Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Guest users can subscribe to a newsletter even if the module is disabled from the Magento admin panel #39757

Closed
1 of 5 tasks
pullemall opened this issue Mar 24, 2025 · 7 comments
Assignees
Labels
Issue: needs update Additional information is require, waiting for response Reported on 2.4.6 Indicates original Magento version for the Issue report.

Comments

@pullemall
Copy link

Preconditions and environment

  • Magento version 2.4.6

Steps to reproduce

  1. Disable the newsletter module in the Magento admin panel
  2. Send the AJAX POST request to the controller newsletter/subscriber/new with necessary data e.g.: email: test@test.test
  3. Check newsletter subscribers

Expected result

When the module is disabled a guest user is unable to subscribe to newsletters

Actual result

When the module is disabled a guest user can subscribe to newsletters

Additional information

The issue happens because the controller's method \Magento\Newsletter\Controller\Subscriber\NewAction::execute doesn't check if the module is enabled or disabled, but the default config allows guests to subscribe to newsletters:

Image

Request data:
Image

Image Image

Release note

No response

Triage and priority

  • Severity: S0 - Affects critical data or functionality and leaves users without workaround.
  • Severity: S1 - Affects critical data or functionality and forces users to employ a workaround.
  • Severity: S2 - Affects non-critical data or functionality and forces users to employ a workaround.
  • Severity: S3 - Affects non-critical data or functionality and does not force users to employ a workaround.
  • Severity: S4 - Affects aesthetics, professional look and feel, “quality” or “usability”.
Copy link

m2-assistant bot commented Mar 24, 2025

Hi @pullemall. Thank you for your report.
To speed up processing of this issue, make sure that the issue is reproducible on the vanilla Magento instance following Steps to reproduce.


Join Magento Community Engineering Slack and ask your questions in #github channel.
⚠️ According to the Magento Contribution requirements, all issues must go through the Community Contributions Triage process. Community Contributions Triage is a public meeting.
🕙 You can find the schedule on the Magento Community Calendar page.
📞 The triage of issues happens in the queue order. If you want to speed up the delivery of your contribution, join the Community Contributions Triage session to discuss the appropriate ticket.

@engcom-Bravo engcom-Bravo self-assigned this Mar 24, 2025
Copy link

m2-assistant bot commented Mar 24, 2025

Hi @engcom-Bravo. Thank you for working on this issue.
In order to make sure that issue has enough information and ready for development, please read and check the following instruction: 👇

  • 1. Verify that issue has all the required information. (Preconditions, Steps to reproduce, Expected result, Actual result).
  • 2. Verify that issue has a meaningful description and provides enough information to reproduce the issue.
  • 3. Add Area: XXXXX label to the ticket, indicating the functional areas it may be related to.
  • 4. Verify that the issue is reproducible on 2.4-develop branch
    Details- If the issue is reproducible on 2.4-develop branch, please, add the label Reproduced on 2.4.x.
    - If the issue is not reproducible, add your comment that issue is not reproducible and close the issue and stop verification process here!
  • 5. Add label Issue: Confirmed once verification is complete.
  • 6. Make sure that automatic system confirms that report has been added to the backlog.

@engcom-Bravo engcom-Bravo added the Reported on 2.4.6 Indicates original Magento version for the Issue report. label Mar 24, 2025
@engcom-Bravo
Copy link
Contributor

Hi @pullemall,

Thanks for your reporting and collaboration.

we have tried to reproduce the issue in latest 2.4-develop instance and we are not able to reproduce the issue.kindly refer the screenshots.

Image Image

unable to subscribe to newsletters.

kindly recheck the issue in latest 2.4-develop instance and elaborate the steps to reproduce if the issue is still reproducible.

Thanks.

@engcom-Bravo engcom-Bravo added the Issue: needs update Additional information is require, waiting for response label Mar 24, 2025
@pullemall
Copy link
Author

pullemall commented Mar 24, 2025

Hi @@engcom-Bravo
Thanks for your reply.
You don't need to disable the module itself on the server, only turn it off from the Magento admin panel. Sorry for the ambiguity.

Image

@engcom-Bravo
Copy link
Contributor

Hi @pullemall,

Thanks for your quick update.

We have tried to reproduce the issue in Latest 2.4-develop instance and we are not able to reproduce the issue.kindly refer the screenshots.

Image Image

guest user is unable to subscribe to newsletters.Could you please let us know if we are missing anything.

Thanks.

@pullemall
Copy link
Author

Hi @engcom-Bravo,

Thanks for checking.

May I ask you how you know that this didn't work? Have you checked the newsletter subscribers, as I described in the third step?

Image

@engcom-Bravo
Copy link
Contributor

Hi @pullemall,

Thanks for your update.

We have tried to reproduce the issue in Latest 2.4-develop instance and we are not able to reproduce the issue.kindly refer the screenshots.

Image Image

guest user is unable to subscribe to newsletters.Could you please let us know if we are missing anything.

Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Issue: needs update Additional information is require, waiting for response Reported on 2.4.6 Indicates original Magento version for the Issue report.
Projects
None yet
Development

No branches or pull requests

2 participants