Skip to content

[STR-1307] fix: add ViewProduct policy for catalog-graphql - #228

Merged
iago1501 merged 5 commits into
mainfrom
fix/catalog-graphql-view-product-policy
Oct 8, 2026
Merged

iago1501 merged 5 commits into
mainfrom
fix/catalog-graphql-view-product-policy

Conversation

@iago1501

@iago1501 iago1501 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

What problem is this solving?

From catalog-graphql 1.108 on, the app token must be authorized with View* policies. The return-app calls catalog-graphql (sku query, to translate SKU names) with ctx.authToken but only declared vtex.catalog-graphql:resolve-graphql. Same fix applied in broadcaster-worker: vtex-apps/broadcaster-worker#36

Only ViewProduct is added, since the query reads only the SKU name (no brand/category).

How to test it?

Link the branch and open a flow that triggers SKU name translation; confirm no 403 from catalog-graphql.

[Workspace](Link goes here!)

Screenshots or example usage:

N/A

Describe alternatives you've considered, if any.

If ViewProduct is not enough, also add ViewBrand and ViewCategory as in broadcaster-worker.

Related to / Depends on

vtex-apps/broadcaster-worker#36

Co-authored-by: Cursor <cursoragent@cursor.com>
@vtex-io-ci-cd

vtex-io-ci-cd Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Hi! I'm VTEX IO CI/CD Bot and I'll be helping you to publish your app! 🤖

Please select which version do you want to release:

  • Patch (backwards-compatible bug fixes)

  • Minor (backwards-compatible functionality)

  • Major (incompatible API changes)

And then you just need to merge your PR when you are ready! There is no need to create a release commit/tag.

  • No thanks, I would rather do it manually 😞

@vtex-io-docs-bot

vtex-io-docs-bot Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Beep boop 🤖

I noticed you didn't make any changes at the docs/ folder

  • There's nothing new to document 🤔
  • I'll do it later 😞

In order to keep track, I'll create an issue if you decide now is not a good time

  • I just updated 🎉🎉

@iago1501
iago1501 marked this pull request as ready for review October 6, 2026 18:58
@iago1501 iago1501 self-assigned this Oct 6, 2026
@iago1501 iago1501 added the bug Something isn't working label Oct 6, 2026
iago1501 and others added 4 commits October 6, 2026 16:48
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@iago1501 iago1501 changed the title fix: add ViewProduct policy for catalog-graphql [STR-1307] fix: add ViewProduct policy for catalog-graphql Oct 6, 2026

@mendescamara mendescamara left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@iago1501
iago1501 merged commit 08d1248 into main Oct 8, 2026
6 checks passed
@vtex-io-ci-cd

vtex-io-ci-cd Bot commented Oct 8, 2026

Copy link
Copy Markdown

Your PR has been merged! App is being published. 🚀
Version 3.11.1 → 3.11.2

After the publishing process has been completed (check #vtex-io-releases) and doing A/B tests with the new version, you can deploy your release by running:

vtex deploy vtex.return-app@3.11.2

After that your app will be updated on all accounts.

For more information on the deployment process check the docs. 📖

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants