  • The Admin Sales menu now displays submenus correctly. Previously, the column break did not work correctly, and some submenus were not displayed. GitHub-37812
  • Select dropdown menu options are now visible on Admin Content > Pages when multiple pages are selected in the grid. GitHub-35386
  • Corrected the path to the default value of system/dashboard/enable_charts in configuration settings. Charts are now displayed in the Admin as expected. GitHub-37668
  • Corrected display issue with Admin Customer grids. Previously, grid columns were not completely contained within the displayed page.
  • Hover colors are now applied as expected on the rows of Admin static grids. GitHub-35358
  • The checkout workflow no longer displays a warning when a shopper enters a postal code for Greece that does not contain a blank space. GitHub-36676
  • The Admin It's time to change your password link now redirects to the Change Admin Password page as expected. GitHub-37902
  • Page title suffixes are now included in both the title tag and the meta title tag for product pages. GitHub-37680
  • The product stock status condition is now correctly applied for related products rules.
  • The Login as Customer button is now displayed correctly on mobile devices.
  • Adobe Commerce no longer displays the Admin Add new customer group button if the logged-in admin user lacks permission to add a new customer group.
  • An admin user with restricted permissions can now save a child product whose parent product is assigned to a different scope. Previously, Commerce invalidated the cache for a parent product that was not assigned to the scope in which the child product was changed.
  • Admin users can now successfully switch between Admin filter views without view data being corrupted or lost. GitHub-37529

Bundle products

  • The customerCart query now returns all applied discounts on bundle products as expected. Previously, the total discounts that were applied to a bundle product were returned as zero.
  • Product detail pages now display the correct price for bundle products for which a 100% discount has been applied. Previously, Magento Open Source did not apply a 100% discount to bundle product prices.
  • Cart price rules are now applied to product bundles instead of to each child product for dynamic-priced bundled products.
  • Corrected an error that occurs when you use the POST V1/shipment endpoint to create a shipment containing a bundle product. The endpoint now adds items as expected and no longer returns this error: The shipment couldn't be saved.
  • You can now use the GET V1/shipment/ API route to create a shipment with a bundle product when the product has the together shipment type set. Bundle products are also now validated based on their shipment type property.
  • Shoppers can now edit the quantity of a bundle product in their storefront shopping cart. Previously, Adobe Commerce did not handle null values for ItemId when products were edited in the storefront shopping cart and displayed an error. GitHub-37696
  • Bundle products can now be successfully added to an Admin order using SKUs that contain a slash (/) character. Previously, admin users could not use this method to add products to an Admin order, and Magento Open Source threw a JavaScript error.
  • Admin users can now set decimal default values for newly added bundle options when Qty Uses Decimal is enabled for the corresponding simple product. Previously, decimal values could be set only for saved selections.
  • Optimized performance for saving bundle products with a large number of options
  • Bundle products are now successfully imported without duplicating SKUs in product options. Previously, Magento Open Source created multiple duplicate SKUs in product options when you imported bundle products with duplicate entries.
  • Bundle product price is now calculated properly when one of the products in the bundle is out of stock. Previously, if a product that was part of the bundle were out of stock, it was removed from the price calculation.
  • Bundle products are now displayed as out of stock when the last of their required child products are bought. Previously, bundle products were displayed as in-stock on the storefront when their simple products were out of stock.
  • Performance issues when adding bundle products with non-required options to the cart using the addBundleProductsToCart mutation have been resolved.
  • The categoryList query now returns all bundle options as expected when the Show out-of-stock products configuration setting is enabled. Previously, out-of-stock options were not included in the query response.
  • Bundle products created with POST V1/products now succeed when catalog price scope is set to website. Previously, an integrity constraint violation occurred. GitHub-35595

Cache

  • Categories are now visible to shoppers in stores where the cache is set to Fastly CDN (Caching Application=Fastly CDN). This affected both guest shoppers and registered customers.
  • Cache cookies after login are now the same after browsing the website. Previously, the login controller sent the wrong cache cookie, and pages might have been cached multiple times.
  • Responses from GraphQL GET operations on CMS pages that contain CMS blocks are now cleared as expected in Fastly cache. Subsequent schedule updates now show accurate, update content for these pages.
  • Page cache is now cleared as expected for a parent product when one of its child products has been saved from the Admin. A plugin check has been introduced to reach cache invalidation for configurable variants, similar to other product types, irrespective of indexer state (scheduled or real time). Previously, prices were not updated properly on the storefront after a configurable variation was updated from the Admin.
  • Added a caching mechanism for AWS credentials. A credentials provider now uses the Commerce cache to cache credentials retrieved from AWS for EC2 configuration.
  • The plugin whose purpose is to add the configurable cache tag when a simple product associated with a configurable product is saved now works as expected. All relevant configurable cache tags are removed as expected when a simple product is updated by POST V1/products. Previously, not all prices were updated on the storefront, and caches had to be manually cleared. GitHub-36726

