Broadleaf Microservices
  • v1.0.0-latest-prod

Cart Services Release Notes for 2.1.6-GA

Tip
The 2.x versions are Spring Boot 3 compatible.

Requirements

  • JDK 17 is required for Broadleaf release trains 2.0.0-GA, and beyond.

New Features & Notable Changes

Historical Cart Lookup

  • Introduced new version of CartEndpoint#readHistoricalCartForAnonymousCustomer that returns only anonymous carts.

    • GET /api/cart/carts?emailAddress=<value>&orderNumber=<value>&historical=true

    • Deprecated older version that returned mixed carts

    • Include Accept-Version=2 as a header to use the new endpoint if calling in custom code, or set broadleaf.cartoperation.cartprovider.readHistoricalCartForAnonymousCustomerEndpointVersion=2 in Cart Operations Service to use the new endpoint.

  • Introduced new endpoint to read historical carts by Order Number only for both anonymous and registered users.

    • GET /api/cart/carts?orderNumber=<value>

    • Additional ownership filtering should be performed by the caller and is automatically performed in Cart Operations Service in the following versions:

      • 2.1.6 (RT 2.1.7)

      • 2.2.3 (RT 2.2.3)

      • 2.3.1 (RT 2.3.1)

Bug Fixes

Hide View Quote Details Admin Action if Missing Impersonation Permission

Previously, the View Quote Details action on the Quote list grid in the Admin would appear even if the user did not have impersonation permissions despite those being required for the action to succeed. To address this, the IMPERSONATE scope has been added to the View Quote Details action to ensure it is hidden for users that lack it so they avoid encountering the error and having to spend time debugging.

View Quote Details Reference

This requires also including the following changes in the Auth Service schema to add a missing security scope and permission-scope mapping for impersonation:

-- Add scope
INSERT INTO blc_security_scope (id, name, open) VALUES ('IMPERSONATE', 'IMPERSONATE', 'N');
-- Map to the root permission
INSERT INTO blc_permission_scope (id, permission, is_permission_root, scope_id) VALUES ('IMPERSONATE', 'IMPERSONATE', 'Y', 'IMPERSONATE');
Tip

If for any reason, you need to disable this change, set the following

broadleaf:
  cart:
    metadata:
      impersonation-permission-required-to-view-quote-details: false