Vendune
frontend/src/admin/storyfronts/README.mdView on GitHub ↗

admin/storyfronts

Merchant management of existing hosted Experiences and optional Storyfront app connections. Hosted mounts come from the tenant-scoped /api/settings/frontends registry used by onboarding. Scene generation and editing remain in the independently deployed private service.

Files and their individual responsibilities are listed in the generated source inventory. Each file starts with its contract summary.

Modules

HOSTED_FRONTEND_EDITOR_URL=https://experience.vendune.ai/design/{alias} links each hosted mount to its existing authenticated editor. It is operator configuration, never a merchant-controlled destination or an access token. See Experience integration for ownership and deployment details.

Verification

Run npm run build, npm test, npm run test:coverage and npm run architecture from frontend/. Coverage includes untested source files; a module in this folder is not automatically fully tested. See the root testing guide for backend integration and coverage limits.

storyfront-management.test.tsx exercises mount discovery without an installed app, editor/storefront navigation, loading and retry, stale workspace responses, missing editor configuration and unsafe URLs. scripts/identity_broker.py verifies the real HTTP/PostgreSQL registry for own, foreign, anonymous and forged tenant requests.

StoryfrontConnections.tsx is shared by the Storyfront workspace and installed app details/interfaces. Both consume the core's persisted frontend app associations; no GET-side install, second editor, iframe fallback for managed connections or browser-side provider credentials. Managed packages explain why pausing requires first disconnecting their frontend dependencies.

The empty-state Add Storyfront integration button opens the shared apps/AppConsent.tsx review used by the app library. It posts the reviewed digest, complete permission list and explicit approval to /api/apps only after merchant confirmation. Cancellation and workspace changes discard the review without an installation. Success emits the shared commerce.apps.changed registry refresh. Reactivating an installed connector uses its revision. An active package without an available surface explains the missing operator service configuration; app installation alone does not provision a managed Experience. Tests cover approval, cancellation, rejection/retry, activation conflicts and read-only roles.