frontend/src/shared/apps/README.mdView on GitHub ↗
shared/apps
Manifest-defined slots, page surfaces and opaque iframe bridge; credentials stay in the host.
Each file starts with its responsibility. See the source inventory for the full map.
Modules
AppFrame.tsx: Opaque-origin app UI. Its SDK can invoke only this app's declared, server-authorized actions.AppSlot.tsx: Generic registered product configuration slot. App packages own labels, input names and business rules.AppSurfaces.tsx: One registry read per workspace; app bundles load only when their surface is mounted.
Verification
Run npm run build, npm test, npm run test:coverage and npm run architecture from frontend/. Coverage includes untested source files. See testing and limitations; file presence does not mean full test coverage.
Language context
Native surfaces and legacy product slots use shared contentText and shop main-language inheritance. Public surfaces read the storefront content locale, including extra enabled languages. AppFrame passes interface/content/main locales and enabled languages to the guest SDK; no credentials or permissions are added. See localization.