Skip to content

Prevent competing Shopify token issuers from expiring shared sessions - #471

Merged
OziinG merged 1 commit into
mainfrom
codex/shopify-token-authority
Oct 1, 2026
Merged

OziinG merged 1 commit into
mainfrom
codex/shopify-token-authority

Conversation

@OziinG

@OziinG OziinG commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Several staff members and background workers can use one Shopify installation concurrently. Previously the app SDK and Route API could each issue or refresh its offline token pair, invalidating the other side's cached refresh token and causing session recovery failures.

This makes the Route API the single offline-token authority per app/shop. A signed server-to-server broker supplies access tokens to the app SDK while keeping the real refresh token encrypted on the server. OAuth rotation and persistence share the existing PostgreSQL privacy lock across processes. Uninstall clears credentials under that lock; delayed or duplicate uninstall events cannot invalidate a later installation. Browser authentication and Shopify's token lifetimes remain unchanged.

Validation: fresh lint, typecheck, build, 2,914 unit tests, and four real PostgreSQL checks covering 20 concurrent requests across two clients, app isolation, privacy fencing, and stale uninstall replay. Independent source/contract review approved with no findings. Secret scan: zero findings. Database-specific suites are also registered in CI.

Rollout: server first, then the paired K-food app adapter. No schema, environment, scope, DNS, or token/session deletion migration. Rollback app first. Production authenticated smoke follows deployment; multiple real staff accounts are not available locally.

Change control: EVNSolution/clever-change-control#308

Paired app adapter: EVNSolution/shopify-clever#315

…entials

Make the Route API the app/shop offline token authority, expose a signed
server-only broker, and serialize OAuth rotation with privacy lifecycle writes.

Constraint: Existing app/shop credentials and schema must remain compatible.
Rejected: Longer access-token lifetime or per-process locks | Neither prevents competing issuers across replicas.
Confidence: high
Scope-risk: moderate
Directive: Deploy the server before the app adapter; roll back the app first.
Tested: 2914 unit tests; lint, typecheck, build; four real PostgreSQL concurrency and uninstall checks; independent security review.
Not-tested: Production multiple-staff browser sessions before deployment.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant