Skip to content

Commit 705ef13

Browse files
Create new Release.
Assisted-By: devx/57e15041-120d-4edf-8669-e6e2a9e14171
1 parent 7b1ccd1 commit 705ef13

9 files changed

Lines changed: 295 additions & 125 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,11 +5,22 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
66
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
77

8+
## [1.0.0]
9+
10+
- **Breaking:** rename the verify result field `new_id_token_response` to `invalid_token_response`, matching the `exchange_using_token_exchange` and `admin_graphql_request` parameters. Update any code that reads this field:
11+
12+
```diff
13+
- result.new_id_token_response
14+
+ result.invalid_token_response
15+
```
16+
817
## [0.1.4]
918

1019
- Verify the dest property is not a malicious URL before making a token exchange request
1120
- Reject App Proxy requests with multiple `shop` query parameters with a 401 response.
1221
- Refreshing a non-expiring token now returns a no-refresh-needed result instead of an error
22+
- Checkout UI and Customer Account UI Extension requests now return `shop` without the `https://` prefix
23+
- Update the README for the package
1324

1425
## [0.1.3]
1526

‎README.md‎

Lines changed: 244 additions & 85 deletions
Large diffs are not rendered by default.

‎shopify_app/__init__.py‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ def verify_pos_ui_ext_req(
130130
request (RequestInput): A RequestInput dict with method, headers, url, and body fields
131131
132132
Returns:
133-
ResultWithExchangeableIdToken: Verification result with ok, shop, user_id, id_token, log, response, and new_id_token_response fields
133+
ResultWithExchangeableIdToken: Verification result with ok, shop, user_id, id_token, log, response, and invalid_token_response fields
134134
"""
135135
return verify_pos_ui_ext_req(request, self.config)
136136

@@ -158,7 +158,7 @@ def verify_admin_ui_ext_req(
158158
request (RequestInput): A RequestInput dict with method, headers, url, and body fields
159159
160160
Returns:
161-
ResultWithExchangeableIdToken: Verification result with ok, shop, user_id, id_token, log, response, and new_id_token_response fields
161+
ResultWithExchangeableIdToken: Verification result with ok, shop, user_id, id_token, log, response, and invalid_token_response fields
162162
"""
163163
return verify_admin_ui_ext_req(request, self.config)
164164

@@ -173,7 +173,7 @@ def verify_app_home_req(
173173
app_home_patch_id_token_path (str): Path to the patch ID token page
174174
175175
Returns:
176-
ResultWithExchangeableIdToken: Verification result with ok, shop, user_id, id_token, log, response, and new_id_token_response fields
176+
ResultWithExchangeableIdToken: Verification result with ok, shop, user_id, id_token, log, response, and invalid_token_response fields
177177
"""
178178
return verify_app_home_req(request, self.config, app_home_patch_id_token_path)
179179

‎shopify_app/_version.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,4 +2,4 @@
22

33
from __future__ import annotations
44

5-
__version__ = "0.1.4"
5+
__version__ = "1.0.0"

‎shopify_app/types.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -272,7 +272,7 @@ class ResultWithExchangeableIdToken:
272272
response: Suggested HTTP response to return
273273
user_id: The user ID from the token's sub claim, or None on failure
274274
id_token: ID token details (exchangeable), or None on failure
275-
new_id_token_response: Pre-built response for token refresh scenarios
275+
invalid_token_response: Pre-built response for token refresh scenarios
276276
"""
277277

278278
ok: bool
@@ -281,7 +281,7 @@ class ResultWithExchangeableIdToken:
281281
response: Res
282282
user_id: Optional[str]
283283
id_token: Optional[IdTokenDetails]
284-
new_id_token_response: Optional[Res]
284+
invalid_token_response: Optional[Res]
285285

286286

287287
@dataclass(frozen=True)

‎shopify_app/verify/_non_exchangeable_id_token.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -219,7 +219,7 @@ def _verify_non_exchangeable_id_token(
219219

220220
# Extract shop from dest claim
221221
dest = payload.get("dest", "")
222-
shop = dest.replace(".myshopify.com", "") if dest else ""
222+
shop = dest.replace("https://", "").replace(".myshopify.com", "") if dest else ""
223223

224224
return ResultWithNonExchangeableIdToken(
225225
ok=True,

‎shopify_app/verify/admin_ui_ext.py‎

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ def verify_admin_ui_ext_req(
4949
response=Res(status=500, body="", headers={}),
5050
user_id=None,
5151
id_token=None,
52-
new_id_token_response=None,
52+
invalid_token_response=None,
5353
)
5454

