Skip to content

feat(apps-nuvemshop): customer profile, addresses and orders - #635

Open
JonasJesus42 wants to merge 2 commits into
mainfrom
JonasJesus42/nuvemshop-account-endpoints
Open

JonasJesus42 wants to merge 2 commits into
mainfrom
JonasJesus42/nuvemshop-account-endpoints

Conversation

@JonasJesus42

@JonasJesus42 JonasJesus42 commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Ports the account endpoints from deco-sites/reserva-nuvemshop#5 into @decocms/apps-nuvemshop:

  • loaders: account/profile, account/addresses, account/orders, account/order
  • actions: account/updateProfile, account/addAddress, account/updateAddress (store form, avoids duplicate)
  • sessionCustomerId() in store.ts (exported); loaders/user now uses it. The LS.customer scrape fails closed unless all matches agree.
  • Registered in manifest.gen.ts (hand-maintained in this package) and the barrel; ./loaders/* and ./actions/* exports already resolve.
  • Docs: references/account.md.

Security invariants (tested in accountData.test.ts)

  • Customer id derived from the session only, never props; no session -> 401, no Admin call.
  • Ids validated with parseId; ownership via String compare; not-yours == not-found (404, same message).
  • Orders post-filtered by customer; address update only for ids in the session customer's list.
  • Allow-listed write fields; no shared cache (raw instrumented nuvemshopAdmin, cache = no-store).
  • Same-origin/CSRF is a site concern (server-fn layer); documented, not implemented here.

Unsupported operations

Address delete/default, logged-in password change, password recovery (store reCAPTCHA).

Notes

  • Barrel/admin client bundles: admin.ts holds no secrets and the barrel was already server-only (store/RequestContext); documented, no code change.
  • Pre-existing failures unrelated to this PR on main: blocks-cli typecheck, tanstack workerEntry.test.ts (2), biome lint in tanstack/algolia, knip devDep-binary warnings.

Test plan

  • bun run test in apps-nuvemshop (115 pass), typecheck and biome clean for the package, secrets audit OK, skills:check OK
  • Wire into reserva-nuvemshop and replace src/platform/account inline copies

Site PR: https://github.com/deco-sites/reserva-nuvemshop/pull/5

🤖 Generated with Claude Code


Summary by cubic

Ports the Nuvemshop customer account endpoints (profile, addresses, orders) from the reserva-nuvemshop site into the apps-nuvemshop package as loaders, actions, docs, with tests. The customer id always comes from the store session via the new sessionCustomerId(), never from props, and loaders/user now shares that path; the session lookup is memoized per request.

Security: every rule is covered by the new accountData.test.ts.

  • Logged out → 401 before anything reaches the Admin API; a foreign or missing id is the same 404, and all caller-supplied ids pass through parseId. Test coverage now includes every loader and action plus a no-cookie request.
  • Loaders are cache = "no-store" over the raw Admin transport, so per-user data never hits the shared GET cache, and orders are post-filtered by the session customer.
  • Writes are allow-listed field by field; email, password, and extra keys are dropped.
  • Same-origin/CSRF stays a site concern (server-fn layer) and is documented in the reference.

Unsupported: address delete/set-default, logged-in password change, and password recovery have no upstream support.

Written for commit 535f338. Summary will update on new commits.

Review in cubic Turn on auto-fix

@JonasJesus42
JonasJesus42 requested a review from a team October 7, 2026 05:57
…-out coverage

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant