Contributions
Shaping the tools I use every day, one pull request at a time
A hand-picked selection: only the contributions worth reading about, not every merged pull request. Articles about Magento and Adobe Commerce are on the blog.
Handle malformed UTF-8 in the CatalogWidget cache key — on GitHub
ProductsList::getCacheKeyInfo() serialized raw $_GET — so a single malformed byte in the query string threw out of json_encode() and took the whole page down to the generic error page. Bots find those bytes for you.
Change quote.applied_rule_ids to TEXT — on GitHub
quote.applied_rule_ids was VARCHAR(255) while quote_item and quote_address_item used TEXT. Past ~100 applied rules the parent column truncated and stopped matching its children.
Stop evaluating project .env values as shell code — on GitHub
loadEnvConfig piped the project .env straight into eval, so cloning a repository and running any warden env command executed whatever the .env author put in a variable value. Replaced with parsing that does not run the file.
Expose invoice and credit memo CRUD, API routes and events — on GitHub
The entities, validators, ACL features and search indexes were already there — nothing exposed them. Added the commands, /api/sales/invoices and /api/sales/credit-memos routes, credit memo events, document number sequences and audit-trail keys across 15 files.
Show the country in order grid address columns — on GitHub
Sales > Orders rendered street, city, region and postcode but not the country, which is ambiguous for anyone shipping internationally. Added country_id to both address aggregators.
Enable the compiled configuration cache for test execution — on GitHub
The compiled_config cache holds the merged di.xml graph, and integration tests rebuilt it instead of reusing it. Straight wall-clock off every suite run.
Handle negative page numbers on category listings — on GitHub
A negative ?p= value was treated as a valid request and ended in an exception instead of a sensible response — trivially reachable by any crawler that guesses at URLs.
Fix the escaping example in the view models guide — on GitHub
Official docs showed $block->escape…() for output escaping and had the @var annotation the wrong way round. Documentation is copy-pasted into production more often than anyone admits.
Escape table names so encryption key rotation survives them — on GitHub
Table names containing special characters broke the generated SQL mid-rotation — a bad moment to discover a quoting bug, given what the tool is re-encrypting.
Only merged work is listed here, and only the parts worth a comment — the full history, including everything still in review, lives on GitHub.
app/bootstrap.phpstill gated on PHP 8.1 whilecomposer.jsondemanded 8.3, so anyone on 8.1 or 8.2 sailed past the friendly message and hit an opaque Composer failure instead.