Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Editor configuration, see https://editorconfig.org
root = true

[*]
charset = utf-8
indent_style = space
indent_size = 2
insert_final_newline = true
trim_trailing_whitespace = true

[*.ts]
quote_type = single
ij_typescript_use_double_quotes = false

[*.md]
max_line_length = off
trim_trailing_whitespace = false
9 changes: 9 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# Copy to .env (gitignored) and fill in your own stack's values for local dev.
# On a hosting platform, set these as real environment variables instead —
# no .env file needed there.

CS_API_KEY=<STACK_API_KEY>
CS_DELIVERY_TOKEN=<DELIVERY_TOKEN>
CS_ENVIRONMENT=development
CS_REGION=US
CS_LIVE_PREVIEW=false
6 changes: 1 addition & 5 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,7 +1,3 @@
* @contentstack/marketplace-pr-reviewers

.github/workflows/sca-scan.yml @contentstack/security-admin

.github/workflows/ @contentstack/security-admin
**/.snyk @contentstack/security-admin

.github/workflows/policy-scan.yml @contentstack/security-admin
57 changes: 57 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
# See https://docs.github.com/get-started/getting-started-with-git/ignoring-files for more about ignoring files.

# Compiled output
/dist
/tmp
/out-tsc
/bazel-out

# Node
/node_modules
npm-debug.log
yarn-error.log

# IDEs and editors
.idea/
.project
.classpath
.c9/
*.launch
.settings/
*.sublime-workspace

# Visual Studio Code
.vscode/*
!.vscode/settings.json
!.vscode/tasks.json
!.vscode/launch.json
!.vscode/extensions.json
!.vscode/mcp.json
.history/*

# Miscellaneous
/.angular/cache
.sass-cache/
/connect.lock
/coverage
/libpeerconnection.log
testem.log
/typings
__screenshots__/

# Playwright
/test-results/
/playwright-report/
/blob-report/
/playwright/.cache/

# System files
.DS_Store
Thumbs.db
.npmrc

# Contentstack credentials (real values) — never commit; use the .example.ts template
src/environments/contentstack.environment.ts
.env
.env.local
.env.*.local
12 changes: 12 additions & 0 deletions .prettierrc
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
{
"printWidth": 100,
"singleQuote": true,
"overrides": [
{
"files": "*.html",
"options": {
"parser": "angular"
}
}
]
}
4 changes: 4 additions & 0 deletions .vscode/extensions.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
{
// For more information, visit: https://go.microsoft.com/fwlink/?linkid=827846
"recommendations": ["angular.ng-template"]
}
20 changes: 20 additions & 0 deletions .vscode/launch.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
{
// For more information, visit: https://go.microsoft.com/fwlink/?linkid=830387
"version": "0.2.0",
"configurations": [
{
"name": "ng serve",
"type": "chrome",
"request": "launch",
"preLaunchTask": "npm: start",
"url": "http://localhost:4200/"
},
{
"name": "ng test",
"type": "chrome",
"request": "launch",
"preLaunchTask": "npm: test",
"url": "http://localhost:9876/debug.html"
}
]
}
9 changes: 9 additions & 0 deletions .vscode/mcp.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
// For more information, visit: https://angular.dev/ai/mcp
"servers": {
"angular-cli": {
"command": "npx",
"args": ["-y", "@angular/cli", "mcp"]
}
}
}
42 changes: 42 additions & 0 deletions .vscode/tasks.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
// For more information, visit: https://go.microsoft.com/fwlink/?LinkId=733558
"version": "2.0.0",
"tasks": [
{
"type": "npm",
"script": "start",
"isBackground": true,
"problemMatcher": {
"owner": "typescript",
"pattern": "$tsc",
"background": {
"activeOnStart": true,
"beginsPattern": {
"regexp": "Changes detected"
},
"endsPattern": {
"regexp": "bundle generation (complete|failed)"
}
}
}
},
{
"type": "npm",
"script": "test",
"isBackground": true,
"problemMatcher": {
"owner": "typescript",
"pattern": "$tsc",
"background": {
"activeOnStart": true,
"beginsPattern": {
"regexp": "Changes detected"
},
"endsPattern": {
"regexp": "bundle generation (complete|failed)"
}
}
}
}
]
}
21 changes: 21 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright (c) 2026 Contentstack

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
75 changes: 74 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
@@ -1 +1,74 @@
# contentstack-spartacus-ecommerce-demo
# SAP Composable Storefront (Spartacus) + Contentstack — Electronics Demo

A B2C electronics storefront built with **Angular 21** and **SAP Composable Storefront
(Spartacus `221121.15.1`)**, using the
[`@contentstack/contentstack-spartacus-connector`](https://github.com/contentstack/contentstack-spartacus-connector)
to drive its CMS layer from **Contentstack**.

Commerce data (products, pricing, cart, checkout) comes from a SAP Commerce Cloud (OCC) backend;
page content — the homepage, navigation, footer, and marketing slots — comes from Contentstack,
rendered as a hybrid over the OCC base (unauthored pages/slots fall back to OCC automatically).

## Prerequisites

| Requirement | Notes |
| --- | --- |
| Node.js | `^22.22.0` (older 22.x prints non-fatal `EBADENGINE` warnings) |
| Angular CLI 21 | `npx -p @angular/cli@21 ng ...` — no global install required |
| SAP RBSC registry access | Needed to install `@spartacus/*` packages — see below |
| A Contentstack stack | Delivery token + API key (read-only) |

### RBSC `.npmrc`

`@spartacus/*` packages are served from SAP's RBSC registry, not public npm. Create a `.npmrc` in
the project root:

```ini
@spartacus:registry=https://<YOUR_RBSC_REGISTRY_HOST>/
//<YOUR_RBSC_REGISTRY_HOST>/:_auth=<YOUR_RBSC_BASE64_AUTH>
legacy-peer-deps=true
```

This file is gitignored — it holds an organization credential and must never be committed.

## Setup

```bash
npm install
cp .env.example .env
# fill in your Contentstack stack's CS_API_KEY / CS_DELIVERY_TOKEN in .env
npm start
```

`npm start` (and `npm run build`) automatically generate
`src/environments/contentstack.environment.ts` from your `.env` via
`scripts/generate-contentstack-env.js` — that generated file is gitignored too, so nothing
credential-bearing ever needs to live in source control. See `.env.example` for all supported
variables.

On a hosting platform, set the same variables (`CS_API_KEY`, `CS_DELIVERY_TOKEN`, `CS_ENVIRONMENT`,
`CS_REGION`, `CS_LIVE_PREVIEW`) as real environment variables instead of a `.env` file — the
generator script reads `process.env` either way.

## Development server

```bash
ng serve
```

Then open `http://localhost:4200/`.

## Build

```bash
ng build
```

Build artifacts are written to `dist/`.

## Notes on credentials

`CS_API_KEY`/`CS_DELIVERY_TOKEN` are **read-only, environment-scoped Contentstack Delivery API
tokens** — safe to ship in the client bundle (they can only read already-published content, not
write or delete). They are kept out of git history for portability/rotation hygiene, not because
they're a runtime secret.
48 changes: 48 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
# Security Policy

## Reporting a vulnerability

If you discover a security vulnerability in this project, please report it
responsibly. **Do not open a public GitHub issue for security reports.**

- Email **security@contentstack.com** with a description of the issue, the
affected version, and steps to reproduce.
- You will receive an acknowledgement, and we will keep you informed as we
investigate and remediate.
- Please give us a reasonable period to address the issue before any public
disclosure.

## Supported versions

This is a reference/demo application tracked on its `main` branch. Security
fixes are applied to `main`; there are no separate maintained release lines.

## Security model of this application

This is a demo storefront (Angular + SAP Composable Storefront / Spartacus)
using [`@contentstack/contentstack-spartacus-connector`](https://github.com/contentstack/contentstack-spartacus-connector)
to source CMS content from Contentstack, alongside a SAP Commerce Cloud (OCC)
backend for commerce data.

### Two-token model — never ship a privileged token

- The storefront uses only a **read-only Contentstack delivery token** (scoped
to a single environment). It is designed to be present in the client bundle.
- A Contentstack **management token** is never used or stored by this
application. Content modeling/seeding is a separate, one-time, dev-machine
operation and is out of scope for this repository.

### Live Preview

- The **preview token** is only required when Live Preview / Visual Builder is
enabled. This demo ships with Live Preview disabled by default.

### Secrets in configuration

- Real credentials belong in environment variables, not in source. See
`.env.example` and `scripts/generate-contentstack-env.js` —
`src/environments/contentstack.environment.ts` is generated at build time
from `CS_API_KEY`/`CS_DELIVERY_TOKEN`/etc. and is gitignored, so no
credential-bearing file is committed to this repository.
- No management tokens, API secrets, or private keys are stored in this
repository.
Loading
Loading