Grants read their own orders

API

Three fixes from developer feedback, plus build time guidance on the Carts page.

What changed

  • A build grant reads its own orders. GET /v1/orders/:id with a build grant used to answer 403. It now returns the order when a build grant from your application built it for that same person, in the same environment. Any other order, including one another application built or one built for another person, is a 404, the same answer as an order that does not exist. See GET /v1/orders/:id.
  • whoami lists each scope once. With your application secret, GET /v1/whoami returned order_status beside order:status. scopes is now ["order:preview", "order:build", "order:status", "places"]. See GET /v1/whoami.
  • A fired test webhook names its order. POST /v1/sandbox/webhooks/fire with an orderId sends that sandbox order's real id, store, item count and total, still with "test": true. The response now carries order, the id, state and store the event described, so you can see which order was sent. An orderId that is not one of your application's sandbox orders is still a 404. See Fire a test webhook.
  • How long a build takes. The Carts page now gives typical build times and how to poll: every 2 to 3 seconds, and stop holding the person after about 4 minutes. See How long a build takes.

Breaking changes

None. If your code looked for the bare order_status string in scopes, look for order:status instead.

All changes