feat(commerce-elastic-path)!: one EP host allow-list, resolved by createEpAuth - #596
Merged
Merged
Conversation
…ateEpAuth createEpAuth resolves the list once: the Elastic Path-operated defaults, plus the hostAllowlist option, plus EP_HOST_ALLOWLIST. Entries extend the defaults. The plugin admits a bundle-supplied host at mint and hands the list to resolveConfig, so the envelope carries the admitted host. BREAKING CHANGE: buildEpCtx takes the session returned by getSession and no longer reads the bundle or takes a list. extractEpProviderConfig and epPlugin require the list. Closes #586
…drop allow-list parsing createEpAuth now reads EP_HOST_ALLOWLIST and hands the list to resolveConfig. The deprecated epProviderHeaders helper is deleted.
…refused The mint's error escaped /ep/anonymous and /ep/refresh, so getSession threw instead of returning its empty session and every page returned 500. Both endpoints now answer 502 shopper_token_mint_failed and log the cause.
…e-586-18d772 Renumber the host allow-list ADR to 0006; #594 took 0005.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #586.
A custom EP API host had to be passed to
createEpAuth,extractEpProviderConfigandbuildEpCtxseparately. Each fell back to the defaults on its own, so a missed call site failed silently in a different way each time.createEpAuthnow resolves one EP host allow-list: the Elastic Path-operated defaults, plushostAllowlist, plusEP_HOST_ALLOWLIST. Entries extend the defaults. The plugin admits the bundle's host at mint and hands the list toresolveConfig; the envelope carries the admitted host from then on. Recorded as ADR-0006.Breaking (server API)
buildEpCtx(session)takes whatgetSession()returns. The bundle and list parameters are gone;locale/currencymove to an optional second argument, andBuildEpCtxSessionInput/BuildEpCtxAccountInputare removed.extractEpProviderConfigandepPluginrequirehostAllowlist.resolveConfigreceives{ hostAllowlist }.Also fixed: a refused shopper-token mint threw out of
/ep/anonymousand/ep/refresh, sogetSessionnever returned its empty session and pages returned 500. Both endpoints now answer 502shopper_token_mint_failed.The rejection message now names the option, the env var and the custom-domain case, and no longer mentions Elastic Path Self Managed Commerce. The example app drops its own env parsing and the deprecated
epProviderHeadershelper.No version bump; the publish gates the break. The
plasmic-nextjsapp host deletions in the issue are a follow-up in that repo.