Commerce Decoupled Checkout
Anyone without logging in could send unsafe order details to the remote order creation data feed. They could add false items to a shopping basket. They could not view other peoples orders.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Commerce Decoupled Checkout to 8.x-1.8.
For developers: what the fix changed
The fix introduces an allowlist for order fields in `OrderCreateResource::validateInput()` to reject unexpected properties, and updates `validateEntity()` to enforce all field constraints. It also adds a settings form in `SettingsForm.php` to configure permitted custom order fields.
README.md+14 −0commerce_decoupled_checkout.install+20 −0commerce_decoupled_checkout.links.menu.yml+5 −0commerce_decoupled_checkout.routing.yml+7 −0config/install/commerce_decoupled_checkout.settings.yml+1 −0config/schema/commerce_decoupled_checkout.schema.yml+10 −0src/Form/SettingsForm.php+106 −0 fixsrc/Plugin/rest/resource/OrderCreateResource.php+99 −12 fix