Unofficial Tracker

Every change to Shopify's App Bridge, tracked automatically.

No changelog, no versioning — just a minified app-bridge.js shipped to CDN and a prayer. We reverse-engineer every build so you don't have to.

Changelog

28 entries

25da58b4

Sidekick API gains surface availability checks, bar visibility control, and stricter open() handling for the mobile online store editor.

  • sidekick.isSurfaceAvailable(surface) is a new method that reports whether the 'mobile-web-online-store-editor' surface is available.
  • sidekick.open() now accepts an optional { surface: 'mobile-web-online-store-editor' } argument, returns a boolean for surface opens, and throws a TypeError for unsupported surface arguments.
  • A new sidekick.setBarVisibility(value) method forwards bar visibility changes to the internal Sidekick API.
Files 11
+73 -38
8 modified
fdd8d994

Adds app-modal module that detects open Polaris modals, allowlists Shopify CDN hosts, and extends telemetry.

  • New app-modal module watches the Polaris portals container and notifies the host through appModal.setOpen when a Polaris modal opens or closes.
  • Script tag validation now accepts any host from a Shopify CDN allowlist (cdn.shopify.com plus shopify-assets domains) over HTTPS instead of only cdn.shopify.com.
  • The fetch module uses the same CDN allowlist check when deciding whether a request targets the Shopify CDN.
Files 21
+132 -116
16 modified
c23dfa58

Minor build update with small title-bar button property changes and otherwise variable renaming across modules.

  • The title-bar module's button action builder now appears to pass a tone property in place of the previous icon property mapping.
  • The title-bar module's selector string for action elements now references a different internal constant.
  • The s-app-window, ui-modal, and ui-nav-menu modules only changed their internal registry references, with no behavior change.
Files 8
+13 -15
4 modified
c3f636fd

Expanded the trusted postMessage origin allowlist and bumped the internal protocol version to 0.38.13.

  • The postMessage origin check in the bootstrap module now also trusts admin.shopify.cn, admin.shopifystaging.cn, and a Shopify test domain in addition to the existing myshopify and shop.dev origins.
  • The bundled Shopify protocol version constant was bumped from 0.38.12+8d1813e6 to 0.38.13+38896b9f.
  • No modules were added or removed in this build.
Files 19
+101 -100
15 modified
df7e36ce

The shopifyQL module gained new availability, readiness, context, and metric-tracking APIs.

  • Added api.shopifyQL.available() to asynchronously check whether the ShopifyQL API is present.
  • Added api.shopifyQL.ready() which checks hasPermissions and falls back after a 30 second timeout.
  • Added an internal getContext() method that throws an error if the ShopifyQL API is not available.
Files 11
+66 -24
7 modified
e57eeaec

Removes a feature flag gate on a CSSStyleSheet polyfill and bumps the Shopify protocols version.

  • The bootstrap module's CSSStyleSheet.replaceSync polyfill no longer checks the MobileBridgeNext flag before running, so it now applies unconditionally rather than only for that flagged rollout.
  • The SHOPIFY_PROTOCOLS constant in _utilities.js was bumped from 0.38.10+52074793 to 0.38.11+c048218d.
Files 3
+4 -5
f524cbbf

Title bar module now hides duplicate native action elements via injected CSS and skips empty secondary action groups.

  • The title-bar module now hides duplicate breadcrumb, primary, secondary, and accessory action elements by injecting a stylesheet instead of manipulating hideElements directly.
  • Secondary title bar actions are now only added to the update payload when the resolved secondary actions array is non-empty, avoiding empty button groups.
  • The MutationObserver that watches for title bar changes now matches against a list of relevant tag names instead of a single hardcoded S-PAGE check.
Files 23
+88 -63
18 modified
b7e0f69c

Sidekick module gains a registerNavigationReadinessProvider method; library version bumped to 0.38.9.

  • The sidekick module adds a new registerNavigationReadinessProvider method that lets apps register a readiness provider and returns an unregister function that cleans up when called.
  • Internal library version string was bumped from 0.38.8+8a261cd7 to 0.38.9+efa5798b.
  • The fetch, print, share, and window.open/history interception helpers were renamed internally with no observable behavior change.
Files 7
+58 -34
4 modified
166e1f5d

Bootstrap now captures an admin_theme parameter, persists it to sessionStorage, and exposes it globally.

  • Bootstrap reads a new admin_theme URL parameter and stores it in sessionStorage under the key app-bridge-admin-theme.
  • When the admin_theme parameter is absent from the URL, App Bridge now falls back to a previously cached sessionStorage value.
  • The captured value is exposed as globalThis.__shopifyAdminTheme so other code in the page can read the active admin theme.
Files 20
+95 -73
15 modified
f90ae585

App nav (v0.38.7) now validates anchor hrefs and warns on unsupported links instead of silently breaking.

  • App nav parsing (used by s-app-nav and ui-nav-menu) now validates each anchor href and only accepts relative app paths, app: URLs, or same-origin http(s) URLs.
  • Anchors with unsupported hrefs are dropped from the nav and logged once via console.warn with a link to the app-nav docs, instead of silently producing a broken URL.
  • app: protocol URLs are now converted to a proper same-origin URL string before being sent in the Menu update payload.
Files 11
+70 -43
8 modified
740e2544

This build only renames internal minified variables and registry comments, with no functional or API changes.

  • No modules were added or removed in this build.
  • The intents, internal-only, pos, and title-bar modules changed only in internal variable names, with identical logic and behavior preserved.
  • The s-app-nav, s-app-window, ui-modal, and ui-nav-menu modules only had their internal registry-reference comments updated.
Files 11
+26 -28
8 modified
d5bb40f6

Reworks save-bar dirty-state tracking, wires it into tools.register, and adds a version field to protocol messages.

  • The save-bar dirty-state utility in _utilities.js was rewritten with a new valuemodified event and a shared capture/settle registry for more reliable change detection.
  • tools.register() now captures save-bar state before invoking a registered handler and settles it afterward via double requestAnimationFrame, keeping the save bar accurate when a tool action modifies form state.
  • Bootstrap now attaches a version field to the client config, and web-vitals includes the same version field in its WebVitals protocol messages.
Files 19
+117 -63
16 modified
6d27951e

Fixes case-sensitive link target handling and URL path normalization, and makes the shopifyQL API always available with lazy resolution.

  • The shopifyQL module now always exposes api.shopifyQL as a lazy proxy with an available() check, instead of only setting it after confirming backend support.
  • Link and window.open target attributes like _blank or _self are now normalized case-insensitively, fixing save-bar interception for links with mixed-case target values.
  • Fixed URL path normalization in parseUrl to collapse multiple leading slashes instead of just prepending one.
Files 12
+39 -36
9 modified
6d9a048d

Minor bootstrap update adds safe-area padding to Polaris modal dialogs on devices with bottom insets.

  • The injected safe-area stylesheet in _bootstrap.js now adds a rule targeting .Polaris-Modal-Dialog__Modal.
  • Modal dialogs get bottom padding equal to the shopify-safe-area-inset-bottom variable so content is not obscured by device insets like home indicators.
  • No modules were added or removed, and no public API methods changed in this build.
Files 2
+4 -4
ccda5568

Telemetry now reports element attributes and Polaris version; cleanup listener switched from beforeunload to pagehide.

  • The telemetry module now includes the custom element's attribute names in its ui-component telemetry payload.
  • Telemetry increment calls now attach the Polaris design system version when globalThis.polaris.version is available.
  • The internal utilities module now cleans up navigation listeners on the pagehide event instead of beforeunload.
Files 3
+14 -9
1 modified
cd7d0f3d

MobileBridgeNext safe area insets now inject styles via Constructable Stylesheets instead of a style element.

  • MobileBridgeNext now injects safe area inset styles using the Constructable Stylesheets API and document.adoptedStyleSheets instead of appending a style element to document.head.
  • Safe area inset style injection now includes feature detection and exits gracefully if CSSStyleSheet or adoptedStyleSheets APIs are unavailable.
  • The function for intercepting native browser APIs was renamed from restoreProperty to interceptProperty, affecting the fetch, print, share, window.open, and history modules.
Files 7
+54 -39
4 modified
c3591477

Navigation handler sets navigationVersion 2 on the shopify global and adds a history.pushState fallback for unresolved link navigations.

  • The navigation system now sets Symbol.for('navigationVersion') to 2 on the global shopify object at initialization, advertising the active navigation protocol version.
  • When home-link click simulation cannot process a URL, a new fallback uses history.pushState and dispatches a popstate event to complete the navigation instead of calling the App Bridge navigate API.
  • When navigating via a home link, the target URL is now derived from the home link element's href attribute rather than the original destination URL.
Files 2
+29 -13
ef8b61d3

The title-bar module adds groupType support to secondary action button groups.

  • The title-bar module now accepts a groupType property on secondary action button groups.
  • groupType is destructured from button group objects alongside label, icon, disabled, and buttons fields.
  • When groupType is provided on a button group, it is forwarded to the title bar protocol.
Files 2
+7 -4
1 modified
6bb9c034

Navigation utilities updated to support s-app-nav elements and fix home link detection via getAttribute fallback.

  • The qt selector function now includes s-app-nav as a navigation container, matching ui-nav-menu support for click interception.
  • App Bridge will now intercept and handle client-side navigation for clickable elements inside s-app-nav components.
  • Home link detection in the navigation handler now uses getAttribute('rel') as a fallback when the rel property is nullish, fixing routing for custom elements.
Files 2
+5 -4
fd311eae

Added idToken timeout and error hardening, sidekick conversation stream events, and title bar button pressed state.

  • The id-token module now enforces a 60-second timeout when requesting session tokens from the host, rejecting with a clear error if the host does not respond in time.
  • The id-token module now validates that retrieved tokens are non-empty strings, throwing an idToken unavailable error for missing or invalid tokens.
  • The fetch module now handles idToken failures gracefully, logging an error and skipping the Authorization header instead of propagating the exception.
Files 21
+107 -71
18 modified
af2eb2f3

The fetch interceptor removes extensionOriginFetch support, simplifying all intercepted requests to use native fetch.

  • The fetch module removes the extensionOriginFetch code path, which previously allowed extension-origin requests to be routed through a custom fetch implementation from internalApiPromise.
  • Helper utilities for serializing Request objects to plain objects and reconstructing Responses from ArrayBuffers were removed from the utilities module alongside extensionOriginFetch.
  • The session token retry logic in the fetch interceptor is simplified, with both the initial request and the auth-header retry now always using native self.fetch directly.
Files 17
+64 -118
14 modified
5fe14787

Intents module gains a reactive request signal and response now only exists when an intent is active.

  • The intents module now exposes api.intents.request as a reactive signal that tracks the current active intent value.
  • The api.intents.response property is now a getter returning undefined when no intent is active, instead of always being defined.
  • Intent request state is kept synchronized with the internal API via subscription and unsubscribed automatically on page unload.
Files 14
+126 -177
10 modified
b3f8e93d

Internal refactoring of private field utilities with a minor defensive hasOwnProperty improvement.

  • The private field access guard in _utilities.js was updated to use {}.hasOwnProperty.call instead of Object.prototype.hasOwnProperty.call, making it more resilient to prototype pollution.
  • Internal private field helpers were renamed and reorganized in _utilities.js: the counter variable and key-creation and field-check functions swapped names.
  • _bootstrap.js was updated to call the renamed private field helpers privateKeyCounter and checkPrivateField consistently.
Files 3
+18 -18
e35faefd

Several modules broadened protocol support from Shopify-only to all protocols, with minor error tracking improvements.

  • toast.show and toast.hide switched from SHOPIFY_PROTOCOLS to ALL_PROTOCOLS, enabling them to work across all protocol environments.
  • sidekick.registerToolHandler and sidekick.registerContextCallback switched from SHOPIFY_PROTOCOLS to ALL_PROTOCOLS.
  • tools.register, tools.unregister, and tools.clear switched from SHOPIFY_PROTOCOLS to ALL_PROTOCOLS.
Files 20
+66 -67
16 modified
07f68577

Added mobile safe area inset support via a CSS custom property when the MobileBridgeNext flag is enabled.

  • Bootstrap now injects a --shopify-safe-area-inset-bottom CSS custom property initialized to 0px when the MobileBridgeNext feature flag is active.
  • The safe area inset bottom value is automatically subscribed to from the host and kept in sync as a CSS variable on the root element.
  • A body::after pseudo-element is added to reserve physical space at the bottom of the page equal to the safe area inset height.
Files 6
+43 -30
3 modified
d934d47f

The fetch module gained extensionOriginFetch support, and several modules narrowed their protocol scope to Shopify-only contexts.

  • The fetch module now supports an extensionOriginFetch handler that routes requests through a custom fetch implementation when available, affecting both initial and retry-on-session requests.
  • The toast module's show and hide methods now only activate in Shopify protocol contexts, replacing the previous all-protocols behavior.
  • The tools module's register, unregister, and clear methods now scope exclusively to Shopify protocols.
Files 24
+140 -188
20 modified
cdc43ba6

This build introduces first-class support for app intents — apps can now read structured intent data from the URL, respond to intents with ok/error/closed outcomes, and detect intent context via `environment.intent`. Two new modules (`analytics` and `tools`) were added, and the title bar gains support for `<s-button-group>` elements.

  • Two new modules registered: `analytics.js` and `tools.js`
  • `intents` module: new `api.data.intent` property that parses and exposes structured intent payload (`type`, `action`, `data`) from the URL's `intent` query parameter
  • `intents` module: new `api.intents.response` object with `ok()`, `error()`, and `closed()` methods for sending a response back to the intent caller (only exposed when an intent is present)
Files 26
+825 -709
21 modified
55c89da0

Initial baseline capture of Shopify's App Bridge CDN bundle. This is the first tracked build — all 38 modules and 4 infrastructure files have been deminified and catalogued.

  • Captured 34 feature modules including navigation, fetch, save-bar, toast, resource-picker, and POS
  • Identified 4 infrastructure files: bootstrap, utilities, remote-ui (RPC), and web-vitals
  • Bundle size: 88.5 KB minified, expanding to ~167 KB deminified across 38 files
+33 new