<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Spryker Documentation</title>
        <description>Spryker documentation center.</description>
        <link>https://docs.spryker.com/</link>
        <atom:link href="https://docs.spryker.com/feed.xml" rel="self" type="application/rss+xml"/>
        <lastBuildDate>Thu, 06 Aug 2026 10:03:36 +0000</lastBuildDate>
        <generator>Jekyll v4.2.2</generator>
        
        
        <item>
            <title>Troubleshooting general technical issues</title>
            <description>This section helps you troubleshoot general technical issues you might encounter when running your Spryker-based project.

## Topics

- [A command fails with a `Killed` message](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/a-command-fails-with-a-killed-message.html)
- [Class Silex/ControllerProviderInterface not found](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/class-silex-controllerproviderinterface-not-found.html)
- [Unable to resolve hosts for Mail, Jenkins, and RabbitMQ](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/unable-to-resolve-hosts-for-mail-jenkins-and-rabbitmq.html)
- [RabbitMQ: `Zed.CRITICAL`: PhpAmqpLib\Exception\AMQPChannelClosedException - Channel connection is closed](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/troubleshooting-rabbitmq/rabbitmq-zed.critical-phpamqplib-exception-amqpchannelclosedexception-channel-connection-is-closed.html)
- [ProcessTimedOutException after queue:task:start](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/processtimedoutexception-after-queue-task-start.html)
- [RuntimeException: Failed to execute regex: PREG_JIT_STACKLIMIT_ERROR](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/runtimeexception-failed-to-execute-regex-preg-jit-stacklimit-error.html)
- [Database tables take up too much space or have ID overflow](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/database-tables-take-up-too-much-space-or-have-id-overflow.html)
- [ERROR: remove spryker_logs: volume is in use](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/error-remove-spryker-logs-volume-is-in-use.html)
- [Fail whale on the front end](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/fail-whale-on-the-frontend.html)
- [No data on the Storefront](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/no-data-on-the-storefront.html)
- [Error response from daemon: OCI runtime create failed: .... \\\&quot;no such file or directory\\\&quot;\&quot;&quot;: unknown](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/error-response-from-daemon-oci-runtime-create-failed-no-such-file-or-directory-unknown.html)
- [Composer version 2 compatibility issues](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/composer-version-2-compatibility-issues.html)
- [Router generates absolute URL with localhost](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/router-generates-absolute-url-with-localhost.html)
- [PHPStan memory issues](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/phpstan-memory-issues.html)
- [Session locking issues](/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/session-locking-issues.html)


{% info_block infoBox %}

If you encounter a general technical issue that is not addressed on this page, try searching by an error output or keywords, or visit the [Spryker Support Portal](https://support.spryker.com) for technical support.

If you found a solution to a repetitive issue,  suggest a change to this page by clicking the **Edit or Report** button.

{% endinfo_block %}
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:09 +0000</pubDate>
            <link>https://docs.spryker.com/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/troubleshooting-general-technical-issues.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/dg/dev/troubleshooting/troubleshooting-general-technical-issues/troubleshooting-general-technical-issues.html</guid>
            
            
        </item>
        
        <item>
            <title>Tisax Certification</title>
            <description>Spryker is a modular commerce solution hosted in Spryker Cloud (PaaS / Platform-as-a-Service), which runs on TISAX-certified AWS infrastructure (Assessment Level 3). While Spryker itself is not TISAX-certified (as it&apos;s not transferable from vendor to projects), we provide an architectural foundation, technical capabilities, and flexibility that can be used to implement TISAX-aligned projects, particularly in regulated industries such as automotive and mobility.

This document outlines how Spryker&apos;s PaaS solution can be used by enterprise customers and system integrators when meeting TISAX security objectives is a requirement, and provides practical guidance for Spryker-based projects in light of TISAX VDA ISA requirements. Spryker&apos;s guidance does not replace a customer&apos;s own evaluation of the applicable requirements or a customer&apos;s compliant implementation on project-level - the responsibility for both lies with the customer.

## What is TISAX

TISAX (Trusted Information Security Assessment Exchange) is an automotive industry-specific information security assessment, based on ISO/IEC 27001, and maintained by the ENX Association. It focuses on the protection of sensitive data - particularly:

- Personal and operational data
- Supplier and prototype information
- Secure data exchange between partners

Each project and/or company must undergo its own assessment, with compliance depending on internal processes, architecture, and hosting setup.

## Key Considerations

🛠 **Spryker cannot transfer TISAX compliance to customers.**  
Due to the flexible, customizable nature of Spryker and the variability in project code and operations, each customer implementation must undergo its own TISAX audit.

However, Spryker uses a TISAX-ready AWS foundation and provides capabilities that can help a customer to meet compliance requirements when used appropriately.

## Spryker&apos;s Compliance-Enabling Capabilities

| TISAX Requirement Area            | Spryker Feature / Architectural Capability                                                                                            |
|----------------------------------|---------------------------------------------------------------------------------------------------------------------------------------|
| Secure Hosting Infrastructure    | Spryker Cloud is hosted on AWS, which is [certified under TISAX](https://aws.amazon.com/de/compliance/tisax/) AL3 across relevant regions.                                       |
| Environment Separation           | Supports fully isolated production, staging, testing, and preview environments to protect sensitive or prototype data.                |
| Access Control and RBAC          | Role-Based Access Control (RBAC) is built into the Back Office (Zed) and API authentication.                                          |
| Secure APIs &amp; Data Exchange      | API-first architecture with token-based authentication, encryption in transit (TLS), and fine-grained access scopes.                  |
| Modular and Auditable Architecture | Code and features are modularized by business domain, simplifying the implementation of least-privilege and audit logging strategies. |
| DevSecOps and CI/CD Compatibility | Supports integration with secure CI/CD practices, including secret management, audit logging, and code scanning tools.                |
| Encryption Support               | Encryption at rest and in transit is supported via AWS services (S3, RDS, etc.).                                                      |
| Custom Security Enhancements     | Customers can implement prototype protection, NDA management, and data classification tagging based on project needs.                 |

## Steps to Achieve TISAX Alignment on Spryker

1. **Define Scope and Target Assessment Level**  
   Identify whether your project will handle sensitive supplier data, prototypes, or vehicle configurations (often triggers TISAX Level 3 requirements).

2. **Choose TISAX-Certified Hosting**  
   Deploy on Spryker Cloud in a TISAX-certified AWS region.

3. **Design Architecture with Isolation &amp; Access Control**  
   Use Spryker&apos;s environment separation, RBAC, and API scopes to minimize data access and enforce protection boundaries.

4. **Secure Development and Customization**  
   Ensure that any partner or internal development follows secure coding guidelines, includes code reviews, and avoids sensitive data in non-production environments.

5. **Implement Logging &amp; Monitoring**  
   Extend Spryker&apos;s default logging to cover key user actions, especially in the Back Office, APIs, and data exports. Consider integrating a SIEM.

6. **Document and Audit**  
   Maintain documentation on your technical setup, access controls, risk assessments, and processes to prepare for the TISAX audit.

## Limitations &amp; Disclaimer

Spryker does not provide TISAX certification out of the box and is not responsible for TISAX compliance for individual customer projects.  
Spryker uses TISAX-aligned architectures through certified AWS infrastructure and secure platform features. Customers are responsible for ensuring full alignment, documentation, and audit-readiness based on their own organizational practices.
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/about/all/certificates-and-compliance/tisax-certification.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/about/all/certificates-and-compliance/tisax-certification.html</guid>
            
            
        </item>
        
        <item>
            <title>Test the asynchronous API</title>
            <description>This document describes how to set up and run AsyncAPI tests.
We use the *Hello World* example throughout this document. All code references the Hello World App and the `Pyz` project namespace. When you set up and run the tests for a different project namespace or module, adjust the names accordingly.

## Prerequisites

&lt;!--Either you followed the instructions on how to Create an App or you have an already created App in place.--&gt;

Make sure the following prerequisites are met:

1. Spryker Testify version 3.50.0 or later is installed. The AsyncAPI SDK is required by this package, however, you don&apos;t need to install it manually.
- Verify the installation status and version of Spryker Testify:

  ```bash
  composer info spryker/testify
  ```

- Install Spryker Testify:

  ```bash
  composer require --dev &quot;spryker/testify:^3.50.0&quot;
  ```

- Update Spryker Testify:

  ```bash
  composer update &quot;spryker/testify:^3.50.0&quot;
  ```

2. Spryker Testify AsyncAPI version 0.1.1 or later is installed. The AsyncAPI SDK is required by this package, however, you don&apos;t need to install it manually.
- Verify the installation status and version of Spryker Testify AsyncAPI:

  ```bash
  composer info spryker/testify-async-api
  ```

- Install Spryker Testify AsyncAPI:

  ```bash
  composer require --dev &quot;spryker/testify-async-api:^0.1.1&quot;
  ```

- Update Spryker Testify AsyncAPI:

  ```bash
  composer update &quot;spryker/testify-async-api:^0.1.1&quot;
  ```

3. Spryks version 0.5.2 or later is installed.
- Verify the installation status and version of Spryks:

  ``` bash
  composer info spryker-sdk/spryk
  ```

- Install Spryks:

  ```bash
  composer require --dev &quot;spryker-sdk/spryk:^0.5.2&quot;
  ```

- Update Spryks:

  ```bash
  composer update &quot;spryker-sdk/spryk:^0.5.2&quot;
  ```

4. There is a valid AsyncAPI schema file in `resources/api/asyncapi.yml`. To create the file, you can use the example provided in Hello World App AsyncAPI.

## Testing the asynchronous API

Testing the asynchronous API implies that all schema files are tested to ensure that they align with the code that handles or produces messages. Each module that has an AsyncAPI schema file must have a dedicated test suite.

To test the asynchronous API, follow these steps:

### 1. Generate the code

To generate the code, you need to provide a valid schema file within your app. The schema file must reside in `resources/api/asyncapi.yml`. In the following example, we use the file provided in the Hello World App AsyncAPI, which you can also use as a starting point for your project.
After you have added the schema file, run the code generator for it using the following command:

```bash
docker/sdk cli vendor/bin/asyncapi code:asyncapi:generate -o Pyz
```

This command adds relevant modules and tests to your project to get you started with the asynchronous API in the `src/` and `tests/` directories.

To verify the introduced changes, check the `src/` and `tests/` directories.

### 2. Build Codeception

Run the following Codeception build command:

```bash
docker/sdk cli vendor/bin/codecept build -c tests/PyzTest/AsyncApi/HelloWorld
```

Not everything can be automatically generated with these commands. You also need to update the Codeception configuration and the project configuration as described in the following sections.

### 3. Update the Codeception configuration

Open the created Codeception configuration file at `tests/PyzTest/AsyncApi/HelloWorld/codeception.yml` and add the generated handlers to the configuration of `AsyncApiHelper`.

The file should contain the following section:

```yml
\Spryker\Zed\TestifyAsyncApi\Business\Codeception\Helper\AsyncApiHelper:
    asyncapi: resources/api/asyncapi.yml
    handlers:
        - \Pyz\Zed\HelloWorld\Communication\Plugin\MessageBroker\UserCreatedMessageHandlerPlugin
```

Depending on your schema file, you need to add your specific handlers. All handlers are located in the `src/Pyz/Zed/HelloWorld/Communication/Plugin/MessageBroker` directory. Add the class name of each handler to your Codeception configuration.

### 4. Update the project configuration

When testing the asynchronous API, all messages must be sent to the local message broker transport. This should only happen when you test the API with automated tests.

Add the following configuration to the `config/Shared/config_local.php` file:

```php
use Spryker\Shared\MessageBroker\MessageBrokerConstants;

$config[MessageBrokerConstants::IS_ENABLED] = true;
$config[MessageBrokerConstants::MESSAGE_TO_CHANNEL_MAP] = [
    &apos;*&apos; =&gt; &apos;test-channel&apos;,
];

$config[MessageBrokerConstants::CHANNEL_TO_TRANSPORT_MAP] = [
    &apos;test-channel&apos; =&gt; &apos;local&apos;,
];
```

{% info_block warningBox &quot;Warning&quot; %}

This is a very generic configuration and shouldn&apos;t be used in a production environment.

{% endinfo_block %}

### 5. Run the tests

Run the tests using the following command:

```bash
docker/sdk testing vendor/bin/codecept run -c tests/PyzTest/AsyncApi/HelloWorld
```

Once the testing process is complete, you get the result of each individual test.

## Example test methods

This section lists some example methods and explains what and how they test.

### Handling messages

Here is the example of handling the messages:

```php
public function testUserCreatedMessageCreatesAUserEntity(): void
{
    // Arrange
    $userCreatedTransfer = $this-&gt;tester-&gt;haveUserCreatedTransfer();

    // Act
    $this-&gt;tester-&gt;runMessageReceiveTest($userCreatedTransfer, &apos;user-events&apos;);

    // Assert
    $this-&gt;tester-&gt;assert...(...);
}
```

In the `Arrange` section, implement the code to allow for a message transfer that you expect to receive from another application.

In the `Act` section, call `runMessageReceiveTest` in `AsyncApiHelper`. The `runMessageReceiveTest` method takes the message that you expect to receive as its first argument and the channel name where you expect the message to come through as its second argument. Internally, the message and the channel name are validated against your `asyncapi.yml` schema file to ensure that both meet the definition.

In the `Assert` section, you make assertions based on your business logic. For example, you might verify the existence of a database entry after the message has been processed.

The underlying `AsyncApiHelper` ensures the following inside the `runMessageReceiveTest` method:

- The message handler can handle the message.
- The expected channel name exists in the schema file.
- The expected message name exists in the schema file.
- The message contains all required attributes defined in the schema file.

The `AsyncApiHelper` also executes the handler with the passed message. After the `runMessageReceiveTest` method execution, you need to make your assertions, such as verifying that a specific change was made in your database after processing the message.
The only remaining tasks for you are to implement the business logic, update the tests according to your business logic, and then run the tests.
To run the tests, use the following command:

```bash
vendor/bin/codecept run -c tests/PyzTest/AsyncApi/HelloWorld/
```

### Publishing messages

Here is the example of publishing the messages:

```php
public function testGreetUserMessageIsEmittedWhenUserWasStoredInTheDatabase(): void
{
    // Arrange
    $expectedGreetUserTransfer = $this-&gt;tester-&gt;haveGreetUserTransfer();

    // Act
    $this-&gt;tester-&gt;getFacade()-&gt;saveUser(...);

    // Assert
    $this-&gt;tester-&gt;assertMessageWasEmittedOnChannel($expectedGreetUserTransfer, &apos;user-commands&apos;);
}
```

In the `Arrange` section, prepare a message transfer that you expect to be sent once your business logic is executed.

In the `Act` section, call your business logic. For example, you could call a facade method where you expect the message to be sent.

In the `Assert` section, call the `assertMessageWasEmittedOnChannel` method with the expected message you created in the `Arrange` section. The first argument is the message that you expect to be sent, and the second argument is the channel name through which you expect the message to be sent. Internally, the message and the channel name are validated against your `asyncapi.yml` schema file to ensure that both meet the definition.

The underlying `AsyncApiHelper` ensures the following inside the `assertMessageWasEmittedOnChannel` method:

- The expected channel name exists in the schema file.
- The expected message name exists in the schema file.
- The message was sent with all required attributes defined in the schema file.
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/dg/dev/guidelines/testing-guidelines/executing-tests/test-the-asynchronous-api.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/dg/dev/guidelines/testing-guidelines/executing-tests/test-the-asynchronous-api.html</guid>
            
            
        </item>
        
        <item>
            <title>Release notes for spryker-php image</title>
            <description>This document describes the changes that have been recently released.
For additional support with this content, contact our support.
If you found a new security vulnerability, contact us at **security@spryker.com**.

## Release notes for spryker-php 20260206.0

### Improvements

- Added support for Alpine 3.23
- Upgraded Composer to 2.9.3
- Upgraded Tideways to 5.32.0
- Upgraded NewRelic to the latest

## Security fixes by image

This section details security vulnerabilities that have been addressed in specific Docker images.

### spryker/php:8.4-alpine3.22

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-61730**: During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

- **CVE-2025-11187**: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.

- **CVE-2025-15469**: The &apos;openssl dgst&apos; command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.

- **CVE-2026-24515**: In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

### spryker/php:8.3-alpine3.22

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2026-24515**: In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-61730**: During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

- **CVE-2025-11187**: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.

- **CVE-2025-15469**: The &apos;openssl dgst&apos; command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.

### spryker/php:8.2-alpine3.22

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-11187**: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification.

- **CVE-2025-15469**: The &apos;openssl dgst&apos; command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error.

### spryker/php:8.4-alpine3.21

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-14178**: A heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-61726**: The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the `net/http.Request.ParseForm` method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-14177**: The getimagesize() function may leak uninitialized heap memory into the APPn segments (for example, APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

- **CVE-2025-14180**: Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges

### spryker/php:8.3-alpine3.21

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

### spryker/php:8.2-alpine3.21

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-61728**: archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-14178**: A heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-61726**: The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the `net/http.Request.ParseForm` method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-61730**: During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

- **CVE-2025-14177**: The getimagesize() function may leak uninitialized heap memory into the APPn segments (for example, APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

### spryker/php:8.4-alpine3.20

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-61728**: archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2025-6491**: When parsing XML data in SOAP extensions, overly large (&gt;2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2025-1220**: NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a month‑generated domain. After receiving a decryption key, it then downloads and executes arbitrary code, creates an encrypted virtual file system (VFS) in the registry, and grants the attacker full remote code execution, data exfiltration, and persistence. NetSarang released builds for each product line that remediated the compromise: Xmanager Enterprise Build 1236, Xmanager Build 1049, Xshell Build 1326, Xftp Build 1222, and Xlpd Build 1224. Kaspersky Lab identified an instance of exploitation in the wild in August 2017.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-1735**: A vulnerability in Palantir&apos;s Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.

- **CVE-2025-14177**: The getimagesize() function may leak uninitialized heap memory into the APPn segments (for example, APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

### spryker/php:8.3-alpine3.20

- **CVE-2025-14178**: A heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-61726**: The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the `net/http.Request.ParseForm` method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

- **CVE-2025-61730**: During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

- **CVE-2025-14180**: Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2025-1220**: NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a month‑generated domain. After receiving a decryption key, it then downloads and executes arbitrary code, creates an encrypted virtual file system (VFS) in the registry, and grants the attacker full remote code execution, data exfiltration, and persistence. NetSarang released builds for each product line that remediated the compromise: Xmanager Enterprise Build 1236, Xmanager Build 1049, Xshell Build 1326, Xftp Build 1222, and Xlpd Build 1224. Kaspersky Lab identified an instance of exploitation in the wild in August 2017.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-1734**: In the Linux kernel, the following vulnerability has been resolved: HID: appleir: Fix potential NULL dereference at raw event handle.

- **CVE-2025-1861**: When parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

- **CVE-2025-1219**: When requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect. This may cause the resulting document to be parsed incorrectly or bypass validations.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-1217**: When http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

- **CVE-2025-1735**: A vulnerability in Palantir&apos;s Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.

- **CVE-2025-14177**: The getimagesize() function may leak uninitialized heap memory into the APPn segments (for example, APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

### spryker/php:8.2-alpine3.20

- **CVE-2025-14178**: A heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-61726**: The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the `net/http.Request.ParseForm` method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

- **CVE-2025-61730**: During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

- **CVE-2025-14180**: Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges

- **CVE-2025-61728**: archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2025-6491**: When parsing XML data in SOAP extensions, overly large (&gt;2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2025-1220**: NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a month‑generated domain. After receiving a decryption key, it then downloads and executes arbitrary code, creates an encrypted virtual file system (VFS) in the registry, and grants the attacker full remote code execution, data exfiltration, and persistence. NetSarang released builds for each product line that remediated the compromise: Xmanager Enterprise Build 1236, Xmanager Build 1049, Xshell Build 1326, Xftp Build 1222, and Xlpd Build 1224. Kaspersky Lab identified an instance of exploitation in the wild in August 2017.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.

- **CVE-2025-1735**: A vulnerability in Palantir&apos;s Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.

- **CVE-2025-14177**: The getimagesize() function may leak uninitialized heap memory into the APPn segments (for example, APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

### spryker/php:8.1-alpine3.20

- **CVE-2025-14178**: A heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.

- **CVE-2025-15468**: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs.

- **CVE-2025-69421**: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function.

- **CVE-2026-22796**: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data.

- **CVE-2026-15467**: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

- **CVE-2025-61726**: The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the `net/http.Request.ParseForm` method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

- **CVE-2025-61730**: During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

- **CVE-2025-14180**: Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges

- **CVE-2025-61728**: archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

- **CVE-2025-69420**: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file.

- **CVE-2025-69418**: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated.

- **CVE-2025-6491**: When parsing XML data in SOAP extensions, overly large (&gt;2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

- **CVE-2026-22801**: LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

- **CVE-2025-1220**: NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a month‑generated domain. After receiving a decryption key, it then downloads and executes arbitrary code, creates an encrypted virtual file system (VFS) in the registry, and grants the attacker full remote code execution, data exfiltration, and persistence. NetSarang released builds for each product line that remediated the compromise: Xmanager Enterprise Build 1236, Xmanager Build 1049, Xshell Build 1326, Xftp Build 1222, and Xlpd Build 1224. Kaspersky Lab identified an instance of exploitation in the wild in August 2017.

- **CVE-2026-22695**: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

- **CVE-2025-66199**: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit.

- **CVE-2025-68160**: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write.

- **CVE-2025-69419**: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer.

- **CVE-2026-22795**: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file.</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/about/all/releases/image-releases/spryker-php/release-notes-spryker-php-20260206.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/about/all/releases/image-releases/spryker-php/release-notes-spryker-php-20260206.html</guid>
            
            
        </item>
        
        <item>
            <title>Release notes 202602.0</title>
            <description>Spryker Cloud Commerce OS is an end-to-end solution for digital commerce. This document contains a business-level description of new features and improvements.

For information about installing Spryker, see [Getting started guide](/docs/dg/dev/development-getting-started-guide).

## B2B Business-Ready Commerce Experiences

### Product Attachments {% include badge.html type=&quot;feature&quot; %}

Introduces out-of-the-box Product Attachments capability commonly required in industrial B2B purchasing.

{% include carousel.html
images=&quot;https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/product_attachments_storefront_pdp.png||::https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/product_attachments_backoffice_pim.png||&quot;
%}

**Key capabilities**
- Back Office management of product-related documents (for example, datasheets, certificates, manuals).
- Provide external links to product attachments via data import.
- Display and download or view attachments on the product details page.

**Business benefits**
- Supporting buyers&apos; decisions by providing more detailed product information.
- Removes approval bottlenecks and shortens the path from product view to first transaction.

**Documentation**
- [Product Attachments overview](/docs/pbc/all/product-information-management/latest/base-shop/feature-overviews/product-feature-overview/product-attachments-overview.html)
- [Install the Product Attachments feature](/docs/pbc/all/product-information-management/latest/base-shop/install-and-upgrade/install-features/install-the-product-attachments-feature.html)

### Product &amp; Merchant Offer Availability Display {% include badge.html type=&quot;feature&quot; %}

Introduces native, configurable product and merchant offer availability display for B2B Commerce and Marketplace scenarios, reducing customization and increasing buyer confidence at the point of decision.

**Key capabilities**
- Native availability display on the product details page (PDP) and in the cart
- Configurable display logic:
  - Availability indicator only (for example Available / Out of Stock)
  - Exact stock quantity combined with indicator
  - Configuration option for the sort order of merchant offers in the B2B Marketplace
- Built on existing Spryker stock data structures

**Business benefits**
- Buyers see reliable availability information at the point of decision.
- Businesses no longer need custom implementations for basic stock visibility.
- Transparent stock visibility increases direct orders and reduces operational overhead.

**Documentation**
- [Product Availability Display feature overview](/docs/pbc/all/warehouse-management-system/latest/base-shop/product-availability-display-feature-overview)
- [Buy Box feature overview](/docs/pbc/all/offer-management/latest/marketplace/buy-box-feature-overview)

### Back Office Configuration Framework {% include badge.html type=&quot;feature,early-access&quot; %}

Introduces a structured, extensible framework to expose business-relevant configuration directly in the Spryker Back Office without code changes or redeployments.

**Key capabilities**
- Structured Business Configuration via UI
  - Developers define configuration options in YAML once.
  - The framework automatically renders validated Back Office UI pages.
- Runtime Configuration Without Deployment
  - Configuration changes are applied at runtime, no code change, no pull request, no deployment required.
- Support for Out-of-the-Box and Custom Features. The framework works for:
  - Standard Spryker features
  - Project-specific customizations
- Built-in Validation &amp; Guardrails
  - Business users can only adjust explicitly defined and validated options, preventing misconfiguration.

**Business benefits**
- Faster Time to Change
  - Business teams adjust approved behaviors instantly, no development sprint required.
- Lower Total Cost of Change
  - Reduces repetitive engineering effort for configuration updates and eliminates custom UI builds per feature.
- Faster Experimentation
  - Test different configuration setups (for example display logic, marketplace sorting) without waiting for release cycles.

### B2B-only Mode Enablement

Reduces project setup time for customers and partners who want B2B Commerce only, without Marketplace complexity.

**Key capabilities**
- Added a **guideline and deployment script** to start the unified demo shop in a standardized **B2B Commerce–only mode**, reducing required manual cleanup and configuration.

**Business benefits**
- Faster project initialization for B2B-only projects.
- Lower implementation cost and reduced efforts.
- Clearer positioning and smoother kick-off experience.

**Documentation**
- [Uninstall the Marketplace from B2B Demo Marketplace](/docs/about/all/uninstall-marketplace-from-b2b-demo-marketplace)

### New Industrial Homepage Sample Data {% include badge.html type=&quot;improvement&quot; %}

The new sample data allows you to explore more realistic B2B Commerce journeys and capabilities without needing to import your own data.

**Key capabilities**
- Updated homepage content to industrial goods and services across key blocks (banners, featured categories, featured products, top sellers).

**Business benefits**
- More realistic demos that reflect real industrial buying journeys.
- Faster evaluations by showing realistic catalog and merchandising scenarios out of the box.
- Less manual demo preparation for partners and solution teams.

### UX &amp; Design Improvements for Storefront &amp; Back Office {% include badge.html type=&quot;improvement&quot; %}

Improves clarity, consistency, and perceived quality across core pages and navigation.

{% include carousel.html
   images=&quot;https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/Menu Icons.png||::https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/Empty_status_page.png||::https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/Toast_notifications.png||&quot;
%}

**Key capabilities**
- Redesigned the Back Office 404 page with clear recovery actions and consistent styling, removing technical error output for a smoother user experience.
- Improved empty states for Addresses, Orders, and Returns pages in storefront to guide users with clear next steps and better first-time usability.
- Updated navigation to Google Material Icons for visual consistency with the Merchant Portal.
- Replaced full-width banner of toast notifications with stacked, auto-dismissing toast notifications for lightweight, non-disruptive feedback.
- Fixed Back Office form validation errors showing untranslated message keys (restored translation rendering).

**Business benefits**
- Faster task completion and reduced confusion in Back Office operations.
- Better first-time experience for B2B customers on key storefront pages.
- Higher perceived product quality and consistency for enterprise users.
- Reduced support noise caused by unclear errors and untranslated validation messages.


### PunchOut: cXML Compatibility in Spryker API &lt;span class=&quot;inline-img&quot;&gt;![feature](https://spryker.s3.eu-central-1.amazonaws.com/docs/scos/user/intro-to-spryker/releases/release-notes/feature.png)&lt;/span&gt;

Enables standardized B2B PunchOut integrations via cXML support.

**Key capabilities**
- Support for **cXML (Commerce XML)** as an additional data exchange format in the Spryker API Platform.
- Documentation and guidance for implementing PunchOut integrations with external eProcurement systems.

**Business benefits**
- Enterprise-ready B2B integration  API Compatibility with leading procurement platforms.
- Simplified implementation of PunchOut scenarios for customers and partners.
- Stronger positioning in complex B2B commerce environments.

**Documentation**
- [PunchOut Development Plan](/docs/integrations/custom-building-integrations/punchout-development-plan)

## Connected, and AI-Enabled Platform

### Spryker AI Foundation: Operable, Structured, and Extensible AI Runtime {% include badge.html type=&quot;early-access,improvement&quot; %}

Enhances the AI Foundation runtime layer to make AI executions easier to operate at scale, safer to integrate into product code, and more extensible for evolving use cases.

**Key capabilities**
- Prompt responses now return **token usage** and **applied AI configuration details** (for example, provider/vendor, model, configuration name, and relevant parameters) for improved transparency and troubleshooting.
- Added **structured response support** aligned with **Spryker Transfers**, enabling validated, contract-based AI outputs rather than fragile free-text parsing.
- Introduced a supported **tool call extension mechanism** for AI Foundation, enabling standardized enrichment of tool call inputs/outputs without project-specific integration workarounds.

**Business benefits**
- Improved cost and performance control through token visibility and configuration traceability.
- More reliable production integrations through typed, validated AI outputs (reduced downstream breakage from phrasing changes).
- Lower long-term maintenance and support effort via a standardized extension mechanism for evolving AI use cases.

**Documentation**
- [AI Foundation](/docs/pbc/all/ai-foundation/latest/ai-foundation.html)
- [Install the AI Foundation module](/docs/dg/dev/ai/ai-foundation/ai-foundation-module.html)
- [Use AI tools with the AiFoundation module](/docs/dg/dev/ai/ai-foundation/ai-foundation-tool-support.html)
- [Use structured responses with the AiFoundation module](/docs/dg/dev/ai/ai-foundation/ai-foundation-transfer-response.html)

### Spryker AI Commerce: Agent Foundations and Smart PIM Improvements {% include badge.html type=&quot;early-access,improvement&quot; %}

Adds foundational capabilities for advanced agent workflows and improves the Back Office Smart PIM with safer, more reliable AI-assisted product description support.

**Key capabilities**
- **Conversation history** support to maintain context across interactions, enabling better multi-step workflows.
- Introduced a **workflow orchestration layer** for predictable multi-step AI executions, including structured transitions, error handling, and auditability.
- Back Office Smart PIM: **AI assistance for product descriptions** directly within abstract and concrete product create and edit pages:
  - Actions to **Translate content** and **Improve content**
  - Review-before-apply workflow to avoid accidental overwrites
- Back Office Smart PIM: **Clear user feedback when AI is not configured or unavailable**:
  - Validates provider credentials before calling external AI services
  - Shows user-facing error messages instead of silent empty responses
  - Logs operator-friendly errors without exposing secrets
  - UI safeguard disables AI actions with an explanatory tooltip when AI is not configured

**Business benefits**
- Higher adoption and trust in AI features due to clear error states and safer interaction patterns.
- Faster catalog enrichment through translation and content improvement with less manual effort and fewer review loops.
- Foundation for advanced B2B agent scenarios through context continuity and orchestrated workflows.
- Improved governance and auditability through workflow execution traceability.

**Documentation**
- [Smart Product Management](/docs/pbc/all/product-information-management/latest/base-shop/third-party-integrations/smart-product-management/smart-product-management.html)
- [Install Smart Product Management](/docs/pbc/all/product-information-management/latest/base-shop/third-party-integrations/smart-product-management/install-smart-product-management.html)
- [Manage conversation history with the AiFoundation module](/docs/dg/dev/ai/ai-foundation/ai-foundation-conversation-history.html)
- [AI workflow orchestration with state machines](/docs/dg/dev/ai/ai-foundation/ai-foundation-workflow-state-machine.html)

### Spryker AI Dev SDK: Additional MCP Tools for Spryker-Aware AI Development {% include badge.html type=&quot;early-access,improvement&quot; %}

Expands MCP tooling to make Spryker context retrieval, module discovery, documentation grounding, and demo data manipulation faster and more reliable for AI-assisted development.

**Key capabilities**
- Added `getSprykerModuleMap` MCP tool to return **comprehensive module information**, including:
  - Paths and core API components (Facade, Client, Service, Config)
  - Available plugin interfaces and extension points
- Added `getSprykerModules` MCP tool to return a **simplified flat list** of unique module names for efficient discovery and reduced token usage.
- Added a **Spryker documentation** MCP tool supporting:
  - Docs web URL
  - GitHub tree URL for the markdown source
  - GitHub API URL for raw markdown retrieval
- Added **read-only database access** tooling for agents to retrieve required information without manual user intervention (SQL query input).
- Added MCP tools to accelerate **import/demo data workflows**:
  - CSV structure analysis (without loading full content)
  - CSV transform operations (update/replace/append)
  - Row deletion by filter criteria
  - ODS-to-CSV export per sheet (supporting Google Sheets → Spryker import pipelines)

**Business benefits**
- Faster and more accurate AI-assisted development through Spryker-aware context (module APIs, extension points, docs grounding).
- Reduced onboarding time and fewer integration mistakes for developers and agents.
- Improved productivity for solution teams by standardizing CSV/ODS workflows and reducing failed import cycles.
- Lower token usage and faster tool responses due to simplified module discovery outputs.

**Documentation**
- [AI Dev SDK Overview](/docs/dg/dev/ai/ai-dev/ai-dev-overview)
- [AI Dev MCP Server](/docs/dg/dev/ai/ai-dev/ai-dev-mcp-server)

### API Platform improvements {% include badge.html type=&quot;early-access,improvement&quot; %}

This release enhances API Platform capabilities to improve your developer experience and reduce manual configuration overhead.

**Key capabilities**
- Enable support for relationships in API Platform.
- Add support for custom validation constraints (FQCN-based) in schema definitions.
- Improve dependency resolution for API Platform packages.
- Add support for Code Buckets.
- Provide API test examples to help you adopt the features more easily.

**Business benefits**
- Generate and validate API resources more cleanly and consistently.
- Reduce the need for manual dependency fixes.
- Improve consistency in your API implementations.
- Accelerate onboarding and increase developer productivity.

**Documentation**
- [Validation Schemas](/docs/dg/dev/architecture/api-platform/validation-schemas.html)
- [Code Buckets](/docs/dg/dev/architecture/api-platform/code-buckets.html)
- [Relationships](/docs/dg/dev/architecture/api-platform/relationships.html)
- [API Test Examples](/docs/dg/dev/architecture/api-platform/testing.html)

### OMS New Visual User Experience {% include badge.html type=&quot;improvement&quot; %}

Spryker transforms the community-driven OMS visualizer into a fully validated and productized capability.

![Screenshot of the OMS visualizer showing order state machine transitions](https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/2026-OMS-visualizer.png)

**Key capabilities**
- Provides a streamlined visualization of complex Order State Machines (OMS).

**Business benefits**
- Enables faster OMS iteration cycles and improves clarity when you develop or validate OMS processes.
- Reduces the time you spend debugging OMS flows by providing better visibility and tooling support.

**Documentation**
- [Original Community Contribution](https://github.com/spryker-community/oms-visualizer)
- [Oms Visualizer Release](https://api.release.spryker.com/release-group/6358)

### Messaging and scheduling modernization {% include badge.html type=&quot;improvement&quot; %}

We introduced Symfony Messenger and Symfony Scheduler as modern, flexible alternatives to the current RabbitMQ adapter and scheduling mechanisms in Jenkins.

**Key capabilities**
- Feature toggle that lets you switch between RabbitMQ and Messenger without breaking compatibility.
- Migration path and supporting documentation to help you transition.
- Messenger becomes the default queue adapter.
- Scheduler lets you control the job schedule from within your application.

**Business benefits**
- Gain greater flexibility in queue transport configuration.
- Align scheduling with the Symfony ecosystem using a modern approach.

**Documentation**
- [Symfony Messenger](/docs/dg/dev/integrate-and-configure/integrate-symfony-messenger.html)
- [Symfony Scheduler](/docs/dg/dev/integrate-and-configure/integrate-symfony-scheduler.html)

### Secure handling of customer data in quote requests {% include badge.html type=&quot;improvement&quot; %}

This update improves the quote request storage mechanism to ensure that the system does not unnecessarily persist sensitive customer data in version records.

Previously, the `spy_quote_request_version` table stored the complete quote JSON, which could include full company customer data, including encrypted passwords. Although the passwords were encrypted, storing them outside the dedicated customer table increased the risk of exposure and did not follow the principle of data minimization.

**Key capabilities**
- Removes unnecessary storage of sensitive customer data, such as encrypted passwords, from the `spy_quote_request_version` table.
- Ensures that customer credentials remain stored exclusively in the `spy_customer` table.
- Improves secure data handling in quote request versioning flows that the Storefront triggers.

**Business benefits**
- Reduces the risk of confidential data exposure.
- Strengthens compliance with secure data handling and data minimization principles.
- Improves overall database hygiene and reduces the attack surface.

**Documentation**
- [Quote Request](https://api.release.spryker.com/release-group/6300)

### Platform &amp; Tooling Upgrades {% include badge.html type=&quot;improvement&quot; %}

We have updated critical application and service components to long-term supported versions to ensure continued stability, performance, and compatibility.

**Key capabilities**
- Upgraded PHPUnit to version 12 (full PHP 8.3 support, improved test data handling).
- Upgraded PHPStan to version 2.x to reduce memory consumption and significantly improve performance.
- Upgraded Angular to the latest supported major version 20.

**Business benefits**
- Faster CI pipelines and reduced waiting times for static analysis.
- Continued alignment with PHP ecosystem and Angular support lifecycles.
  - Resolved a vulnerability in `@angular/common` affecting Spryker applications. The issue (CVE-2025-66035) allowed potential XSRF token leakage via protocol-relative URLs in Angular HTTP clients, potentially exposing CSRF tokens to attacker-controlled domains.
- Improved quality assurance and development tooling performance across projects.

**Documentation**
- [Upgrade to Angular 20](https://docs.spryker.com/docs/dg/dev/upgrade-and-migrate/upgrade-to-angular-20.html)
- [Release unlocking the new PHPUnit version](https://api.release.spryker.com/release-group/6334)
- Spryker is fully compatible with PHPStan 2.x, update it at your own schedule.

### Quality, Performance &amp; Stability Fixes {% include badge.html type=&quot;improvement&quot; %}

This release resolves several performance bottlenecks and technical inconsistencies identified in customer projects.

**Key capabilities**
- Improved Stock Data Import performance by removing the usage of `\ProductAbstractCheckExistenceStep` and `\ProductConcreteCheckExistenceStep`, which eliminates unnecessary full database loads.
- Preserved correct HTTP error codes by returning 4xx responses for expected application errors, such as invalid cart operations, instead of 500.
- Optimized customer session validation by removing resource-intensive password hash checks.
- Stabilized OpenTelemetry monitoring and New Relic instrumentation to prevent memory issues and improve trace grouping for Zed and Gateway traffic.
- Fixed concrete product publishing and product filter handling, including whitelist-aware category suggestions and hidden facets, to restore complete and consistent search results.
- Corrected the Data Import CSV reader configuration so that offset and limit options work as expected for partial imports.
- Restored Back Office form validation translations and eliminated redundant SQL execution in category rules.
- Improved cart behavior in the Glue API by merging guest carts with product bundles on login and introducing SKU-level quantity restriction plugins.

**Business benefits**
- Improved backend performance and reduced database and CPU load.
- Delivered more reliable and predictable product search, filtering, and category navigation for end users.
- Enabled more stable imports and storefront builds with safer customizations and improved dependency management.
- Improved Back Office and cart usability to reduce operational overhead and user friction.
- Add guidance to the public Spryker documentation on how to adopt the Cypress boilerplate.

**Documentation**
- See [Spryker Releases](https://api.release.spryker.com/release-history) or use `composer` to update all packages.
- [E2E Testing with Cypress](/docs/dg/dev/guidelines/testing-guidelines/cypress-testing.html)

### Architecture Guidelines &lt;span class=&quot;inline-img&quot;&gt;![improvement](https://spryker.s3.eu-central-1.amazonaws.com/docs/scos/user/intro-to-spryker/releases/release-notes/improvement.png)&lt;/span&gt;

A set of practical, reusable guidelines to reduce delivery risk, prevent recurring implementation pitfalls, and standardize engineering practices across Spryker projects.

**Key capabilities**
- **APM monitoring and troubleshooting using New Relic**
  - Standardized end-to-end troubleshooting workflow (metrics → transactions → DB queries → traces).
  - Clear mapping of New Relic entities to Spryker applications (Yves, Zed, Glue, Merchant Portal).
  - Practical examples for diagnosing common performance issues.
- **Performance best practices: common challenges and optimization strategies**
  - Documented top recurring performance pitfalls from real projects (symptoms, root cause patterns, proven optimizations).
  - Guidance on recognizing issues via response time, query patterns, and logs.
- **How to start a Spryker project**
  - Step-by-step setup guidance covering project structure, CI/CD basics, team practices, and quality tooling.
  - Focus on &quot;must-do&quot; principles to avoid rework and long-term quality degradation.

**Business benefits**
- Faster onboarding for partners and new project teams through standardized, actionable guidance.
- Reduced escalation rate by addressing known recurring delivery and performance pitfalls early.
- Improved project consistency and upgradeability through repeatable architecture and documentation patterns.
- Better diagnosability and prevention of performance degradation with a shared troubleshooting methodology.

**Documentation**
- [APM — New Relic based troubleshooting](/docs/dg/dev/guidelines/performance-guidelines/apm-newrelic-based-troubleshooting.html)
- [Perfromance best practices](/docs/dg/dev/guidelines/performance-guidelines/performance-guidelines.html)
- [Updated how to start Spryker project](/docs/dg/dev/development-getting-started-guide.html)

### Architecture as Code for Spryker projects &lt;span class=&quot;inline-img&quot;&gt;![improvement](https://spryker.s3.eu-central-1.amazonaws.com/docs/scos/user/intro-to-spryker/releases/release-notes/improvement.png)&lt;/span&gt;

Live, version-controlled architecture documentation using industry standards that scales with your codebase. Enables team collaboration, decision traceability, and onboarding without custom tooling or specialized training.

**Key capabilities**
- Ready-to-use architecture templates for living, version-controlled architecture documentation that evolves with your code, based on arc42 (12 sections) and the C4 model (4-level visualization).
- Traceable architectural decision templates through Solution Designs (RFC-style exploration) and ADRs.
- Diagrams as code using Mermaid and PlantUML, with real examples for automated validation, generation, and AI analysis.

**Business benefits**
- Faster onboarding - with globally-recognized standards and all needed architecture documentation in one place - your code
  - Better decision making - RFC-style exploration and full decision history eliminate tribal knowledge
  - Alignment with business - Capture project requirements, trade-offs before implementation, ensuring delivery matches intent. Evolve further with architecture decision records  and Solution designs
  - AI-ready format - Markdown and code-based diagrams enable intelligent automation and documentation generation

**Documentation**
- [Architecture as a Code](/docs/dg/dev/architecture/architecture-as-code.html)

### ERP Integration Template &lt;span class=&quot;inline-img&quot;&gt;![improvement](https://spryker.s3.eu-central-1.amazonaws.com/docs/scos/user/intro-to-spryker/releases/release-notes/improvement.png)&lt;/span&gt;

Provides a standardized foundation for building ERP integrations without starting from scratch.

**Key capabilities**
- Reusable module structure (Client and Shared layers) with transfer object definitions.
- Pre-built base classes (`BaseRequest`, `BaseRequestBuilder`) for:
  - Request handling and timeout configuration
  - Headers and authentication
  - Logging and error management
- Request/response mapper pattern for ERP-specific format transformations.
- Guzzle client configuration guidance with environment-specific credentials and connection setup.

**Business benefits**
- Faster ERP integration development with reduced boilerplate.
- Consistent architecture across projects and ERP systems.
- Lower risk of integration defects due to standardized logging and error handling.
- Improved maintainability and onboarding for new ERP integrations.

**Documentation**
- [ERP Integration Template](/docs/integrations/custom-building-integrations/erp-integration-template.html)

### Payment Integration Template (PSP Template) &lt;span class=&quot;inline-img&quot;&gt;![improvement](https://spryker.s3.eu-central-1.amazonaws.com/docs/scos/user/intro-to-spryker/releases/release-notes/improvement.png)&lt;/span&gt;

Delivers a production-ready template repository for building payment service provider (PSP) integrations.

**Key capabilities**
- Covers all mandatory integration touchpoints with the SCCOS that must be considered when integrating a payment provider (business logic, configurations, OMS, frontend forms)  and payment lifecycle handling, with practical implementation examples.
- Support for core payment flows: **Authorize → Capture → Cancel**.
- Two payment method templates (for example Credit Card, Invoice) including:
  - OMS state machines for synchronous and asynchronous authorization.
- Webhook infrastructure:
  - Payload logging
  - Signature validation
  - Route provider setup
- Data import configuration with payment method CSV templates and glossary translations (EN, DE).
- Automated module renaming and setup guidance to accelerate project adoption.
- Comprehensive integration checklist to ensure no required system part is missed during implementation.

**Business benefits**
- Reduced development time for new PSP integrations
- Consistent payment architecture and OMS alignment across projects.
- Improved reliability through standardized webhook and lifecycle handling.
- Clear separation of module developer and project integrator responsibilities.

**Documentation**
- [PSP Integration Template](/docs/integrations/custom-building-integrations/psp-integration-template.html)

### New Algolia Eco-Module Integration &lt;span class=&quot;inline-img&quot;&gt;![improvement](https://spryker.s3.eu-central-1.amazonaws.com/docs/scos/user/intro-to-spryker/releases/release-notes/improvement.png)&lt;/span&gt;

Replaces the legacy Algolia App model with a code-visible eco-module.

**Key capabilities**
- New Algolia integration as a standard Spryker eco-module.
- Full code visibility and extensibility for customers and partners.
- Support for current Algolia Search license–related features.
- Updated documentation for integration and customization.

**Business benefits**
- Increased flexibility and customization options.
- Reduced dependency on black-box App Spryker support and evolution implementations.
- Better alignment with project-level architecture and extension patterns.

**Documentation**
- [Integrate Algolia](/docs/pbc/all/search/latest/base-shop/third-party-integrations/algolia/integrate-algolia.html)

## Efficient and Flexible Cloud Foundation

### Cloud Self-Service Portal update {% include badge.html type=&quot;improvement&quot; %}

The Cloud Self-Service Portal is now available on a new platform that improves usability and accelerates value delivery.

{% include carousel.html
   images=&quot;
   https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/cloud-hub1.png||::
   https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/cloud-hub2.png||::
   https://spryker.s3.eu-central-1.amazonaws.com/docs/About/Releases/release-notes-202602/cloud-hub3.png||&quot;
%}

**Key capabilities**
- Spryker has moved the Cloud Self-Service Portal to a new platform to provide a better user experience and faster value delivery.
- In the new portal, you can access centralized Single Sign-On (SSO) management.

**Business benefits**
- Provides a structured migration path to Single Sign-On (SSO) to help you simplify access management.

**Portal access**
- [Customer Portal](https://portal.spryker.com/)

### RabbitMQ 4.1 rollout {% include badge.html type=&quot;improvement&quot; %}

This update completes the rollout of RabbitMQ 4.1 across all platform environments.

**Key capabilities**
- Upgrade to RabbitMQ 4.1 for improved messaging infrastructure.
- Platform-wide rollout to ensure consistency across environments.

**Business benefits**
- Improved stability and performance of asynchronous processing.
- Enhanced scalability for event-driven workloads.
- Reduced operational risk through alignment with the latest supported messaging version.

**Documentation**
- [Docker SDK service configuration](/docs/dg/dev/integrate-and-configure/configure-services.html)
- [System Requirements](/docs/dg/dev/system-requirements/latest/system-requirements.html)

### Security RSS feed: Docker image updates {% include badge.html type=&quot;improvement&quot; %}

This update integrates Docker image security release notes into the official Spryker security RSS feed, ensuring timely notifications for infrastructure updates.

**Key capabilities**
- RSS Feed Integration: Docker image security releases are now automatically published to the security RSS stream (/feed-security.xml)
- Automated Visibility: Real-time visibility of image-related security patches alongside standard application news.

**Business benefits**
- Improved Security Posture: Ensures DevOps and Security teams are immediately alerted to infrastructure-level vulnerabilities and patches.
- Streamlined Compliance: Easier tracking and auditing of container image versions through a centralized, standardized feed.
- Proactive Maintenance: Reduces the window of exposure by eliminating the need to manually check for image updates.

**Documentation**
- [Spryker Security RSS Feed](/feed-security.xml)
- [Release notes](/docs/about/all/releases/product-and-code-releases.html)
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/about/all/releases/release-notes-202602.0.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/about/all/releases/release-notes-202602.0.html</guid>
            
            
        </item>
        
        <item>
            <title>Recurring Orders feature overview</title>
            <description>{% info_block warningBox &quot;Early Access&quot; %}

This feature is in Early Access. We&apos;d love for you to try it out and share feedback as we work toward general availability.

{% endinfo_block %}

The *Recurring Orders* feature lets B2B buyers set up automated repeat purchases directly from the checkout. Once configured, the system places orders automatically at the chosen interval, sends notifications before each execution, and pauses for buyer review when prices change or products become unavailable.

![Recurring order list](https://spryker.s3.eu-central-1.amazonaws.com/docs/Features/Recurring+Orders/RecurringOrders_1.png)

![Recurring order detail](https://spryker.s3.eu-central-1.amazonaws.com/docs/Features/Recurring+Orders/RecurringOrders_2.png)

## Concepts

| TERM | DESCRIPTION |
| --- | --- |
| Recurring schedule | The configuration record that drives automated order placement. Stores the cadence, the serialized quote snapshot, and the state machine state. |
| Cadence | The interval at which the order is placed. One of: weekly, bi-weekly, monthly, or every N weeks. |
| Trigger date | The date on which the state machine attempts to place the next order. |
| Notification window | The number of hours before the trigger date when the pre-trigger notification is sent to the buyer. |
| Review Required | A state the schedule enters when price increases or product issues are detected at pre-placement validation. The buyer must accept or adjust the order before it is placed. |

## Setting up a recurring order

At checkout, an eligible buyer can enable the recurring order setup widget. The buyer selects a cadence (for example, weekly or monthly) and optionally sets a schedule name and an interval value for the *every N weeks* cadence.

When the order is placed, the system:

1. Saves a serialized snapshot of the quote — including products, quantities, prices, shipment method, and payment method.
2. Creates a recurring schedule record in `spy_recurring_schedule` with the first trigger date calculated from the cadence.
3. Registers the schedule with the `RecurringOrder` state machine in the `draft` state and immediately activates it.

A recurring schedule is **only available** for quotes that meet all of the following conditions:

- The quote is not locked (not sent for approval).
- The quote does not originate from a Request for Quote (RFQ).
- The customer is not a guest.
- The payment method is invoice-based (`invoice`, `purchaseOnAccount`, or a configured equivalent).

