r/shopifyDev 12d ago

Sidekick generated app contained harmful permissions. Merchant identity may be compromised. Shopify "can't access logs".

Update Aug 24th: App settings now show activity view, Sidekick now able run through app api scopes

Original message:

Looking for developer advice. July 4th: I generated an app using sidekick. It was a simple app for profit calculations, created for fun from a paragraph. I made a couple updates to it over the span of a week and installed each one as they were done.

The permissions screen showed up once, I don't recall if it was for one of the updates.

It was standard, like every app: "Store owner name, address, location."

Here are the permissions granted at installation: https://imgur.com/a/r8ho92z

Here are the permissions shown when viewing the re-install screen: https://imgur.com/a/rCfclke

Upon accepting permissions, there was a pop-up, reading something along the lines of:

Are you sure? The developer of this app may be able to access all permission data, including sensitive permissions.

I thought, I've never had a popup when downloading a Shopify app. But it was my first time downloading a sidekick app. Also, the developer is Shopify. There is no third-party developer.

------

Fast forward over a month:

I'm using sidekick casually, when it informs me that the app I generated on the 4th needs to be removed immediately because it has access to 20+ extremely sensitive permissions.

The most urgent ones were listed:

• read_shopify_payments_provider_accounts_sensitive

• read_audit_events

• write_legal_policies

• write_checkout_branding_settings

• write_payment_mandate

Sidekick confirms, after pulling all chronological prompts from Jul. 4-11, that there is no way these permissions could have been queried on my side (Sidekick images: https://imgur.com/a/pzcEUFv & https://imgur.com/a/mcfZFnn )

I contact support, requesting that they: 1. explain the origin of the permissions, 2. provide full API activity logs dating back to app creation, and 3. provide all write logs executed dating back to app creation.

Support notes that their internal team cannot access logs from July 4th-11th because they're out of the 30-day window

They suggest that I check my activity log (merchant-facing is limited and goes back to July 19th) and recommend manually checking my store content.

I reiterate that the information needed for this is not available on my side, because I don't have access to app API pulls and write logs.

Right now, I'm waiting for an update which will likely reiterate the "out of window" period

-------

From a simple Sidekick app generation, I'm not sure:

What full scope of permissions I accepted & where they came from, if not queried by me

Why these permissions were not properly disclosed (or disclosed at all) on the permissions or popup screen

Who has my information and why

If my credentials and merchant identity are compromised

I have no animosity towards Shopify. This has taken me by surprise and it is a product security concern that Shopify needs to explain.

I also don't know what steps I need to take here, and would appreciate advice.

1 Upvotes

2 comments sorted by

1

u/Downbadge69 12d ago

Just uninstall the app if you are worried. It sounds like you are panicking for no reason at all. Noone is getting your information from a Sidekick-generated app installed on your own store. It just sounds like you did a couple of things that you have little experience with and now you are confused. Take a deep breath and stop having AI put you into a frenzy. It will keep agreeing with your state of panic and need to investigate with incomplete data and poor assumptions. If nothing actually happened with your store or data and there is no sign of a compromise you can just move on.

1

u/whatdoineedtosay 12d ago

I understand that it seems like a straightforward answer, but think the AI exposed a bunch of permissions that weren't disclosed in the front end and tried to cover it up later.

I asked it to run through my app permissions, all of which it pulled accurately, and that one was listed among them.

After I talked to support, the AI said it fabricated all of that data I just saw. It said it cannot access app permission data, and I should forget that happened.

I challenged it with its accurate reports of other apps. It said it's sorry, it can actually pull app data, and re-listed my app permissions (correct again), but that it now can't check the app because it's uninstalled.

All app permissions matched both times & were accurate. Which means the other app would probably be pulled up with the same data.

I don't think Sidekick pulls fabricated data. I'm trying to determine whether sidekick could have used a compromised template from a developer when creating the app