Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungTCP vs UDP: The Two Ways to Move Data, and Why Neither Is "Better"(21.09.2026 um 09:31 Uhr)
Sichere ProgrammierungBukan Sekadar Variabel, Tapi Nyawa dari Aplikasi Kamu! 🚀(21.09.2026 um 09:36 Uhr)
Sichere ProgrammierungAI voice agent for customer service: what stops callers hanging up?(21.09.2026 um 09:42 Uhr)
Sichere ProgrammierungReading a small model's confidence instead of its prose(21.09.2026 um 09:47 Uhr)
Sichere ProgrammierungTCP vs UDP: The Two Ways to Move Data, and Why Neither Is "Better"(21.09.2026 um 09:31 Uhr)
Sichere ProgrammierungBukan Sekadar Variabel, Tapi Nyawa dari Aplikasi Kamu! 🚀(21.09.2026 um 09:36 Uhr)
Sichere ProgrammierungAI voice agent for customer service: what stops callers hanging up?(21.09.2026 um 09:42 Uhr)
Sichere ProgrammierungReading a small model's confidence instead of its prose(21.09.2026 um 09:47 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

6 things I learned building an app for Shopify's new native B2B

This spring, Shopify quietly did something big: native B2B — Companies, catalogs, net terms — became available on all plans, not just Plus. Millions of stores can now sell wholesale without a $2k/month subscription or a heavyweight app sui…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

This spring, Shopify quietly did something big: native B2B — Companies, catalogs, net terms — became available on all plans, not just Plus. Millions of stores can now sell wholesale without a $2k/month subscription or a heavyweight app suite.



I spent the last month building a small app on top of these APIs (Tradelane, it handles the wholesale application/approval flow that Shopify left out). Here's what I wish I'd known on day one.






1. One email = one company contact. Plan for it.



The constraint that bit me hardest: a customer email can only be the main contact of one company. If a buyer applies twice, or a merchant re-approves someone whose email is already attached to another company, companyCreate succeeds but the contact assignment fails silently unless you handle it.



My fix: treat "approved, but contact not assigned" as a first-class state with a clear message to the merchant, instead of pretending the whole operation failed. Partial success with an explanation beats a rollback nobody understands.






2. The app proxy is underrated for public-facing features



If your app needs a public page on the merchant's storefront (forms, portals, status pages), Shopify's app proxy gives you a route at store.com/apps/your-app/... that forwards to your server with an HMAC signature. Same origin as the storefront, no CORS, no theme code.



Two practical notes: authenticate.public.appProxy(request) (in the Remix/React Router template) gives you the shop and an admin API client, and because the page is same-origin you can later embed it in a theme app extension with a plain <iframe> — no postMessage gymnastics.






3. React escapes your <style> tags. Yes, really.



I shipped a form whose fonts silently fell back to Times New Roman. The culprit:




<style>{`
body { font-family: -apple-system, "Segoe UI", sans-serif; }
`
}</style>






React escapes text children — including inside <style> — so "Segoe UI" becomes "Segoe UI", which is invalid CSS, which invalidates the whole declaration. Border-radius from the same stylesheet worked fine, so it took me days to notice. Same thing breaks url("data:...") values.



The fix is the escape hatch that exists precisely for this (spaces added between the braces so this renders on dev.to — in real code they'd be together):




<style dangerouslySetInnerHTML={ { __html: `...` } } />









4. Validate EU VAT numbers with VIES — it's free and merchants love it



If your app touches B2B in Europe, the EU's VIES service validates VAT numbers (and returns the registered business name) via a free API. Fake wholesale applications are more common than I expected, and "VAT valid ✓" next to an application turned out to be one of the most-mentioned features in feedback.



Cache the result — VIES is slow and occasionally down, so check once per application and store valid | invalid | unavailable.






5. hCaptcha over Turnstile for multi-tenant storefronts



My form renders on any merchant's domain via the app proxy. Cloudflare Turnstile wants per-hostname configuration; hCaptcha sitekeys work on any hostname by default. For a multi-tenant Shopify app, that's the whole decision. (Also: append ?hl=en to the script URL, or the widget renders in the visitor's browser language while the rest of your form is English.)






6. Fire-and-forget your emails, but never your writes



Every notification email in my submit path is void sendEmail().catch(log) — if the email provider hiccups, the application still saves and the buyer still sees the success page. A missed email is a degraded state; a lost application is a lost customer. Decide explicitly which failures are allowed to break the request and which aren't.






The gap, if you're looking for one: native B2B handles pricing, catalogs and payment terms well, but onboarding is still rough. The free Forms app can take applications, yet it creates the Company before approval (junk piles up in the admin), skips VAT validation, and doesn't assign catalogs. That's the hole I built Tradelane into. If you're building on the Companies API and hit something weird, my DMs are open. Happy to compare notes.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten 6 things I learned building an app for Shopify's new native B2B

Thematisch verwandte Begriffe: things, learned, building, Shopifys · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94030 | A security vulnerability has been detected in SerenityOS up to 3d83e4509…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick