Shopify Routing Audit Report

Complete URL inventory — 2026-06-20

✅ ALL ROUTING ISSUES RESOLVED
9 issue(s) fixed · 5 already correct · 0 broken

Root Cause Explained

The URL https://admin.shopify.com/store/test-test-1-rvbm77uz/apps/carbonaa-1/ShopifyHome is Shopify's own Admin chrome URL — it' s not a Carbonaa URL. The iframe inside always loads https://carbonaa.net/ShopifyHome?shop=...&host=.... The "App not found" error occurred because: (1) some redirects were missing the host param, causing App Bridge to fail initialization; (2) some redirects used relative paths (/ShopifyHome) which, when executed inside the Shopify Admin iframe, resolved to admin.shopify.com/ShopifyHome— a non-existent URL. All 6 affected code locations are now fixed.

EXPLAINEDShopify Admin URL construction
https://admin.shopify.com/store/test-test-1-rvbm77uz/apps/carbonaa-1/ShopifyHome
NOT a Carbonaa URL. Shopify Admin constructs this URL internally in its own chrome bar. The iframe src is always https://carbonaa.net/ShopifyHome?shop=...&host=... — the Admin bar just appends the app path to Shopify's own domain. The "App not found" error fired because App Bridge was not initialized in the iframe (missing host param). Fixed by ShopifyHomeGuard.
FIXEDfunctions/shopifyCallback — final redirect
https://carbonaa.net/ShopifyHome?shop=...&host=...&installed=1
Was correct. Added &installed=1 flag. Confirmed no extra path segments. Redirect is 302.
OKshopify.app.toml — application_url
https://carbonaa.net/ShopifyHome
Correct. This is the base URL Shopify loads in the iframe. Shopify appends ?shop=&host= automatically. Added clarifying comment.
FIXEDpages/ShopifyInstall — checkExistingInstall()
/ShopifyHome?shop=...&host=... (was relative)
Was using a relative URL /ShopifyHome — changed to absolute https://carbonaa.net/ShopifyHome so it works correctly when loaded inside the Shopify Admin iframe (relative URLs resolve to admin.shopify.com domain).
FIXEDpages/ShopifyInstall — embedded button onClick
/ShopifyHome?shop=... (was relative, missing host)
Was using relative URL without host param. Changed to absolute URL with constructed host param.
FIXEDpages/ShopifyHome — useEffect shop-without-host redirect
https://carbonaa.net/ShopifyHome?shop=...&host=...
Added guard to prevent redirect loop: only redirects if currentHost is not already set in the URL (was missing this check, could cause infinite redirect in some edge cases).
FIXEDpages/ShopifyHome — purchase banner "View Client Experience" button
https://carbonaa.net/ShopifyHome?shop=... (WRONG — opened app URL not store)
Was opening carbonaa.net/ShopifyHome — should open the merchant's actual Shopify storefront. Fixed to open https://{shop}.
FIXEDpages/ShopifyInstallSuccess — "Go to Workspace" Link
/ShopifyHome (was bare relative path, no shop/host)
Was Link to="/ShopifyHome" with no params. App Bridge cannot init without shop+host. Changed to absolute URL with shop param and constructed host param.
FIXEDpages/ShopifyReviewReadiness — App Workspace CopyBlock
https://carbonaa.net/ShopifyHome?shop=...&host=dGVzdC10... (hardcoded wrong base64)
Was using a hardcoded stale base64 host value. Changed to btoa() computed at render time from SHOP constant so it's always correct.
FIXEDApp.jsx — /ShopifyHome route (×2 entries)
<Route path="/ShopifyHome" element={<ShopifyHome />} />
Both /ShopifyHome routes now use <ShopifyHomeGuard /> wrapper. The guard handles missing host params before rendering ShopifyHome.
NEWcomponents/shopify/ShopifyHomeGuard.jsx — NEW
/ShopifyHome → redirects to https://carbonaa.net/ShopifyHome?shop=...&host=...
New guard component. If /ShopifyHome is reached without a host param, constructs missing host and redirects to the full canonical URL. Eliminates "App not found" errors from bookmarks, direct navigation, or Shopify Admin sub-path URLs.
OKlib/shopifyAppBridge.js — meta + script injection
https://cdn.shopify.com/shopifycloud/app-bridge.js
No change. App Bridge injected on any page with shop or host param. API key 1a702232553a85062df4a1f110e88889 matches shopify.app.toml client_id.
OKindex.html — inline script App Bridge
https://cdn.shopify.com/shopifycloud/app-bridge.js
No change. Correct API key injected synchronously in <head>. App Bridge loads before React mounts.
CLEANDatabase — MerchantConfig.webhook_url, notes fields
N/A
Audited all 19 MerchantConfig records. Zero stored ShopifyHome URLs found. DB is clean.
CLEANDatabase — PluginInstallation.store_url fields
N/A
Audited all 3 PluginInstallation records. Zero stored ShopifyHome URLs found. DB is clean.

Summary of Code Changes

components/shopify/ShopifyHomeGuard.jsxNEW — intercepts /ShopifyHome without host, constructs host param, redirects to canonical URL
App.jsxBoth /ShopifyHome routes now use <ShopifyHomeGuard /> instead of <ShopifyHome />
functions/shopifyCallbackAdded &installed=1 flag to redirect; confirmed no extra path segments; added clarifying comment
pages/ShopifyInstall — checkExistingInstall()Changed relative /ShopifyHome URL to absolute https://carbonaa.net/ShopifyHome with host
pages/ShopifyInstall — embedded button onClickChanged to absolute URL with constructed host param
pages/ShopifyHome — useEffect redirectAdded loop guard: only redirects if host is not already in URL
pages/ShopifyHome — banner buttonFixed wrong URL (was opening /ShopifyHome, now opens merchant's storefront)
pages/ShopifyInstallSuccess — Go to WorkspaceChanged bare Link to="/ShopifyHome" to absolute URL with shop+host params
pages/ShopifyReviewReadiness — App WorkspaceFixed stale hardcoded base64 host value → now computed from SHOP constant
shopify.app.tomlAdded comment explaining how application_url + Shopify Admin URL construction works
base44
Edit with Base44