## Cadence types

| CADENCE | DESCRIPTION |
| --- | --- |
| Weekly | Places an order every 7 days. |
| Bi-weekly | Places an order every 14 days. |
| Monthly | Places an order on the same calendar day each month. If the scheduled day does not exist in the target month, the date overflows: for example, a schedule anchored to January 31 next fires on March 3 (not February 28), and all subsequent executions are anchored to the third of each month. To avoid drift, use a start date on the twenty-eighth or earlier. |
| Every N weeks | Places an order every N weeks. Requires a positive integer value for N. |

![Recurring order setup at checkout](https://spryker.s3.eu-central-1.amazonaws.com/docs/Features/Recurring+Orders/RecurringOrders_3.png)

## Schedule lifecycle

The recurring schedule moves through states managed by the `RecurringOrder` state machine. The following diagram describes the full lifecycle:

| STATE | DESCRIPTION |
| --- | --- |
| `draft` | Newly created. Transitions to `active` immediately after checkout. |
| `active` | Running. The state machine checks the trigger date on every cron run. |
| `notifying` | The trigger date is within the notification window. The system sends a pre-trigger notification to the buyer. |
| `pre_trigger_notified` | The buyer has been notified. The schedule waits for the placement window to open or for a manual action (skip or cancel). |
| `validation` | Pre-placement validation is running. Price and availability are checked. |
| `confirmed` | Validation passed. The order is ready for placement. |
| `order_placed` | The checkout has been initiated. The system waits for confirmation. |
| `completing` | The order was successfully placed. The next trigger date is calculated and the schedule returns to `active`. |
| `skipped` | The buyer skipped the current execution. The next trigger date is advanced by one full cadence interval. |
| `review_required` | Validation detected an issue (price increase or product unavailability). The buyer must review before placement can proceed. |
| `paused` | The buyer manually paused the schedule. No orders are placed until it is resumed. |
| `failed` | The last order placement attempt failed. The buyer can retry, which moves the schedule to `review_required`. |
| `cancelled` | The schedule has been permanently stopped. This is a terminal state. |

### Buyer actions

Buyers can perform the following manual actions from the recurring order detail page on the storefront:

| ACTION | AVAILABLE FROM STATES | DESCRIPTION |
| --- | --- | --- |
| Pause | `active` | Temporarily stops order placement. The schedule can be resumed at any time with an optional custom resume date. |
| Resume | `paused` | Reactivates the schedule. The buyer can set a new next trigger date or keep the existing one. |
| Skip | `active`, `pre_trigger_notified`, `review_required` | Skips the next scheduled execution. The new trigger date is calculated by advancing the current trigger date by one cadence interval. If the current trigger date is already in the past due to processing lag, the recalculated date may also fall in the past and the schedule will process on the next cron run. |
| Cancel | `active`, `paused`, `pre_trigger_notified`, `review_required`, `failed`, `draft` | Permanently cancels the schedule. This action cannot be undone. The `draft` state is transient and is normally activated synchronously at checkout; cancellation from `draft` is a safety fallback. |
| Review | `review_required` | Opens the Review Required page where the buyer can accept price changes, remove unavailable items, and place the order. |
| Retry | `failed` | Moves the schedule to `review_required` so the buyer can review and re-attempt placement. |

![Recurring order list with attention banner](https://spryker.s3.eu-central-1.amazonaws.com/docs/Features/Recurring+Orders/RecurringOrders_4.png)

## Pre-trigger notification

Before each order placement, the system sends an email to the buyer within the configured **Schedule Grace Period** (default: 48 hours before the trigger date). The notification includes:

- The schedule name and the upcoming execution date.
- A link to the schedule detail page where the buyer can skip, pause, or cancel before the order is placed.

The Schedule Grace Period is configured globally in the Back Office under **Configuration &gt; Recurring Orders &gt; General &gt; Schedule**.

## Review Required flow

Before placing each order, the system validates the stored quote snapshot against current product and pricing data. If issues are detected, the schedule moves to the `review_required` state and the buyer receives a review notification email.

The buyer reviews the flagged items on the **Review Required** page. The following table lists common issue types. The full set of checkout error types that map to each group is configurable via `getReviewReasonGroupMap()` in `OrderExperienceManagementConfig`.

| ISSUE | DESCRIPTION |
| --- | --- |
| Price increased | The current unit price is higher than the reference price stored on the schedule item. |
| Unavailable | The product is out of stock, inactive, or blocked by a merchant or product approval rule. |
| Packaging unit unavailable | The product packaging unit constraints cannot be satisfied — for example, the required minimum or lead quantity is not available. |
| Discontinued | The product has been discontinued. |
| Substituted | The product has been replaced by another product. |
| Not approved | The product is pending approval and cannot be purchased. |
| Price unavailable | No current price could be resolved for the product. |
| Configurable bundle unavailable | A member of a configurable bundle is unpurchasable, so the entire bundle is dropped. |

Items flagged as **unavailable** or **not approved** are non-purchasable and must be removed before the order can proceed. Items with a price increase can be accepted or removed. The buyer confirms the changes, which updates the stored quote snapshot and places the order.

![Review Required page](https://spryker.s3.eu-central-1.amazonaws.com/docs/Features/Recurring+Orders/RecurringOrders_5.png)

## Execution history

Each recurring schedule maintains a full execution history. Every significant event is recorded:

| EVENT | DESCRIPTION |
| --- | --- |
| Placed | An order was successfully placed. The history entry links to the resulting sales order. |
| Failed | An order placement attempt failed. The entry includes the failure reason. |
| Skipped | The execution was skipped by the buyer. |
| Paused | The schedule was paused. |
| Resumed | The schedule was resumed. |
| Cancelled | The schedule was permanently cancelled. |

## Storefront pages

| PAGE | PATH | DESCRIPTION |
| --- | --- | --- |
| Recurring order list | `/recurring-orders` | Lists all recurring schedules for the current buyer, with status, cadence, and trigger date. Company users with the appropriate permission can filter by scope (own, company, or business unit). |
| Recurring order detail | `/recurring-orders/{uuid}` | Shows the full schedule configuration, the items and quantities, the next execution date, and the full execution history. |
| Review Required | `/recurring-orders/{uuid}/review-required` | Shows flagged items with issue reasons and price comparisons. The buyer accepts changes and places the order from this page. |

## B2B visibility and permissions

By default, a buyer can only view their own recurring schedules. Company users with additional permissions can view schedules across their organization:

| PERMISSION | DESCRIPTION |
| --- | --- |
| `SeeCompanyOrdersPermissionPlugin` | Grants visibility over all recurring schedules within the company. |
| `SeeBusinessUnitOrdersPermissionPlugin` | Grants visibility over all recurring schedules within the buyer&apos;s business unit. |

These permissions are registered as company role permissions and assigned in the Back Office under **Customers &gt; Company Roles**.

## Attention banner

When a buyer has schedules in the `paused`, `review_required`, or `failed` states, an attention banner is displayed on the storefront. The banner shows the count of schedules requiring attention and provides quick-access links to filter the recurring order list by each status.

## Related documents

- [Install the Recurring Orders feature](/docs/pbc/all/order-experience-management/latest/base-shop/install-and-upgrade/install-features/install-the-recurring-orders-feature.html)
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:09 +0000</pubDate>
            <link>https://docs.spryker.com/docs/pbc/all/order-experience-management/latest/base-shop/feature-overviews/recurring-orders-feature-overview.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/pbc/all/order-experience-management/latest/base-shop/feature-overviews/recurring-orders-feature-overview.html</guid>
            
            
        </item>
        
        <item>
            <title>Marketplace Product Options feature: Domain model and relationships</title>
            <description>The *Marketplace Product Options* feature lets merchants create their product option groups and values. Currently, you can [import product options](/docs/pbc/all/product-information-management/latest/marketplace/import-and-export-data/import-file-details-merchant-product-option-group.csv.html) where you specify the merchant reference.

## Module dependency graph

The following diagram illustrates the dependencies between the modules for the *Marketplace Product Options* feature.

![Module Dependency Graph](https://confluence-connect.gliffy.net/embed/image/d8882366-b2dd-4d6c-b401-01db47a00481.png?utm_medium=live&amp;utm_source=custom)

| NAME | DESCRIPTION |
| --- | --- |
| [MerchantProductOption](https://github.com/spryker/merchant-product-option) | Provides merchant product option main business logic and persistence. |
| [MerchantProductOptionDataImport](https://github.com/spryker/merchant-product-option-data-import) | Provides data import functionality for merchant product options. |
| [MerchantProductOptionStorage](https://github.com/spryker/merchant-product-option-storage) | Provides publish and sync functionality for merchant product options. |
| [MerchantProductOptionGui](https://github.com/spryker/merchant-product-option-gui) | Provides Back Office UI for merchant product options management. |
| [ProductOption](https://github.com/spryker/product-option) | Provides additional layer of optional items that can be sold with the actual product. |
| [ProductOptionStorage](https://github.com/spryker/product-option-storage) | Provides publish and sync functionality for product options. |
| [ProductOptionWidget](https://github.com/spryker-shop/product-option-widget) | Provides widgets for displaying product options. |

## Domain model

The following schema illustrates the Marketplace Product Options domain model:

![Domain Model](https://confluence-connect.gliffy.net/embed/image/90a0e5bc-a0d9-4cb2-a215-c5d08a786115.png?utm_medium=live&amp;utm_source=custom)

                                                                                                                                                      |
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/pbc/all/product-information-management/latest/marketplace/domain-model-and-relationships/marketplace-product-options-feature-domain-model-and-relationships.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/pbc/all/product-information-management/latest/marketplace/domain-model-and-relationships/marketplace-product-options-feature-domain-model-and-relationships.html</guid>
            
            
        </item>
        
        <item>
            <title>Marketplace Product Offer Prices feature: Domain model and relationships</title>
            <description>This document provides technical details about the Marketplace Product Offer Prices feature.

## Module dependency graph

The following diagram illustrates the dependencies between the modules for the *Marketplace Product Offer Prices* feature.

![Entity diagram](https://confluence-connect.gliffy.net/embed/image/f128877d-eb61-4d87-b1af-5f166eb45c45.png?utm_medium=live&amp;utm_source=confluence)

| MODULE     | DESCRIPTION                |
|------------|----------------------------|
| PriceProductOffer | Provides product offer price-related functionality, price persistence, current price resolvers per currency/price mode.   |
| PriceProductOfferDataImport | Imports data for product offer prices.    |
| PriceProductOfferGui | Back Office UI Interface for managing prices for product offers.    |
| PriceProductOfferStorage | Provides functionality to store data about product offer prices in the storage.   |
| PriceProductOfferVolume | Provides functionality to handle volume prices for product offers.    |
| PriceProductOfferVolumeGui | Back Office UI Interface for managing volume prices for product offers.    |
| PriceProductOfferExtension | Provides plugin interfaces for extending `PriceProductOffer` module functionality.   |
| PriceProductOfferStorageExtension | Provides plugin interfaces used by Price Product Offer Storage bundle.    |
| PriceProductOfferVolumesRestApi | Provides plugins to add `product-offer-volume-prices` to the `product-offer-prices`.   |
| ProductOfferPricesRestApi | Provides Rest API endpoints to manage product offer prices.   |
| ProductOfferPricesRestApiExtension | Provides plugin interfaces for extending the `ProductOfferPricesRestApi` module.    |
| Price | Handles product pricing and provides plugins for products to populate prices.  |
| PriceProduct | Provides product price-related functionality, price persistence, current price resolvers per currency/price mode.    |
| PriceProductStorage | Provides functionality to store data about product prices in the storage.    |
| PriceProductVolume | Provides functionality to handle volume prices for products.  |
| ProductOffer | Provides the core functionality for product offer features.   |

## Domain model

The following schema illustrates the Marketplace Product Offer Prices domain model:

![Entity diagram](https://confluence-connect.gliffy.net/embed/image/0ad490bb-f21f-4e4a-b6eb-e0102a8c7b42.png?utm_medium=live&amp;utm_source=confluence)
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/pbc/all/price-management/latest/marketplace/domain-model-and-relationships/marketplace-product-offer-prices-feature-domain-model-and-relationships.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/pbc/all/price-management/latest/marketplace/domain-model-and-relationships/marketplace-product-offer-prices-feature-domain-model-and-relationships.html</guid>
            
            
        </item>
        
        <item>
            <title>Integrating with Spryker OMS</title>
            <description>Order Management System (OMS) in Spryker is a built-in workflow engine that manages the lifecycle of an order - from placement to delivery. It defines each step (for example payment, shipping, cancellation) as part of a process, with clear transitions and conditions.

For third-party integrations, you can primarily use OMS for event-driven and API-driven integrations.

## Event-driven integration (OMS as the source)

- OMS can be used to publish events (for example `Order.Paid`, `Order.Shipped`) when an order transitions to a specific state.
- Your third-party integration can then subscribe to these events (for example via a message queue like RabbitMQ) to trigger actions in an external system (for example update ERP, notify logistics partner, send customer email).

## API-driven integration (OMS as the target)

- You can expose Glue API endpoints that trigger specific OMS commands or state transitions (for example set order status to shipped, initiate return).
- This allows external systems (for example a Warehouse Management System, a Call Center application) to update the order status or trigger actions within Spryker&apos;s OMS.
- You can also extend the OMS process with custom states and transitions specifically designed for your third party&apos;s workflow.

## Further reading

For details on implementing creating OMS processes, see [Set up an Order Management System](/docs/dg/dev/backend-development/data-manipulation/set-up-an-order-management-system.html).</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/integrations/custom-building-integrations/integrating-with-spryker-oms/integrating-with-spryker-oms.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/integrations/custom-building-integrations/integrating-with-spryker-oms/integrating-with-spryker-oms.html</guid>
            
            
        </item>
        
        <item>
            <title>Install the Multi-Factor Authentication feature</title>
            <description>This document describes how to install the [Multi-Factor Authentication (MFA) feature](/docs/pbc/all/multi-factor-authentication/latest/multi-factor-authentication.html).

## Prerequisites

| FEATURE                    | VERSION          | INSTALLATION  GUIDE                                                                                                                                                                                                                     |
|----------------------------|------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Spryker Core               | {{page.release_tag}} | [Install the Spryker Core feature](/docs/pbc/all/miscellaneous/latest/install-and-upgrade/install-features/install-the-spryker-core-feature.html)                                                                             |
| Spryker Core Back Office   | {{page.release_tag}} | [Install the Spryker Core Back Office feature](/docs/pbc/all/back-office/latest/base-shop/install-and-upgrade/install-the-spryker-core-back-office-feature.html)                                                                      |
| Customer Account Management | {{page.release_tag}} | [Install the Customer Account Management feature](/docs/pbc/all/customer-relationship-management/latest/base-shop/install-and-upgrade/install-features/install-the-customer-account-management-feature.html)                  |
| Agent assist               | {{page.release_tag}} | [Install the Agent Assist feature](/docs/pbc/all/user-management/latest/base-shop/install-and-upgrade/install-the-agent-assist-feature.html)                                                                                          |
| Glue Rest API              | {{page.release_tag}} | [Install the Spryker Core Glue API](/docs/pbc/all/miscellaneous/latest/install-and-upgrade/install-glue-api/install-the-spryker-core-glue-api.html)   |
| Back Office dropdown navigation | {{page.release_tag}} | [Install Back Office dropdown navigation](/docs/pbc/all/back-office/latest/base-shop/install-and-upgrade/install-back-office-dropdown-navigation.html) |
| Backend API Application | {{page.release_tag}} | [Integrate Backend API Application](/docs/integrations/spryker-glue-api/backend-api/integrate-backend-api/integrate-backend-api.html) |

## 1) Install the required modules

Install the required modules using Composer:

```bash
composer require spryker/multi-factor-auth:&quot;^2.1.0&quot; spryker/multi-factor-auth-extension:&quot;^1.2.0&quot; --update-with-dependencies
```

{% info_block warningBox &quot;Verification&quot; %}

Make sure the following modules have been installed:

| MODULE                   | EXPECTED DIRECTORY                         |
|--------------------------|--------------------------------------------|
| MultiFactorAuth          | vendor/spryker/multi-factor-auth           |
| MultiFactorAuthExtension | vendor/spryker/multi-factor-auth-extension |

{% endinfo_block %}

## 2) Set up configuration

MFA is configured separately for customers and users (Back Office users and agents). Make sure to define values for both user types by implementing the corresponding methods in the `MultiFactorAuthConfig` class, such as `getCustomerCodeLength()` and `getUserCodeLength()`.

### Configure MFA code length for customers

**src/Pyz/Shared/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Shared\MultiFactorAuth;

use Spryker\Shared\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specifications:
     * - Defines the length of the authentication code for customer.
     * 
     * @api
     *
     * @return int
     */
    public function getCustomerCodeLength(): int
    {
        return 6;
    }
}
```

### Configure MFA code length for users

**src/Pyz/Shared/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Shared\MultiFactorAuth;

use Spryker\Shared\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specification:
     * - Returns the multi-factor authentication code length for user.
     *
     * @api
     *
     * @return int
     */
    public function getUserCodeLength(): int
    {
        return 6;
    }
}
```

### Configure MFA code validity time for customers

Configure the time interval in minutes during which an authentication code is valid by extending the `MultiFactorAuthConfig` class:

**src/Pyz/Zed/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Zed\MultiFactorAuth;

use Spryker\Zed\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specifications:
     * - Defines the time interval in minutes during which the authentication code is valid.
     * 
     * @api
     *
     * @return int
     */
    public function getCustomerCodeValidityTtl(): int
    {
        return 30;
    }
}
```

### Configure MFA code validity time for users

Configure the time interval in minutes during which an authentication code is valid by extending the `MultiFactorAuthConfig` class:


**src/Pyz/Zed/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Zed\MultiFactorAuth;

use Spryker\Zed\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specification:
     * - Returns the code validity TTL in minutes for user.
     *
     * @api
     *
     * @return int
     */
    public function getUserCodeValidityTtl(): int
    {
        return 30;
    }
}
```


### Configure brute-force protection limit for customers

Configure the maximum number of failed MFA attempts a customer can make before brute force protection is triggered. This is done by extending the `MultiFactorAuthConfig` class:


**src/Pyz/Zed/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Zed\MultiFactorAuth;

use Spryker\Zed\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specifications:
     * - Defines the number of failed attempts a customer can make to enter the authentication code in order to prevent brute force attacks.
     * 
     * @api
     *
     * @return int
     */
    public function getCustomerAttemptLimit(): int
    {
        return 3;
    }
}
```



### Configure brute-force protection limit for users

Configure the maximum number of failed MFA attempts a customer can make before brute force protection is triggered. This is done by extending the `MultiFactorAuthConfig` class:


**src/Pyz/Zed/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Zed\MultiFactorAuth;

use Spryker\Zed\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specification:
     * - Returns the multi-factor authentication code validation attempt limit for user.
     *
     * @api
     *
     * @return int
     */
    public function getUserAttemptsLimit(): int
    {
        return 3;
    }
}
```


### Configure protected routes and forms for customers

**src/Pyz/Yves/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Yves\MultiFactorAuth;

use Spryker\Yves\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specifications:
     * - Defines the routes and forms that require MFA authentication.
     * 
     * @api
     *
     * @return array&lt;string, array&lt;string&gt;&gt;
     */
    public function getEnabledRoutesAndForms(): array
    {
        return [
            &apos;YOUR_ROUTE_NAME&apos; =&gt; [&apos;YOUR_FORM_NAME&apos;],
        ];
    }
}
```

{% info_block warningBox &quot;&quot; %}

You can configure multiple forms on the same page to require MFA authentication.

{% endinfo_block %}


### Configure protected routes and forms for users


**src/Pyz/Zed/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Zed\MultiFactorAuth;

use Spryker\Zed\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * Specifications:
     * - Returns a list of enabled routes and their corresponding forms for user multi-factor authentication in the following format
     * [
     *    &apos;routeName&apos; =&gt; [&apos;formName&apos;],
     * ]
     * 
     * @api
     *
     * @return array&lt;string, array&lt;string&gt;&gt;
     */
    public function getEnabledRoutesAndForms(): array
    {
        return [
            &apos;YOUR_ROUTE_NAME&apos; =&gt; [&apos;YOUR_FORM_NAME&apos;],
        ];
    }
}
```

{% info_block warningBox &quot;&quot; %}

You can configure multiple forms on the same page to require MFA authentication.

{% endinfo_block %}


### Configure protected routes and forms for Storefront API

**src/Pyz/Glue/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Glue\MultiFactorAuth;

use Spryker\Glue\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * @return array&lt;string&gt;
     */
    public function getRestApiMultiFactorAuthProtectedResources(): array
    {
        return [
            &apos;YOUR_RESOURCE_NAME&apos;,
        ];
    }
}
```


### Configure protected routes for Backend API

Only resource routes are supported for MFA protection. Custom routes defined via `RouteProviderPlugins` can&apos;t be protected with MFA.

For more information about Glue Backend API resources, see [Create backend resources](/docs/integrations/spryker-glue-api/backend-api/developing-apis/create-backend-resources.html).

**src/Pyz/Glue/MultiFactorAuth/MultiFactorAuthConfig.php**

```php
namespace Pyz\Glue\MultiFactorAuth;

use Spryker\Glue\MultiFactorAuth\MultiFactorAuthConfig as SprykerMultiFactorAuthConfig;

class MultiFactorAuthConfig extends SprykerMultiFactorAuthConfig
{
    /**
     * @return array&lt;string&gt;
     */
    public function getMultiFactorAuthProtectedBackendResources(): array
    {
        return [
            &apos;YOUR_RESOURCE_NAME&apos;,
        ];
    }
}

```

### Configure Back Office ACL access

To allow access to MFA requests during the login process in the Back Office, define a public ACL rule.


**config/Shared/config_default.php**

```php
$config[AclConstants::ACL_DEFAULT_RULES] = [
    [
        &apos;bundle&apos; =&gt; &apos;multi-factor-auth&apos;,
        &apos;controller&apos; =&gt; &apos;*&apos;,
        &apos;action&apos; =&gt; &apos;*&apos;,
        &apos;type&apos; =&gt; &apos;allow&apos;,
    ],
];
```

**src/Pyz/Zed/SecurityGui/SecurityGuiConfig.php**

```php
&lt;?php
namespace Pyz\Zed\SecurityGui;

use Spryker\Zed\SecurityGui\SecurityGuiConfig as SprykerSecurityGuiConfig;

class SecurityGuiConfig extends SprykerSecurityGuiConfig
{
    /**
     * @var string
     */
    protected const IGNORABLE_ROUTE_PATTERN = &apos;^/(...|multi-factor-auth|...)&apos;;
}
```

### Configure protected endpoints

MFA protection is configured differently for each API type. The Storefront API implementation already has default protected endpoints configured.

The configuration below focuses on Backend API. If you&apos;re only using Storefront API, you can [skip to the next step](#set-up-the-database-schema-and-transfer-objects).


Configure protected endpoints for Glue Backend API:

**src/Pyz/Shared/GlueBackendApiApplicationAuthorizationConnector/GlueBackendApiApplicationAuthorizationConnectorConfig.php**

```php
namespace Pyz\Shared\GlueBackendApiApplicationAuthorizationConnector;

class GlueBackendApiApplicationAuthorizationConnectorConfig extends SprykerGlueBackendApiApplicationAuthorizationConnectorConfig
{
    public function getProtectedPaths(): array
    {
        return [
            &apos;/multi-factor-auth-types&apos; =&gt; [
                &apos;isRegularExpression&apos; =&gt; false,
            ],
            &apos;/multi-factor-auth-trigger&apos; =&gt; [
                &apos;isRegularExpression&apos; =&gt; false,
            ],
            &apos;/multi-factor-auth-type-activate&apos; =&gt; [
                &apos;isRegularExpression&apos; =&gt; false,
            ],
            &apos;/multi-factor-auth-type-verify&apos; =&gt; [
                &apos;isRegularExpression&apos; =&gt; false,
            ],
            &apos;/multi-factor-auth-type-deactivate&apos; =&gt; [
                &apos;isRegularExpression&apos; =&gt; false,
            ],
        ];
    }
}
```


## 3) Set up the database schema and transfer objects

Apply database changes and generate entity and transfer changes:

```bash
console propel:install
console transfer:generate
```

{% info_block warningBox &quot;Verification&quot; %}

Make sure that the following changes have been applied in the database:

| DATABASE ENTITY                               | TYPE  | EVENT |
|-----------------------------------------------|-------|-------|
| spy_customer_multi_factor_auth                | table | added |
| spy_customer_multi_factor_auth_codes          | table | added |
| spy_customer_multi_factor_auth_codes_attempts | table | added |
| spy_user_multi_factor_auth                    | table | added |
| spy_user_multi_factor_auth_codes              | table | added |
| spy_user_multi_factor_auth_codes_attempts     | table | added |

{% endinfo_block %}

{% info_block warningBox &quot;Verification&quot; %}

Make sure the following changes have been applied in transfer objects:

| TRANSFER                          | TYPE     | EVENT   | PATH                                                                    |
|-----------------------------------|----------|---------|-------------------------------------------------------------------------|
| MultiFactorAuth                   | class    | created | src/Generated/Shared/Transfer/MultiFactorAuthTransfer                   |
| MultiFactorAuthCode               | class    | created | src/Generated/Shared/Transfer/MultiFactorAuthCodeTransfer               |
| MultiFactorAuthTypesCollection    | class    | created | src/Generated/Shared/Transfer/MultiFactorAuthTypesCollectionTransfer    |
| MultiFactorAuthValidationRequest  | class    | created | src/Generated/Shared/Transfer/MultiFactorAuthValidationRequestTransfer  |
| MultiFactorAuthValidationResponse | class    | created | src/Generated/Shared/Transfer/MultiFactorAuthValidationResponseTransfer |
| MultiFactorAuthCriteria           | class    | created | src/Generated/Shared/Transfer/MultiFactorAuthCriteria                   |
| MultiFactorAuthCodeCriteria       | class    | created | src/Generated/Shared/Transfer/MultiFactorAuthCodeCriteriaTransfer       |

{% endinfo_block %}

## 4) Add translations

1. Append glossary according to your configuration:

&lt;details&gt;
&lt;summary&gt;data/import/common/common/glossary.csv&lt;/summary&gt;

```csv
multi_factor_auth.multi_factor_auth.list.title,&quot;Set up Multi-Factor Authentication&quot;,en_US
multi_factor_auth.multi_factor_auth.list.title,&quot;Multi-Faktor-Authentifizierung einrichten&quot;,de_DE
multi_factor_auth.error.invalid_code,&quot;Invalid multi-factor authentication code. You have %remainingAttempts% attempt(s) left.&quot;,en_US
multi_factor_auth.error.invalid_code,&quot;Ungültiger Multi-Faktor-Authentifizierungscode. Sie haben %remainingAttempts% Versuch(e) verbleiben.&quot;,de_DE
multi_factor_auth.error.attempts_exceeded,&quot;You have exceeded the number of allowed attempts. Please try again after the page has been refreshed.&quot;,en_US
multi_factor_auth.error.attempts_exceeded,&quot;Sie haben die Anzahl der zulässigen Versuche überschritten. Bitte versuchen Sie es erneut, nachdem die Seite aktualisiert wurde.&quot;,de_DE
multi_factor_auth.error.expired_code,&quot;The multi-factor authentication code has expired. Please try again.&quot;,en_US
multi_factor_auth.error.expired_code,&quot;Der Multi-Faktor-Authentifizierungscode ist abgelaufen. Bitte versuchen Sie es erneut.&quot;,de_DE
multi_factor_auth.error.authentication_method_not_selected,&quot;Unable to proceed. A multi-factor authentication method must be selected. Please refresh the page and try again or contact support if the problem persists.&quot;,en_US
multi_factor_auth.error.authentication_method_not_selected,&quot;Kann nicht fortgesetzt werden. Es muss eine Multi-Faktor-Authentifizierungsmethode ausgewählt werden. Bitte aktualisieren Sie die Seite und versuchen Sie es erneut oder wenden Sie sich an den Support, wenn das Problem weiterhin besteht.&quot;,de_DE
multi_factor_auth.error.corrupted_code,&quot;The provided code is empty or invalid. Please try again.&quot;,en_US
multi_factor_auth.error.corrupted_code,&quot;Der angegebene Code ist leer oder ungültig. Bitte versuchen Sie es erneut.&quot;,de_DE
multi_factor_auth.method.select,&quot;Select Authentication Method&quot;,en_US
multi_factor_auth.method.select,&quot;Authentifizierungsmethode auswählen&quot;,de_DE
multi_factor_auth.code.validation,&quot;Enter Authentication Code&quot;,en_US
multi_factor_auth.code.validation,&quot;Authentifizierungscode eingeben&quot;,de_DE
multi_factor_auth.enter_code_for_method,&quot;We sent the authentication code to your %type%. Type it below to continue.&quot;,en_US
multi_factor_auth.enter_code_for_method,&quot;Wir haben Ihnen den Authentifizierungscode per %type% gesendet. Geben Sie ihn unten ein, um fortzufahren.&quot;,de_DE
multi_factor_auth.access_denied,&quot;Access is strictly restricted until multi-factor authentication verification is successfully completed. Please ensure that JavaScript is enabled in your browser, refresh the page, and try again. If the problem persists, you may need to complete the multi-factor authentication process again.&quot;,en_US
multi_factor_auth.access_denied,&quot;Zugriff ist bis zur erfolgreichen Vollziehung der Multi-Faktor-Authentifizierung eingeschränkt. Bitte stellen Sie sicher, dass JavaScript in Ihrem Browser aktiviert ist, die Seite aktualisieren und erneut versuchen. Wenn das Problem weiterhin besteht, sollten Sie die Multi-Faktor-Authentifizierungprozess erneut abschließen.&quot;,de_DE
multi_factor_auth.activation.success,&quot;The multi-factor authentication has been activated.&quot;,en_US
multi_factor_auth.activation.success,&quot;Die Multi-Faktor-Authentifizierung wurde aktiviert.&quot;,de_DE
multi_factor_auth.deactivation.success,&quot;The multi-factor authentication has been deactivated.&quot;,en_US
multi_factor_auth.deactivation.success,&quot;Die Multi-Faktor-Authentifizierung wurde deaktiviert.&quot;,de_DE
multi_factor_auth.activation.error,&quot;The multi-factor authentication could not be activated.&quot;,en_US
multi_factor_auth.activation.error,&quot;Die Multi-Faktor-Authentifizierung konnte nicht aktiviert werden.&quot;,de_DE
multi_factor_auth.deactivation.error,&quot;The multi-factor authentication could not be deactivated.&quot;,en_US
multi_factor_auth.deactivation.error,&quot;Die Multi-Faktor-Authentifizierung konnte nicht deaktiviert werden.&quot;,de_DE
multi_factor_auth.selection.error.required,&quot;Please choose how you would like to verify your identity.&quot;,en_US
multi_factor_auth.selection.error.required,&quot;Bitte wählen Sie aus, wie Sie Ihre Identität überprüfen möchten.&quot;,de_DE
multi_factor_auth.continue,&quot;Continue&quot;,en_US
multi_factor_auth.continue,&quot;Fortfahren&quot;,de_DE
multi_factor_auth.verify_code,&quot;Verify Code&quot;,en_US
multi_factor_auth.verify_code,&quot;Code überprüfen&quot;,de_DE
multi_factor_auth.required_options,&quot;You must choose one option to continue!&quot;,en_US
multi_factor_auth.required_options,&quot;Sie müssen eine Option auswählen, um fortzufahren!&quot;,de_DE
multi_factor_auth.invalid_csrf_token,&quot;Invalid CSRF token.&quot;,en_US
multi_factor_auth.invalid_csrf_token,&quot;Ungültiges CSRF-Token.&quot;,de_DE
multi_factor_auth.note_mfa_affects,&quot;Note, any changes made here will also affect how MFA works in other environments like the Back Office, since your accounts are linked.&quot;,en_US
multi_factor_auth.note_mfa_affects,&quot;Hinweis: Alle hier vorgenommenen Änderungen wirken sich auch darauf aus, wie MFA in anderen Umgebungen wie dem Back Office funktioniert, da Ihre Konten verknüpft sind.&quot;,de_DE
```

&lt;/details&gt;

2. Import data:

```bash
console data:import glossary
```

{% info_block warningBox &quot;Verification&quot; %}

Make sure that, in the database, the configured data are added to the `spy_glossary` table.

{% endinfo_block %}

## 5) Set up widgets

{% info_block warningBox &quot;Only for customers or agents&quot; %}

Apply the changes in this section only if you&apos;re integrating MFA for customers or agents in Yves (Storefront).

{% endinfo_block %}

Register the following plugins to enable widgets:

| PLUGIN                           | SPECIFICATION                                             | PREREQUISITES | NAMESPACE                               |
|----------------------------------|-----------------------------------------------------------|---------------|-----------------------------------------|
| MultiFactorAuthHandlerWidget     | Provides MFA handling functionality.                      |               | SprykerShop\Yves\MultiFactorAuth\Widget |
| SetMultiFactorAuthMenuItemWidget | Adds an MFA menu item to the customer profile navigation. |               | SprykerShop\Yves\MultiFactorAuth\Widget |

**src/Pyz/Yves/ShopApplication/ShopApplicationDependencyProvider.php**

```php
&lt;?php
namespace Pyz\Yves\ShopApplication;

use SprykerShop\Yves\ShopApplication\ShopApplicationDependencyProvider as SprykerShopApplicationDependencyProvider;
use Spryker\Yves\MultiFactorAuth\Widget\MultiFactorAuthHandlerWidget;
use Spryker\Yves\MultiFactorAuth\Widget\SetMultiFactorAuthMenuItemWidget;

class ShopApplicationDependencyProvider extends SprykerShopApplicationDependencyProvider
{
    protected function getGlobalWidgets(): array
    {
        return [
            SetMultiFactorAuthMenuItemWidget::class,
            MultiFactorAuthHandlerWidget::class,
        ];
    }
}
```


## 6) Set up behavior

Enable the following behaviors by registering the plugins:

| PLUGIN                                                    | SPECIFICATION                                                                                                                      | PREREQUISITES | NAMESPACE                                                                             |
|-----------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------|---------------|---------------------------------------------------------------------------------------|
| CustomerMultiFactorAuthenticationHandlerPlugin            | Handles customer login MFA.                                                                                                        |               | Spryker\Yves\MultiFactorAuth\Plugin\AuthenticationHandler\Customer                    |
| UserMultiFactorAuthenticationHandlerPlugin                | Handles user login MFA.                                                                                                            |               | Spryker\Zed\MultiFactorAuth\Communication\Plugin\AuthenticationHandler\User           |
| MultiFactorAuthCustomerRouteProviderPlugin                | Provides routes for customer MFA.                                                                                                  |               | Spryker\Yves\MultiFactorAuth\Plugin\Router\Customer                                   |
| MultiFactorAuthAgentRouteProviderPlugin                   | Provides routes for agent user MFA.                                                                                                |               | Spryker\Yves\MultiFactorAuth\Plugin\Router\Agent                                      |
| MultiFactorAuthExtensionFormPlugin                        | Provides customer form validation against corrupted requests.                                                                      |               | Spryker\Yves\MultiFactorAuth\Plugin\Form                                              |
| MultiFactorAuthExtensionFormPlugin                        | Provides user form validation against corrupted requests.                                                                          |               | Spryker\Zed\MultiFactorAuth\Communication\Plugin\Form                                 |
| RemoveMultiFactorAuthCustomerTableActionExpanderPlugin    | Removes the MFA table action from the customer table in the Back Office.                                                           |               | Spryker\Zed\MultiFactorAuth\Communication\Plugin\Customer                             |
| PostCustomerLoginMultiFactorAuthenticationPlugin          | Handles customer MFA after successful login.                                                                                       |               | SprykerShop\Yves\CustomerPage\Plugin\MultiFactorAuth                                  |
| PostAgentLoginMultiFactorAuthenticationPlugin             | Handles agent user MFA after successful login.                                                                                     |               | SprykerShop\Yves\AgentPage\Plugin\MultiFactorAuth                                     |
| PostUserLoginMultiFactorAuthenticationPlugin              | Handles user MFA after successful login.                                                                                           |               | Spryker\Zed\SecurityGui\Communication\Plugin\MultiFactorAuth                          |
| MultiFactorAuthSetupNavigationPlugin                      | Adds the optional MFA menu item to the dropdown navigation in the Back Office.                                                     |               | Spryker\Zed\MultiFactorAuth\Communication\Plugin\Navigation                           |
| MultiFactorAuthRestUserValidatorPlugin                    | Validates requests against MFA for Glue REST API.                                                                                  |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi                           |
| MultiFactorAuthTypesResourcePlugin                        | Provides available MFA methods for Glue REST API.                                                                                  |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi                           |
| MultiFactorAuthTriggerResourcePlugin                      | Triggers code sending for the provided enabled MFA method for Glue REST API.                                                       |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi                           |
| MultiFactorAuthActivateResourcePlugin                     | Triggers code sending the provided MFA method to be activated for Glue REST API.                                                   |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi                           |
| MultiFactorAuthDeactivateResourcePlugin                   | Deactivates the provided MFA method for Glue REST API.                                                                             |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi                           |
| MultiFactorAuthTypeVerifyResourcePlugin                   | Verifies MFA code and activates the provided MFA method for Glue REST API.                                                         |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi                           |
| MultiFactorAuthBackendApiRequestValidatorPlugin           | Validates requests against MFA for Backend API.                                                                                    |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication                         |
| MultiFactorAuthBackendResourcePlugin                      | Provides available MFA methods for Backend API.                                                                                    |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication                         |
| MultiFactorAuthTriggerBackendResourcePlugin               | Triggers code sending for the provided enabled MFA method for Backend API.                                                         |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication                         |
| MultiFactorAuthTypeActivateBackendResourcePlugin          | Triggers code sending the provided MFA method to be activated for Backend API.                                                     |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication                         |
| MultiFactorAuthTypeDeactivateBackendResourcePlugin        | Deactivates the provided MFA method for Backend API.                                                                               |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication                         |
| MultiFactorAuthTypeVerifyBackendResourcePlugin            | Verifies MFA code and activates the provided MFA method for Backend API.                                                           |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication                         |
| MultiFactorAuthStorefrontApiRequestValidatorPlugin        | Validates requests against MFA for Storefront API.                                                                                 |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueStorefrontApiApplication                      |
| MultiFactorAuthStorefrontResourcePlugin                   | Provides available MFA methods for Storefront API.                                                                                 |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueStorefrontApiApplication                      |
| MultiFactorAuthTriggerStorefrontResourcePlugin            | Triggers code sending for the provided enabled MFA method for Storefront API.                                                      |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueStorefrontApiApplication                      |
| MultiFactorAuthTypeActivateStorefrontResourcePlugin       | Triggers code sending the provided MFA method to be activated for Storefront API.                                                  |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueStorefrontApiApplication                      |
| MultiFactorAuthTypeDeactivateStorefrontResourcePlugin     | Deactivates the provided MFA method for Storefront API.                                                                            |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueStorefrontApiApplication                      |
| MultiFactorAuthTypeVerifyStorefrontResourcePlugin         | Verifies MFA code and activates the provided MFA method for Storefront API.                                                        |               | Spryker\Glue\MultiFactorAuth\Plugin\GlueStorefrontApiApplication                      |


### Register the plugins for customers


**src/Pyz/Yves/CustomerPage/CustomerPageDependencyProvider.php**

```php
namespace Pyz\Yves\CustomerPage;

use Spryker\Yves\MultiFactorAuth\Plugin\AuthenticationHandler\Customer\CustomerMultiFactorAuthenticationHandlerPlugin;
use SprykerShop\Yves\CustomerPage\CustomerPageDependencyProvider as SprykerShopCustomerPageDependencyProvider;

class CustomerPageDependencyProvider extends SprykerShopCustomerPageDependencyProvider
{
    protected function getCustomerAuthenticationHandlerPlugins(): array
    {
        return [
            new CustomerMultiFactorAuthenticationHandlerPlugin(),
        ];
    }
}
```



**src/Pyz/Yves/MultiFactorAuth/MultiFactorAuthDependencyProvider.php**

```php
namespace Pyz\Yves\MultiFactorAuth;

use SprykerShop\Yves\CustomerPage\Plugin\MultiFactorAuth\PostCustomerLoginMultiFactorAuthenticationPlugin;
use Spryker\Yves\MultiFactorAuth\MultiFactorAuthDependencyProvider as SprykerMultiFactorAuthDependencyProvider;

class MultiFactorAuthDependencyProvider extends SprykerMultiFactorAuthDependencyProvider
{
    protected function getPostLoginMultiFactorAuthenticationPlugins(): array
    {
        return [
            new PostCustomerLoginMultiFactorAuthenticationPlugin(),
        ];
    }
}
```


**src/Pyz/Yves/Router/RouterDependencyProvider.php**

