diff --git a/vendor/magento/module-customer/Model/AccountManagement.php b/vendor/magento/module-customer/Model/AccountManagement.php index 3b00721ac8b9..7c75095c895f 100644 --- a/vendor/magento/module-customer/Model/AccountManagement.php +++ b/vendor/magento/module-customer/Model/AccountManagement.php @@ -842,11 +842,6 @@ public function getConfirmationStatus($customerId) */ public function createAccount(CustomerInterface $customer, $password = null, $redirectUrl = '') { - $groupId = $customer->getGroupId(); - if (isset($groupId) && !$this->authorization->isAllowed(self::ADMIN_RESOURCE)) { - $customer->setGroupId(null); - } - if ($password !== null) { $this->checkPasswordStrength($password); $customerEmail = $customer->getEmail(); diff --git a/vendor/magento/module-customer/Model/AccountManagementApi.php b/vendor/magento/module-customer/Model/AccountManagementApi.php index 02a05705b57e..8b4f78ab26c7 100644 --- a/vendor/magento/module-customer/Model/AccountManagementApi.php +++ b/vendor/magento/module-customer/Model/AccountManagementApi.php @@ -6,16 +6,127 @@ namespace Magento\Customer\Model; +use Magento\Customer\Api\AddressRepositoryInterface; +use Magento\Customer\Api\CustomerMetadataInterface; +use Magento\Customer\Api\CustomerRepositoryInterface; use Magento\Customer\Api\Data\CustomerInterface; +use Magento\Customer\Api\Data\ValidationResultsInterfaceFactory; +use Magento\Customer\Helper\View as CustomerViewHelper; +use Magento\Customer\Model\Config\Share as ConfigShare; +use Magento\Customer\Model\Customer as CustomerModel; +use Magento\Customer\Model\Metadata\Validator; +use Magento\Framework\Api\ExtensibleDataObjectConverter; +use Magento\Framework\App\Config\ScopeConfigInterface; +use Magento\Framework\AuthorizationInterface; +use Magento\Framework\DataObjectFactory as ObjectFactory; +use Magento\Framework\Encryption\EncryptorInterface as Encryptor; +use Magento\Framework\Event\ManagerInterface; +use Magento\Framework\Exception\AuthorizationException; +use Magento\Framework\Mail\Template\TransportBuilder; +use Magento\Framework\Math\Random; +use Magento\Framework\Reflection\DataObjectProcessor; +use Magento\Framework\Registry; +use Magento\Framework\Stdlib\DateTime; +use Magento\Framework\Stdlib\StringUtils as StringHelper; +use Magento\Store\Model\StoreManagerInterface; +use Psr\Log\LoggerInterface as PsrLogger; /** * Account Management service implementation for external API access. + * * Handle various customer account actions. * * @SuppressWarnings(PHPMD.CookieAndSessionMisuse) + * @SuppressWarnings(PHPMD.CouplingBetweenObjects) */ class AccountManagementApi extends AccountManagement { + /** + * @var AuthorizationInterface + */ + private $authorization; + + /** + * @param CustomerFactory $customerFactory + * @param ManagerInterface $eventManager + * @param StoreManagerInterface $storeManager + * @param Random $mathRandom + * @param Validator $validator + * @param ValidationResultsInterfaceFactory $validationResultsDataFactory + * @param AddressRepositoryInterface $addressRepository + * @param CustomerMetadataInterface $customerMetadataService + * @param CustomerRegistry $customerRegistry + * @param PsrLogger $logger + * @param Encryptor $encryptor + * @param ConfigShare $configShare + * @param StringHelper $stringHelper + * @param CustomerRepositoryInterface $customerRepository + * @param ScopeConfigInterface $scopeConfig + * @param TransportBuilder $transportBuilder + * @param DataObjectProcessor $dataProcessor + * @param Registry $registry + * @param CustomerViewHelper $customerViewHelper + * @param DateTime $dateTime + * @param CustomerModel $customerModel + * @param ObjectFactory $objectFactory + * @param ExtensibleDataObjectConverter $extensibleDataObjectConverter + * @param AuthorizationInterface $authorization + * @SuppressWarnings(PHPMD.ExcessiveParameterList) + */ + public function __construct( + CustomerFactory $customerFactory, + ManagerInterface $eventManager, + StoreManagerInterface $storeManager, + Random $mathRandom, + Validator $validator, + ValidationResultsInterfaceFactory $validationResultsDataFactory, + AddressRepositoryInterface $addressRepository, + CustomerMetadataInterface $customerMetadataService, + CustomerRegistry $customerRegistry, + PsrLogger $logger, + Encryptor $encryptor, + ConfigShare $configShare, + StringHelper $stringHelper, + CustomerRepositoryInterface $customerRepository, + ScopeConfigInterface $scopeConfig, + TransportBuilder $transportBuilder, + DataObjectProcessor $dataProcessor, + Registry $registry, + CustomerViewHelper $customerViewHelper, + DateTime $dateTime, + CustomerModel $customerModel, + ObjectFactory $objectFactory, + ExtensibleDataObjectConverter $extensibleDataObjectConverter, + AuthorizationInterface $authorization + ) { + $this->authorization = $authorization; + parent::__construct( + $customerFactory, + $eventManager, + $storeManager, + $mathRandom, + $validator, + $validationResultsDataFactory, + $addressRepository, + $customerMetadataService, + $customerRegistry, + $logger, + $encryptor, + $configShare, + $stringHelper, + $customerRepository, + $scopeConfig, + $transportBuilder, + $dataProcessor, + $registry, + $customerViewHelper, + $dateTime, + $customerModel, + $objectFactory, + $extensibleDataObjectConverter + ); + } + /** * @inheritDoc * @@ -23,9 +134,30 @@ class AccountManagementApi extends AccountManagement */ public function createAccount(CustomerInterface $customer, $password = null, $redirectUrl = '') { + $this->validateCustomerRequest($customer); $customer = parent::createAccount($customer, $password, $redirectUrl); $customer->setConfirmation(null); return $customer; } + + /** + * Validate anonymous request + * + * @param CustomerInterface $customer + * @return void + * @throws AuthorizationException + */ + private function validateCustomerRequest(CustomerInterface $customer): void + { + $groupId = $customer->getGroupId(); + if (isset($groupId) && + !$this->authorization->isAllowed(self::ADMIN_RESOURCE) + ) { + $params = ['resources' => self::ADMIN_RESOURCE]; + throw new AuthorizationException( + __("The consumer isn't authorized to access %resources.", $params) + ); + } + } } diff --git a/vendor/magento/module-customer/Plugin/AsyncRequestCustomerGroupAuthorization.php b/vendor/magento/module-customer/Plugin/AsyncRequestCustomerGroupAuthorization.php new file mode 100644 index 000000000000..5b5c8ce1fc0c --- /dev/null +++ b/vendor/magento/module-customer/Plugin/AsyncRequestCustomerGroupAuthorization.php @@ -0,0 +1,78 @@ +authorization = $authorization; + } + + /** + * Validate groupId for anonymous request + * + * @param MassSchedule $massSchedule + * @param string $topic + * @param array $entitiesArray + * @param string|null $groupId + * @param string|null $userId + * @return null + * @throws AuthorizationException + * @SuppressWarnings(PHPMD.UnusedFormalParameter) + */ + public function beforePublishMass( + MassSchedule $massSchedule, + string $topic, + array $entitiesArray, + string $groupId = null, + string $userId = null + ) { + foreach ($entitiesArray as $entityParams) { + foreach ($entityParams as $entity) { + if ($entity instanceof CustomerInterface) { + $groupId = $entity->getGroupId(); + if (isset($groupId) && !$this->authorization->isAllowed(self::ADMIN_RESOURCE)) { + $params = ['resources' => self::ADMIN_RESOURCE]; + throw new AuthorizationException( + __("The consumer isn't authorized to access %resources.", $params) + ); + } + } + } + } + return null; + } +} diff --git a/vendor/magento/module-customer/composer.json b/vendor/magento/module-customer/composer.json index 7479d6662845..a9548f9037d3 100644 --- a/vendor/magento/module-customer/composer.json +++ b/vendor/magento/module-customer/composer.json @@ -35,7 +35,8 @@ "suggest": { "magento/module-cookie": "100.4.*", "magento/module-customer-sample-data": "Sample Data version: 100.4.*", - "magento/module-webapi": "100.4.*" + "magento/module-webapi": "100.4.*", + "magento/module-asynchronous-operations": "100.4.*" }, "autoload": { "files": [ diff --git a/vendor/magento/module-customer/etc/di.xml b/vendor/magento/module-customer/etc/di.xml index 156986b7b4a3..120a8dda8aec 100644 --- a/vendor/magento/module-customer/etc/di.xml +++ b/vendor/magento/module-customer/etc/di.xml @@ -560,4 +560,9 @@ + + +