Exit store auth early for preview stores#7950
Merged
Merged
Conversation
4 tasks
Contributor
Author
This stack of pull requests is managed by Graphite. Learn more about stacking. |
4 tasks
c833ade to
3cc6585
Compare
307d191 to
c608d3d
Compare
Preview stores aren't a logged-in experience: there's no OAuth flow and no way to grant additional Admin API scopes after creation. Running the standard store auth flow against one confuses callers (including agents that habitually run store auth before store execute). Detect a cached preview-store session up front and abort with a clear message that store auth is unavailable, listing the scopes already preapproved at creation time and pointing at store execute / store info. Assisted-By: devx/f38d0794-3b14-4a2a-a849-b95ae665f83d
c608d3d to
518dabd
Compare
3cc6585 to
4671bfd
Compare
Assisted-By: devx/7c2ea919-8429-480e-a789-203d7c9c0902
dmerand
approved these changes
Jun 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

WHY are these changes introduced?
Preview stores aren't a logged-in experience. There's no OAuth flow to run and no way to grant additional Admin API scopes after creation — the scopes are fixed at creation time and cached locally (#7948). Running the standard
store authflow against a preview store therefore can't work. In practice, agents habitually runstore authbeforestore execute, get confused when the flow fails for preview stores, and stall. We should fail fast with a clear, actionable message instead.Final PR in the stack:
store info --json.store authearly for preview stores #7950 (this PR) — Exitstore authearly for preview stores, listing the preapproved scopes.WHAT is this pull request doing?
auth/index.ts: detect a cached preview-store session up front inauthenticateStoreWithApp— before any metadata recording or OAuth — via a newthrowIfPreviewStorehelper. When the current session for the store iskind: 'preview', throw anAbortError:`store auth` is unavailable for preview stores.none).shopify store executedirectly (nostore authneeded), orshopify store info --jsonto see the preapproved scopes.getCurrentStoredStoreAppSessionis injected as a dependency so the early-exit check is testable.No changeset — preview stores aren't released yet.
How to test your changes?
kind: 'preview'session).shopify store auth --store <preview-store>.store authstill works normally for non-preview stores.Unit tests cover: early exit without starting OAuth or recording fqdn metadata, and that the error surfaces the preapproved scope list.
Checklist