From 1030aaa314654b4ed48a4df19e1ccd8348ad31d0 Mon Sep 17 00:00:00 2001 From: Adam Mueller Date: Thu, 17 Sep 2026 15:30:21 -0700 Subject: [PATCH] Reduce permitted attributes for cart update The storefront cart controller was using the permitted_order_attributes which allow for editing address, delivery, payment, confirm, and line item attributes. However, the cart endpoint is only actively used to update line item quantities. Furthermore, some of the attributes that it permits aren't actually usable by this endpoint. For example, passing payment attributes is entirely useless outside of creating new check payments. All other payment methods require a source and it's not possible to pass through source_attributes in this method because it doesn't make use of the PaymentCreate object that handles setting up the source from the attributes. (And you can't modify existing payments because ID is not a valid attribute.) The only allowed attributes moving forward are: - Customer metadata - Email (our specs establish this as a valid attribute, so I've left it in.) - Line item attributes (the primary use-case) If an app still needs or wants to use the cart controller for updating other attributes, they can easily add more to the permitted_cart_attributes method. --- .../templates/app/controllers/carts_controller.rb | 10 +++++++++- storefront/templates/spec/requests/carts_spec.rb | 10 ++++++++++ 2 files changed, 19 insertions(+), 1 deletion(-) diff --git a/storefront/templates/app/controllers/carts_controller.rb b/storefront/templates/app/controllers/carts_controller.rb index c1438932cee..d2f5a80f802 100644 --- a/storefront/templates/app/controllers/carts_controller.rb +++ b/storefront/templates/app/controllers/carts_controller.rb @@ -55,12 +55,20 @@ def accurate_title def order_params if params[:order] - params[:order].permit(*permitted_order_attributes) + params[:order].permit(*permitted_cart_attributes) else {} end end + def permitted_cart_attributes + permitted_attributes.customer_metadata_attributes + + [ + :email, + line_items_attributes: permitted_line_item_attributes, + ] + end + def assign_order @order = current_order unless @order diff --git a/storefront/templates/spec/requests/carts_spec.rb b/storefront/templates/spec/requests/carts_spec.rb index aa3132c68a0..52f68692ae8 100644 --- a/storefront/templates/spec/requests/carts_spec.rb +++ b/storefront/templates/spec/requests/carts_spec.rb @@ -60,6 +60,16 @@ expect(response).to redirect_to checkout_state_path("address") end + + context "when sending payment attributes" do + let(:check) { create(:check_payment_method) } + + it "does not allow creating a payment" do + expect { + patch cart_path, params: {order: {payments_attributes: [{amount: 10.0, payment_method_id: check.id}]}} + }.not_to change { order.reload.payments.count } + end + end end end