Documentation
¶
Overview ¶
Package shopify provides fail-closed verification for Shopify Admin API access tokens against an operator-trusted store origin.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Verifier ¶
type Verifier struct {
// contains filtered or unexported fields
}
Verifier checks a token only when apiURL has been set from trusted operator configuration. Finding-controlled store_domain metadata is never used for routing, preventing wrong-issuer false-inactive results and credential forwarding to an untrusted host.
func NewForTrustedInstance ¶ added in v1.8.0
NewForTrustedInstance accepts only an operator-selected canonical myshopify.com store origin. Custom domains and repository metadata are not routing authority for Admin API credentials.
func (*Verifier) Verify ¶
func (v *Verifier) Verify(ctx context.Context, raw detector.RawFinding) finding.VerificationResult
Verify performs a read-only GraphQL shop identity query. Only HTTP 401 on the trusted store is definitive inactivity; authorization and GraphQL errors remain verify_error.