Skip to content

Store storefront config in encrypted ejson files - #577

Draft
kieran-osgood-shopify wants to merge 1 commit into
kieran-osgood/e2e-checkout-customer-accountfrom
ejson
Draft

Store storefront config in encrypted ejson files#577
kieran-osgood-shopify wants to merge 1 commit into
kieran-osgood/e2e-checkout-customer-accountfrom
ejson

Conversation

@kieran-osgood-shopify

Copy link
Copy Markdown
Contributor

What changes are you making?

How to test


Before you merge

Important

  • I've added tests to support my implementation
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (platforms/swift/README.md and/or platforms/android/README.md)

Releasing a new Swift version?
  • I have bumped the version in ShopifyCheckoutKit.podspec
  • I have bumped the version in platforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swift
  • I have updated the SwiftPM/CocoaPods version snippets in platforms/swift/README.md (major version only)
Releasing a new Embedded Checkout Protocol version?
  • I have bumped embeddedCheckoutProtocolAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated protocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.api if the public API changed
Releasing a new Android version?
  • I have bumped checkoutKitAndroid in platforms/android/gradle/libs.versions.toml
  • I have updated the Gradle/Maven version snippets in platforms/android/README.md

Tip

See the Contributing documentation for the full release process per platform.

Copy link
Copy Markdown
Contributor Author

Root `.env` currently serves both the sample apps and the E2E suite, so
running the suite overwrites the storefront config a developer keeps for
their own store, and none of those values can be shared or reviewed.

This first step adds the encrypted source of truth and the tooling around
it. Nothing reads these files yet, so behaviour is unchanged.

- `config/secrets/demo.ejson` and `config/secrets/e2e.ejson` hold every
  value, secret and non-secret, so no plaintext config exists to commit by
  accident. Each holds one `environment` object, the only key `ejson2env`
  reads, plus a `_description` that ejson leaves unencrypted.
- `scripts/ejson_lint` fails on any unencrypted value and reports key names
  only. It needs no private key, so it runs on forks. Wired into `dev check`.
- `scripts/install_ejson_key` fetches the private key from GCP Secret
  Manager into the ejson keydir during `dev up`. The key travels through a
  redirect, so it never reaches argv, an environment variable, or the
  output. Every failure path exits 0: a developer without the key keeps
  full control of their own `.env`.
- `scripts/secrets_edit` backs `dev secrets edit <demo|e2e>`. It decrypts to
  a private temporary copy, opens $EDITOR, restores the ciphertext of
  unchanged values so the diff shows only real changes, then writes back
  content that is already encrypted. No plaintext reaches the working tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant