Skip to content

Add support for trusted Shopify domain .shop.dev#1949

Merged
Shinomix merged 2 commits intomainfrom
add-support-for-trusted-shop-dev
Mar 14, 2025
Merged

Add support for trusted Shopify domain .shop.dev#1949
Shinomix merged 2 commits intomainfrom
add-support-for-trusted-shop-dev

Conversation

@Shinomix
Copy link
Contributor

What this PR does

In this PR we add a new hostname .shop.dev to Shopify trusted domains to prevent internal flows from treating this hostname as a potential phishing attack.

Reviewer's guide to testing

  • Install a Shopify App, such as Shop channel locally. Requests referred from the Admin should not be treated as phishing and be nullified.
[ ShopifyApp | INFO | Shop Not Found ] host param from callback is not from a trusted domain
[ ShopifyApp | INFO | Shop Not Found ] redirecting to root as this is likely a phishing attack

Checklist

Before submitting the PR, please consider if any of the following are needed:

  • Update CHANGELOG.md if the changes would impact users
  • Update README.md, if appropriate.
  • Update any relevant pages in /docs, if necessary
  • For security fixes, the Disclosure Policy must be followed.

@Shinomix Shinomix requested a review from a team as a code owner March 13, 2025 10:14
Copy link
Contributor

@lizkenyon lizkenyon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@lizkenyon
Copy link
Contributor

@Shinomix could you add a line to the CHANGELOG.md before merging! Thanks!

@Shinomix Shinomix merged commit 35e89c7 into main Mar 14, 2025
8 checks passed
@Shinomix Shinomix deleted the add-support-for-trusted-shop-dev branch March 14, 2025 17:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants