Template
- Storefront customer operations in graphql/customer.js and a server-safe services/shopify/customer.ts - Session held in an httpOnly, sameSite=lax cookie set by the /api/account handlers; the access token never reaches client JS - Pages: /account/login, /register, /recover, /reset/[id]/[token] and /activate/[id]/[token] for Shopify's emailed links - /account renders order history as master-detail on one screen, since the Storefront API has no standalone order-by-id query for customers - Header user icon: links to sign-in when signed out, otherwise a menu with name, email, order history, and sign out - Login errors are collapsed and password recovery responds identically for known and unknown emails, so neither form enumerates accounts Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016jWbNNJLksC1QG8z8845FX
20 lines
602 B
TypeScript
20 lines
602 B
TypeScript
import { getSessionToken } from '@/services/shopify/session';
|
|
import { getCustomer } from '@/services/shopify/customer';
|
|
|
|
// Minimal session probe for the header menu — never returns the access token.
|
|
export async function GET() {
|
|
const token = await getSessionToken();
|
|
if (!token) return Response.json({ customer: null });
|
|
|
|
const customer = await getCustomer(token, 0);
|
|
if (!customer) return Response.json({ customer: null });
|
|
|
|
return Response.json({
|
|
customer: {
|
|
displayName: customer.displayName,
|
|
email: customer.email,
|
|
firstName: customer.firstName,
|
|
},
|
|
});
|
|
}
|