freento/module-disable-carts-endpoint 问题修复 & 功能扩展

解决BUG、新增功能、兼容多环境部署,快速响应你的开发需求

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

freento/module-disable-carts-endpoint

Composer 安装命令:

composer require freento/module-disable-carts-endpoint

包简介

Magento 2 module that blocks the PUT /V1/guest-carts/:cartId/order REST API endpoint to prevent card testing (carding) attacks via guest checkout.

README 文档

README

Magento 2 module that blocks the PUT /V1/guest-carts/:cartId/order REST API endpoint to prevent card testing (carding) attacks via guest checkout.

Problem

Magento's core exposes PUT /V1/guest-carts/:cartId/order as an anonymous endpoint (ref="anonymous"). It is not used by the default frontend checkout but is fully functional. Bots exploit it to test stolen credit cards — they can place orders with minimal API calls and no authentication.

How it works

The module intercepts requests at the WebAPI validation layer via a plugin on RequestValidatorInterface. When enabled, any PUT request matching /V1/guest-carts/:cartId/order is rejected with a 404 response, making the endpoint appear non-existent.

The standard checkout endpoint POST /V1/guest-carts/:cartId/payment-information is not affected.

Installation

composer require freento/module-disable-carts-endpoint
bin/magento module:enable Freento_DisableCartsEndpoint
bin/magento setup:upgrade

Configuration

The module is disabled by default. Enable it in the admin panel:

Stores → Configuration → Freento → Disable Carts Endpoint → General Settings → Disable PUT /V1/guest-carts/:cartId/order endpoint → Yes

Compatibility

  • Magento 2.4.x
  • Adobe Commerce / Magento Open Source

统计信息

  • 总下载量: 0
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 0
  • 点击次数: 6
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 0
  • Watchers: 0
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2026-03-26

承接程序开发

PHP开发

VUE

Vue开发

前端开发

小程序开发

公众号开发

系统定制

数据库设计

云部署

网站建设

安全加固