bfcbbfac393687cf14f05a62969fb85ba74cbfff
PUT /api/orders/:uuid forwarded the browser's body to the CMS unchanged. It
now forwards { data } with only the seven fields of the checkout's steps:
email, acceptedTermsAndConditionsAt, invoiceAddress, deliveryAddress,
invoiceAddressStructured, deliveryAddressStructured and delivery. Any other
field, a field beside data, or a body of another shape is answered 400
"Invalid order update" with the CMS's error format, without calling the
CMS. The values are left to the CMS, which checks them and stays the
authority; this is defence in depth.
pickCustomerUpdate (server/utils/customerUpdate.ts) is pure and tested with
the exact payloads of steps 1 and 2 and with every server-only attribute of
the order.
Refs libretech/mp#71
libreshop/shop
Vue/Nuxt-style storefront base.
Part of the libreshop toolkit. Image
published at git.librete.ch/libreshop/shop on every push to main
and on v* tags.
Source
This repo was extracted from mp/shop/ on 2026-04-29; mp was the
first concrete adapter consuming the toolkit. mp's compose.yml now
pulls git.librete.ch/libreshop/shop:<pin> instead of building locally.
Build locally
docker build -t libreshop/shop:dev .
Adapter contract
See docker-entrypoint.sh and Dockerfile for the runtime surface.
Adapters configure the component via env vars and bind-mounted volumes;
do not patch the running container or rely on internal paths.
Languages
Vue
68.2%
TypeScript
31.4%
Dockerfile
0.3%
CSS
0.1%