5555
headers = request.get("headers")
@@ -65,7 +65,7 @@ def verify_admin_ui_ext_req(
6565
response=Res(status=500, body="", headers={}),
6666
user_id=None,
6767
id_token=None,
68-
new_id_token_response=None,
68+
invalid_token_response=None,
6969
)
7070

7171
url = request.get("url")
@@ -81,7 +81,7 @@ def verify_admin_ui_ext_req(
8181
response=Res(status=500, body="", headers={}),
8282
user_id=None,
8383
id_token=None,
84-
new_id_token_response=None,
84+
invalid_token_response=None,
8585
)
8686

8787
client_secret = config.get("client_secret", "")
@@ -116,7 +116,7 @@ def verify_admin_ui_ext_req(
116116
),
117117
user_id=None,
118118
id_token=None,
119-
new_id_token_response=None,
119+
invalid_token_response=None,
120120
)
121121

122122
# Check for Authorization header
@@ -132,7 +132,7 @@ def verify_admin_ui_ext_req(
132132
response=Res(status=401, body="Unauthorized", headers={}),
133133
user_id=None,
134134
id_token=None,
135-
new_id_token_response=None,
135+
invalid_token_response=None,
136136
)
137137

138138
# Extract the Bearer token
@@ -153,7 +153,7 @@ def verify_admin_ui_ext_req(
153153
),
154154
user_id=None,
155155
id_token=None,
156-
new_id_token_response=None,
156+
invalid_token_response=None,
157157
)
158158

159159
id_token = auth_header[7:] # Remove "Bearer " prefix
@@ -204,7 +204,7 @@ def verify_admin_ui_ext_req(
204204
),
205205
user_id=None,
206206
id_token=None,
207-
new_id_token_response=None,
207+
invalid_token_response=None,
208208
)
209209

210210
# Verify the audience (aud) matches the clientId
@@ -225,7 +225,7 @@ def verify_admin_ui_ext_req(
225225
),
226226
user_id=None,
227227
id_token=None,
228-
new_id_token_response=None,
228+
invalid_token_response=None,
229229
)
230230

231231
# Extract shop from dest claim
@@ -250,7 +250,7 @@ def verify_admin_ui_ext_req(
250250
token=id_token,
251251
claims=payload,
252252
),
253-
new_id_token_response=Res(
253+
invalid_token_response=Res(
254254
status=401,
255255
body="",
256256
headers={"X-Shopify-Retry-Invalid-Session-Request": "1"},

‎shopify_app/verify/app_home_req.py‎

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ def _build_patch_id_token_redirect(
9191
),
9292
user_id=None,
9393
id_token=None,
94-
new_id_token_response=None,
94+
invalid_token_response=None,
9595
)
9696

9797

@@ -129,7 +129,7 @@ def verify_app_home_req(
129129
),
130130
user_id=None,
131131
id_token=None,
132-
new_id_token_response=None,
132+
invalid_token_response=None,
133133
)
134134

135135
if app_home_patch_id_token_path == "":
@@ -148,7 +148,7 @@ def verify_app_home_req(
148148
),
149149
user_id=None,
150150
id_token=None,
151-
new_id_token_response=None,
151+
invalid_token_response=None,
152152
)
153153

154154
# Validate request object
@@ -169,7 +169,7 @@ def verify_app_home_req(
169169
),
170170
user_id=None,
171171
id_token=None,
172-
new_id_token_response=None,
172+
invalid_token_response=None,
173173
)
174174

175175
headers = request.get("headers")
@@ -189,7 +189,7 @@ def verify_app_home_req(
189189
),
190190
user_id=None,
191191
id_token=None,
192-
new_id_token_response=None,
192+
invalid_token_response=None,
193193
)
194194

195195
client_secret = config.get("client_secret", "")
@@ -249,7 +249,7 @@ def verify_app_home_req(
249249
),
250250
user_id=None,
251251
id_token=None,
252-
new_id_token_response=None,
252+
invalid_token_response=None,
253253
)
254254
id_token = auth_header[7:] # Remove "Bearer " prefix
255255

@@ -269,7 +269,7 @@ def verify_app_home_req(
269269
),
270270
user_id=None,
271271
id_token=None,
272-
new_id_token_response=None,
272+
invalid_token_response=None,
273273
)
274274

275275
payload = None
@@ -332,7 +332,7 @@ def verify_app_home_req(
332332
),
333333
user_id=None,
334334
id_token=None,
335-
new_id_token_response=None,
335+
invalid_token_response=None,
336336
)
337337

338338
# Verify the audience (aud) matches the clientId
@@ -360,7 +360,7 @@ def verify_app_home_req(
360360
),
361361
user_id=None,
362362
id_token=None,
363-
new_id_token_response=None,
363+
invalid_token_response=None,
364364
)
365365

