Repository navigation
Release new version - #441
Merged
Merged
Conversation
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
October 8, 2026 06:12
07455f2 to
ccc6bbd
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
October 8, 2026 06:14
ccc6bbd to
b6c4691
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@labdigital/commercetools-mock@5.0.0
Major Changes
#428
28773deThanks @korsvanloon! - Scope the/meandas-associateendpoints to the caller, and fail closed.This is a breaking change. Both scopes used to answer from the whole
collection:
/me/orders/{id}returned any order, and an associate-scopedrequest accepted any
associateIdand ignored the business unit in the path.A test asserting that a shopper cannot read someone else's order, or that an
associate cannot see a colleague's cart, passed whether or not the code under
test actually scoped its request.
/menow answers for the customer or anonymous session the bearer token wasissued for, and returns
403 insufficient_scopewithout one. A resourcebelonging to someone else is
404, not a leak. Resources created through/meare stamped with the caller.
as-associateresolves the associate named in the path against the businessunit named in the path, collects the permissions of their AssociateRoles, and
enforces all 47 of them.
Mymeans the resource's customer is the actingassociate;
Othersmeans a different customer in the same business unit. A listrequest with only the
Mypermission is narrowed rather than refused; anythingelse missing returns
403 AssociateMissingPermissioncarrying the permissionsthat would have sufficed. A resource of another business unit is
404.Migrating. Tests that call these endpoints now need to say who is calling.
A new
@labdigital/commercetools-mock/testingentrypoint exportscustomerSession,loginCustomerandanonymousSessionfor/me, andcreateAssociateScopefor the associate scope, which seeds the customer,associate role and business unit in one call.
Identity resolution no longer depends on
enableAuthentication: the mock alwaysreads the identity from a token it issued, so scoping works without turning
authentication on.
Also in this change, because the scopes are unusable without them:
POST /oauth/{projectKey}/anonymous/tokenhonours a suppliedanonymous_idinstead of always generating one.
PaymentDraft.customerandanonymousIdare stored.businessUnit.GET /me/active-cartanswers for the caller instead of returning the firstactive cart in the project.
Minor Changes
#438
88f3808Thanks @korsvanloon! - Support the seller's side of the quote flow:quoteRequestVersion, prices the offer in a copy of the requested cart, and honoursquoteRequestStateToAccepted.Pendingstate (it wasAccepted) from anInProgressstaged quote only, checksstagedQuoteVersion, carries the staged quote'svalidTo,sellerComment, business unit and store, and honoursstagedQuoteStateToSent.changeStagedQuoteState,setSellerCommentandsetValidTo.changeQuoteStateandrequestQuoteRenegotiation.DeclinedForRenegotiationcan only be reached through a renegotiation request.#442
74ac7b5Thanks @mvantellingen! - Support thesetCarrierupdate action on shipping methods#435
7a33c6bThanks @robertmoelker! - Support custom fields on addresses.BaseAddressis polymorphic between read and write, so address drafts can carry acustomfield holding aCustomFieldsDraft. Drafts and update actions carrying such an address (customer, business unit, cart, order and channel) now resolve it toCustomFieldsagainst the referenced type, returning a 400ReferencedResourceNotFoundwhen the type does not exist. In strict mode the generated draft schemas accept and validatecustomon an address.Customer and business unit creation, and the
addAddresscustomer action, now go through the sharedcreateAddresshelper, which means the addresscountryfield is enforced there as well.#430
2e8ae39Thanks @mvantellingen! - PersistexpansionPaths,dependenciesandadditionalContextwhen creatingan API Extension.
The Extension repository only copied
key,timeoutInMs,destinationandtriggersout of the draft, so the three fields added by the 2026-03-12 APIrelease were silently dropped on create.
POST /{projectKey}/extensionswithexpansionPathsreturned an extension without them, which made it look likethe field was rejected. The
setExpansionPaths,setDependenciesandsetAdditionalContextupdate actions were already implemented, so only thecreate path was affected.
dependenciesare now resolved through the storage layer like every otherresource identifier, so they can be given by
keyas well as byid(on bothcreate and
setDependencies, which previously assumedidwas set) and anunknown dependency returns a
ReferencedResourceNotFounderror instead of areference with
id: undefined.Patch Changes
#442
f45820eThanks @mvantellingen! - Update dependencies#433
74adf7cThanks @robertmoelker! - Update astro (docs) to v7.* for security reasons#432
756eb56Thanks @robertmoelker! - Enforce BusinessUnit key uniqueness within a project. Creating a business unit with a key that is already taken now returns a 400DuplicateFielderror on thekeyfield instead of silently storing a second unit under the same key.#432
756eb56Thanks @robertmoelker! -clear()now also resets the auth store. Tokens issued before aclear()used to stay valid and keep resolving to customers and anonymous sessions that no longer existed, leaking identity between tests. Tests that issue a token (for example throughcustomerSession) must do so after eachclear().#436
8a8a282Thanks @jsm1t! - Fixcontains any/contains allthrowing on resources where the field is notset.
The handler rejected any non-array value, so a predicate such as
custom(fields(orderNumbers contains any ("R-123")))raisedThe field 'orderNumbers' does not support this expression.as soon as oneresource in the collection lacked the field — failing the entire query rather
than filtering that resource out. Real commercetools treats an unset set as
having no members, so it simply does not match.
An unset (
undefinedornull) field now evaluates tofalse. A field that ispresent but is not a set still raises a
PredicateError, since that is agenuine type mismatch.
#434
cb56f14Thanks @robertmoelker! - Scope customer email uniqueness to the stores a customer is assigned to. The same email can now be used in different stores, matching commercetools behaviour. Customers created through an in-store endpoint are assigned to that store, and the in-store password flow only matches customers of that store.Implement the
addStore,removeStoreandsetStorescustomer update actions, which re-validate email uniqueness for any store scope the customer newly enters (including becoming a global customer again).Store resource identifiers are now validated by
keyas well as byid, so referencing a non-existent store in a draft returns a 400ReferencedResourceNotFounderror instead of silently passing through. This also fixesgetStoreKeyReference, which previously always failed forid-based references.In-store endpoints (
/{projectKey}/in-store/key={storeKey}/...) now return a 404ResourceNotFoundwhen the store in the path does not exist, matching commercetools.#439
b120400Thanks @jsm1t! - Support the infixnot inoperator in query predicates.A predicate such as
custom(fields(externalOrderType not in :hiddenOrderTypes))failed with
Unexpected token: not, becausenotwas only understood as aprefix (
not (...)). Real commercetools documentsage not in (42, 43, 44)asa membership check, so
not innow matches every resource thatinwould not.The prefix
not (...)form also forwards query variables to the negatedexpression now, so
not (field in :values)no longer ignores:values.