Storefront Import
The public Tryout detects and captures Shopify, Shopline, or
WooCommerce storefronts. A committed live_transition can
start for Shopify or Shopline. Shopify has the active end-to-end
migration pipeline; Shopline can securely authorize and create its
Storefront token, then stops at a visible source-import blocker until
the dedicated worker is ready. WooCommerce live migration is not
startable yet.
botanic-pretti5-l-skincare.myshopify.com, multi-store
installation is disabled, and the active app version still requests
only read_themes. Do not ask Pretti5 to approve the app
until the matching pretti5-full-migration.v1 app version,
control plane, worker, and template are published together. The
replacement client secret is encrypted in platform secrets and the
initial credential was revoked. The candidate
release includes the Shopify authorization, managed Storefront
runtime, detected account connection, segmented source
capture, fixed worker, compatibility compiler/runtime, exact Preview
deployment, deployment-bound browser and commerce evidence,
fail-closed parity, and editable Wok handoff. No merchant-authorized
Pretti5 run has passed, and no production template or migration
worker is active. WooCommerce stops before committed journey
creation and is directed to public Tryout. Never paste a token,
secret, cookie, or nonce into the Storefront URL, Wang chat, an
issue, or frontend code. DNS and Shopify theme publication remain
unavailable.
Choose the migration intent
"Progressive migration" can mean testing whether the import is worthwhile, or moving the complete live store first and redesigning it afterward. Import must ask which job the merchant is doing before it asks for connections.
Try it first
Start with the storefront URL and an owned Preview Wok. The one assigned password-protected development store can connect through the same Shopify app used for the live-store pilot; TellWang keeps its private discovery gates locked until authorization. TellWang can capture the visible site without touching live traffic. A future authorized source capture can add richer private source evidence, then let the merchant stop. It does not compile or deploy a Wok. Runtime catalog, accounts, checkout, production domains, and cutover are not required.
Provider access is still an administrative change. A Shopify app remains installed until revoked or uninstalled, so TellWang must show the exact access and revocation action before approval. WooCommerce admin setup is outside the Pretti5 release.
The future Shopify Tryout dynamically requests
read_themes as an optional scope plus only other approved
read-only source scopes, never write_themes. WooCommerce
authorization and source-connector work is outside the Pretti5
release.
The current workspace implements only this URL-based public capture. Provider-authorized Tryout is not live yet.
Move a live store
This customer path can start for Shopify or Shopline. A committed Shopify merchant gets one resumable guided run for source authorization, runtime catalog and cart access, accounts, data continuity, checkout, consent, analytics, production-host readiness, rollback origin, and route acceptance. A committed Shopline merchant gets the same Preview and secure connection setup, and its catalogue is read and recorded from the Shopline Admin Open API. It then stops at an explicit gate: theme analysis, candidate compile, and deploy are not implemented for Shopline, so no Shopline storefront is served yet.
The complete Shopify permission set is disclosed and approved during the first app connection. This is the only planned app approval in a normal migration. TellWang provisions Storefront runtime access from that grant. Customer-account configuration and domains remain distinct, receipted operations inside the same resumable run.
The full versioned permission contract is approved early. TellWang
creates or reuses the app-owned Storefront token when the runtime
needs it; the merchant does not install Headless or paste a token for
that managed Storefront runtime. A store already using Shopify's
newer Customer Accounts may still need its Headless-channel public
client setup. Account settings and adapter setup appear when discovery
proves they are needed. Production domains,
Shopify's stable legacy origin, and the whole-host DNS plan appear
near launch, after their
evidence is current. The Pretti5 release does not offer a redirect
theme or request write_themes.
The source stays online and authoritative through cutover and for as long as commerce, synchronization, a provider handoff, or the rollback window depends on it. Production DNS remains a deployment-bound, owner-approved operation. Shopify keeps the original published theme live and performs no theme action. Redirect-theme publication is outside the Pretti5 release so the old storefront remains independently usable as the hot backup.
For Shopify, every public storefront route needs a verified Wok
baseline before the hostname moves; the native Shopify theme cannot
remain transparently proxied under selected paths. The merchant can
launch a native / while product pages use the imported
compatibility frontend and Shopify continues to power commerce and
checkout.
WooCommerce passthrough and progressive route activation are future work. They are not available from the committed migration UI and do not affect the Shopify/Pretti5 workflow.
| Route state | Meaning after cutover |
|---|---|
| Compatibility | Imported, evidence-backed Wok behavior. Shopify storefront routes begin here. |
| Native | Merchant-edited Wok route. Visual parity is intentionally waived, while the frozen functional contract still runs. |
| Provider handoff | Verified provider checkout, account, or extension journey that cannot run under the Wok route. Unknown or session-unsafe handoffs block activation. |
The committed Shopify flow is a separate resumable journey today.
Reusing public Tryout evidence through a new immutable-input child
execution is planned follow-up; it must revalidate the current Shopify
MAIN theme rather than mutate a started request.
Minimum needed to start
- Confirm that you own the source store or are authorized to migrate it.
- A public Tryout needs only the storefront URL. Admin access is not required until the merchant chooses an authorized source capture or live transition.
- For a connected Shopify run, use a staff role that can manage apps and sales channels. Do not create WooCommerce keys or install a connector for this iteration; WooCommerce can use public Tryout only.
- Keep the existing storefront and checkout live. A reference capture is not a deployable copy.
-
Let Import create a journey-unique Wok and linked Preview, or choose
an active owned Preview that is empty and not assigned to another
migration. TellWang's managed
.claude/skills/tellwang/SKILL.mdfile is neutral Wok context; other.claudefiles still count as customer work. Preview uses a stable HTTPS hostname such as<wok-id>.tellwang.com. - For a live transition, inventory accounts, payments, subscriptions, tax, shipping, search, reviews, loyalty, analytics, consent, and every app or extension that changes the storefront.
- Confirm which source-backed capabilities remain in use. TellWang derives and displays each connection lifecycle; a credential or connector stays active while synchronization or runtime behavior depends on it.
- Do not change production DNS yet.
Know which connection you need
| Connection | Purpose | Credential boundary |
|---|---|---|
| Shopify migration authorization |
Imports the exact published MAIN theme.
|
One server-handled approval of the exact
pretti5-full-migration.v1 contract. Admin access
is read-only; no merchant-created Admin key.
|
| Storefront runtime |
Supplies live catalog, content, Markets, cart, and Shopify's
exact returned checkoutUrl.
|
TellWang creates or reuses an app-owned Storefront token, verifies it server-side, and stores it encrypted. Nothing is copied from Shopify Admin. |
| Customer accounts |
Import detects the live /account mode and binds
classic customer-access-token or new Customer Account API
sessions.
|
Classic reuses managed Storefront access automatically. New mode may additionally need a public Customer Account client ID and exact Preview URLs. It never uses a browser client secret. |
The production hostname is not another API credential. It stays on Shopify during Preview acceptance.
Shopify setup
Shopify setup has one planned app approval. TellWang then provisions the Storefront runtime automatically from the approved contract. The merchant does not install the Headless channel, create a Storefront token, or paste one into Import for that managed runtime. A store already using Shopify's newer Customer Accounts may still need Headless-channel public-client setup for account login.
This complete section applies to Move a live store. Provider-authorized Tryout and evidence reuse are planned follow-up. Today a committed Shopify migration starts its own resumable journey and captures the current published theme before admission. A confirmed start retires its browser retry key; only an uncertain network outcome keeps the key for safe replay.
Approve the complete migration permission set
For a new migration, TellWang first creates the Wok and its editable
Preview automatically. The dashboard names that work
Create Preview Wok, shows the elapsed time, and tells
the merchant to keep the page open because no action is required.
Only after provisioning finishes does the journey surface
Connect Shopify as its first provider action. TellWang
then creates a short-lived, browser-bound install intent and opens
Shopify's approval screen. The generated custom install link stays in
platform secrets. After installation, Shopify returns to TellWang,
which verifies Shopify's signed request and automatically continues
authorization. Sign in to Shopify and approve the exact
pretti5-full-migration.v1 contract once.
The Shopify Admin scopes are read-only:
read_themesread_productsread_product_listingsread_publicationsread_online_store_navigationread_online_store_pagesread_metaobjectsread_metaobject_definitionsread_marketsread_localesread_translationsread_legal_policies
The shopper-facing Storefront scopes are:
unauthenticated_read_product_listingsunauthenticated_read_product_inventoryunauthenticated_read_product_tagsunauthenticated_read_contentunauthenticated_read_metaobjectsunauthenticated_read_selling_plansunauthenticated_read_checkoutsunauthenticated_write_checkoutsunauthenticated_read_customersunauthenticated_write_customers
The Storefront write scopes let shoppers update only their own
checkout and account state through Shopify. TellWang requests no
Admin write, order, payment, domain, or traffic scope. Import shows
the contract version, SHA-256 digest, full lists, and lifecycle before
continuing. The authorization route stores its
expiring offline credential in an encrypted control-plane connection.
The broad token never reaches the migration worker. The worker can
only resolve the published MAIN theme, read bounded
theme-file pages, and verify the same snapshot through fixed
control-plane operations.
Completing the action pins that connection and creates one idempotent
discovery capture bound to the organization, Preview Wok, canonical
source, and Shopify platform. A complete public route universe is
retained by digest and divided into independently budgeted reference
captures of at most 20 routes. Import exposes aggregate and segment progress, verified-stage
progress, total elapsed time, and time since the latest status check.
Active work refreshes every four seconds. The journey warns when the
worker has not accepted a capture within two minutes or an accepted
capture has no fresh status for three minutes. A password page fails
visibly and asks for the Online Store password in Import. TellWang
exchanges it server-side for temporary storefront access, discards
the raw password, and restarts the same capture. Other access
challenges remain blocked. Later setup forms remain hidden until they
are actionable, and Resume
retries only failed segments. The journey remains blocked until every
immutable admission input exists. Once admitted, the fixed worker
imports and verifies the exact published MAIN theme,
compiles it, and deploys only to Preview. It never modifies or
publishes a Shopify theme.
The production connection uses server-handled OAuth through the dedicated, single-store Shopify app. Its exact installation and OAuth callbacks, encrypted client credentials and install link, control-plane encryption key, and full permission contract must be healthy together. Full migration execution still needs merchant installation and authorization, the fixed-worker installation, and signed Marketplace publication. The encrypted connection is retained and its rotating offline grant is renewed in the background for source refresh and the required near-launch source recheck without another merchant approval. That recheck is not implemented yet and remains a production release gate. Shopify asks the merchant to connect again only if the grant becomes impossible to renew, an extended outage lets it expire, the app is uninstalled or revoked, or a future migration materially expands the permission contract. Transient renewal and token-provisioning failures are retried without involving the merchant. When a reconnect is genuinely required, the same journey displays Connect Shopify with the complete permission disclosure. TellWang archives only secret-free lineage digests, invalidates the old source capture and execution, and starts a fresh capture and re-import after approval.
The connection uses the store's permanent Shopify identity, such as
acme.myshopify.com, even when shoppers currently use
acme.com. TellWang should detect and display that
identity for confirmation; do not substitute the new Wok hostname.
If access must be removed, use Disconnect in Import.
TellWang blocks the journey, stops active work, removes Shopify
configuration from linked Preview and Published Woks, scrubs the full
encrypted connection family, and confirms every active Wok restart
before reporting success. Then uninstall the TellWang app in Shopify
Admin to finish provider-side revocation. If a restart cannot be
confirmed, the connection remains fail-closed in
revoking; retry Disconnect rather than assuming the old
runtime is safe.
Once a Shopify journey claims its Preview, visual changes go through Wok Git. Direct frontend, app-server, edge-function, promotion, and custom-domain writes are blocked while the journey is active. This makes every edit run the post-edit commerce checks and keeps the source hostname on Shopify throughout Preview testing.
Do not create a Shopify custom app or paste a Shopify app client secret or Admin token into TellWang. Shopify no longer permits new admin-created custom apps, and a multi-merchant TellWang product must use Shopify's install and token flow. Source import remains locked until the connection is consumed by the bounded importer and its artifact, freshness, and credential-boundary receipts are durable.
Let TellWang provision Storefront access
After Shopify returns from the one approval, Import provisions the
runtime connection automatically. TellWang uses the encrypted Admin
grant inside the control plane to find its exact app-owned Storefront
token or create one when none exists. It accepts only the ten
Storefront scopes disclosed above, verifies the permanent shop,
navigation, catalog, content, localization, empty-cart creation, and
Shopify's HTTPS checkout URL, then stores the token encrypted for the
protected Wok server. The connection reports
auth_mode: managed_public_token without returning the
token to Import or browser code.
The merchant does not install Shopify's Headless sales channel, add a
Headless storefront, change shared Headless permissions, or copy a
Storefront credential for the normal Pretti5 flow. A safe retry
reuses the app-owned token; even an ambiguous Shopify timeout is
followed by a bounded re-check before TellWang considers creating
another one. Transient failures return
CP_STOREFRONT_SHOPIFY_MANAGED_RUNTIME_UNAVAILABLE and do
not require another approval. If Shopify says the app cannot create a
Storefront token,
CP_STOREFRONT_SHOPIFY_MANAGED_RUNTIME_NOT_EXTENDABLE sends
the repair to a TellWang operator, who publishes a storefront-capable,
extendable app version and retries with the existing merchant
approval.
storefrontAccessTokenCreate succeeds. Until that real
canary passes, keep the existing Shopify storefront live and do not
tell Pretti5 that automatic runtime provisioning is proven.
The Wok calls
https://<shop>.myshopify.com/api/<version>/graphql.json
from the server. Ordinary Storefront API calls do
not need the Wok hostname in a Shopify origin
allowlist.
A copied theme's own scripts expect that endpoint on the storefront
they are running on, so the Wok answers
/api/<version>/graphql.json on its own hostname and
forwards each document to Shopify server-side. The request must be a
same-origin POST; the storefront token stays on the
server and never reaches browser code. Without this route a browser's
cart mutations are refused while server-side commerce checks still
pass.
Read Shopify's official Storefront token creation reference, Storefront API setup, and Storefront API authentication rules.
Connect customer accounts
-
In Import, select
Detect and connect customer accounts. TellWang
probes the committed journey's live public
/accountroute and login handoff, then records digest-boundclassicornewevidence. If neither mode can be proven, setup stops without changing the connection. Verify the result in Shopify Admin → Settings → Customer accounts. -
Pretti5 currently resolves
/accountto its same-origin legacy login form, so TellWang detects Legacy customer accounts. Do not upgrade it during preparation. TellWang keeps this mode and uses Shopify's legacy customer-access-token flow through the Wok server. -
For a legacy-account store, no additional Shopify setup is needed.
TellWang already verified that the managed Storefront runtime has
unauthenticated_read_customersandunauthenticated_write_customers. Do not create a Customer Account API client or add callback origins for this mode. - Use a dedicated test customer during the real Preview canary. Its password is posted over HTTPS to the Wok only for Shopify's login mutation; TellWang must neither persist nor log it. The customer access token is encrypted in a secure, HTTP-only Preview cookie.
- Only for stores already using the newer Customer accounts, Import may ask the merchant to install or open Shopify's Headless channel, then open Sales channels → Headless → the TellWang storefront → Customer Account API settings.
-
Under Permissions, preserve every currently enabled
shared permission and add only missing customer data used by the
Wok. Account and order-history flows normally need
customer_read_customersandcustomer_read_orders. Addcustomer_write_customersonly for profile or address editing, and add company, location, subscription, draft-order, metaobject, market, or store-credit scopes only for captured features. - Create a Public client. TellWang uses Authorization Code with PKCE S256 and accepts the Client ID only. Never generate or paste a browser client secret.
- Under Application setup, add the exact Preview callback, logout URL, and JavaScript origin that TellWang displays. Add production values later, when the launch hostname is fixed.
-
TellWang appends
sso=silentto Shopify's exact returned checkout URL after a verified Customer Account session. Localized account paths pass their exact locale to Shopify's hosted login and return to that path. Complete a merchant-assisted real Preview login, logout, order-history, and checkout canary. Mode detection or discovery alone does not prove account UI parity.
For either account mode, the first Preview must render the imported
Shopify customer login and account templates, including their styles
and interactions. An authenticated generic TellWang login page is not
parity evidence. The production canary fails closed while the runtime
reports ui_parity_verified: false.
Preview callback: https://<wok-id>.tellwang.com/account/authorize
Production callback: https://acme.com/account/authorize
Preview logout: https://<wok-id>.tellwang.com/
Production logout: https://acme.com/
For a public web client, add
https://<wok-id>.tellwang.com and
https://acme.com as separate JavaScript origins.
A callback URL contains a path. A JavaScript origin contains only
scheme, host, and optional port. Shopify rejects
localhost and HTTP here. Do not guess the callback path;
copy the values from the Wok's domain step. See Shopify's
Customer Account API setup
and
customer access-scope list.
Treat privacy consent as a blocker when the store uses it
The current compatibility runtime has no reviewed Shopify Customer
Privacy adapter. Its fixed browser policy permits same-origin
connections only, so a theme script cannot make cross-origin privacy
calls work by adding Shopify's checkout domain to
connect-src. Do not create another public token or loosen
that policy during the current Pretti5 migration. If the source uses
Shopify's Customer Privacy API or Shopify cookie banner, retain it as
an unresolved dependency: the candidate cannot pass merchant
acceptance or launch until a reviewed adapter exists and its consent
journeys pass.
A future adapter may expose the existing managed public Storefront token only through its reviewed browser-safe configuration; it must never expose the broad Admin OAuth grant. Bind the Storefront API, storefront root, and checkout root explicitly; keep storefront and checkout under the same registrable root; and verify accept, reject, preferences, sale-of-data, regional banner, and storefront-to-checkout consent continuity against Preview. Shopify documents the required parameters in its Customer Privacy API guide.
Add the storefront, legacy, and checkout hosts
Attach acme.com or www.acme.com through
TellWang's Wok custom-domain connection. The production Import domain
step will wrap that existing connection and return the exact ownership
and routing DNS records; that Import step is not live yet. Do not set
the hostname as a Shopify custom-storefront target: Shopify's domain
target UI supports Shopify-hosted Hydrogen custom storefronts, not an
external TellWang Wok.
Before launch, add and verify a stable legacy hostname such as
legacy.acme.com for Shopify's Online Store. Keep the
original published theme active there and test home, product, cart,
account, and extension journeys directly. The legacy hostname must not
redirect to acme.com, the Wok, or another hostname that
will move at cutover.
For branded Shopify checkout, add checkout.acme.com under
Shopify Admin → Settings → Domains, point only that
subdomain to Shopify using Shopify's DNS values, and verify its
certificate during preparation. Use the exact Shopify routing values
returned for checkout and prove that the resulting
checkoutUrl does not loop through the storefront
hostname. Shopify documents checkout routing in its
traffic migration guide.
The default signed policy is legacy_hot_standby. The
original Online Store and published theme stay live at
legacy.acme.com; cutover moves the whole storefront
hostname to TellWang with theme_action: none. Default
rollback restores routing to that already-live origin with
theme_action: none. It does not depend on republishing a
theme.
The Pretti5 release rejects redirect_theme and never
requests write_themes. The original published theme
remains available at the legacy origin as the independently usable hot
backup.
Shopline setup
Start with the permanent store identity shown in Shopline Admin, such
as acme.myshopline.com. After the Preview Wok is ready,
choose Connect Shopline. TellWang opens Shopline's
public-app approval screen with the complete
shopline-headless-migration.v2 permission disclosure. The
Admin permissions are read-only; the shopper-facing permissions cover
cart, checkout, customer information, and metaobjects.
Shopline gates selling-plan access behind a separate subscription
commerce qualification. The baseline connection does not request
read_selling_plan_group, so ordinary stores can authorize
without that qualification. A source that uses Shopline subscriptions
remains blocked until TellWang's public app has the qualification and
the subscription runtime has passed its migration canary.
A Shopline development store may keep its normal storefront password screen enabled. TellWang recognizes Shopline's same-store password redirect only to preserve the permanent store identity; it does not copy the redirect query or ask for the password during secure app connection.
Provisioning reserves the Preview Wok and its hostname; it does not make that hostname a website. Import shows the Preview link only after a frontend deployment has been verified. Until the Shopline importer reaches that stage, the dashboard says that the Preview website is still waiting for deployment instead of opening an empty host.
Shopline returns a signed, short-lived authorization code. TellWang binds the permanent store, Shopline shop ID, and merchant ID; stores the ten-hour Admin credential encrypted; renews it before expiry; and creates the app-owned Storefront API token automatically. Merchants do not paste either token into the dashboard. TellWang also verifies or creates the current-version uninstall subscription through Shopline's Admin API before committing the connection. Signed uninstall and mandatory customer/merchant redaction webhooks scrub or receipt the matching connection without retaining customer payloads.
MIGRATION_SHOPLINE_SOURCE_IMPORT_PENDING. The live
Shopline storefront remains untouched while the dedicated
theme/catalog importer, compiler, Preview runtime, and parity suite
are built and health-gated. Do not describe a connected Shopline
journey as an imported or editable storefront yet.
WooCommerce (future)
live_transition. Do not generate a REST key, install a
connector, configure webhooks, or change a WordPress origin for
TellWang. A WooCommerce URL may still be used in
Try it first for bounded public detection and
capture only.
Hostname map
| Hostname | Before cutover | After cutover |
|---|---|---|
<wok-id>.tellwang.com
|
Stable Preview Wok | Can remain Preview; never the source API identity. |
acme.com / www.acme.com
|
Existing Shopify Online Store | TellWang Wok only after a future owner-approved whole-host switch. It does not move during Preview acceptance. |
<shop>.myshopify.com
|
Shopify API/store identity | Remains the Shopify API/store identity. Do not repoint it. |
legacy.acme.com |
Verified Shopify Online Store fallback using the original published theme | Remains live and unchanged through the rollback window. It must not redirect to the Wok or moved storefront hostname. |
checkout.acme.com |
Optional Shopify checkout hostname | Still points to Shopify. |
The hostname attached through TellWang's Wok custom-domain connection controls public traffic and TLS. It does not replace the provider's source API identity, and it does not make a credential valid. TellWang verifies credentials and hostnames as separate gates. DNS moves the whole hostname once; later path-by-path migration is Wok routing, not DNS.
Credential lifecycles
| Connection | Lifecycle | When it ends |
|---|---|---|
| Shopify migration OAuth |
retain_while_migration_depends
|
One approval covers the full versioned contract. TellWang retains its encrypted connection and renews its rotating grant in the background for source refresh and the required near-launch source recheck. That recheck is not implemented yet and remains a production release gate. A new approval is needed only if renewal becomes impossible, the app is uninstalled or revoked, or the contract expands. Disconnect returns the same journey to Connect Shopify and requires a fresh capture and re-import; old capture or execution evidence is never reused. It also scrubs TellWang credentials and Wok bindings; uninstall the app in Shopify to finish provider-side cleanup. |
| Shopify Storefront API |
retain_while_runtime_depends
|
TellWang retains its app-owned token while the Wok depends on Shopify. Disconnect or an uninstall event scrubs the runtime binding. Safe provisioning retries reuse the same token. |
| Shopify customer accounts |
retain_while_runtime_depends
|
Classic follows managed Storefront access and retains only TellWang's sealed session key plus buyer-session cookies. New mode rotates the public client after Preview and production account journeys pass. Re-run detection if the merchant changes account type. |
Secrets stay in the secrets backend. Migration state stores opaque connection references, never Admin tokens, consumer keys, connector credentials, cookies, cart tokens, or nonces.
What TellWang accepts today
Production currently keeps Shopify/WooCommerce public Tryout capture.
This candidate adds Shopline to public capture and lets a
customer-facing live_transition reach secure Shopline
connection setup, but it is not active yet. Once the matching app,
control plane, worker, and template are published together, a Shopify
merchant can provide a
public source host, attest migration authority, create a
journey-unique pair or choose a fresh empty unassigned Preview,
recover the journey, and begin its server-owned Shopify authorization
action through the configured pilot app. Completing authorization
creates one durable source-bound discovery capture. A complete route
universe is divided into independently budgeted, digest-bound captures of at most 20 routes.
Once representative home, product, collection, page, blog, and cart
templates are captured, TellWang builds the editable Preview while
the remaining route audit continues. Candidate evidence and launch
remain blocked until every declared route completes; TellWang then
replaces the sampled execution with the complete audit lineage
automatically. Resume retries only failed segments. The control plane
retains dormant WooCommerce application-authorization and WordPress
connector-pairing foundations, but the server and dashboard cannot
start or advance a WooCommerce live migration. Those foundations are
not evidence that WooCommerce migration is available.
The candidate release can admit a Preview-only Shopify execution after
Preview ownership, full migration OAuth, the managed Storefront
runtime, the
detected classic
or new customer-account connection, all representative reference templates,
and the signed template dependencies verify. A classic connection can
complete without a public client, but that does not make the migration
ready: merchant-assisted account/order/checkout evidence and exact
account UI parity remain separate blockers. Once installed, the fixed
leased worker imports Shopify MAIN, compiles the compatibility
runtime, and deploys to Preview. An accepted candidate is hydrated
into storefront/ in canonical Wok Git and deployed from
that exact commit. Its receipt keeps the imported source, compiler
gzip, Git export, Wok commit, and live-runtime digests separate.
Visual definitions and retained assets remain editable; the generated
server and commerce provider are protected so a design edit cannot
silently replace product, cart, account, or checkout behavior. Failed
activation reverts only managed Shopify paths and preserves unrelated
Wok edits.
The worker captures that exact Preview against the sealed source segments. Before execution, Import lists Customer Accounts, each known app capability, and each genuinely unknown live API with its exact accepted adapter SHA-256. Multiple scripts, extension assets, proxies, and API calls from one known app appear as one capability; Shopify infrastructure, hCaptcha, and optional telemetry are covered by their owning flows. These bindings come from TellWang's authenticated root-owned registry; merchants never upload adapter modules or secrets. A missing adapter is platform-owned work and blocks admission while Shopify stays live. The pinned gate compares desktop/mobile pixels, DOM landmarks, document height, scroll reach and effects, interactions, console errors, and network failures. Commerce evidence must pass product view, variant selection, cart add/update/remove, search, Customer Accounts, Shopify-hosted checkout handoff, and every discovered app capability or unknown dependency. Missing, duplicate, stale, malformed, wrong-deployment, or failed evidence blocks the report.
After the initial candidate passes, every Git push of the imported Shopify source is only provisional until the authenticated loopback harness reruns the baseline-bound product, variant, cart, checkout, account, search, and discovered-dependency suite. TellWang stores signed evidence bound to the deployment, both Git revisions, runtime digest, and adapter hashes before acceptance. An unavailable harness, failed flow, or adapter drift restores the prior Preview; Shopify remains untouched. URL, SEO, accessibility, and merchant-specific payment canaries remain separate launch gates.
This is not a live Pretti5 migration: no merchant-authorized Pretti5 run has produced passing candidate receipts; no Pretti5 account, app-extension, checkout, or payment canary; merchant review; independent QA; DNS change; theme publication; or rollback drill has passed.
A completed capture is an oracle for implementation and comparison,
not storefront code. It keeps migration_ready:false.
Unknown platforms or dependencies, missing browser evidence,
incomplete source streams, and route-cap exhaustion remain visible and
block later parity claims.
Editable-Wok and cutover gate
choose and sign the migration-run policy
→ approve the complete versioned Shopify migration contract once + attest source rights
→ stream and verify immutable source artifact
→ reconcile the complete route and dependency inventory
→ provision managed Shopify runtime access, configure accounts when required, compile, and deploy the complete Wok Preview
→ produce browser, session, and commerce evidence for the selected launch candidate
→ block every unknown environment or dependency
→ stop for owner review
→ edit visual Wok source and rerun the post-edit functional contract
→ keep hostname activation as a separate future approval
The release requires one signed published Shopify MigrationTemplate before admission and binds its exact workflow bundle, dependency-only base runtime, and parity profile to the tenant journey. Full-scope Shopify grants use the latest published immutable template. The captured-presentation release is 1.31.0 with the template-first 1.1.43 worker; older template receipts remain immutable. A copied theme's own scripts reach the Storefront API on the Wok hostname, and app scripts load from the vendor's own origin rather than the source shop's signed proxy, so browser cart mutations and app widgets work on the copy. Captured product pages recover their live Shopify variant, price, and availability state without replacing their editable layout, and the evidence probe reads that live selector before capture-redacted controls. Preview-local calls, Shopify's own storefront paths, captcha, and telemetry stay within their owning flows, while known vendor endpoints appear once under the corresponding app. A deterministic evidence mismatch or commerce failure stops for review instead of starting another complete capture. A Preview built before the exhaustive route audit finishes is clearly marked as audit-pending and cannot produce launch evidence. When the audit completes, TellWang upgrades it to the full immutable lineage without deleting the editable Preview. The source storefront's Shopify CDN resources stay on its authorized Shopify origin while internal navigation stays on the Preview. The source importer, compiler/runtime, fixed production worker, Shopify driver, Preview deployment bridge, candidate evidence producer, and parity verifier are wired behind that boundary. Pretti6 authorization, capture, source import, and grouped app preflight are active. Release still requires a deployed editable Preview that passes every browser, customer-account, cart, checkout, and configured-app journey before Pretti5 authorization or any separately approved hostname cutover. WooCommerce remains dormant and is not startable.
Before the initial host switch
- Provider connections are verified server-side with no secrets in the browser or migration record.
- The immutable source artifact is durable. The one approved, encrypted migration connection is retained and renewed in the background for source refresh and the required near-launch source recheck. That recheck is not implemented yet; production stays blocked until it is implemented and passes. Disconnect scrubs TellWang-held credentials; Shopify app uninstall finishes provider-side cleanup.
- Every route and dependency is reconciled; unknowns block the run.
-
Every Shopify public route has its applicable current gate: baseline
parity for compatibility routes;
post-edit-functional-v1, SEO, and accessibility evidence for native routes; and a verified contract for every provider-owned handoff. - Every intentionally retained source route still has a reachable, loop-free origin.
- Customer-account callbacks and required Store API origins contain stable Preview and production HTTPS values.
- The owner approves the current launch candidate, exact DNS change, and tested rollback.
No finite run proves every behavior of an arbitrary storefront. Reports must state the exact routes, states, environments, dependencies, browser conditions, and commerce journeys tested. Missing or unknown evidence fails closed.