366366
# Extract shop from dest claim (parse as URL and get hostname)
@@ -380,8 +380,8 @@ def verify_app_home_req(
380380
"Link": '<https://cdn.shopify.com>; rel="preconnect", <https://cdn.shopify.com/shopifycloud/app-bridge.js>; rel="preload"; as="script", <https://cdn.shopify.com/shopifycloud/polaris.js>; rel="preload"; as="script"',
381381
}
382382

383-
# Build new_id_token_response
384-
new_id_token_response = None
383+
# Build invalid_token_response
384+
invalid_token_response = None
385385
if not has_authorization_header:
386386
# Document request - build patch ID token URL
387387
clean_query = _remove_query_param(parsed_url.query, "id_token")
@@ -394,7 +394,7 @@ def verify_app_home_req(
394394

395395
patch_id_token_location = f"{parsed_url.scheme}://{parsed_url.netloc}{app_home_patch_id_token_path}?{patch_id_token_query}"
396396

397-
new_id_token_response = Res(
397+
invalid_token_response = Res(
398398
status=302,
399399
body="",
400400
headers={
@@ -403,7 +403,7 @@ def verify_app_home_req(
403403
)
404404
else:
405405
# Fetch request
406-
new_id_token_response = Res(
406+
invalid_token_response = Res(
407407
status=401,
408408
body="",
409409
headers={
@@ -435,5 +435,5 @@ def verify_app_home_req(
435435
token=id_token,
436436
claims=payload,
437437
),
438-
new_id_token_response=new_id_token_response,
438+
invalid_token_response=invalid_token_response,
439439
)

‎shopify_app/verify/pos_ui_ext.py‎

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ def verify_pos_ui_ext_req(
3232
config (dict): The app configuration with client_id, client_secret and optional old_client_secret
3333
3434
Returns:
35-
ResultWithExchangeableIdToken: Verification result with ok, shop, log, response, user_id, id_token, and new_id_token_response fields
35+
ResultWithExchangeableIdToken: Verification result with ok, shop, log, response, user_id, id_token, and invalid_token_response fields
3636
"""
3737
req = redact_http_log(request)
3838
# Validate request object
@@ -53,7 +53,7 @@ def verify_pos_ui_ext_req(
5353
),
5454
user_id=None,
5555
id_token=None,
56-
new_id_token_response=None,
56+
invalid_token_response=None,
5757
)
5858

5959
headers = request.get("headers")
@@ -73,7 +73,7 @@ def verify_pos_ui_ext_req(
7373
),
7474
user_id=None,
7575
id_token=None,
76-
new_id_token_response=None,
76+
invalid_token_response=None,
7777
)
7878

7979
url = request.get("url")
@@ -93,7 +93,7 @@ def verify_pos_ui_ext_req(
9393
),
9494
user_id=None,
9595
id_token=None,
96-
new_id_token_response=None,
96+
invalid_token_response=None,
9797
)
9898

9999
client_id = config.get("client_id", "")
@@ -128,7 +128,7 @@ def verify_pos_ui_ext_req(
128128
),
129129
user_id=None,
130130
id_token=None,
131-
new_id_token_response=None,
131+
invalid_token_response=None,
132132
)
133133

134134
# Check for Authorization header
@@ -148,7 +148,7 @@ def verify_pos_ui_ext_req(
148148
),
149149
user_id=None,
150150
id_token=None,
151-
new_id_token_response=None,
151+
invalid_token_response=None,
152152
)
153153

154154
# Extract the Bearer token
@@ -169,7 +169,7 @@ def verify_pos_ui_ext_req(
169169
),
170170
user_id=None,
171171
id_token=None,
172-
new_id_token_response=None,
172+
invalid_token_response=None,
173173
)
174174

175175
id_token = auth_header[7:] # Remove "Bearer " prefix
@@ -223,7 +223,7 @@ def verify_pos_ui_ext_req(
223223
),
224224
user_id=None,
225225
id_token=None,
226-
new_id_token_response=None,
226+
invalid_token_response=None,
227227
)
228228

229229
# Verify the audience (aud) matches clientId
@@ -244,7 +244,7 @@ def verify_pos_ui_ext_req(
244244
),
245245
user_id=None,
246246
id_token=None,
247-
new_id_token_response=None,
247+
invalid_token_response=None,
248248
)
249249

250250
# Extract shop from dest claim (format: https://shop-name.myshopify.com)
@@ -273,5 +273,5 @@ def verify_pos_ui_ext_req(
273273
token=id_token,
274274
claims=payload,
275275
),
276-
new_id_token_response=None,
276+
invalid_token_response=None,
277277
)

0 commit comments

Comments
 (0)