Skip to content
CAI
Software that uses CAICheck a score

Shopify/shopify_app

59.5

Adequate · 19 September 2026

3.5k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Ruby gem that provides the foundational infrastructure for building and managing Shopify applications within Rails environments. It handles the complete lifecycle of app authentication, including OAuth flows, session storage, and token management for both shop and user contexts. The library also offers robust tools for managing webhooks, script tags, and app proxies, while providing a suite of Rails generators to scaffold essential components like controllers, models, and background jobs.

How it got here

2008–2015 — Modernization and engine isolation

30 changes.

The project underwent a comprehensive modernization, removing legacy Rails 2 generators and ActiveResource-based components in favor of a unified, isolated ShopifyApp engine. This shift introduced explicit routing, centralized configuration, and robust scaffolding tools for embedded apps using App Bridge 2. The work was supported by a complete overhaul of the test infrastructure to ensure the new architecture functioned correctly.

2016–2018 — Embedded app architecture and Polaris UI migration

21 changes.

This period focused on restructuring the gem to support embedded apps, introducing modular controller concerns for authentication and security, and migrating the UI to Shopify Polaris components. It also established new generators and managers for webhooks, script tags, and post-authentication jobs, while refactoring session storage to handle token lifecycles and refreshes.

2019–2025 — Embedded auth and session management overhaul

25 changes.

This period focused on modernizing the authentication flow by introducing a new embedded strategy with dedicated concerns for session validation and deep-link handling. It expanded support for per-user sessions and granular access scope management, while adding generators and background jobs to streamline token rotation, webhook processing, and GDPR compliance.

Features

Add background jobs for script tag and webhook management

Introduces two new Active Job classes, ScriptTagsManagerJob and WebhooksManagerJob, to handle the asynchronous creation of script tags and webhooks for Shopify shops. These jobs allow the application to offload these operations to a configurable background queue, improving responsiveness during shop setup or configuration updates.

app/jobs · high confidence

Add controllers generator for Shopify App engine

Introduces a new Rails generator that copies Shopify App controller files from the gem's source directory into the host application's \app/controllers/shopify\_app/\ directory, enabling users to easily scaffold or override default controllers.

_lib/generators/shopify\app/controllers · high confidence

The Shopify App generator now includes an \add\_privacy\_jobs\ command that scaffolds three new ActiveJob classes: \CustomersDataRequestJob\, \CustomersRedactJob\, and \ShopRedactJob\. These jobs are designed to handle GDPR compliance webhooks by extending \ShopifyAPI::Webhooks::WebhookHandler\, allowing applications to easily implement customer data requests and redaction processes for shops.

_lib/generators/shopify\_app/add\_privacy\jobs · high confidence

Add generator for Shopify token rotation job and rake task

The Shopify App now provides a generator that installs a background job and a rake task to automate the rotation of access tokens for active shops. When invoked, the generator copies \RotateShopifyTokenJob\ to \app/jobs/shopify/\ and a \rotate\_shopify\_tokens\ rake task to \lib/tasks/shopify/\. The job contacts the Shopify Admin API to exchange a refresh token for a new access token and updates the shop's stored token, while the rake task iterates over all active shops to trigger this rotation, allowing developers to schedule regular token updates to maintain API access.

_lib/generators/shopify\_app/rotate\_shopify\_token\job · high confidence

Added AfterAuthenticateJob template for post-authentication tasks

The generator now includes a template for an \AfterAuthenticateJob\ class that inherits from \ActiveJob::Base\. When generated, this job provides a scaffold for executing logic after a user authenticates with Shopify, specifically by finding the shop record and opening a Shopify session via \with\_shopify\_session\, allowing developers to add custom post-authentication logic.

_lib/generators/shopify\_app/add\_after\_authenticate\job/templates · high confidence

Added user model and fixture templates for multi-user support

The generator now includes a new User model template that includes ShopifyApp::UserSessionStorage and defines an api\_version method, alongside a corresponding users.yml fixture file. This enables applications to support per-user authentication and session storage, allowing multiple users to have distinct access tokens and scopes within the same shop context.

_lib/generators/shopify\_app/user\model/templates · high confidence

Adds default route templates for authentication and webhooks

The generator now includes a new \routes.rb\ template that defines default routes for session management (login, authentication callback, and logout) and a namespace for receiving webhooks. This provides a standard routing configuration for applications using the Shopify App generator.

_lib/generators/shopify\app/routes/templates · high confidence

Generator for App Proxy controller and routes

A new Rails generator has been added to scaffold App Proxy support. Running it creates an AppProxyController that includes ShopifyApp::AppProxyVerification, an index view template demonstrating Liquid rendering with shop details, and injects the necessary namespace routes into config/routes.rb.

_lib/generators/shopify\_app/app\_proxy\controller · high confidence

Initial project scaffolding and configuration setup

The repository is initialized with essential configuration files including \.babelrc\, \.gitignore\, \.nvmrc\ (Node 20.10.0), \.rubocop.yml\, and \.ruby-version\ (Ruby 3.2.2). Documentation and governance files such as \README.md\, \CHANGELOG.md\, \LICENSE\, \SECURITY.md\, \CONTRIBUTING.md\, and \CODE\_OF\_CONDUCT.md\ are added. Build and test infrastructure is established with \karma.conf.js\ and \webpack.config.js\ for JavaScript testing, and \Rakefile\ is updated to use \bundler/gem\_tasks\ and \rake/testtask\ instead of legacy gem packaging tasks. Legacy files like \README.textile\, \init.rb\, and \install.rb\ are removed.

(repo-wide) · high confidence

New client-side redirect helper for embedded apps

A new JavaScript module (app/assets/javascripts/shopify\_app/redirect.js) has been added to handle redirects within embedded Shopify apps. This script looks for an element with the ID 'redirection-target', reads a URL from its data attribute, and opens that URL in the top-level browsing context. It includes logic to ensure the redirect fires reliably in both standard DOM load events and Turbolinks contexts, addressing potential issues where standard event listeners might not consistently trigger.

app/assets · high confidence

New dedicated managers for script tags and webhooks

The gem introduces \ScriptTagsManager\ and \WebhooksManager\ classes to centralize the lifecycle management of script tags and webhooks. The \ScriptTagsManager\ handles queueing, creating, destroying, and recreating script tags, including logic to check for app block support in themes before creation. The \WebhooksManager\ manages webhook registration, destruction, and recreation, deducing the webhook path from the address if not explicitly provided, and supporting filters and metafield namespaces. These managers provide a structured way to handle these Shopify API interactions within the application.

_lib/shopify\app/managers · high confidence

New embedded app generator templates with App Bridge 2 and flash handling

The install generator now provides a complete set of templates for embedded apps, including a layout (\embedded\_app.html.erb\) that loads App Bridge 2, a session store template, and JavaScript files (\shopify\_app.js\, \flash\_messages.js\) that initialize the App Bridge client, render a TitleBar, and display flash notices/errors via App Bridge Toasts. The configuration template (\shopify\_app.rb.tt\) is updated to enable the new embedded auth strategy by default, register GDPR and uninstalled webhooks, and enforce the presence of API credentials.

_lib/generators/shopify\app/install/templates · high confidence

New generator for AuthenticatedController base class

Developers can now use the new \authenticated\_controller\ generator to create a base \AuthenticatedController\ class in \app/controllers/authenticated\_controller.rb\. This generated controller includes the \ShopifyApp::EnsureHasSession\ concern, providing a standardized way to enforce session requirements for authenticated routes in Shopify apps.

_lib/generators/shopify\_app/authenticated\controller · high confidence

New generator for a products controller

Added a new Rails generator that scaffolds a \ProductsController\ inheriting from \AuthenticatedController\ and registers a \/products\ route. The generated controller fetches up to 10 products via the Shopify API and returns them as JSON, providing a ready-to-use endpoint for product data.

_lib/generators/shopify\_app/products\_controller, lib/generators/shopify\app/views · high confidence

New generator for adding AfterAuthenticateJob configuration

A new Rails generator (\AddAfterAuthenticateJobGenerator\) has been introduced to streamline the setup of the \after\_authenticate\_job\ feature. When invoked, this generator automatically injects the necessary configuration block into \config/initializers/shopify\_app.rb\ and creates a corresponding job template in \app/jobs/\. It also supports invoking the configured test framework to generate associated test files, ensuring that developers can quickly scaffold the authentication callback job with proper testing infrastructure.

_lib/generators/shopify\_app/add\_after\_authenticate\job · high confidence

New generator for adding webhook jobs and configuration

A new \add\_webhook\ generator has been added to the Shopify App library, allowing developers to scaffold webhook handling with a single command. By specifying a webhook topic and path, the generator automatically updates the \config/initializers/shopify\_app.rb\ file to register the webhook and creates a corresponding job class in \app/jobs/\ to handle the incoming webhook payload, including support for custom job namespaces.

_lib/generators/shopify\_app/add\webhook · high confidence

New generator for declarative webhook setup

A new Rails generator (\AddDeclarativeWebhookGenerator\) has been added to scaffold declarative webhook implementations. When invoked with \--topic\ and \--path\ options, it creates a dedicated job class (respecting the configured \webhook\_jobs\_namespace\), a webhook controller that handles verification and enqueues the job, and the corresponding route in \config/routes.rb\. This simplifies the process of adding new webhooks by providing pre-built, verified templates for the job and controller logic.

_lib/generators/shopify\_app/add\_declarative\webhook · high confidence

New generator templates for authenticated and unauthenticated home controllers

The generator now provides distinct templates for generating a HomeController: an authenticated version that inherits from AuthenticatedController and includes shop access scope verification, and an optional unauthenticated version that handles embedded app redirection and session validation. The generated views display products and webhooks, with the embedded view utilizing App Bridge session tokens for secure API calls and supporting both Importmap and traditional asset pipeline setups.

_lib/generators/shopify\_app/home\controller/templates · high confidence

New install generator for Shopify App integration

The \lib/generators/shopify\_app/install/install\_generator.rb\ file has been added to provide a standardized way to scaffold a new Shopify app within a Rails project. This generator creates essential configuration files, including a \shopify\_app.rb\ initializer (defaulting to API version 2025-10) and a \session\_store.rb\ initializer. For embedded apps, it sets up the necessary layout views, flash message partials, and JavaScript assets, supporting both Webpacker and Importmap asset pipelines. It also automatically configures the Rails development environment to allow ngrok and Cloudflare tunnel hosts for secure OAuth redirects and mounts the Shopify App engine at the root path.

_lib/generators/shopify\app/install · high confidence

New test helpers for Shopify sessions and webhook verification

Added \ShopifySessionHelper\ and \WebhookVerificationHelper\ modules to simplify testing in Shopify apps. The session helper provides a \setup\_shopify\_session\ method to stub session loading and activation, while the webhook helper offers \authorized\_webhook\_verification\_headers!\ and \unauthorized\_webhook\_verification\_headers!\ to easily simulate valid and invalid HMAC signatures for webhook tests.

_lib/shopify\_app/test\helpers · high confidence

Removals

Removal of legacy Rails 2 generator and templates

The legacy Rails 2 generator for the Shopify app has been removed, including the \shopify\_app\_generator.rb\, the custom route insertion logic (\insert\_routes.rb\), and all associated template files (helpers, stylesheets, and the \shopify.yml\ configuration). This cleanup eliminates the old scaffolding that relied on Rails 2 conventions, such as \map.root\ routing and the \script/generate\ command, preparing the codebase for a transition to a newer generator architecture.

generators · high confidence

Removal of legacy Shopify app login template

The legacy login view template for the Shopify app generator has been removed. This file previously provided the UI for the app installation flow, including the form for entering the shop URL and the authentication button. Its deletion indicates that this specific view is no longer part of the generated application structure.

_generators/shopify\app/templates/app/views/login · high confidence

Removed legacy HomeController and LoginController templates

The generator no longer includes the \HomeController\ and \LoginController\ template files. This removes the previously generated code that handled basic product/order display and the older, simpler Shopify authentication flow (including session creation and redirect logic), indicating a shift in how the generated application handles home pages and user login.

_generators/shopify\app/templates/app/controllers · high confidence

Removed legacy application layout template

The legacy \application.html.erb\ layout template, which previously included outdated XHTML structure, Prototype JavaScript library, and hardcoded navigation tabs, has been removed from the generator. This change eliminates the old default layout structure from newly generated Shopify apps.

_generators/shopify\app/templates/app/views/layouts · high confidence

Removed legacy home view templates

The generator no longer includes the \design\, \index\, and \welcome\ view templates for the home section. These files, which previously provided a styled overview of HTML elements, a dashboard-style listing of orders and products, and a multi-step authentication guide, have been deleted from the generated application structure.

_generators/shopify\app/templates/app/views/home · high confidence

Behavioural changes

Added Rails application preparation script to prevent Spin infrastructure misidentification

A new executable script, .spin/rails/prepare-application, has been added to the project. This script runs 'bundle install' and serves to prevent the Spin infrastructure from incorrectly inferring the project as a standard Rails application, thereby avoiding snapshot failures associated with that misidentification.

.spin · high confidence

App uninstalled job now raises an error when the shop is not found

The generated job for handling app uninstalled webhooks has been updated to explicitly raise an ActiveRecord::RecordNotFound error if the shop associated with the uninstalled event cannot be located in the database. Previously, the job would simply log an error and continue, but it now fails fast to ensure that missing shop records are not silently ignored during the uninstallation process.

_lib/generators/shopify\_app/add\_app\_uninstalled\job · high confidence

Automatic token refresh on 401 Unauthorized errors

The Shopify Admin API client now automatically handles 401 Unauthorized errors by exchanging the current ID token for a new access token and retrying the request, rather than failing immediately. This change, implemented in the new \WithTokenRefetch\ module, ensures that transient authentication issues do not disrupt API calls, improving reliability for users interacting with the Shopify Admin API.

_lib/shopify\_app/admin\api · high confidence

Explicitly defined engine routes for authentication, callbacks, and webhooks

The application now explicitly defines its internal routing table within the ShopifyApp engine, replacing implicit or mounted route behavior. This change introduces dedicated routes for the login flow (including a new \patch\_shopify\_id\_token\ endpoint for session token updates), the OAuth callback, and webhook reception. To ensure backward compatibility, legacy route paths are preserved as fallbacks when custom configuration paths differ from the defaults, preventing breaking changes for existing integrations while standardizing the route structure.

config · high confidence

Extracted token exchange logic into a dedicated class with improved error handling

The token exchange process has been refactored from a concern into a dedicated \ShopifyApp::Auth::TokenExchange\ class. This change centralizes the logic for exchanging session tokens for both offline and online access tokens, ensuring that the correct token type is requested based on configuration. The new implementation includes robust error handling for invalid JWT tokens, HTTP response errors, and concurrent access issues (such as \ActiveRecord::RecordNotUnique\ or \RecordInvalid\), preventing crashes during race conditions while still logging relevant debug information. Users benefit from more reliable session management and clearer error reporting during the authentication flow.

_shopify\app · high confidence

Inline CSS styles added for Polaris UI components

The Shopify app installation and layout views now include embedded CSS styles for core Polaris components, including buttons, cards, forms, empty states, typography, and page layout. This change ensures consistent visual presentation of the app installation page and related interfaces by defining styles for elements like .Polaris-Button, .Polaris-Card, .Polaris-TextField, and .Polaris-EmptyState directly within the view partials.

_app/views/shopify\app/partials · high confidence

Introduce access scope strategies for granular scope management

The library now uses dedicated strategy classes to determine when and how access scopes are updated. A new \NoopStrategy\ disables automatic scope updates, while \ShopStrategy\ and \UserStrategy\ handle scope verification and updates for shop-level and user-level sessions respectively, allowing the app to react to configuration changes based on the specific session context.

_lib/shopify\_app/access\scopes · high confidence

Major library restructuring and removal of legacy components

The library has been completely rewritten to modernize its architecture. The legacy \lib/shopify\_api.rb\ module, which previously provided its own session management and ActiveResource-based models, has been removed in favor of the external \shopify\_api\ gem. Similarly, the \ShopifyLoginProtection\ concern has been deleted, with authentication logic now handled by a comprehensive set of new controller concerns (such as \login\_protection\, \token\_exchange\, and \payload\_verification\) and a new \PostAuthenticateTasks\ class that manages webhook and script tag installation. The gem now relies on \redirect\_safely\ and \addressable\ for core utilities and introduces dedicated managers for webhooks and script tags.

lib · high confidence

Migrate full-page redirect to use App Bridge

The shared redirect view now loads the App Bridge library from the Shopify CDN and utilizes it to handle redirections, replacing the previous implementation. This change ensures that redirects are processed correctly within the Shopify admin iframe context, improving reliability and responsiveness for users navigating between apps and the host shop.

_app/views/shopify\app/shared · high confidence

New App Bridge layout template for session token patching

A new layout template (app\_bridge.html.erb) has been added to the Shopify App views, providing the base HTML structure for App Bridge integration. This layout includes the App Bridge JavaScript library from Shopify's CDN, injects the application's API key, and yields content to support the new route for patching session tokens from App Bridge Next.

_app/views/shopify\app/layouts · high confidence

New embedded authentication strategy and session validation concerns

The app introduces a new embedded authentication flow controlled by the \use\_new\_embedded\_auth\_strategy?\ configuration. When enabled, controllers use the new \EnsureHasSession\ and \EnsureInstalled\ concerns which rely on \TokenExchange\ and \activate\_shopify\_session\ instead of the legacy \LoginProtection\ and \validate\_non\_embedded\_session\. A new \EnsureAuthenticatedLinks\ concern handles JWT validation for deep links, redirecting to a splash page with embedded parameters if the JWT is missing. Additionally, \ShopAccessScopesVerification\ now skips scope checks for the new strategy, as scope updates are handled automatically via token exchange.

app/controllers/concerns · high confidence

New session storage architecture with automatic token refresh and deprecation of legacy scopes modules

The session management layer has been restructured to use a new \SessionRepository\ that delegates to separate \ShopSessionStorage\ and \UserSessionStorage\ modules, replacing the previous unified approach. The new \ShopSessionStorage\ now automatically handles access scopes, expiry dates, and refresh tokens, and includes logic to automatically refresh expired offline access tokens using a stored refresh token. The legacy \ShopSessionStorageWithScopes\ and \UserSessionStorageWithScopes\ modules are now deprecated and will be removed in version 24.0.0. Additionally, an \InMemorySessionStore\ is provided for development and testing, which raises an error if used in production.

_lib/shopify\app/session · high confidence

Optional unauthenticated home controller generator

The home controller generator now supports creating an unauthenticated home controller when the app is configured as embedded. Previously, the generator always produced a controller requiring authentication; it now conditionally selects between the standard authenticated template and a new 'unauthenticated\_home\_controller.rb' template based on whether the app is embedded and if the user explicitly opts out of authentication requirements.

_lib/generators/shopify\_app/home\controller · high confidence

Redesigned app installation page with Polaris styling and dynamic branding

The app installation view has been updated to use Shopify Polaris design components, providing a consistent and modern user interface for the login and installation flow. The page now dynamically displays the application name from the configuration, falling back to a default title if not set, and includes improved error handling to show inline validation messages when an invalid shop domain is entered.

_app/views/shopify\app/sessions · high confidence

Refactored authentication and security into modular controller concerns

The authentication and security logic in the gem has been reorganized into a set of dedicated controller concerns to improve clarity and maintainability. Key changes include the introduction of \TokenExchange\ to handle JWT-based session activation and token patching, \LoginProtection\ to manage session validation and login redirects, and \EmbeddedApp\ to handle embedded-specific headers and redirections. Security is now enforced through separate concerns: \CsrfProtection\ skips forgery protection when a valid session token is present, \AppProxyVerification\ validates HMAC signatures for proxy requests, and \WebhookVerification\ validates webhook payloads. Additional concerns like \EnsureBilling\ manage subscription checks, \PayloadVerification\ provides reusable HMAC logic, and \FrameAncestors\ configures Content Security Policy headers for embedded contexts. This structure allows developers to compose specific security and authentication behaviors for their controllers.

_lib/shopify\_app/controller\concerns · high confidence

Refactored authentication and webhook controllers to use ShopifyAPI

The Shopify app gem's core controllers have been rewritten to integrate with the new ShopifyAPI library, shifting session persistence and OAuth logic from the gem to the application. The SessionsController now supports a new embedded authentication strategy that redirects users to the Shopify managed install path, while the CallbackController handles the OAuth completion by validating auth callbacks, saving sessions, and managing user token flows. Additionally, the WebhooksController now utilizes the ShopifyAPI::Webhooks::Registry for processing incoming webhooks, and a new ExtensionVerificationController has been added to handle HMAC verification for app extensions.

_app/controllers/shopify\app · high confidence

Shop model generator now includes API version method and session storage

The generated Shop model now includes the ShopifyApp::ShopSessionStorage concern and defines an api\_version method that delegates to ShopifyApp.configuration.api\_version, ensuring shops automatically use the configured API version. Additionally, a new shops.yml fixture is generated to provide sample shop data for development and testing.

_lib/generators/shopify\_app/shop\model/templates · high confidence

Shop model generator now supports access scopes and token refresh migrations

The shop model generator has been updated to optionally create additional database migrations for storing OAuth access scopes and token refresh data. When generating the Shop model, users are now prompted to include an \access\_scopes\ column migration and a migration for token expiration fields (\expires\_at\, \refresh\_token\, \refresh\_token\_expires\_at\). These additions can be bypassed during automated CLI usage via the \--new-shopify-cli-app\ flag. The generator also updates the main initializer to replace the in-memory session store with the new Shop model and creates corresponding test fixtures.

_lib/generators/shopify\_app/shop\model · high confidence

Shopify App gem v23.0.3: Configuration, Engine, and Utilities Refactor

This release introduces a centralized \ShopifyApp::Configuration\ class to manage app settings (such as \myshopify\_domain\, \unified\_admin\_domain\, and authentication strategies) and a new \ShopifyApp::Engine\ that isolates the namespace and handles asset precompilation and job parameter redaction. It also adds a \ShopifyApp::Utils\ module for domain sanitization and URL generation, alongside dedicated error classes and a logger that inherits from the Shopify API gem, all bundled in version 23.0.3.

_lib/shopify\app · high confidence

Shopify App routes are now explicitly mounted via generator instead of auto-mounted

The Shopify App engine no longer automatically mounts its routes at the root path. Instead, the new \RoutesGenerator\ explicitly injects session routes into the application's \config/routes.rb\ and removes the previous \mount ShopifyApp::Engine, at: '/'\ line. This change gives developers explicit control over how and where Shopify App routes are mounted in their Rails application, rather than relying on implicit engine mounting.

_lib/generators/shopify\app/routes · high confidence

Unified generator for Shopify app scaffolding

The \shopify\_app\ generator now provides a single entry point that automatically orchestrates the creation of essential app components. Running this generator triggers the addition of uninstalled and privacy webhooks, the installation of the core gem configuration, the creation of the shop model, the setup of the authenticated controller concern, and the generation of a home controller, streamlining the initial setup process for new applications.

_lib/generators/shopify\app · high confidence

Updated Shop model database migration templates

The database migration templates for the Shop model have been updated to include new columns for managing access scopes and token expiry. Specifically, the \create\_shops\ migration now establishes the base table, while new migrations add an \access\_scopes\ column (defaulting to an empty string), as well as \expires\_at\, \refresh\_token\, and \refresh\_token\_expires\_at\ columns to support access token lifecycle management.

_lib/generators/shopify\_app/shop\model/templates/db · high confidence

Updated user model database schema with access scopes and expiration support

The database migration templates for the user model have been updated to support per-user token management. A new migration adds an \access\_scopes\ column (string, defaulting to empty string) to the users table, and another adds an \expires\_at\ column (datetime) to track token validity. The primary \create\_users\ migration now includes a \shopify\_token\ column, establishing the foundation for storing individual user credentials rather than a single shared token.

_lib/generators/shopify\_app/user\model/templates/db · high confidence

User model generator now supports access scopes and session expiry storage

The Shopify App user model generator has been updated to optionally add \access\_scopes\ and \expires\_at\ columns to the User model via new migrations. When generating a new app, users are prompted to include these columns, which allow the app to store OAuth access scopes and check session expiry dates without immediate API calls. The generator also automatically updates the Shopify App initializer to use the User model for session storage instead of the in-memory store.

_lib/generators/shopify\_app/user\model · high confidence

Webhook job generator now raises an error when the shop is not found

The template for generated webhook jobs has been updated to explicitly check for the existence of the shop record during processing. If the shop cannot be found by its domain, the job now logs an error and raises an ActiveRecord::RecordNotFound exception, rather than proceeding with a nil shop object. This change ensures that webhook processing fails fast and visibly when the associated shop is missing, improving error handling and debugging for webhook jobs.

_lib/generators/shopify\_app/add\webhook/templates · high confidence

Test coverage

Add test configuration initializer for ShopifyApp; Added FakeSessionStorage test helper; Added Rails test dummy application configuration; Added controller tests for callback, session, and extension verification flows; Added development environment test template; Added generator tests for ShopifyApp scaffolding; Added integration tests for the webhooks controller; Added route tests for the ShopifyApp engine; Added test coverage for ScriptTagsManager and WebhooksManager; Added test coverage for controller concerns; Added test coverage for controller concerns; Added test dummy application for engine testing; Added test environment configuration for the engine dummy app; Added test fixtures for Rails application configuration and routing; Added test infrastructure and helpers for the engine; Added test support helpers for access scopes and session store strategies; Added tests for Admin API token refetch behavior; Added tests for RailsGeneratorRuntime utility; Added tests for Shopify session test helper; Added tests for access scope update strategies; Added tests for configuration, CSP helpers, and domain utilities; Added tests for post-authenticate tasks and token exchange logic; Added tests for redirect functionality and storage access fixture; Added tests for session storage and repository components; Updated test app templates for Shopify App configuration.

Dependencies

Shopify App gem v23.0.3 requires Rails 7.1+ and Ruby 3.2+

The Shopify App gem has been updated to version 23.0.3, which raises the minimum supported versions to Ruby 3.2 and Rails 7.1 (up to version 9). This release also updates the underlying shopify\_api dependency to version 16.0 and includes updated lock files for both Ruby (Gemfile.lock) and JavaScript (yarn.lock) to reflect these new constraints and their transitive dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 60.

Lenses

  • Code Health 70
  • Architecture 92
  • Maturity 62
  • Readiness 52
  • Security 66
  • Accessibility 68

Changes since last survey

  • 300 commits — 265 feature/other, 35 fixes

By area

  • (repo) — 136 commits
  • (root) — 91 commits
  • lib/shopify_app — 25 commits
  • docs/shopify_app — 13 commits
  • .github/workflows — 7 commits
  • lib/generators — 6 commits
  • test/controllers — 4 commits
  • test/shopify_app — 4 commits
  • .claude/skills — 2 commits
  • .github/CODEOWNERS — 2 commits
  • docs/Upgrading.md — 2 commits
  • test/generators — 2 commits
  • app/assets — 1 commit
  • app/views — 1 commit
  • config/locales — 1 commit
  • docs/Quickstart.md — 1 commit
  • docs/Releasing.md — 1 commit
  • test/app_templates — 1 commit

Notable commits

  • fix: Fix Rails 7.1 compatibility issues - Phase 2
  • fix: Fix Rails 7.1 test compatibility issues
  • fix: Fix Rails 7.1 test suite compatibility - Phase 1
  • fix: Fix Ruby 3.4 compatibility in billing error tests
  • fix: Fix TypeError in webhook job templates with shopify_api >= 16.0.0
  • fix: Fix access scopes doc url
  • fix: Fix bug where locale is not read from session
  • fix: Fix changelog style for 22.2.1 and unreleased
  • fix: Fix deprecated version warning
  • fix: Fix deprecation warnings for Rails 7.1+
  • fix: Fix engine initialization
  • fix: Fix full page redirection at top level
  • fix: Fix loading issues with modern rails versions
  • fix: Fix name in docs
  • fix: Fix remaining Rails 7.1 test failures - Phase 3
  • fix: Fix unified admin install path for spin
  • fix: Fix up upgrading guide
  • fix: Merge branch 'main' into fix-deprecation-warnings
  • fix: Merge pull request #1847 from BaggioGiacomo/fix-broken-new-embedded-app-authorization-strategy-url-on-docs
  • fix: Merge pull request #1877 from Shopify/fix-spin-install-link
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Shopify/shopify_app was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit eec09b2f8d2d469c08456f27324df366a671f866 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.