```php
namespace Pyz\Yves\Router;

use Spryker\Yves\Router\RouterDependencyProvider as SprykerRouterDependencyProvider;
use Spryker\Yves\MultiFactorAuth\Plugin\Router\Customer\MultiFactorAuthCustomerRouteProviderPlugin;

class RouterDependencyProvider extends SprykerRouterDependencyProvider
{
    protected function getRouteProvider(): array
    {
        return [
            new MultiFactorAuthCustomerRouteProviderPlugin(),
        ];
    }
}
```



**src/Pyz/Yves/Form/FormDependencyProvider.php**

```php
namespace Pyz\Yves\Form;

use Spryker\Yves\Form\FormDependencyProvider as SprykerFormDependencyProvider;
use Spryker\Yves\MultiFactorAuth\Plugin\Form\MultiFactorAuthExtensionFormPlugin;

class FormDependencyProvider extends SprykerFormDependencyProvider
{
    protected function getFormPlugins(): array
    {
        return [
            new MultiFactorAuthExtensionFormPlugin(),
        ];
    }
}
```



### Register the plugins for agent users


**src/Pyz/Yves/AgentPage/AgentPageDependencyProvider.php**

```php
namespace Pyz\Yves\AgentPage;

use Spryker\Yves\MultiFactorAuth\Plugin\AuthenticationHandler\Agent\AgentUserMultiFactorAuthenticationHandlerPlugin;
use SprykerShop\Yves\AgentPage\AgentPageDependencyProvider as SprykerShopAgentPageDependencyProvider;

class AgentPageDependencyProvider extends SprykerShopAgentPageDependencyProvider
{
    protected function getAgentUserAuthenticationHandlerPlugins(): array
    {
        return [
            new AgentUserMultiFactorAuthenticationHandlerPlugin(),
        ];
    }
}
```



**src/Pyz/Yves/MultiFactorAuth/MultiFactorAuthDependencyProvider.php**

```php
namespace Pyz\Yves\MultiFactorAuth;

use SprykerShop\Yves\AgentPage\Plugin\MultiFactorAuth\PostAgentLoginMultiFactorAuthenticationPlugin;
use Spryker\Yves\MultiFactorAuth\MultiFactorAuthDependencyProvider as SprykerMultiFactorAuthDependencyProvider;

class MultiFactorAuthDependencyProvider extends SprykerMultiFactorAuthDependencyProvider
{
    protected function getPostLoginMultiFactorAuthenticationPlugins(): array
    {
        return [
            new PostAgentLoginMultiFactorAuthenticationPlugin(),
        ];
    }
}
```



**src/Pyz/Yves/Router/RouterDependencyProvider.php**

```php
namespace Pyz\Yves\Router;

use Spryker\Yves\Router\RouterDependencyProvider as SprykerRouterDependencyProvider;
use Spryker\Yves\MultiFactorAuth\Plugin\Router\Agent\MultiFactorAuthAgentRouteProviderPlugin;

class RouterDependencyProvider extends SprykerRouterDependencyProvider
{
    protected function getRouteProvider(): array
    {
        return [
            new MultiFactorAuthAgentRouteProviderPlugin(),
        ];
    }
}
```



**src/Pyz/Yves/Form/FormDependencyProvider.php**

```php
namespace Pyz\Yves\Form;

use Spryker\Yves\Form\FormDependencyProvider as SprykerFormDependencyProvider;
use Spryker\Yves\MultiFactorAuth\Plugin\Form\MultiFactorAuthExtensionFormPlugin;

class FormDependencyProvider extends SprykerFormDependencyProvider
{
    protected function getFormPlugins(): array
    {
        return [
            new MultiFactorAuthExtensionFormPlugin(),
        ];
    }
}
```


### Register the plugins for Back Office users


**src/Pyz/Zed/Customer/CustomerDependencyProvider.php**

```php
namespace Pyz\Zed\Customer;

use Spryker\Zed\Customer\CustomerDependencyProvider as SprykerCustomerDependencyProvider;
use Spryker\Zed\MultiFactorAuth\Communication\Plugin\Customer\RemoveMultiFactorAuthCustomerTableActionExpanderPlugin;

class FormDependencyProvider extends SprykerFormDependencyProvider
{
    protected function getCustomerTableActionExpanderPlugins(): array
    {
        return [
            new RemoveMultiFactorAuthCustomerTableActionExpanderPlugin(),
        ];
    }
}
```


**src/Pyz/Zed/Form/FormDependencyProvider.php**

```php
namespace Pyz\Zed\Form;

use Spryker\Zed\Form\FormDependencyProvider as SprykerFormDependencyProvider;
use Spryker\Zed\MultiFactorAuth\Communication\Plugin\Form\MultiFactorAuthExtensionFormPlugin;

class FormDependencyProvider extends SprykerFormDependencyProvider
{
    protected function getFormPlugins(): array
    {
        return [
            new MultiFactorAuthExtensionFormPlugin(),
        ];
    }
}
```


**src/Pyz/Zed/Gui/GuiDependencyProvider.php**

```php
namespace Pyz\Zed\Gui;

use Spryker\Zed\Gui\GuiDependencyProvider as SprykerGuiDependencyProvider;
use Spryker\Zed\MultiFactorAuth\Communication\Plugin\Navigation\MultiFactorAuthSetupNavigationPlugin;

class GuiDependencyProvider extends SprykerGuiDependencyProvider
{
    protected function getDropdownNavigationPlugins(): array
    {
        return [
            new MultiFactorAuthSetupNavigationPlugin(),
        ];
    }
}
```



**src/Pyz/Zed/MultiFactorAuth/MultiFactorAuthDependencyProvider.php**

```php
namespace Pyz\Zed\MultiFactorAuth;

use Spryker\Zed\MultiFactorAuth\MultiFactorAuthDependencyProvider as SprykerMultiFactorAuthDependencyProvider;
use Spryker\Zed\SecurityGui\Communication\Plugin\MultiFactorAuth\PostUserLoginMultiFactorAuthenticationPlugin;

class MultiFactorAuthDependencyProvider extends SprykerMultiFactorAuthDependencyProvider
{
    protected function getPostLoginMultiFactorAuthenticationPlugins(): array
    {
        return [
            new PostUserLoginMultiFactorAuthenticationPlugin(),
        ];
    }
}
```



**src/Pyz/Zed/SecurityGui/SecurityGuiDependencyProvider.php**

```php
namespace Pyz\Zed\SecurityGui;

use Spryker\Zed\MultiFactorAuth\Communication\Plugin\AuthenticationHandler\User\UserMultiFactorAuthenticationHandlerPlugin;
use Spryker\Zed\SecurityGui\SecurityGuiDependencyProvider as SprykerSecurityGuiDependencyProvider;

class SecurityGuiDependencyProvider extends SprykerSecurityGuiDependencyProvider
{
    protected function getUserAuthenticationHandlerPlugins(): array
    {
        return [
            new UserMultiFactorAuthenticationHandlerPlugin(),
        ];
    }
}
```


### Register the plugins for Storefront API


**src/Pyz/Glue/GlueApplication/GlueApplicationDependencyProvider.php**

```php
namespace Pyz\Glue\GlueApplication;

use Spryker\Glue\GlueApplication\GlueApplicationDependencyProvider as SprykerGlueApplicationDependencyProvider;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi\MultiFactorAuthActivateResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi\MultiFactorAuthRestUserValidatorPlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi\MultiFactorAuthTriggerResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi\MultiFactorAuthTypeDeactivateResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi\MultiFactorAuthTypesResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueApplication\RestApi\MultiFactorAuthTypeVerifyResourcePlugin;

class GlueApplicationDependencyProvider extends SprykerGlueApplicationDependencyProvider
{
    protected function getResourceRoutePlugins(): array
    {
        return [
            new MultiFactorAuthTypesResourcePlugin(),
            new MultiFactorAuthTriggerResourcePlugin(),
            new MultiFactorAuthActivateResourcePlugin(),
            new MultiFactorAuthTypeVerifyResourcePlugin(),
            new MultiFactorAuthTypeDeactivateResourcePlugin(),
        ];
    }
    
    protected function getRestUserValidatorPlugins(): array
    {
        return [
            new MultiFactorAuthRestUserValidatorPlugin(),
        ];
    }
}
```


### Register plugins For Glue Backend API

**src/Pyz/Glue/GlueBackendApiApplication/GlueBackendApiApplicationDependencyProvider.php**

```php
namespace Pyz\Glue\GlueBackendApiApplication;

use Spryker\Glue\GlueBackendApiApplication\GlueBackendApiApplicationDependencyProvider as SprykerGlueBackendApiApplicationDependencyProvider;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication\MultiFactorAuthActivateBackendResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication\MultiFactorAuthBackendApiRequestValidatorPlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication\MultiFactorAuthTriggerBackendResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication\MultiFactorAuthTypeActivateBackendResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication\MultiFactorAuthTypeDeactivateBackendResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication\MultiFactorAuthTypeVerifyBackendResourcePlugin;
use Spryker\Glue\MultiFactorAuth\Plugin\GlueBackendApiApplication\MultiFactorAuthTypesBackendResourcePlugin;

class GlueBackendApiApplicationDependencyProvider extends SprykerGlueBackendApiApplicationDependencyProvider
{
    protected function getResourcePlugins(): array
    {
        return [
            new MultiFactorAuthTypesBackendResourcePlugin(),
            new MultiFactorAuthTriggerBackendResourcePlugin(),
            new MultiFactorAuthActivateBackendResourcePlugin(),
            new MultiFactorAuthTypeVerifyBackendResourcePlugin(),
            new MultiFactorAuthTypeDeactivateBackendResourcePlugin(),
            new MultiFactorAuthTypeActivateBackendResourcePlugin(),
        ];
    }
    
    protected function getRequestAfterRoutingValidatorPlugins(): array
    {
        return [
            // This is a crucial part of the MFA integration as this plugin checks all requests to protected resources and enforces Multi-Factor Authentication validation
            new MultiFactorAuthBackendApiRequestValidatorPlugin(),
        ];
    }
}
```


{% info_block warningBox &quot;Verification&quot; %}

Make sure you can authenticate with MFA using Storefront API. For instructions, see [Authenticate through MFA](/docs/pbc/all/multi-factor-authentication/latest/manage-using-glue-api/glue-api-authenticate-through-mfa.html).

{% endinfo_block %}


## 7) Set up the frontend

Add the following settings:

&lt;details&gt;
&lt;summary&gt;frontend/settings.json&lt;/summary&gt;

```javascript
{
    const globalSettings = {
        ...
        paths: {
            ...
            sprykerCore: &apos;./vendor/spryker/spryker/Bundles&apos;,
            ...
        };
        
    const paths = {
        ...
        sprykerCore: globalSettings.paths.sprykerCore,   
        ...
        };

    return {
        ...
        find: {
            componentEntryPoints: {
                dirs: [
                    ...
                    join(globalSettings.context, paths.sprykerCore),
                    ...
                ],
                ...
            },
            componentStyles: {
                dirs: [
                    ...
                    join(globalSettings.context, paths.sprykerCore),
                    ...
                ],
                ...
            },
            ...
        },
        ... 
    };
}
```

&lt;/details&gt;

**tsconfig.mp.json**

```javascript
{
    &quot;extends&quot;: &quot;./tsconfig.base.json&quot;,
    &quot;compilerOptions&quot;: {
        &quot;target&quot;: &quot;ES2022&quot;,
        &quot;paths&quot;: {
            ...
            &quot;@mp/multi-factor-auth&quot;: [&quot;vendor/spryker/spryker/Bundles/MultiFactorAuth/mp.public-api.ts&quot;],
            ...
        }
    }
}
```


2. Build the MFA frontend assets:

```bash
docker/sdk up --assets
```

{% info_block warningBox &quot;Verification&quot; %}

- Integrate one of the supported MFA methods, see [Multi-Factor Authentication](/docs/pbc/all/multi-factor-authentication/latest/multi-factor-authentication.html#multi-factor-authentication-methods).
- Make sure the **Set up Multi-Factor Authentication** menu item is displayed in the navigation menu.
- Clicking the menu should open one the following pages depending on your user:
  - Customers:`https://yves.mysprykershop.com/multi-factor-auth/set`
  - Agents: `https://yves.mysprykershop.com/agent/multi-factor-auth/set`
  - Back Office users: `https://backoffice.mysprykershop.com/multi-factor-auth/user-management/set-up`

{% endinfo_block %}
</description>
            <pubDate>Thu, 06 Aug 2026 09:52:53 +0000</pubDate>
            <link>https://docs.spryker.com/docs/pbc/all/multi-factor-authentication/latest/install-multi-factor-authentication-feature.html</link>
            <guid isPermaLink="true">https://docs.spryker.com/docs/pbc/all/multi-factor-authentication/latest/install-multi-factor-authentication-feature.html</guid>
            
            
        </item>
        
    </channel>
</rss>
