Serve Studio design time from a session-free catalog route - #661
Merged
Merged
Conversation
…free catalog route A designer editing in Studio has to see their own store's catalog — real names, real images, the store's own extension slugs and hierarchy node ids, none of which a fixture supplies. The shopper session cannot carry that: better-auth's SameSite=Lax cookie never reaches Studio's editing frame once a customer hosts their app host on their own registrable domain. createEpDesignRoutes is a separate file so "never reads the session" is a property of what it imports: no cookie parser, no getSession, no cart writer. It serves four declared names — getProduct, getProductList, getProductPage, getRelatedProducts — imported per module so the closed list is structural, and refuses everything else. It is not a forwarder: its implicit token is public and can write to /carts and /checkout. CORS is * with no credentials and no origin gate, and trustedOrigins takes no entry for it (ADR-0001). The browser forks on realm once, before the request, so no proxy failure can retry against a route that cannot see the shopper. The artboard is detected through usePlasmicCanvasContext; the app-host document through window.__CanvasPkgs, read per call because Studio injects it asynchronously. An off-allowlist name soft-fails on the artboard, where the mock floor renders in its place, and throws in the Configure panel, where nothing sits behind a null to tell it apart from a wrong binding. A transport failure throws in both: a caller's fallback is its own empty shape, so an unmounted route would read as "Product not found" rather than as labelled sample data. That case also emits one console warning naming the route and how to mount it. registerAll registers no server functions, asserted by a test, and the canvas-packages entry carries the comment for the half that cannot be. Deletes window.__epProxyOrigin: unreachable where needed, unnecessary where reachable, set by nobody. Closes #537
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #537.
A designer editing in Studio has to see their own store's catalog — real names, real images, the store's own extension slugs and hierarchy node ids, none of which a fixture supplies. The shopper session cannot carry that: better-auth's
SameSite=Laxcookie never reaches Studio's editing frame once a customer hosts their app host on their own registrable domain.createEpDesignRoutes(epAuth)lives in its own file so "never reads the session" is a property of what it imports: no cookie parser, nogetSession, no cart writer. It serves four declared names —getProduct,getProductList,getProductPage,getRelatedProducts— imported per module so the closed list is structural, and refuses everything else. It is not a forwarder: its implicit token is public and can write to/cartsand/checkout. CORS is*with no credentials and no origin gate, andtrustedOriginstakes no entry for it (ADR-0001).The browser forks on realm once, before the request, so no proxy failure can retry against a route that cannot see the shopper. The artboard is detected through
usePlasmicCanvasContext; the app-host document throughwindow.__CanvasPkgs, read per call because Studio injects it asynchronously.registerAllregisters no server functions, asserted by a test. The half that cannot be asserted from inside the package —canvas-packagesgrowing a./serverimport — carries a comment instead.Deletes
window.__epProxyOrigin: unreachable where needed, unnecessary where reachable, set by nobody.Two deviations from the issue
A transport failure throws in both realms rather than soft-failing to the caller's fallback. Soft-failing left the canvas showing "Product not found" when the route is unmounted — a caller's
nullis its own empty shape, not a mock floor — which fails the issue's own "sees clearly labelled sample data" criterion. Throwing routes the component to its error branch, which is where the"Sample"fixtures live. Off-allowlist names keep the issue's soft-fail-on-the-artboard, throw-in-the-panel split.epAuth.configgainsclientId,hostandresolveConfig. The issue says no new config is needed becauseepAuth.config.clientIdis already server-side; it was not onconfig, and a consumer reading its store from the Plasmic bundle bootstraps the factory with placeholders, so the static pair alone names a store that does not exist.