shopify

package
v1.8.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 11, 2026 License: MIT Imports: 11 Imported by: 0

Documentation

Overview

Package shopify provides fail-closed verification for Shopify Admin API access tokens against an operator-trusted store origin.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Verifier

type Verifier struct {
	// contains filtered or unexported fields
}

Verifier checks a token only when apiURL has been set from trusted operator configuration. Finding-controlled store_domain metadata is never used for routing, preventing wrong-issuer false-inactive results and credential forwarding to an untrusted host.

func NewForTrustedInstance added in v1.8.0

func NewForTrustedInstance(instanceURL string) (*Verifier, error)

NewForTrustedInstance accepts only an operator-selected canonical myshopify.com store origin. Custom domains and repository metadata are not routing authority for Admin API credentials.

func (*Verifier) Type

func (v *Verifier) Type() string

Type returns the detector ID this verifier handles.

func (*Verifier) Verify

Verify performs a read-only GraphQL shop identity query. Only HTTP 401 on the trusted store is definitive inactivity; authorization and GraphQL errors remain verify_error.

func (*Verifier) WithTrustedInstance added in v1.8.0

func (*Verifier) WithTrustedInstance(instanceURL string) (verifier.Verifier, error)

WithTrustedInstance implements verifier.TrustedInstanceConfigurer.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL