diff --git a/storefront/templates/app/controllers/carts_controller.rb b/storefront/templates/app/controllers/carts_controller.rb index c1438932ce..d2f5a80f80 100644 --- a/storefront/templates/app/controllers/carts_controller.rb +++ b/storefront/templates/app/controllers/carts_controller.rb @@ -55,12 +55,20 @@ def accurate_title def order_params if params[:order] - params[:order].permit(*permitted_order_attributes) + params[:order].permit(*permitted_cart_attributes) else {} end end + def permitted_cart_attributes + permitted_attributes.customer_metadata_attributes + + [ + :email, + line_items_attributes: permitted_line_item_attributes, + ] + end + def assign_order @order = current_order unless @order diff --git a/storefront/templates/spec/requests/carts_spec.rb b/storefront/templates/spec/requests/carts_spec.rb index aa3132c68a..52f68692ae 100644 --- a/storefront/templates/spec/requests/carts_spec.rb +++ b/storefront/templates/spec/requests/carts_spec.rb @@ -60,6 +60,16 @@ expect(response).to redirect_to checkout_state_path("address") end + + context "when sending payment attributes" do + let(:check) { create(:check_payment_method) } + + it "does not allow creating a payment" do + expect { + patch cart_path, params: {order: {payments_attributes: [{amount: 10.0, payment_method_id: check.id}]}} + }.not_to change { order.reload.payments.count } + end + end end end