diff --git a/src/services/shopify/client.ts b/src/services/shopify/client.ts index 45f9278..b9c9da1 100644 --- a/src/services/shopify/client.ts +++ b/src/services/shopify/client.ts @@ -58,7 +58,7 @@ export const storefront = createStorefrontClient({ type: 'public', requestContext, config: { - storeDomain: SHOPIFY_STORE_DOMAIN!, + storeDomain: SHOPIFY_STORE_DOMAIN, apiVersion: SHOPIFY_API_VERSION, publicStorefrontToken: SHOPIFY_PUBLIC_ACCESS_TOKEN, fetch: storefrontFetch, diff --git a/src/services/shopify/config.ts b/src/services/shopify/config.ts index 18cb68d..4846528 100644 --- a/src/services/shopify/config.ts +++ b/src/services/shopify/config.ts @@ -2,15 +2,25 @@ // // These are all `VITE_*`, so Vite inlines them at build time and they are safe // to read from the browser bundle as well as the Hono server. -export const SHOPIFY_STORE_DOMAIN = import.meta.env.VITE_SHOPIFY_DOMAIN; +const CONFIGURED_STORE_DOMAIN = import.meta.env.VITE_SHOPIFY_DOMAIN?.trim(); + +/** + * Store domain, falling back to the tokenless `mock.shop` demo store when the + * variable is unset or blank — the Storefront client rejects an empty domain. + */ +export const SHOPIFY_STORE_DOMAIN = CONFIGURED_STORE_DOMAIN || 'mock.shop'; /** * Public Storefront API access token. Safe to expose to the browser — that is * what "public" means here. Omitted for tokenless storefronts such as * `mock.shop`. Never put a *private* token behind a `VITE_` name. + * + * Only used alongside a configured domain: a token belongs to one store, so it + * is never sent to the `mock.shop` fallback. */ -export const SHOPIFY_PUBLIC_ACCESS_TOKEN = import.meta.env - .VITE_SHOPIFY_PUBLIC_ACCESS_TOKEN; +export const SHOPIFY_PUBLIC_ACCESS_TOKEN = CONFIGURED_STORE_DOMAIN + ? import.meta.env.VITE_SHOPIFY_PUBLIC_ACCESS_TOKEN?.trim() || undefined + : undefined; export const SHOPIFY_API_VERSION = import.meta.env.VITE_SHOPIFY_API_VERSION || '2026-07';