commerce_decoupled_checkoutThis module enables REST endpoints for a decoupled Commerce experience which allow for remote order creation.
The module doesn't sufficiently sanitize order data passed into the order creation endpoint, which allows for potentially unsafe order properties to be set on an order.
Install the latest version of the module:
- Update to Commerce Decoupled Checkout 8.x-1.8.
The standard order fields type, email, store, and order_items remain accepted by default.
Sites submitting additional custom order fields must explicitly enable them at /admin/commerce/config/decoupled-checkout. Requests containing fields outside this allowlist will be rejected.
Run database updates and configure the required customer-writable fields before resuming checkout.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team