Skip to content

LTRAC-1946: fix(cli) - Correct the managed-zone checkout URL advice - #3240

Merged
jorgemoya merged 4 commits into
canaryfrom
jorgemoya/ltrac-1946-cli-stop-telling-merchants-a-checkout-subdomain-cant-be
Sep 28, 2026
Merged

jorgemoya merged 4 commits into
canaryfrom
jorgemoya/ltrac-1946-cli-stop-telling-merchants-a-checkout-subdomain-cant-be

Conversation

@jorgemoya

@jorgemoya jorgemoya commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Linear: LTRAC-1946

Targets canary. #3243 is stacked on this.

What/Why?

The cross-domain checkout diagnostic told merchants on an auto-generated hostname (<project>.catalyst-sandbox.store) that no checkout URL could ever be set, and sent them to buy a custom domain. That was wrong. It now names the checkout hostname, c.<project>.<zone>, and prints the catalyst channels update --checkout-url command that sets it. Setting the URL is what provisions the hostname.

Worth a look:

  • Managed-zone detection is a fixed zone list. It mirrors ignition's reservedBaseDomainSuffixes. Deriving zones from deployment_hostnames counted merchant domains from catalyst domains add, which appear there too.
  • suggestCheckoutUrl gains a managedZone mode that suggests c. instead of checkout..

Testing

checkout-url, channels and channel-site-flow specs pass; tsc and eslint are clean. New cases cover the printed command, a merchant subdomain not being treated as managed, and the old "cannot be issued a certificate" text not coming back.

Migration

None.

🤖 Generated with Claude Code

@changeset-bot

changeset-bot Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: be6bdeb

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@bigcommerce/catalyst Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
catalyst Ready Ready Preview Sep 28, 2026 8:26pm UTC

Request Review

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Bundle Size Report

Comparing against baseline from f75acc2 (2026-09-28).

No bundle size changes detected.

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Unlighthouse Performance Comparison — Vercel

Comparing PR preview deployment Unlighthouse scores vs production Unlighthouse scores.

Summary Score

Aggregate score across all categories as reported by Unlighthouse.

Prod Desktop Prod Mobile Preview Desktop Preview Mobile
Score 91 94 93 95

Category Scores

Category Prod Desktop Prod Mobile Preview Desktop Preview Mobile
Performance 77 86 72 83
Accessibility 95 98 95 92
Best Practices 100 100 100 100
SEO 88 100 100 100

Core Web Vitals

Metric Prod Desktop Prod Mobile Preview Desktop Preview Mobile
LCP 3.5 s 4.1 s 4.1 s 4.7 s
CLS 0 0 0.039 0
FCP 1.2 s 1.2 s 1.2 s 1.2 s
TBT 0 ms 10 ms 0 ms 10 ms
Max Potential FID 40 ms 60 ms 40 ms 60 ms
Time to Interactive 3.6 s 4.1 s 4.2 s 5.2 s

Full Unlighthouse report →

@jorgemoya
jorgemoya force-pushed the jorgemoya/ltrac-1946-cli-stop-telling-merchants-a-checkout-subdomain-cant-be branch from 75362a0 to 63d7c03 Compare September 24, 2026 15:43
@jorgemoya
jorgemoya changed the base branch from canary to TRAC-1896/fix/cli-pnpm12-dlx-allow-build September 24, 2026 15:45
@jorgemoya
jorgemoya marked this pull request as ready for review September 24, 2026 19:39
@jorgemoya
jorgemoya requested a review from a team as a code owner September 24, 2026 19:39
@jorgemoya
jorgemoya marked this pull request as draft September 24, 2026 19:47
Base automatically changed from TRAC-1896/fix/cli-pnpm12-dlx-allow-build to canary September 24, 2026 20:03
@jorgemoya
jorgemoya marked this pull request as ready for review September 25, 2026 16:15
jorgemoya and others added 4 commits September 28, 2026 15:25
The cross-domain checkout diagnostic told merchants that a storefront on an
auto-generated deployment hostname could never have a checkout URL, because a
checkout subdomain of one "cannot be issued a certificate", and pointed them at
`catalyst domains add` to buy a custom domain instead.

That reasoning is wrong. The auto-generated hostnames are Cloudflare for SaaS
custom hostnames rather than names covered by a single-level wildcard
certificate, and custom hostnames have no label-depth limit — each is issued its
own certificate. The harm was sending merchants to acquire a domain they do not
need.

The diagnostic now names the checkout hostname that will exist and reports it as
not provisioned yet, and no longer recommends adding a custom domain.

`suggestCheckoutUrl` gains a managed-zone mode. It prefixed `checkout.`
unconditionally, naming a hostname nobody will create on a managed zone and
spending nine characters of a 64-character certificate common-name budget the
project name has to share.

Behaviour is otherwise unchanged: a checkout URL is still neither offered nor
suggested on a managed zone, since the hostname is not provisioned yet. Correct
the two comments that justified that guard with the same wrong premise — the
guard matters more than they implied, because BigCommerce would accept such a
URL and leave checkout resolving without a certificate.

Fixes LTRAC-1946
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… hostname

The managed-zone diagnostic said the checkout hostname "isn't provisioned
yet", as if something else would create it later. Testing on integration
showed the checkout-url PUT is itself what provisions it: BigCommerce
registers the hostname with bcserver, which creates the Cloudflare custom
hostname and issues its certificate.

The diagnostic now names the hostname and prints the exact
`channels update --checkout-url` command that sets it. The guards that skip
the generic advice on a managed zone stay; their comments now give the real
reason.

Managed-zone detection now uses the zones native hosting generates
hostnames under, mirroring ignition's reserved suffix list. Deriving zones
from `deployment_hostnames` counted merchant domains added with
`catalyst domains add`, which appear there too, so a merchant's own domain
could be called an auto-generated hostname. The check is now synchronous,
so the "zone unknown" fallback and the projects lookup go away.

Refs LTRAC-1946
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Refs LTRAC-1946
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Refs LTRAC-1946
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@jorgemoya
jorgemoya force-pushed the jorgemoya/ltrac-1946-cli-stop-telling-merchants-a-checkout-subdomain-cant-be branch from 57eeab4 to be6bdeb Compare September 28, 2026 20:25
@jorgemoya
jorgemoya added this pull request to the merge queue Sep 28, 2026
Merged via the queue into canary with commit 55fb9bc Sep 28, 2026
17 of 18 checks passed
@jorgemoya
jorgemoya deleted the jorgemoya/ltrac-1946-cli-stop-telling-merchants-a-checkout-subdomain-cant-be branch September 28, 2026 20:55

This branch was successfully deployed

1 active deployment
Preview — be6bdebb Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants