此外本次更新修正了超过25个安全性的加强并且更优化了跨站程序(XSS)攻击的潜在危险。其中使用者比较有感的会是网址列中的 session id 将会被移除,而这个也是一个潜在个安全弱点。


Elasticsearch 支持 7.5 版本。还在使用 Elasticsearch 2.x, 5.x版本的都会被建议停用,而 Magento 2.4.0 时将移除过时版本。


Worldpay (Direct Post)
Signifyd fraud protection
Google Shopping ads Channel

加强 PWA 的功能
B2B 功能的效率加强
Page Builder 整合 Yotpo
Vertex 加强跨国税率的应用,加强虚拟商品的税率机制。

Magento 2.3.5 新特性的英文版如下:
What is expected from the latest Magento 2.3.5 Release:
Substantial Security Enhancements
More than 25 security improvements to address remote code execution (RCE) and cross-site scripting (XSS) vulnerabilities
Content Security Policy, an HTTP response header that browsers can use to enhance the security of a web page, implemented
Session ID from URLs removed
Platform Upgrades
Elasticsearch 7.5 supported
Deprecation of the integrations of the Authorize.Net, eWay, CyberSource, and Worldpay payment methods. Check here.
The core feature – Signifyd Fraud Protection Code, not supported anymore.
Symfony components upgraded
Migration of dependencies on Zend Framework to the Laminas project
Performance Boosts
Introducing a new way to invalidate all customer sections data that avoids a known issue with local storage when custom sections.xml invalidations are active
Redis performance improved
Enhancements in Infrastructure
The PayPal Pro payment method now no longer requires access to the customer’s session that the default Chrome same-46 site cookie did not permit.
A PHPStan code analysis check is now integrated into Magento static builds that perform static code analysis to identify additional issues that were not detected by PHP CodeSniffer and PHP Mess Detector till now.
Merchant Tool Enhancements
Page Builder (For Magento Commerce 2.3.5)
Included the templated that can be created from the existing content and applied to the new content areas
Video backgrounds can now be used for the rows, banners, and sliders
Option to set the height of page builder rows, banners, and sliders to the full height of the page are now included
Content type upgrade library
Inventory Management
Bulk API for checkout and cart verification
New extension point for SourceDataProvider and StockDataProvider
View the allocated inventory sources from the Orders list
Ability to use products and categoryList queries in order to retrieve information about products and categories that have been added to a staged campaign
Importer performance improved
Engagement Cloud and Magento B2B integrated to allow the B2B merchants to leverage their B2B data and engage with the customers in a better way.
Google Shopping ads Channel is no longer supported.
Apart from these awesome features, the Magento 2.3.5 release also includes improvements in the vendor developed extensions like Klarna, Yotpo, and Vertex.

The awesomeness does not end here!

Magento 2.3.5 is power-packed with enhancements like:
Enhanced Adobe Stock integration
Bundle product prices are now calculated correctly on the product pages
Improvements in the cart, checkout, catalog, CMS content, Javascript framework, payment methods, shipping, UI, and other general fixes.
The WYSIWYG editor now works as expected on Internet Explorer 11.x, display two or more editors on a catalog product edit page, and it no longer hangs indefinitely when you try to upload an image from the admin.
For Magento Commerce 2.3.5, the improvements in B2B includes:

“Could not save shared catalog” error solved.
Ability to configure a downloadable product’s link options from the Admin View Quote page
Admin can now place a quote order when paying with PayPal, when assigned appropriate permissions.
Now, the products can be added to cart from Quick Order after a user’s Customer Group is updated
The products with special characters are now displayed correctly in the Shared Catalogs in the admin
and many more.

Magento 2.3.5 is all set to release this April. The merchants are requested to upgrade the Magento 2 stores to the latest version in order to avail these exciting features, offer a secure online shopping platform and get the competitive edge!
版权声明:本文为CSDN博主「剑池」的原创文章,遵循CC 4.0 BY-SA版权协议,转载请附上原文出处链接及本声明。