metatrondelivery/shopify.app.toml
metatroncubeswdev 0538980eb5 fix: drop unused read_customers scope — likely the real GDPR gate trigger
Commenting out the 3 compliance-topic webhook subscriptions (previous
commit) didn't clear the "not approved to subscribe to webhook topics
containing protected customer data" error — same 3 errors, same wording,
even with those blocks fully removed from shopify.app.toml. That means the
gate isn't about our webhook declarations at all; it's much more likely
triggered by the `read_customers` OAuth scope itself; Shopify's Protected
Customer Data Access requirement applies to the scope, and the CLI's error
message just reuses the same generic wording for the whole policy category
regardless of which part of the config triggered it.

Removed read_customers from shopify.app.toml, .env, and .env.example.
This is also independently correct per CLAUDE.md's "request the minimum
OAuth scopes needed" — nothing in the codebase actually calls the Customers
API; Booking.customerEmail/customerPhone come straight off the
orders/create webhook payload, which read_orders already covers. Add it
back only when a feature that genuinely needs it exists, and expect to
need Protected Customer Data Access granted at that point regardless.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-23 23:25:10 -04:00

88 lines
3.5 KiB
TOML

# Learn more about configuring your app at https://shopify.dev/docs/apps/tools/cli/configuration
client_id = "890f611da9f31c1a8e3183b5300b2f53"
name = "Metatron-delivery"
application_url = "https://shopify.dev/apps/default-app-home"
embedded = true
[access_scopes]
# Learn more at https://shopify.dev/docs/apps/tools/cli/configuration#access_scopes
# read_customers deliberately omitted: no feature currently calls the
# Customers API (Booking.customerEmail/customerPhone come straight off the
# orders/create webhook payload, covered by read_orders) — requesting it
# unused would also gate this app behind Shopify's Protected Customer Data
# Access approval for no reason. Add it back only when a feature (e.g. the
# "recognize returning customers" parity item) actually needs it, and
# expect to need that approval granted at that point.
scopes = "read_locales,read_locations,read_markets,read_metaobjects,read_orders,read_products,write_cart_transforms,write_delivery_customizations,write_metaobjects,write_orders,write_payment_customizations"
[auth]
redirect_urls = [ "https://shopify.dev/apps/default-app-home/api/auth" ]
[webhooks]
api_version = "2026-10"
# Handled by: app/routes/webhooks.app.uninstalled.tsx
[[webhooks.subscriptions]]
uri = "/webhooks/app/uninstalled"
topics = ["app/uninstalled"]
# Handled by: app/routes/webhooks.app.scopes_update.tsx
[[webhooks.subscriptions]]
uri = "/webhooks/app/scopes_update"
topics = ["app/scopes_update"]
# Handled by: app/routes/webhooks.orders.create.tsx
[[webhooks.subscriptions]]
uri = "/webhooks/orders/create"
topics = ["orders/create"]
# Handled by: app/routes/webhooks.orders.updated.tsx
[[webhooks.subscriptions]]
uri = "/webhooks/orders/updated"
topics = ["orders/updated"]
# Handled by: app/routes/webhooks.orders.cancelled.tsx
[[webhooks.subscriptions]]
uri = "/webhooks/orders/cancelled"
topics = ["orders/cancelled"]
# Mandatory GDPR compliance topics — required for Built-for-Shopify /
# public app review. TEMPORARILY DISABLED: `shopify app dev`/`deploy`
# refuses to push these until the org has requested and been granted
# "Protected customer data access" in the Partner Dashboard (Apps ->
# this app -> API access -> Protected customer data) — that's a manual
# questionnaire/approval step, not something the CLI or config can
# bypass. RE-ENABLE these three blocks (handlers already exist and are
# wired: app/routes/webhooks.customers.data_request.tsx,
# webhooks.customers.redact.tsx, webhooks.shop.redact.tsx) once that
# access is granted, and before any public launch/BfS submission.
# [[webhooks.subscriptions]]
# uri = "/webhooks/customers/data_request"
# compliance_topics = ["customers/data_request"]
# [[webhooks.subscriptions]]
# uri = "/webhooks/customers/redact"
# compliance_topics = ["customers/redact"]
# [[webhooks.subscriptions]]
# uri = "/webhooks/shop/redact"
# compliance_topics = ["shop/redact"]
# App proxy so the storefront Theme App Extension can call our backend
# without CORS issues (see IMPLEMENTATION_PLAN.md §5.3). `shopify app dev`
# points this at your dev tunnel automatically when
# automatically_update_urls_on_dev is true (see [build] below); if it
# doesn't, set it manually to `<your-tunnel-url>/apps/scheduling` — the
# Remix routes it forwards to (apps.scheduling.*.tsx) assume that exact
# prefix.
[app_proxy]
url = "https://replace-with-your-tunnel-url.example.com/apps/scheduling"
subpath = "scheduling"
prefix = "apps"
[build]
include_config_on_deploy = true
automatically_update_urls_on_dev = true