Cart and checkout

  • Magento Open Source now optimizes performance by not loading user-specific quote data when generating full-page cacheable pages such as Product Details Pages (PDP) and CMS pages when persistent cart is enabled. Previously, the system would unnecessarily load user-specific session and quote data during the generation of these pages, which affected performance.
  • Custom address custom attributes are now saved as expected in the database. Previously, attribute values that were saved in the database were prepended with attribute code.
  • Generation of cart rules filter text for product attributes has been improved. Individual products are no longer loaded multiple times.
  • Magento Open Source now displays an informative error message when an error occurs during checkout and no longer returns the shopper to an earlier checkout step. Previously, the shopper was returned to the shipping page.
  • The cart query no longer returns shipping method and address for virtual carts. Previously, when a cart contained both physical and virtual products, and all physical products were removed, the cart query response continued to include shipping information.
  • Magento Open Source now displays informative messages when an add-to-cart action is triggered. Previously, the The requested qty is not available was not always displayed as needed on the storefront.
  • Checkout page load times have been improved for customers with large address books. Magento Open Source now processes only the number of customer addresses specified in the Customer Addresses Limit setting. Previously, Magento Open Source loaded the entire address book.
  • Product quantity can now be changed in the cart as expected for in-stock items when one item is out of stock. Previously, shoppers could not change product quantity of any items when one was out of stock.
  • The AdvancedSalesRule product attribute filter now works correctly with the decimal attribute backend type. As a result, the cart rules with Coupon Type set to No Coupon now work as expected.
  • The full amount of a whole cart discount is now applied as expected to carts that contain both bundle and configurable products.
  • Customer Section cookies now honor the cookie’s domain setting. Previously, the mini cart was not updating as expected in stores that contained subdomains, even though the session was shared.
  • Shipping an order to multiple addresses no longer triggers an error during region ID processing.
  • Fixed-discount amounts that are applied at the cart level are now correct.GitHub-37496
  • Coupons are now applied successfully to an order when a shopper applies the coupon after selecting the flat rate shipping method where a cart price rule with shipping method set as a condition applies. Previously, the cart page displayed the Coupon is Not valid error, and the coupon was not applied. GitHub-34866
  • Coupons are now applied successfully to an order when a shopper applies the coupon after selecting the flat rate shipping method where a cart price rule with shipping method set as a condition applies. Previously, the cart page displayed the Coupon is Not valid error, and the coupon was not applied. GitHub-34866
  • The My billing and shipping address are the same checkbox now remains checked by default when a shopper uses Chrome autocomplete to fill in their shipping address and then clicks Next before the shipping methods block is reloaded. GitHub-33725
  • The applied_rule_ids value in the quote_item table now includes a correct list of applied rule IDs. Previously, this value contained only the last applied rule ID.
  • Mini-cart and customer data in local storage now resets when a session is removed from the server. Previously, this data still appeared when the session file was removed.
  • Discrete carts are no longer mistakenly merged from the Admin when persistent cart is enabled.
  • The cart tax and shipping estimator now accurately reflect the default destination configuration. Previously, when you configured default tax destination calculation settings and specified State/Region and ZIP, only the ZIP value was shown in the cart under Estimate Tax and Shipping. This resulted from Magento Open Source setting the region ID to undefined before invoking the conditional statement that set the default region ID from the Admin.
  • Magento Open Source no longer throws this error during checkout when persistent shopping cart is enabled: Invalid state change requested. Previously, when this error was thrown, multiple orders with the same quote_id were occasionally created.
  • The mini cart now displays bundle product prices that reflect cart tax configuration settings. Previously, the mini cart always included taxes in the prices of bundle products.
  • The shipping estimate provided from the cart page is now accurate. collectShippingRates is now set only once. Previously, the shipping estimate was duplicated. GitHub-36648
  • The cart query no longer returns an error when a product in the specified cart is out of stock. Previously, shoppers using this query to make a purchase could not complete their purchase when an item was out of stock, and their checkout page was blank.
  • Guest API requests to POST V1/guest-carts/<cartId>/shipping-information no longer return a cancel status if the page reloads during login in a mobile environment. Previously, Magento Open Source threw a 500 error and logged this exception: TypeError: Argument 2 passed to Magento\CustomerCustomAttributes\Model\Plugin\ProcessCustomerShippingAddressCustomAttributes::beforeSaveAddressInformation() must be of the type string, null given.
  • Free shipping eligibility is now calculated as expected when the Subtotal (Excl. Tax) condition for cart rules is applied. GitHub-36760
  • The cart query now returns the correct tier pricing for a product. GitHub-29655
  • Informative error messages have been added to the checkout page to guide shoppers when the application of a coupon on the shipping page conflicts with the selected shipping method. Previously, a message told shoppers to return to the previous page.
  • The authentication popup is now initialized only when it is needed instead of whenever guest checkout is enabled. It is now initialized when the guest shopper tries to proceed to checkout, and guest checkout is disabled. GitHub-30672

Cart price rule

  • The cart price rule product subselect condition now includes the total (incl.tax) option as expected. GitHub-34871
  • The If an item is FOUND/NOT FOUND in the cart with ALL/ANY of these conditions true catalog price rule condition now works correctly with category and SKU attributes. Previously, this condition was not correctly applied in cart price coupon logic, and invalid coupons were applied to orders. GitHub-37660
  • You can now successfully save a new cart price rule with the Magento_OfflineShipping extension disabled. Previously, Magento Open Source threw this error: report.ERROR: Warning: Undefined array key "simple_free_shipping". GitHub-37580
  • Cart price rules are now applied as expected when a cart price rule related to one shipping method is configured for the store, and this shipping method is changed to another during checkout. Previously, the applied_rule_ids value was never changed in the sales_order_item table, and the cart price rule was not applied to the order.
  • Coupons are now applied successfully to an order when a shopper applies the coupon after selecting the flat rate shipping method where a cart price rule with shipping method set as a condition applies. Previously, the cart page displayed the Coupon is Not valid error, and the coupon was not applied. GitHub-34866

Catalog

  • Running bin/magento cache:clean or bin/magento cache:flush no longer flushes the entire built-in or Varnish full-page cache unless specified. GitHub-38301
  • Merchants can now use the Product Carousel to create CMS blocks when catalog_product_price dimensions-mode is set to website. Previously, Magento Open Source did not save the block and threw this SLQ error: report.CRITICAL: PDOException: SQLSTATE[42S02]: Base table or view not found: 1146 Table.
  • Magento Open Source no longer displays duplicate images when the product color is changed on a product detail page. GitHub-36243
  • Optimized the algorithm for synchronizing website-specific values after adding a new store or changing an existing one in large, multi-store environments.
  • The clean-up process for cached image files has been improved to avoid the creation of hidden directories in the pub/media/catalog/product folder. Previously, hidden directories led to disk space issues during clean-up operations. The operation could be terminated, which left behind temporary hidden directories that were never deleted.
  • Bundle product prices are now calculated correctly, and an issue with the order of operations when calculating prices have been resolved. GitHub-35665
  • An unnecessary clause has been removed from catalog_product_price index queries, which has improved performance of this indexer on stores with large catalogs. GitHub-32382
  • Magento Open Source no longer inserts product description text into the product detail page Meta Description field when this field has been left empty. Previously, when a product description contained HTML code that was generated by Page Builder or another HTML editor, the HTML was displayed in the Meta Description field, and you could not leave this field empty.
  • Configurable product options on configurable product PDP pages are no longer affected by other configurable product options on the page. Previously, configurable products with drop-down attributes no longer trigger an exception when a product carousel is present on the product details page. Configurable product options were not selectable when other configurable products with swatch options were present on the page.
  • Recently viewed product information is now displayed in accordance with store view configuration. Previously, the recently viewed product data was not updated per store view, including name and preferred language.
  • Vimeo videos now play as expected on product pages in mobile view in Chromium-based web browsers.
  • The bin/magento catalog:images:resize command now correctly generates product images for the products that are assigned to a custom website with a custom theme.
  • Metadata with NULL or NOT NULL values are now saved for the default store according to the Use Default Value checkbox as expected. Previously, metadata with NULL value was not saved when this checkbox was unchecked.
  • Merchants can now successfully delete an existing image from the product details page, then upload a new image with the same name. Previously under those circumstances, the storefront product page did not display the correct image.
  • The productDetail query now returns the product name instead of null when the product image alt attribute is set as empty.
  • Orders that include both downloadable and physical products now include working links to the downloadable product as soon as the order has been completed. Previously, links to downloadable products were not available until the physical products in the same order shipped.
  • URL rewrites are now updated when a category is moved from one store/root category to another store/root category. Obsolete database entries are now removed when the sub-categories are transferred to new parent categories. The database now includes only relevant entries. Previously, the url_path was not updated with the proper store ID.
  • The REST V1/products/<sku>/media endpoint can now process the simultaneous upload of multiple media images. Previously, while processing several requests simultaneously, inconsistent data was created, and Magento Open Source threw an error when this data was saved into the database.
  • Partial re-index performance for the Category Products and Product Categories indexers has been improved. Previously, the indexer_update_all_views cron job ran re-indexers multiple times per single product or category.
  • When product stock status is automatically updated to out of stock based on stock configuration (quantity), stock status will be subsequently updated to in stock when the stock quantity is updated. Previously, the stock_status_changed_auto setting was ignored when a product’s stock configuration was updated to in stock.
  • Toolbar sorting now works as expected on Search pages when the Remember Category Pagination setting is enabled. GitHub-33220
  • Multi-select attributes are now saved as expected when Use Default Value checkbox in the store-view scope is selected. Previously, this checkbox was unchecked when the product was edited and the default value was saved.
  • Admin users with website-limited access can now add images to a product that falls within their scope. If the admin user does not have access rights to the product, Magento Open Source displays an informative message. Previously, admin users with website-limited access could not add images to products to which they had access.
  • Magento Open Source now displays the correct name after sorting products by name in Admin > Category > Products in category in multistore deployments where product names vary by store. GitHub-36208
  • The addProductsToCart mutation now returns customizable options with data. Previously, it returned only empty customizable options. GitHub-37599
  • Product backordered status is now displayed correctly on the storefront. Previously, products that were available for shipment were incorrectly identified as backordered.
  • Exported products now have the correct manage_stock value when the use_config_manage_stock value equals 1. Previously, this default value was incorrect.
  • Accessing downloadable products from the Admin no longer results in an error when the admin user changes the store view from the view used during product creation to another store view. Product prices are now successfully converted to float when an admin user switches store view from all store views to the default store view. Previously, Magento Open Source threw an error. GitHub-37519
  • Magento Open Source no longer displays a warning message when you save a product that was created with custom options after deleting its image.
  • Product thumbnail images are now displayed as expected in the product stock alert email that is sent when a product is back in stock. Previously, this image was not displayed in the alert email
  • The product count in the category tree (Admin Catalog > Category) is now accurate. Previously, the category products count could not be retrieved from the catalog_category_product_index table. The typo that triggered this bug has been fixed. GitHub-35417
  • The main product image on the product details page no longer visibly shifts downward during page load when product_image_white_borders in theme view.xml is disabled. Previously, the product image visibly shifted downward during page load due to incorrect height settings in Fotorama JS.
  • Customers are now notified about drops in product price when the customer is subscribed to price drop alerts. Previously, price-drop notifications were not always sent due to application-level caching.
  • Server-side validation has been added to the process of creating product attributes through the web API. You cannot enable the Use in Layered Navigation Catalog field when the Catalog Input Type for Store Owner field value is Text Field, Text Area, Text Editor, Date, or Date and Time. Previously, products were omitted from categories and search results.
  • The category page now re-loads with the correct pagination after a shopper opens the page, changes the pagination, navigates to a product page, and then returns to the category page. GitHub-36563
  • Out-of-stock simple products that are options for a configurable product are now displayed as disabled on the storefront when Display Out of Stock Products is set to Yes. Previously, all options were displayed as available, despite their status and real availability.
  • Updating the website scope attribute in a specific store view no longer overrides the value of that attribute in global scope. Previously, importing product prices when multiple rows are available with the same SKU and store_view_code resulted in inaccurate prices for the default and All Store view scopes.
  • Merchants can now add a GIF image to a product’s image gallery from the Admin. Previously, Magento Open Source displayed this error: imagecolorsforindex(): Argument #2 ($color) is out of range.
  • Checks have been added to handle errors that result from undefined array keys. Previously, an error occurred during declarative schema whitelist generation.
  • Magento Open Source now returns a valid result for the custom date 01/01/1970. Previously, the custom attribute returned this error: Invalid input datetime format of value '1/01/1970. GitHub-37274
  • routes queries that use fragments now return category information as expected. Previously, an internal server error occurred on the category page. GitHub-35906
  • Issues with the cataloginventory_stock partial re-indexing process have been resolved, and indexer performance has improved. Previously, stock and product categories were not accurately updated.
  • Magento Open Source now generates a 301 redirect for a product when the category it belongs to has been moved to a new parent. GitHub-37039

Catalog rules

  • Catalog rules are now correctly indexed when enabled by schedule update. As a result, discounted prices are now correctly generated and indexed. Previously, when two catalog rules were available, and one rule is activated after the first rule before the first rule’s the catalog rule indexing operation has completed, the catalog rule discount prices were not generated for the second catalog rule.
  • Catalog rules are now applied as expected in a multi-website environment.

Configurable products

  • Merchants can now select Skip quantity at this time and **Skip image uploading at this ** when configuring a configurable product without affecting the source of associated simple products. Previously, selecting Skip quantity at this time resulted in the disappearance of product sources.
  • The As low as label is no longer displayed for a configurable product price when all options have the same price.
  • Admin users with website permissions can now save a child product that is part of a configurable product in a different store context. Re-indexing processes now skip this type of configurable product.
  • Configurable products with two child products are no longer marked as out of stock when one child product is disabled by a scheduled update. This was a known issue for 2.4.7-beta1.
  • The performance of save operations for configurable products with multiple options has improved. Previously, timeouts could occur during product save operations. GitHub-36928
  • The storefront display of configurable product prices now changes as expected when a shopper selects a product option. GitHub-37378

Coupons

  • Coupon codes with a limited number of uses per customer can now be used a second time when the order for which it was previously used fails. Previously, the promo code was not released when the prior order was canceled.
  • Coupon codes that contain space characters are no longer invalidated. Previously, if a coupon code contained a space character (before or after the actual code), validation failed. GitHub-38048
  • A shopper’s single-use coupon value is now restored as expected when the order to which it was applied is canceled.
  • The GET V1/coupons/<couponId> endpoint now returns the full expected response for manually created coupons just as it does for autogenerated coupons. Previously, some fields were omitted (for example, usage_limit, usage_per_customer, and created_at).

cron

  • The aggregate_sales_report_bestsellers_data cron job no longer creates very large temporary MySQL tables and now completes successfully. This cron job now inserts data per store, not for all stores at once. Previously, this cron job could result in No space left on device errors.
  • The number of pending records in the cron_schedule table has been reduced by preventing cron jobs from trying to acquire unnecessary cron job locks. Previously, cron jobs tried to acquire locks when it was too late to run the job. Cron jobs in cron_schedule were not marked as missed even though they had already passed their scheduled time. Magento Open Source also displayed this error repeatedly in the error log: report.WARNING: Could not acquire lock for cron job: indexer_update_all_views.
  • Fixed the divide-by-zero fatal error in cron expressions. GitHub-37804
  • The sales_clean_quotes cron process has been optimized to run faster by adding a composite index on store_id and updated_at columns in the quote table. This change improves cron job performance when processing many quotes.
  • Admin users can now view which task the bin/magento cron:run process is currently performing. The title of the currently running process now lists the group and job names. GitHub-34321

Customer

  • Magento Open Source now displays the Date of Birth, Tax/VAT Number, Gender, Telephone, Company, and Fax fields on the edit customer page based on configuration settings. GitHub-36196

Email

  • Emails that contain diacritics or accents (that is, utf8 email) are now supported for customers and companies as well as for order placing by guests and registered customers. Previously, Magento Open Source did not save customer records that contained diacritics and displayed this error: Something went wrong while saving the customer.
  • Email sender names can no longer include colon characters. A new validation rule now prevents the saving of sender names that contain colon characters from the Store Email Addresses section of Admin Stores > General. Previously, merchants could save a sender name that contained a colon character, which resulted in mail server errors.
  • Customer email addresses can now include diacritics. Previously, front-end validation prohibited the creation of a user with diacritics in their email address. GitHub-12075
  • Stock and price alert emails are now translated according to the language configured for the website default store view. Previously, these emails were not translated.
  • POST V1/order/notify-orders-are-ready-for-pickup now sends an email alerting customers that an order is ready for pickup only when the order is ready. Email is now triggered only when the request has been fulfilled without an exception.

Frameworks

  • Improved debugging by adding the UNCACHEABLE value when outputting an HTTP header with Varnish is in use. Previously, only HIT or MISS values were outputted. GitHub-37912
  • Added code to support default Varnish compression handling. GitHub-38309
  • The varnish:vcl:generate command now includes an input-file argument. This supports the addition of a custom VCL to a Git repository, relative to the Commerce root. GitHub-37363
  • Support for Varnish 4.x and 5.x has been removed from the codebase. GitHub-38304
  • phpcodesniffer-composer-installer in composer.json has been upgraded to v1.0.0. GitHub-36913
  • Fixed an incorrect PHP doc tag in the Magento\Reports\Block\Adminhtml\Shopcart\Product\Grid class. GitHub-38186
  • Refactored code throughout the codebase that was created when coding practice dictated that any cache section that was included in the app/etc/env.php file would include a frontend section. This refactoring addresses potential problems when upgrading Magento Open Source pre-2.4.4 deployments. GitHub-38363
  • Clarified the error message that is associated with StockItemValidator.php when a stock ID with a value of 0 is supplied during an API call. GitHub-31107
  • Added a default empty array to $tagGenerators in CompositeTagGenerator to prevent errors during dependency injection compilation. Previously, running the bin/magento setup:upgrade command when the Magento_DirectoryGraphQl and Magento_StoreGraphQl modules were disabled resulted in an error. GitHub-38165
  • The unused AlgorithmProviderFactory class has been removed as well as dependencies on this class in classes including JweAlgorithmManagerFactory.php, JweContentAlgorithmManagerFactory.php, and JwsAlgorithmManagerFactory. GitHub-37783
  • The var/log/system.log file no longer contains main.INFO error messages. The menu entry log has been moved from level INFO to DEBUG. Previously, the var/log/system.log file was flooded with messages like this: Add of item with id Magento_Theme::design_config was processed … .
  • Redis preloading no longer fails when exec() returns false. Verification has been added to the preloading process to prevent array_combine from receiving false as a second argument. As a result, preloading will continue to run when exec() returns false. GitHub-37509
  • Refactored the Magento_CatalogWidget module to replace $block escaping functions with $escaper escaping functions. GitHub-37107
  • Swaziland has been updated to Eswatini throughout the codebase. GitHub-37873
  • Added the new Nicaraguan currency (NIO) to the list of available currencies.
  • Corrected a variable name in CatalogRule/Controller/Adminhtml/Promo/Catalog/NewConditionHtml.php. GitHub-38093
  • Resolved subtotal rounding errors that occurred in transactions for products for which decimal quantity has been enabled. GitHub-37817
  • The date filter for the Admin customer grid now works as expected according to the specified locale.
  • The bin/magento setup:upgrade command no longer fails due to the $schemaPatch variable data type. Previously, the string value was passed to the get_class function, which caused the error. GitHub-37545
  • The connection to the MySQL database is now restored if the connection times out during a transaction when you set max_messages = 0 for consumer. Previously, the connection was terminated.
  • The magento/module-release-notification core module has been marked as deprecated in the 2.4-develop code with this comment: Starting from Magento 2.4.7, Magento_ReleaseNotification module is deprecated in favor of another in-product messaging mechanism.
  • Proxy code generation now generates Proxy and Factory files as expected for deployments running in production mode. GitHub-35252
  • The Indian state of Ladakh is now listed as an option in the Admin address State dropdown menus. GitHub-33698
  • The event countdown ticker is now displayed as expected on the category page.
  • The forbidden @author tag has been removed from the code base, including these modules: Magento_user-variable-wee, Magento_Catalog, and Magento_Customer, Magento_Wishlist, Magento_Review Tax, and throughout the framework. GitHub-37245, GitHub-37246, GitHub-37249, GitHub-37263
  • The JSON serializer in the User module has been replaced with a new, more accurate serializer (JsonHexTag). Previously, Magento Open Source sometimes crashed when trying to use data serialized by the regular serializer when it contained unescaped elements. GitHub-31377
  • Broken pipeline errors no longer occur while running a full reindex (bin/magento indexer:reindex). AMPQ connections are now closed before the process manager forks processes.
  • The queue message validator now validates the subtype of all array elements. Previously, Magento Open Source threw an exception.
  • The queue connection configuration per topic in app/etc/env.php now works correctly. Previously, the product alert queue does not generate correctly when a new message queue was created with a custom exchange. If the queue connection for a topic was configured in app/etc/env.php with a custom exchange, a new binding was created for all topics with that custom exchange. Merchants could not process product alerts.
  • Temporal formats marked with a /* mariadb-5.3 */ comment no longer cause errors during bin/magento setup:install when upgrading MariaDB server to version 10.5.1 or higher.
  • The AwsS3 driver now works as expected as a replacement for the base default file storage implementation. Previously, data could be corrupted when this driver was configured for file storage. GitHub-37844
  • bin/magento config:show and set commands that use $_ENV variables now support the use of website and store codes that contain camel case or uppercase characters.
  • Added classes with !important as used in Tailwind 3 for CSS layout support. GitHub-37568
  • A missing jQuery dependency has been added to the trim-input.js file. GitHub-37683
  • Event-specific details are now passed as a second attribute (context) of the log method. GitHub-37879
  • Aspect ratio values have been added to catalog images and unnecessary scripts have been removed from the UI framework. GitHub-37691
  • Revised error messages triggered by invalid XML configuration to be more informative. GitHub-37788
  • Refactored deprecated code related to the creation of dynamic properties throughout the codebase.
  • The performance of indexers for large stores with extremely active product databases has improved. Indexers now index the latest product information once for each index rather than multiple times. Previously, products disappeared from the website, and product data could be out of date on the website. GitHub-30012
  • mview_state record status now accurately indicates state based on changelog activity when a slave database connection is available. Previously, these records remained in a waiting state in cloud deployments even when there were no new entries in the changelog.
  • Added support for the precision option for currency format to preserve feature parity with the deprecated ZendCurrency class.
  • Cookie messages have been converted into observable attributes, and developers can now manipulate state, which can potentially trigger UI changes. Previously, cookies were read-only and could not be manipulated. GitHub-37308
  • Admin users can now generate an invoice when their Magento Open Source instance is connected to S3 storage. Previously, Magento Open Source displayed this error: Cannot create image resource. File not found. GitHub-35706
  • Magento Open Source now logs an exception message as expected when VAT number validation by the VIES validation service fails. GitHub-36065
  • The Administrators name has been removed from the query used to fetch an administrator’s role during admin role creation. GitHub-36998
  • The bin/magento setup:config:set command no longer fails when an invalid database user name is included in the app/etc/env.php file. GitHub-37409
  • Sorting by column on reserved words in a default Admin UI component no longer results in an SQL error in var/log/exception.log. GitHub-37423
  • Added AddDataForCostaRica.php to provide state information for Costa Rica. GitHub-37382.
  • Improved error message for scenario where user tries to access an invalid URL from the Admin. GitHub-35682.
  • Param $options[position] for currency symbols now works as expected and supports the customization of the currency symbol position. Previously, after migrating from Zend Framework 1, the toCurrency method ignored the position parameter. This issue occurred throughout the Admin interface.
  • Mutex has been implemented for orders to prevent race conditions during update by concurrent requests. Previously, concurrent requests (race conditions) for order cancellations caused duplicated entries in the inventory_reservation table.
  • The populateWithArray function now transforms object properties to snake case correctly, making it compatible with the AbstractModel getters and setters. Previously, the snake case formatting was incorrect when the data attribute name contained several uppercase letters in a row.
  • The auto increment value in the catalog_product_entity_varchar table now increments correctly after a product is saved. Previously, this value increased by ten.
  • Magento Open Source no longer throws this file system exception when you try to flush the JavaScript/CSS cache: No such file or directory.
  • The value of value_id in customer_entity_int is now incremented correctly. An update query is executed instead of insert on duplicate key update when updating an entity that incorporates these attributes. As a result, the auto-increment columns used within the EAV model now grow in a linear fashion. Previously, the auto-increment process for columns skipped values due to failed insert queries. GitHub-28387
  • Removed unnecessary white space from id attributes that do not require it. (This bug was introduced by a Magento Open Source 2.4.6 code change.)
  • Store codes no longer appear in the store URL when the store is in single-store mode. GitHub-36831
  • Minor updates have been made to around plugins. GitHub-31443
  • The swatches Helper has been refactored to remove misleading import aliases. GitHub-31373
  • Admin users can now delete or rename a sitemap.xml file as expected. Previously, an admin user could delete the file from the Admin, but it remained in the file system. GitHub-37468
  • Coupons are no longer flagged as used when payment fails for the order to which they have been applied. Queue messages are now processed in the order in which they are published when the consumer is started. Previously, the first message was pulled from the queue to simply check whether messages were queued, and was rejected afterward, which caused the first message to be processed last.
  • Magento Open Source no longer throws an exception in the log file when a user tries to print a shipping label. Previously, if an extension modifies response headers that contain an attachment, the system threw an exception in the log file.
  • Support for more HTML classes has been added to elements.xsd. GitHub-36891

General fixes

  • Changed the name of the reponseBody variable to responseBody in app/code/Magento/CatalogRule/Controller/Adminhtml/Promo/Catalog/NewConditionHtml.php.GitHub-38093
  • Scheduling product updates no longer clears multi-select attribute data. Previously, when an update was scheduled for a product, the product’s multi-select attribute data was erroneously cleared. GitHub-37675
  • Saving a product with a non-default store scope no longer results in unchanged attributes becoming store-scoped when loaded using ProductRepository. GitHub-8897
  • Informative error messages have been added to custom field validation on product detail pages. GitHub-38006
  • Special characters can now be used in name fields. Previously, the ampersand character (&) was restricted in the name validator, which blocked customer add or edit operations when the customer name contained an ampersand. GitHub-38080
  • Admin users with restricted access to a specific store can now use a mass update action to update product reviews. Previously, Magento Open Source threw this exception: report.CRITICAL: TypeError: array_intersect(): Argument #1 ($array) must be of type array, null given in app/code/Magento/AdminGws/Model/Models.php:439.
  • The storefront login page’s Show Password functionality now displays passwords as expected. Previously, passwords were not displayed. GitHub-37432
  • The product comparison list is now always website-specific for guest shoppers and does not contain products that were added from the other websites, including products that were assigned to both websites.
  • CMS content blocks that contain emojis are no longer truncated after the emoji when saved to the database. Previously, content was truncated after the emoji because the default database configuration did not support four-byte characters.
  • Passwords are now displayed as expected when the Show Password checkbox on the login page is active.
  • The Reset Password Token system attribute of customer entity (rp_token) validation has been removed from attribute validation during customer account creation, and diacritics validation is included only in the resulting customer email. Previously, Magento Open Source did not save the customer record and displayed this error: Something went wrong while saving the customer.
  • You can now successfully save edits to the Admin Pages and Block grid after deleting a column. GitHub-37525
  • Customers can now log in successfully with a new password from one device after resetting their password on a different device.
  • The Admin customer address State/Province field now retains the last saved value as expected. Previously, when you removed the value from this field, Magento Open Source continued to display the deleted value in the State/Province field. GitHub-36846
  • Errors no longer occur during requests for an RSS feed for categories when RSS Feed Top Level Category is enabled. Previously, browsing the RSS feed category page resulted in Elasticsearch CRITICAL errors in log files when RSS Feed Top Level Category was enabled.
  • The correct value is now saved for gws_store_groups when role scope is changed during user role creation. Previously, when role scope was selected as All, the gws_store_groups value was saved as null during user creation but not during role editing. Also, if role scope was selected as Custom, then the gws_store_groups value was always saved as null.
  • The reset password page can now be accessed by clicking the Admin reset password link on the Admin login page when the Add Store Code to Urls setting is enabled. The Admin reset password link previously opened the login page or 404 page.
  • The date range in the Admin statistics dashboard is now calculated based on the time zone that is set in configuration settings, then converted to UTC to fetch data from the database.
  • The CMS hierarchy filter works as expected after you filter a store view then click Save on Admin Content > Hierarchy. Previously, clicking Save refreshed the page, but the context was lost, and the selected store view was no longer displayed.
  • Clicking the Send invitation button (Admin Marketing > Private sales > Invitation) now submits a POST request along with the form key and sends the invitation successfully. Previously, when you clicked this button, neither the HTTP POST method nor the form key were present.
  • Zero-byte files can now be successfully copied to remote storage with AWS S3.
  • Admin users can now add a new customer address from the Admin when that customer has been created for another website whose store ID does not match the website ID. Previously, Magento Open Source displayed this pop-up message: Something went wrong. GitHub-36582
  • The CMS block editor page now displays the correct widget block_id value. GitHub-29644

GraphQL

  • The getCustomerWishlist query no longer results in an internal server error when querying lists that contain configurable products.
  • The customerCart query now returns all applied discounts on bundle products as expected. Previously, the total discounts that were applied to a bundle product were returned as zero.
  • The getCustomerWishlist query no longer results in an internal server error when querying lists that contain configurable products.
  • The declaration of the is_subscribed flag, its resolver, cache, and associated tests have been moved from the CustomerGraphQl module to the NewsletterGraphQl module.
  • The addProductsToCart mutation no longer reports unrelated errors in user_errors. Previously, errors related to the cart were included in user_errors along with the expected operation errors. GitHub-37908
  • The products query product filter can now return partial match results as well as full matches. The new match_type (PARTIAL, FULL) attribute supports specifying match type. Previously, the query returned full matches only.
  • Mutex has been added to the addConfigurableProductsToCart query to prevent race conditions during an update by concurrent requests. Previously, when a merchant sent two parallel requests to add the same configurable product to a cart, two separate items with the same product SKU were added. GitHub-37847
  • Product aggregation in GraphQL responses now includes non-zero values for attributes when Use in Layered Navigation is set to Filterable (no results). Previously, only non-zero values were returned.
  • Improved the performance of the setShippingAddressForEstimate query for cart-related operations that involve custom product attributes. Previously, the query loaded all product attributes when parameters were sent as variables.
  • The products query ConfigurableProduct.configurable_options field now returns only values that have at least one enabled product. Previously, this field returned disabled simple products.
  • Improved the performance of the GetCategories query by reducing the number of unnecessary SQL queries it generates.
  • Address error handling for GraphQL library components now works as expected.
  • The products query now returns all relevant storefront pricing details when dynamic pricing is set to no and discounts are applied. Previously, the price range for products was not returned. GitHub-35649
  • GraphQL transaction names now include top-level query names only in the New Relic logs. Previously, transaction names also included secondary query names.
  • Address error handling for GraphQL library components now works as expected.
  • When the Visibility setting for a product is set to Catalog, products queries on that product now resolve the setting correctly. Previously, any filter provided was switched to the Visibility: Catalog setting. GitHub-36591
  • The customer query now returns a product_sale_price field that includes tax on orders when the product price has been configured to include tax. GitHub-36946
  • Product attributes of type DateTime now map to the FilterRangeTypeInput filter in products queries. Previously, these attributes were mapped to FilterMatchTypeInput. As a result of this change, queries filtering on DateTime attributes require from and to values instead of match values.
  • The customer query now returns only customer reviews related to a specific store view as expected when filtered by store ID.
  • The categories query no longer returns an error when the items.redirect_code response value contains a null value. GitHub-36675
  • The changeCustomerPassword mutation now triggers email as expected after successfully resetting a password.
  • urlResolver and route queries now return a result when the Target Path of URL rewrite is an absolute URL. Previously, the urlResolver query returned NULL when you used it to retrieve redirect data.
  • The products query now returns correct labels. GitHub-29635
  • The categoryList query now returns a populated product section of the options block for bundle products’ child products as expected. Previously, no information about bundle product child products was returned.
  • The route query now returns routes for categories and products as expected without an internal server error. GitHub-36544
  • The products query now fetches url_key values when multiple categories are selected.
  • products queries now return aggregations only for products that are assigned to the specified shared catalog.
  • Transaction names have been added to New Relic GraphQL transactions. GitHub-36874
  • The OptionValueProvider class get() method now returns an attribute option value based on the given option_id as expected. Previously, it returned an error. GitHub-35910
  • The products query now returns all available aggregations (filters) and their correctly translated labels. Previously, price and category aggregation labels were not translated as expected. GitHub-36140
  • You can now use a fragment ProductCard when querying related_products, upsell_products, and crossell_products on ProductInterface. GitHub-29769
  • The products query now returns related, upsell, and cross-sell products in the order in which they were saved. GitHub-36461
  • GraphQL queries now return related products data sorted by position. GitHub-33010
  • category_url_path has been added to ProductAttributeFilterInput, which supports requesting all products for a category in a single query. GitHub-32460
  • Corrected an error in which the method that sets the current store in a GraphQL mutation executed before the method that handles validation. GitHub-31336

Image

  • The Admin favicon icon upload form now supports .ico file types. GitHub-34858

Import/export

  • The product import process now parses values with the correct separator. Previously, the import process used the pipe (“|”) operator to parse multi-select values until the determined value separator was not equal to the default value. The import process subsequently failed.
  • 301 redirects are now automatically created when URL Key values are updated by CSV import.
  • Shipping table rates are now updated as expected in the table rate import CSV file. The table rate upload file is temporarily stored until the asynchronous configuration processor cron job runs. This cron job picks up the new location of the file and processes it accordingly. Previously, table rates were not updated as expected because the asynchronous processor looked for the file in the wrong location.
  • The Export Files grid now shows all exported files regardless of timestamp. Previously, the grid did not display all exported files that had the same timestamp. GitHub-36951
  • Products with customizable options can now be imported successfully. Previously, options data was lost during import. GitHub-37598
  • Special characters in exported CSV files are now represented as expected in Excel. GitHub-37921
  • Importing stock sources and customer addresses using the Customers and Addresses (single file) option now completes successfully.
  • Product import no longer fails due to lack of memory. Previously, importing any number of products to a database that already contains approximately ten million products failed due to lack of memory.
  • Validation checks now halt the import process as expected when there is no valid data to import, and Magento Open Source now displays this error: There are no valid rows to import. Previously, validation passed under these conditions, but the import process failed with this message: entity values are mixed. GitHub-32905
  • Importing URL keys with the same product no longer overwrites or deletes existing default store view keys. URL rewrites are now regenerated for store views only when there is no overridden url_key value. Previously, importing URL rewrites with the same URL key overwrote the existing default store view URL key. (key_store URL rewrites were deleted, but the URL rewrite on the Default store view level for the product was still set to key_store.)
  • Product count no longer changes unexpectedly during import. Cache flush is now postponed until after the import process.
  • The status of scheduled import actions now accurately represents the success or failure of the import operation. Previously, all actions were logged as successful.
  • Magento Open Source now takes into account the Disable Automatic Group Change Based on VAT ID setting during import of customer records. Previously, the disable_auto_group_change value in the import files was ignored. GitHub-36409
  • Magento\Framework\Convert\Excel now successfully handles numbers that are preceded by a space. The Excel XML now encodes fields as a String. Previously, the Excel writer encoded these values as number, which resulted in invalid files. GitHub-33422
  • Merchants can now specify the locale in which import data is presented and how data validators should parse this data. If a locale value is not specified, Magento Open Source uses the default configuration locale (not the default store view) to parse the data. In the Admin, import and export processes continue to use the admin user interface locale to import, parse, and format data respectively.
  • Importing products with country_of_manufacture attributes that were created by an admin user with a different locale setting than the admin user who is importing the products no longer throws a validation error. Previously, this import operation could result in a validation error on the country_of_manufacture attribute.
  • Exported products now have the correct manage_stock value when the use_config_manage_stock value equals 1. Previously, this default value was incorrect.
  • Magento Open Source now displays an informative error message in the scheduled import grid when an image is not imported successfully during a scheduled import operation. Previously, no error message was displayed.
  • The product import process is no longer interrupted when product images are missing. Previously, when a product image was missing during the import of a third-party service using a CSV file, Magento Open Source displayed this error: Maximum error count has been reached or a system error is occurred!.
  • The product import process no longer throws a validation error when an attribute value in configurable_variations column contains a comma.
  • Decoding has been excluded from the export process. The CSV export file text remains unchanged after import. As a result, the description does not change after re-import. Previously, HTML tags were removed in the Page Builder editor after product export and import.
  • Non-default configurations (website or store scope) that are added as environment variables no longer interrupt the app:config:import process with a recursion error.
  • Catalog search and price indexers in Update on Save mode are no longer invalidated after import. Previously, the Elasticsearch Indexer document version changed version when new and existing products were imported.
  • Product reports are now exported to the var directory. Previously, these reports were exported to the document root directory, which is a read-only directory in cloud instances.
  • Empty multi-select customer address fields no longer interrupt or halt the export process.

Index

  • Improved performance of the catalogrule_product indexer when no catalog rule is set. GitHub-34784
  • Problems with price indexer performance have been resolved. Indexer performance no longer gradually degrades. The indexer has been refactored to increase indexer processing speed by changing how temporary tables are created. These temporary tables are now recreated instead of being addressed by more time-consuming DELETE statements.
  • Price indexer performance has been improved. An index hint has been added to the price indexer that improves the run times of MySQL queries that are fired during indexing.
  • All indexers now use the same colors to represent indexer state. GitHub-34648
  • The performance of the Catalog Rule Product indexer in deployments where rules are not assigned to all websites has been improved.
  • Creating a custom product type when indexers are set to Update on schedule no longer causes the index update cron task to fail. GitHub-36471
  • bin/magento indexer:reindex customer_grid no longer fails with a MySQL error when the customer grid includes newly created custom customer attributes. GitHub-36233
  • Changing indexer mode for multiple indexers (that is, a mass action indexer mode change) now changes an indexer’s mode only when the current mode differs from the one being applied. This improves performance by preventing unnecessary trips to the database. GitHub-36823
  • Indexing products with many attribute options has been improved. GitHub-36386

Infrastructure

  • Added a missing return statement to the Admin usage enable controller. Previously, there was no return statement, and the controller in FrontendController class was handled incorrectly. GitHub-31374
  • Replaced MySQL CREATE TEMPORARY TABLE ... LIKE with refactored CREATE TEMPORARY TABLE for compliance with MySQL 8.x. GitHub-37926
  • Magento Open Source no longer includes the full path to the root of the server in the error message that it displays when a malformed HTTP request has been sent to the server. Only strings are now passed to the explode method as a second argument.
  • restricted_classes.php has replaced Zend_Validate_File_Upload. Previously, the validator crashed during upload of an import file larger than the value configured in php.ini . GitHub-37281
  • The email template engine can now correctly process certain nested directives (for example, {{if}}{{depend}}...{{/depend}}{{/if}}). GitHub-36438
  • product queries with aggregation data now return the correct label values for Boolean type product attributes. GitHub-29123
  • Added Ukrainian regions to the directory_country_region table. GitHub-35187
  • CSS files are no longer corrupted when merged when var/tmp and pub/static are on different filesystems and CSS Merging Enabled is enabled. Temporary files have been created in the same static directory as the target file to ensure that both files are on the same filesystem. As a result, the call to rename it is atomic. GitHub-29172
  • Fixed a potential error when calling a member function getId() on int, which occasionally triggered an exception when a customer was viewed in the Admin.
  • Type checks are now enforced for array type in the design theme config processor. GitHub-34440

