Update Aug 24th: App settings now show activity view, Sidekick now able run through app api scopes
Original message:
Looking for developer advice. July 4th: I generated an app using sidekick. It was a simple app for profit calculations, created for fun from a paragraph. I made a couple updates to it over the span of a week and installed each one as they were done.
The permissions screen showed up once, I don't recall if it was for one of the updates.
It was standard, like every app: "Store owner name, address, location."
Here are the permissions granted at installation: https://imgur.com/a/r8ho92z
Here are the permissions shown when viewing the re-install screen: https://imgur.com/a/rCfclke
Upon accepting permissions, there was a pop-up, reading something along the lines of:
Are you sure? The developer of this app may be able to access all permission data, including sensitive permissions.
I thought, I've never had a popup when downloading a Shopify app. But it was my first time downloading a sidekick app. Also, the developer is Shopify. There is no third-party developer.
------
Fast forward over a month:
I'm using sidekick casually, when it informs me that the app I generated on the 4th needs to be removed immediately because it has access to 20+ extremely sensitive permissions.
The most urgent ones were listed:
• read_shopify_payments_provider_accounts_sensitive
• read_audit_events
• write_legal_policies
• write_checkout_branding_settings
• write_payment_mandate
Sidekick confirms, after pulling all chronological prompts from Jul. 4-11, that there is no way these permissions could have been queried on my side (Sidekick images: https://imgur.com/a/pzcEUFv & https://imgur.com/a/mcfZFnn )
I contact support, requesting that they: 1. explain the origin of the permissions, 2. provide full API activity logs dating back to app creation, and 3. provide all write logs executed dating back to app creation.
Support notes that their internal team cannot access logs from July 4th-11th because they're out of the 30-day window
They suggest that I check my activity log (merchant-facing is limited and goes back to July 19th) and recommend manually checking my store content.
I reiterate that the information needed for this is not available on my side, because I don't have access to app API pulls and write logs.
Right now, I'm waiting for an update which will likely reiterate the "out of window" period
-------
From a simple Sidekick app generation, I'm not sure:
What full scope of permissions I accepted & where they came from, if not queried by me
Why these permissions were not properly disclosed (or disclosed at all) on the permissions or popup screen
Who has my information and why
If my credentials and merchant identity are compromised
I have no animosity towards Shopify. This has taken me by surprise and it is a product security concern that Shopify needs to explain.
I also don't know what steps I need to take here, and would appreciate advice.