Launch of the S3 Store Development Process #20
fthobe
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Introduction into S3-Store
A project to render Solidus EU compliant and fully functional as a standalone web shop.
Introduction
The S3 Project was born out of the necessity to have a variable web store. During our research process several solutions were discarded in favour of a fork of Solidus / Spree, below a summary of our findings:
As written in the first paragraph we decided to go with Solidus.
Capabilities and Limitations of Solidus
Features
Solidus historically derives from Spree and was hard forked in mid 2010s.
Solidus inherited many logics that made it immedietly attractive for us such as:
A very robust and variable implementation of Categories called Taxonomies are present and Solidus comes with a very variable tax logic and pricing logic that has proven over the past few months to be very easy to adjust.
It has to be said that the entire system is very US centric in sense that functionalities work very well on the American market but need adjustments for the European market.
Limitations of Solidus
Tax Model
The entire tax model works in Europe for a Direct to Consumer webshop. There are significant features lacking though for a B2B shop:
Hereby it's important to notice that significant progress has been made and that the logic for taxes was robust enough to easily integrate the features. Pricelists and groups will probably be released in the first half of April 2025 allowing to proceed with net and gross pricing.
Localisation
Solidus comes with basic translation models for the interface derived from i18. There's no support for more sophisticated content strategies though inside the core. When we started the work most of the extensions where broken, we have brought them into a working state by now.
Marketing Integrations
GDPR
Solidus lacks core functionalities regarding GDPR.
Following features need to be implemented:
* Addresses are currently not deletable which is violation of GDPR. While not problematic in the US, this is a challenging situation in Europe.
Security
Solidus has a very solid user system derived from Devise, there are some issues attached to it though:
There's no separation of Admin and user accounts making features like user impersonation complex and Devise is not maintained anymore beyond security updates. The current configuration does not allow an effective way to reach PCI compliance as features are missing:
Some of those features can be achieved via alternative ways, we have fixed:
They all allow MFA, allowing effectively MFA by enforcement of social auth.
Desired Outcome
The outcome is to model and implement all features above and integrate them into the core of the S3_Store with the goal of having a fully functional system.
Beta Was this translation helpful? Give feedback.
All reactions