All notable, unreleased changes to this project will be documented in this file. For the released changes, please visit the Releases page.
-
Fix missing denormalization of shipping methods metadata when creating an order.
- Shipping method metadata is now copied to dedicated order fields (
shipping_method_metadataandshipping_method_private_metadata) during checkout-to-order conversion. This ensures that order metadata remains consistent even if the original shipping method is modified or deleted. As a result, updates made to a shipping method's metadata after order creation will no longer be reflected in the order'sshippingMethod.metadatafield. - Shipping method metadata is now also denormalized during draft order finalization, ensuring consistent behavior across all order creation flows.
- Shipping method metadata is now copied to dedicated order fields (
-
Fields
options,mountandtargetare removed fromAppExtensionandAppManifestExtensiontypes. UsemountName,targetNameandsettings -
Deprecate the
hasVariantsfield onProductType. This setting is a legacy artifact from the former Simple/Configurable product distinction. Products can have multiple variants regardless of this flag. Previously, it only prevented assigning variant attributes to a product type; this restriction will no longer apply. -
Improved error handling in Federation - #18718 by @NyanKiyoshi
The type for GraphQL field
representationsin{ _entities(representations: [_Any!]!) { ... } }was changed.Before:
[_Any]After:[_Any!]!Make sure to adapt your GraphQL queries if you use the
_entitiesquery. -
Mutations
channelCreateandchannelUpdatenow raise GraphQL errors insteadINVALIDwhen negativeMINUTE/HOUR/DAYvalues are passed. -
AppInstallInputforappInstallmutation now requiresappNameandmanifestUrlfields in the schema, matching the validation that was always enforced by the mutation logic. -
Removed Adyen plugin (payment gateway). Switch to the app.
-
Removed
partialfield from thePaymentGraphQL type. This field was an Adyen-specific workaround and always returnedfalseafter the Adyen plugin removal. Ensure you are not relying on this field (on Adyen gateway in general) before upgrading. -
Removed the NP Atobarai payment gateway plugin (
saleor.payment.gateways.np_atobarai). Use the App instead.
- Gift cards support as payment method within Transaction API (read more in the docs).
Attributefieldsname,slugandtypeare now non-nullable in schema.- Added new scalar
NonNegativeIntwhich allows integer values greater than or equal to zero. - Scalars
Minute,HourandDaynow inherit fromNonNegativeInt, which mean GraphQL disallows negative values for time units. - Removed
partialfield from thePaymentGraphQL type.
- For order webhook events, sync webhooks (such as
ORDER_CALCULATE_TAXESandORDER_FILTER_SHIPPING_METHODS) are no longer pre-fired before sending async webhook events. Sync webhooks are now only triggered when their data is actually requested, improving performance and decoupling async event delivery from sync webhook execution. - Building payloads for webhook order events (including draft orders and fulfillments) is now delegated to a separate background task. This speeds up the execution of most order mutations by deferring the expensive payload serialization out of the request path.
-
Introduced
deliveryOptionsCalculatemutation to give storefronts explicit, deterministic control over when shipping webhook calls happen. PreviouslySHIPPING_LIST_METHODS_FOR_CHECKOUTandCHECKOUT_FILTER_SHIPPING_METHODSwebhooks were fired implicitly, inside checkout mutations (e.g., on address change) and while resolving query fields, causing unpredictable latency, uncontrolled webhook traffic, and increased costs. Developers can now decide exactly when to fetch delivery options by callingdeliveryOptionsCalculate, which returns a list ofDeliveryobjects.The selected delivery method is available on the new
Checkout.deliveryfield, which replaces the deprecatedCheckout.shippingMethodandCheckout.deliveryMethodfields.To help storefronts detect when the delivery method requires attention, two new problem types are introduced in
Checkout.problems:CheckoutProblemDeliveryMethodStale: the currently selected method may be outdated due to checkout changes (e.g., a different shipping address, an applied voucher). This problem does not block checkout completion but triggers re-validation of the delivery method whencheckoutCompleteis called. CallingdeliveryOptionsCalculatewill re-validate the assigned delivery.CheckoutProblemDeliveryMethodInvalid: the selected delivery method is no longer valid (e.g., the shipping address no longer falls within it). This problem blockscheckoutCompleteuntil a valid delivery method is assigned viacheckoutDeliveryMethodUpdate.
See the upgrading guide to learn more.
-
checkoutDeliveryMethodUpdatemutation now acceptsCheckoutDeliveryID asdeliveryMethodId(ID returned bydeliveryOptionsCalculatemutation). Usage ofShippingMethodID is deprecated in favor ofCheckoutDeliveryID.
- Fix Google OAuth OIDC login failing with
invalid_scopeerror whenenable_refresh_tokenis enabled. Google does not support theoffline_accessscope; useaccess_type=offlineauthorization parameter instead. - #18919 by @dnplkndll - Fix send order confirmation email to staff - #18342 by @Shaokun-X
- Validation on
AppExtensionis now removed. Saleor will accept string values formountandtargetfrom Manifest during App installation and JSON value foroptionsfield. Validation is now performed on the frontend (Dashboard). This change increases velocity of features related to apps and extensions, now Dashboard is only entity that ensures the contract - Add optional usage telemetry. - #18789 by @wcislo-saleor
- The app can now be installed without providing a
tokenTargetUrlin the manifest file. - Removed the setting
JWT_EXPIREwhich allowed to configure Saleor to ignore the JWT token expiration. - #18856 by @NyanKiyoshi - Removed support for custom
UserDB models in./manage.py createsuperusercommand. - #18890 by @NyanKiyoshi
- Improved page search with search vectors. Pages can now be searched by slug, title, content, attribute values, and page type information.
- Improve user search. Use search vector functionality to enable searching users by email address, first name, last name, and addresses.
- Improved checkout search with search vectors. The
search_index_dirtyflag is set whenever indexed checkout data changes, and a background task runs every minute to update search vectors for dirty checkouts, processing the oldest first. Search results are returned in order of best match relevance. - Enhanced search functionality across key entities (products, orders, gift cards, checkouts, pages, and users) with advanced query capabilities:
- Prefix matching: partial word searches (e.g., "coff" matches "coffee")
- Boolean operators:
AND,OR, and-(NOT) for complex queries - Exact phrase matching: use quotation marks
" "for precise searches - Accent-insensitive search: queries automatically normalize diacritical marks, allowing searches to match regardless of accents (e.g., "cafe" matches "café")
- Relevance-based ranking: exact matches score higher than prefix matches and appear first by default (can be overridden with
sortByparameter) - New
RANKsort field available when using search filters to sort by relevance score
- Deprecate the
hasVariantsfield onProductType. - Deprecate export mutations (
exportProducts,exportGiftCards,exportVoucherCodes). All data can be fetched via the GraphQL API and parsed into the desired format by apps or external tools.