Skip to content

feat(commerce-elastic-path)!: one EP host allow-list, resolved by createEpAuth - #596

Merged
field123 merged 5 commits into
masterfrom
claude/plasmic-issue-586-18d772
Sep 28, 2026
Merged

field123 merged 5 commits into
masterfrom
claude/plasmic-issue-586-18d772

Conversation

@field123

@field123 field123 commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #586.

A custom EP API host had to be passed to createEpAuth, extractEpProviderConfig and buildEpCtx separately. Each fell back to the defaults on its own, so a missed call site failed silently in a different way each time.

createEpAuth now resolves one EP host allow-list: the Elastic Path-operated defaults, plus hostAllowlist, plus EP_HOST_ALLOWLIST. Entries extend the defaults. The plugin admits the bundle's host at mint and hands the list to resolveConfig; the envelope carries the admitted host from then on. Recorded as ADR-0006.

Breaking (server API)

  • buildEpCtx(session) takes what getSession() returns. The bundle and list parameters are gone; locale/currency move to an optional second argument, and BuildEpCtxSessionInput/BuildEpCtxAccountInput are removed.
  • extractEpProviderConfig and epPlugin require hostAllowlist.
  • resolveConfig receives { hostAllowlist }.

Also fixed: a refused shopper-token mint threw out of /ep/anonymous and /ep/refresh, so getSession never returned its empty session and pages returned 500. Both endpoints now answer 502 shopper_token_mint_failed.

The rejection message now names the option, the env var and the custom-domain case, and no longer mentions Elastic Path Self Managed Commerce. The example app drops its own env parsing and the deprecated epProviderHeaders helper.

No version bump; the publish gates the break. The plasmic-nextjs app host deletions in the issue are a follow-up in that repo.

…ateEpAuth

createEpAuth resolves the list once: the Elastic Path-operated defaults,
plus the hostAllowlist option, plus EP_HOST_ALLOWLIST. Entries extend the
defaults. The plugin admits a bundle-supplied host at mint and hands the
list to resolveConfig, so the envelope carries the admitted host.

BREAKING CHANGE: buildEpCtx takes the session returned by getSession and no
longer reads the bundle or takes a list. extractEpProviderConfig and
epPlugin require the list.

Closes #586
…drop allow-list parsing

createEpAuth now reads EP_HOST_ALLOWLIST and hands the list to
resolveConfig. The deprecated epProviderHeaders helper is deleted.
…refused

The mint's error escaped /ep/anonymous and /ep/refresh, so getSession
threw instead of returning its empty session and every page returned 500.
Both endpoints now answer 502 shopper_token_mint_failed and log the cause.
…e-586-18d772

Renumber the host allow-list ADR to 0006; #594 took 0005.
@field123
field123 merged commit a42ccbc into master Sep 28, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Spec: one EP host allow-list, resolved by createEpAuth and carried in the shopper envelope

1 participant