Packages
shopifex
0.3.5
2.4.0
2.3.0
2.2.2
2.2.1
2.2.0
2.1.20
2.1.19
2.1.18
2.1.17
2.1.16
2.1.15
2.1.14
2.1.13
2.1.12
2.1.11
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.1
2.0.0
1.1.1
1.1.0
1.0.1
1.0.0
0.6.2
0.6.1
0.6.0
0.5.7
0.5.6
0.5.5
0.5.4
0.5.3
0.5.2
0.5.1
0.5.0
0.4.1
0.4.0
0.3.6
0.3.5
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.1
0.2.0
0.1.5
0.1.4
0.1.3
0.1.2
0.1.1
0.1.0
Phoenix boilerplate for Shopify Embedded App SDK
Current section
Files
Jump to
Current section
Files
lib/shopifex/plug/shopify_entrypoint.ex
defmodule Shopifex.Plug.ShopifyEntrypoint do
import Plug.Conn
def init(options) do
# initialize options
options
end
@doc """
Ensures that the connection has a valid Shopify HMAC token in the URL param, then sets
`conn.private.valid_hmac` in the conn. You may want to handle this in your entry point
by allowing the user without a valid HMAC to an install app page.
"""
def call(conn = %{params: %{"hmac" => hmac}}, _) do
hmac = String.upcase(hmac)
query_string =
String.split(conn.query_string, "&")
|> Enum.map(fn query ->
[key, value] = String.split(query, "=")
{key, value}
end)
|> Enum.filter(fn {key, _} ->
key != "hmac"
end)
|> Enum.map(fn {key, value} ->
"#{key}=#{value}"
end)
|> Enum.join("&")
our_hmac =
:crypto.hmac(
:sha256,
Application.fetch_env!(:shopifex, :secret),
query_string
)
|> Base.encode16()
if our_hmac == hmac do
conn
|> put_private(:valid_hmac, true)
else
conn
|> put_private(:valid_hmac, false)
end
end
def call(conn, _) do
conn
|> put_private(:valid_hmac, false)
end
end