megachangelog
Improvement2.21.2

Performance Improvement for Search Route

The /store/search route now restricts field retrieval to only those defined on the index being searched, preventing data hydration outside the index for better performance. This release includes multiple bug fixes for search indexing, caching, promotions, payments, and dashboard internationalization.

Disallow Expanding Fields Outside of Index in Search Route

The /store/search route now only allows retrieving fields that are defined on the index being searched. It no longer allows fetching data outside the index by hydrating through query.graph. This is for better search performance and ensures you clearly define what can be retrieved on your indexed data model.

Bugs

  • fix: Disallow expanding beyond index fields on search endpoint by @sradevski in #17044
  • fix: Wait for search cache to settle before setting or invalidating by @sradevski in #16966
  • fix(search): stop search index versions from piling up by @sradevski in #16930
  • fix: Correctly count when using distinct by @sradevski in #16928
  • fix(promotion): correlate the automatic promotion prefilter with the candidate promotions by @DylanCuure in #16954
  • fix(medusa): allow omitting deprecated options in admin product updates by @Dextheking1 in #16959
  • fix(workflow-engine-redis): nest RedisWorkflowsOptions under redis in the module options type by @Asgabani in #16730
  • fix(payment): avoid double-prefixing an already pp_-prefixed provider by @RoxasZohbi in #16899
  • fix(draft-order): fix admin crash when selecting a customer without an email by @kelvin511 in #16952
  • fix(utils): strip g/y flags in buildRegexpIfValid for CORS origins by @wakqasahmed in #16568
  • fix(dashboard): internationalize order payment labels by @luxapan in #16846
  • fix(dashboard): i18n fill the 5 missing keys in fi hr pl sv tr by @theluckystrike in #16933
  • fix(dashboard): add readable validation messages to create region form by @NikhilDhillon in #16720
  • fix(dashboard): point refund and return reason row links at their edit routes by @Minhal128 in #16742
  • fix(dashboard): correct shipping profile row link path by @Asgabani in #16728
  • fix(dashboard): i18n placeholders in de and pl that don't match en.json by @Na5co in #16907
  • fix: rename misspelled orignalSet parameter to originalSet by @Dextheking1 in #16908
  • chore: fix handling of invalid translation json by @shahednasser in #17002

Documentation

Chores

Other Changes

New Contributors

Full Changelog: v2.21.1...v2.21.2

searchperformanceapisearch-indexbug-fixes

Source: original entry ↗

More from Medusa

Follow Medusa to get its new changes in your feed and email digest.

Feature2.21.1

v2.21.1: Search Module

Introduces a new Search Module that lets you manage and search through indexes for any data model, with built-in PostgreSQL and Medusa Cloud providers. Also includes improvements to the loyalty plugin's store credit features, new admin translations for Finnish and Swedish, and numerous bug fixes across authentication, payments, inventory, and shipping.

searchmoduleapiloyaltytranslation
Breaking2.21.0

Strict allowed fields in Store API and Exported Admin Components

Store API routes now enforce a strict allowed-fields list, returning only explicitly declared fields and relations to prevent unintended data exposure. Disallowed fields are silently stripped; use the allowFields middleware to re-expose specific fields if needed.

store-apisecuritybreaking-changefieldsrelations
Security2.20.1

Field Filter Stripping Fix, Search Stability, Schema Index Validation

Fixed a security issue where field filter restrictions (allowed query config and http.restrictedFields) were only applied when RBAC was enabled; now they are always enforced. Also fixed search correlated flag and schema index JSON validation.

securityfield-filteringrbacsearchschema
See all Medusa changes →