Skip to content

Etsy setup: catch wrong app keys at setup, not at the first call - #881

Merged
keysersoft merged 2 commits into
mainfrom
keysersoft/etsy-setup-checks
Oct 5, 2026
Merged

keysersoft merged 2 commits into
mainfrom
keysersoft/etsy-setup-checks

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

From the weekly stuck-users report (5 Oct): the Etsy failures after the 3 Oct deploy are wrong app keys, not a bug in the request.

Case Shared secret stored Etsy's answer
A 24 chars (the keystring again) Invalid API credentials… shared secret is missing
B 52 chars with a colon (keystring:secret) Invalid API key: should be in the format 'keystring:shared_secret'
C 10 chars, fine token lacks scope shops_r (their Etsy app)

The sign-in succeeded for all three: Etsy's token exchange does not check the shared secret, so the setup said "is ready" and the first call failed.

Changes

  • After the sign-in: the setup page already ran the connector test (Etsy: /openapi-ping with x-api-key), but ignored its result. An auth_failed now sends the user back to the keys with Etsy's message instead of "is ready".
  • Patterns: Keystring ^[a-z0-9]{20,30}$, Shared secret ^[a-z0-9]{8,32}$, each with a message on what to paste. Checked against production (shapes only): working connectors all have a 24-char lowercase keystring and a 10- or 25-char lowercase secret; no value with a colon, space or other symbol ever worked.
  • envVarMeta.patternMessage (validator updated); settings passed from the chat via setup_install_connector are checked against the pattern too.

Tests

  • Backend 6660 passed (new: pattern refused from the chat).
  • Frontend e2e 105 passed (new: wrong keys after sign-in go back to the form; pattern message shown).

Etsy's sign-in succeeds with a wrong shared secret (its token exchange
does not use it), so the guided setup said "is ready" and every call then
failed with 403. Seen in the weekly stuck-users report: a secret pasted
as "keystring:secret", the keystring pasted twice.

- After the sign-in, the setup page already called the connector test;
  a refusal (auth_failed) now sends the user back to the keys with the
  provider's message instead of "is ready".
- Etsy's Keystring and Shared secret get a pattern and a message saying
  what to paste (lowercase letters and digits, no colon). Checked against
  production: every working Etsy connector has a 24-character keystring
  and a 10- or 25-character secret; no value with a colon or space ever
  worked.
- envVarMeta gains patternMessage; settings passed from the chat
  (setup_install_connector) are checked against the pattern too.
@keysersoft
keysersoft enabled auto-merge (squash) October 5, 2026 11:41
@keysersoft
keysersoft merged commit ae223b6 into main Oct 5, 2026
13 checks passed
@keysersoft
keysersoft deleted the keysersoft/etsy-setup-checks branch October 5, 2026 11:44
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 5, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant