Prevent competing Shopify token issuers from expiring shared sessions - #471
Merged
Merged
Conversation
…entials Make the Route API the app/shop offline token authority, expose a signed server-only broker, and serialize OAuth rotation with privacy lifecycle writes. Constraint: Existing app/shop credentials and schema must remain compatible. Rejected: Longer access-token lifetime or per-process locks | Neither prevents competing issuers across replicas. Confidence: high Scope-risk: moderate Directive: Deploy the server before the app adapter; roll back the app first. Tested: 2914 unit tests; lint, typecheck, build; four real PostgreSQL concurrency and uninstall checks; independent security review. Not-tested: Production multiple-staff browser sessions before deployment.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Several staff members and background workers can use one Shopify installation concurrently. Previously the app SDK and Route API could each issue or refresh its offline token pair, invalidating the other side's cached refresh token and causing session recovery failures.
This makes the Route API the single offline-token authority per app/shop. A signed server-to-server broker supplies access tokens to the app SDK while keeping the real refresh token encrypted on the server. OAuth rotation and persistence share the existing PostgreSQL privacy lock across processes. Uninstall clears credentials under that lock; delayed or duplicate uninstall events cannot invalidate a later installation. Browser authentication and Shopify's token lifetimes remain unchanged.
Validation: fresh lint, typecheck, build, 2,914 unit tests, and four real PostgreSQL checks covering 20 concurrent requests across two clients, app isolation, privacy fencing, and stale uninstall replay. Independent source/contract review approved with no findings. Secret scan: zero findings. Database-specific suites are also registered in CI.
Rollout: server first, then the paired K-food app adapter. No schema, environment, scope, DNS, or token/session deletion migration. Rollback app first. Production authenticated smoke follows deployment; multiple real staff accounts are not available locally.
Change control: EVNSolution/clever-change-control#308
Paired app adapter: EVNSolution/shopify-clever#315