← back to Designer Wallcoverings
Strip hardcoded Shopify API tokens from source (env-first); no rotation/deploy — response to Shopify exposed-credentials notice
0478a4c3946e18302668d8720a6fbb43ff193977 · 2026-07-16 09:59:12 -0700 · Steve
Files touched
M US-001-IMPLEMENTATION.mdM test-koroseal-sample.ts
Diff
commit 0478a4c3946e18302668d8720a6fbb43ff193977
Author: Steve <steve@designerwallcoverings.com>
Date: Thu Jul 16 09:59:12 2026 -0700
Strip hardcoded Shopify API tokens from source (env-first); no rotation/deploy — response to Shopify exposed-credentials notice
---
US-001-IMPLEMENTATION.md | 2 +-
test-koroseal-sample.ts | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/US-001-IMPLEMENTATION.md b/US-001-IMPLEMENTATION.md
index 2f786478..918cc6bd 100644
--- a/US-001-IMPLEMENTATION.md
+++ b/US-001-IMPLEMENTATION.md
@@ -158,7 +158,7 @@ await client.updateProduct(productId, {
```bash
SHOPIFY_STORE_DOMAIN=designer-laboratory-sandbox.myshopify.com
SHOPIFY_ADMIN_API_VERSION=2024-01
-SHOPIFY_ADMIN_ACCESS_TOKEN=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
+SHOPIFY_ADMIN_ACCESS_TOKEN=shpat_REDACTED
```
### Shopify API Endpoints Used
diff --git a/test-koroseal-sample.ts b/test-koroseal-sample.ts
index 205d1327..8b55bf72 100755
--- a/test-koroseal-sample.ts
+++ b/test-koroseal-sample.ts
@@ -4,7 +4,7 @@ const fetch = globalThis.fetch; // node-fetch shim removed -- Node 26 global fet
const config = {
storeDomain: 'designer-laboratory-sandbox.myshopify.com',
apiVersion: '2024-01',
- accessToken: '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'
+ accessToken: (process.env.SHOPIFY_ADMIN_TOKEN || '')
};
async function getSample() {
← afc033fa PR naturals v10 mailer: SISAL tile -> sisal search (page 1),
·
back to Designer Wallcoverings
·
auto-save: 2026-07-17T19:47:29 (351 files) — DW-Agents/dw-ag 0e13b87c →