Skip to content

fix(discovery): allow root UCP profile route - #256

Closed
Björn Meyer (BrocksiNet) wants to merge 5 commits into
mainfrom
fix/ucp-profile-root-route-scope
Closed

Björn Meyer (BrocksiNet) wants to merge 5 commits into
mainfrom
fix/ucp-profile-root-route-scope

Conversation

@BrocksiNet

Copy link
Copy Markdown
Contributor

Summary

  • Whitelist the SDK UCP profile controller during Shopware route-scope validation.
  • Register the whitelist in the Shopware container.
  • Add unit and functional regression coverage for the root profile endpoint.

Issue

Closes #251

A request to /.well-known/ucp on the root storefront domain can be rejected with 412 Invalid route scope before Shopware resolves the sales-channel domain. The same endpoint works on a localized domain.

Validation

  • Trunk request: GET /.well-known/ucp returns 200 application/json.
  • PHPUnit route-scope regression test: 2 tests, 3 assertions.
  • PHP-CS-Fixer and PHP syntax checks pass.

@BrocksiNet
Björn Meyer (BrocksiNet) marked this pull request as ready for review September 23, 2026 10:11
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T10:14:48.927460Z d9f8f22 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@dgrothaus-sw

Copy link
Copy Markdown
Contributor

Björn Meyer (@BrocksiNet) Could you actually reproduce the behaviour? Because I couldn't with a setup that is similar to the mentioned one. If you could reproduce, then perhaps something is broken with my environment. But if not, this perhaps is caused by a plugin.

If you could reproduce, this fix is not complete. There's no test that fails with the old behaviour and succeeds with the fix. The unit test only shows that it honours an allow-list. The integration test hits the same domain as the sibling test.

And the fix itself only covers one route. Every SDK route inherits from the storefront scope (routes.php:43-45) as does /.well-known/api-catalog. The discovery of the domain would pass, but every call to cart, catalog or checkout would return 412.

@BrocksiNet

Copy link
Copy Markdown
Contributor Author

Thanks, Dominik Grothaus (@dgrothaus-sw). I rechecked the earlier logs and repeated the trunk checks with the whitelist disabled. Both root and language-prefixed discovery routes return 200 locally, including with five sales-channel domains. The 412 was observed on the reported shop, not reproduced on trunk.

Closing this PR because we have not established the cause or a failing regression test, and the profile-only whitelist leaves the API catalog failure unresolved. Issue #251 remains open; we are asking for the exact versions, active plugins, and relevant routing configuration to investigate a possible plugin or configuration interaction.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UCP profile endpoint fails with "Invalid route scope" on the root domain, but works on a language-suffixed domain of the same host

2 participants