承接 jeanmarcos/module-customer-bypass 相关项目开发

从需求分析到上线部署,全程专人跟进,保证项目质量与交付效率

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

jeanmarcos/module-customer-bypass

Composer 安装命令:

composer require jeanmarcos/module-customer-bypass

包简介

Magento 2 development module that bypasses storefront customer authentication so any password is accepted for any existing customer. For local development only — guarded against production mode.

README 文档

README

📦 jeanmarcos/module-customer-bypass — published to Packagist.

🏠 Source repository for issues, PRs and releases: jeanmarcos-dev/magento-local-development. The standalone jeanmarcos-dev/module-customer-bypass repo is a read-only mirror auto-generated by CI on every release — direct commits to it are overwritten.

Development_CustomerBypass

Packagist

⚠️ FOR LOCAL DEVELOPMENT ONLY — NEVER ENABLE IN PRODUCTION

Bypasses Magento 2 customer authentication. Any password is accepted for any existing customer account on storefront login.

What it does

  • BypassCustomerAuthentication (plugin around on Magento\Customer\Model\AccountManagement::authenticate) — resolves the customer via CustomerRepositoryInterface::get($username) and returns it, ignoring the password.

No new users are created; only existing customers can be impersonated.

Safety model

Guarded by Magento's application mode:

Mode Allow in Production flag Behavior
developer / default any active — password ignored
production No (default) inactive — normal authentication
production Yes active — explicit override

Implementation: Development_Core (Development\Core\Model\ProductionGuard::isEnabled()), wired via a virtualType in etc/di.xml bound to the config path development/customer_bypass/allow_in_production. When disabled, the plugin delegates to $proceed($username, $password) and Magento authenticates normally.

Configuration

Panel path: Stores → Configuration → ⚠ Development Modules → Customer Bypass → General → Allow in Production

  • Default: No.
  • Changing the flag requires bin/magento cache:clean config.

Install

composer require --dev jeanmarcos/module-customer-bypass
bin/magento module:enable Development_CustomerBypass
bin/magento setup:upgrade
bin/magento setup:di:compile
bin/magento cache:flush

Kill switch

bin/magento module:disable Development_CustomerBypass
bin/magento setup:upgrade
bin/magento cache:flush

For permanent removal:

composer remove jeanmarcos/module-customer-bypass

Security risks

  • Anyone who knows a customer's email/username can log in as them without the password.
  • Exposes full order history, addresses, saved payment methods (if stored), and wishlists.
  • No audit trail: bypassed logins look identical to legitimate ones in the session.

File structure

CustomerBypass/
├── Plugin/
│   └── BypassCustomerAuthentication.php  # password bypass around plugin
├── etc/
│   ├── acl.xml
│   ├── adminhtml/
│   │   └── system.xml
│   ├── config.xml
│   ├── di.xml                            # plugin wiring + ProductionGuard virtualType
│   └── module.xml                        # depends on Development_Core
├── composer.json
├── registration.php
└── README.md

The production-guard helper lives in the shared core package jeanmarcos/module-core-local-development.

Troubleshooting

  • Toggle doesn't take effect: bin/magento cache:clean config.
  • "Invalid login or password" still appears: the plugin only overrides AccountManagement::authenticate; some integrations (OAuth, external SSO) use different entry points and are unaffected.

Compatibility

  • Magento 2.4.x
  • PHP 8.1+
  • Depends on jeanmarcos/module-core-local-development (installed automatically by Composer).

License

MIT

jeanmarcos/module-customer-bypass 适用场景与选型建议

jeanmarcos/module-customer-bypass 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 0 次下载、GitHub Stars 达 0, 最近一次更新时间为 2026 年 04 月 27 日, 在 PHP 生态内属于活跃度较高的组件。

它主要适用于以下技术方向: 「customer」 「development」 「auth」 「magento」 「bypass」 「dev-tools」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。

我们在过去多个企业项目中使用过 jeanmarcos/module-customer-bypass 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。

围绕 jeanmarcos/module-customer-bypass 我们能提供哪些服务?
定制开发 / 二次开发

基于 jeanmarcos/module-customer-bypass 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。

BUG 修复 & 性能优化

线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。

项目外包 & 长期维护

承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。

yvsm@zunyunkeji.com QQ:316430983 微信:yvsm316 西安尊云信息科技 · 专注 PHP / Go / 分布式系统研发

统计信息

  • 总下载量: 0
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 0
  • 点击次数: 47
  • 依赖项目数: 1
  • 推荐数: 0

GitHub 信息

  • Stars: 0
  • Watchers: 0
  • Forks: 0
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2026-04-27