|
Tip
|
The 2.x versions are Spring Boot 3 compatible. |
Introduced new version of CartEndpoint#readHistoricalCartForAnonymousCustomer that returns only anonymous carts.
GET /api/cart/carts?emailAddress=<value>&orderNumber=<value>&historical=true
Deprecated older version that returned mixed carts
Include Accept-Version=2 as a header to use the new endpoint if calling in custom code, or set broadleaf.cartoperation.cartprovider.readHistoricalCartForAnonymousCustomerEndpointVersion=2 in Cart Operations Service to use the new endpoint.
Introduced new endpoint to read historical carts by Order Number only for both anonymous and registered users.
GET /api/cart/carts?orderNumber=<value>
Additional ownership filtering should be performed by the caller and is automatically performed in Cart Operations Service in the following versions:
2.1.6 (RT 2.1.7)
2.2.3 (RT 2.2.3)
2.3.1 (RT 2.3.1)
Previously, the View Quote Details action on the Quote list grid in the Admin would appear even if the user did not have impersonation permissions despite those being required for the action to succeed.
To address this, the IMPERSONATE scope has been added to the View Quote Details action to ensure it is hidden for users that lack it so they avoid encountering the error and having to spend time debugging.
This requires also including the following changes in the Auth Service schema to add a missing security scope and permission-scope mapping for impersonation:
-- Add scope
INSERT INTO blc_security_scope (id, name, open) VALUES ('IMPERSONATE', 'IMPERSONATE', 'N');
-- Map to the root permission
INSERT INTO blc_permission_scope (id, permission, is_permission_root, scope_id) VALUES ('IMPERSONATE', 'IMPERSONATE', 'Y', 'IMPERSONATE');
|
Tip
|
If for any reason, you need to disable this change, set the following
|