Inventory management

  • Products are now automatically returned to In-stock status after a credit memo that includes a return of product quantity. Previously, if a product was out of stock but a credit memo returned stock of this product, merchants had to manually change product stock status.
  • Improved performance of the inventory indexer in async mode by removing redundant requests to re-index default source items.
  • Corrected issues with the Inventory indexer that affected the accuracy of the storefront stock count of configurable products. GitHub-36421
  • Updating inventory source items via REST V1/inventory/source-items now works faster. The call no longer triggers a re-index or a clean-cache operation on unchanged inventory products.
  • REST V1/products/<sku> now triggers an automated stock re-index when updating a product’s stock status. Previously, a stock re-index was not triggered for the product that was being updated.
  • Configurable product stock status is now updated on the storefront as expected when child products are updated by V1/inventory/source-items.
  • The POST <store_code>/V1/inventory/source-items REST call now validates payload for whitespace in returned inventory source items and sends an error message about validation as needed.
  • Merchants can now notify shoppers that an order is ready for pickup when the No Manage Stock setting is enabled for a product. Previously, when this setting was enabled, Magento Open Source displayed this error message: Your order is not ready for pickup.
  • Merchants can now create a credit memo for orders from which a simple product that is associated with a configurable product has been deleted. Previously, merchants could not create the credit memo, and Magento Open Source threw a TypeError exception.
  • The Admin grid source count now returns valid records after a filter has been applied. Previously, the getSourcesCount method always returned the total number of sources after a filter was applied.
  • The Category page no longer redirects to the Admin dashboard when you sort products using the “Move out of Stock to bottom” option. The issue has been resolved by putting the SQL join statement inside the conditional statement only after ensuring that it is already not included. Previously, the page redirected to the Admin dashboard with the message:Invalid security or form key. Please refresh the page.
  • AUTO_INCREMENT of the inventory_source_item table is no longer increased with every UPDATE operation. Previously, each update increased the AUTO_INCREMENT of this table, which eventually caused the AUTO_INCREMENT value to be out of range when adding a new record to the inventory_source_item table. As a result, admin users received the following error when they tried to create a new product from the Admin: Numeric value out of range....
  • Admin users can now add a product to a customer cart from the Admin for a particular store view scope with Inventory management. Previously, the stock ID was not determined properly, and admin users could not add the product to the customer cart.
  • Synchronization between Inventory and catalog no longer relies on the Synchronize with Catalog configuration setting. Previously, products were properly synchronized only when this setting was enabled.
  • Magento Open Source no longer throws an error after page reload when a shopper deducts a product quantity from an order that falls within the range of product available while selecting shipping source.
  • Configurable product stock status is now properly updated when a configurable product and its child products Stock Availability value is updated by a mass inventory update. Previously, you could not return a configurable product and its child products back to into stock by mass update.
  • The datatype for non-default sources has been updated to DECIMAL (12, 4) to support up to eight integer digits, which is the same limit implemented for default stock. This value is now in sync with the Admin add and edit product pages, which support input validation for up to eight digits for all types of inventory sources. Previously, the input for the Quantity field (for non-default sources) was supported up to six digits only.
  • Both default and non-default sources now display the correct information for product salable quantity when a non-default source that was ordered from the storefront is processed for shipment. Previously, Magento Open Source displayed incorrect stock status for product sources.
  • \Magento\Catalog\Model\Product::getIsSalable() now returns stock status based on the scope defined in the product object (\Magento\Catalog\Model\Product::getStoreId()). Previously, getIsSalable() returned stock status based on current scope regardless of the product object.

Logging

  • Admin users can now see the logs for bulk actions that are created by integrations in the Bulk Actions Log section of the Admin.

Login

  • Resetting a password in one browser and subsequently logging in through a different browser no longer results in an exception. GitHub-36447
  • Customers are now redirected to the login page after activating an account as expected. Previously, customers were automatically logged in.

Newsletter

  • Commerce now checks whether the newsletter subscription functionality is enabled before accepting new subscribers to a newsletter. GitHub-33040

Orders

  • Products moved from the Admin shopping cart to the list of items to order are now deleted as expected from the shopping cart. GitHub-37538
  • Merchants can now create credit memos as expected for the partial return of orders that were paid for in part by reward points. Previously, when a merchant created a partial return, order status was incorrectly identified as closed, and the Admin order page did not display credit memo options.
  • Magento Open Source now applies the correct discount amount to partially canceled orders. Previously, the discount amount as calculated in the base_discount_cancelled column was incorrectly calculated when an order was changed. Support for negative values has been added to invoices for discounted orders.
  • Magento Open Source now sorts custom customer address attributes based on the sort order that was provided when the admin user created the order in the Admin.
  • The Admin Sales Order Grid page now loads as expected when a merchant initiates a search from this page. Previously, when a merchant tried to search orders from this table, the page froze, and Magento Open Source displayed a Request-URI Too Long error in the browser console.
  • Improved the performance of the OrderRepository::get() method by reducing the number of times it loads an order from the database. Previously, this method loaded an order multiple times. GitHub-36636
  • Merchants can now generate credit memos for orders that contain some items with a zero total when other order items are available for refund. Previously, merchants could not perform multiple refunds when a customer had a 100% discount on some items in the order.
  • Links between child and parent products are now displayed on the order page during re-order of the child product from the Admin. GitHub-37028
  • Emulation now starts during send() calls once the emulation has completed during the getInfoBlockHtml() call, and no error are logged. Previously, the system.log file was flooded with this error: main.ERROR: Environment emulation nesting is not allowed. GitHub-35603
  • Merchants can now generate credit memos for orders that contain some items with a zero total when other order items are available for refund. Previously, merchants could not perform multiple refunds when a customer had a 100% discount on some items in the order.
  • Links between child and parent products are now displayed on the order page during re-order of the child product from the Admin. GitHub-37028
  • The header section of the order page now contains the expected information about the sent invoice, credit memo, and shipment. GitHub-27474
  • Credit memos for orders that contain only one configurable product are now generated correctly. Previously, the isLast() function did not return true as expected. GitHub-36722
  • Improved performance of the aggregate_sales_report_bestsellers_data cron job by optimizing the main data query.
  • Order status is now correct when a partial refund has been made for an order that contains bundle products. Previously, order status was listed as complete after a partial refund was issued, even though the remaining order was not complete. GitHub-37377
  • Shoppers can no longer order a product using a custom price when an order is first generated from the Admin using the one-off custom price. Previously, if an order contained an item with custom prices, this custom price was applied for other orders placed with the re-order functionality.
  • Shoppers can no longer save incorrect order statuses on the order page. Order status is no longer changed from Complete to Processing when an item is shipped. Previously, Magento Open Source did not check current order status before saving order status after a shopper entered a comment. GitHub-36562
  • The sales order grid is now asynchronously synced with all orders as expected. GitHub-36562
  • The filter-by-purchase-date functionality in the customer orders section of the orders page now works as expected. Previously, a JavaScript error occurred when the timezone conversion logic threw an error when the same time zone was provided to the method.
  • The Admin dashboard now displays the correct orders statistics on first load. Previously, the dashboard displayed incorrect order information, but displayed the correct information once the time period was updated.
  • Admin users are now redirected as expected to the order page after selecting a store view during new order creation from the Admin.
  • The GET V1/orders/<OrderID> endpoint now returns information on both the configurable and simple products in the order regardless of the stock status of the simple products. Admin users can place orders now only if the selected items (products) are in stock or salable. Previously, this API returned information only about the products that were in stock.
  • The credit memo page no longer crashes when free shipping is enabled when shipping price includes tax, and tax calculations are applied after discounts. Previously, Magento Open Source threw a Division by zero exception. GitHub-36800
  • Using the rest/V1/orders/{id}/comments endpoint to post a comment about an order without providing order status no longer affects the display of the order. Previously, order status was logged as NULL in the sales_order and sales_order_grid tables, and neither the My Orders page or the Admin order grid displayed the order. GitHub-34180