Multi-tenancy
The shop API served one merchant per deployment, so each merchant’s data was in a separate system. On Shopend, every shop’s data is in the same system. Suppose a clothing business opens a shop called threadline. The mug merchant must not be able to change the prices in threadline. The server has to enforce that.
Serving many merchants from one running system, while keeping each merchant’s data separate, is called multi-tenancy. Each merchant is a tenant.
Multi-tenancy affects authorization. A merchant’s role now applies within a shop. The mug merchant holds the merchant role in mugshop and no role in threadline, so a mutation sent to /shops/threadline/graphql that changes a product fails the role check. The server responds with FORBIDDEN.
Ownership now includes the shop. Every product, cart, and order stores the shop it belongs to, and the data access code looks up each one by its identifier and the shop in the request’s path. If the mug merchant sends a mutation to /shops/mugshop/graphql that changes a product belonging to threadline, the lookup finds nothing. The server responds with NOT_FOUND.
We also have to decide whether a shopper account works at one shop or at every shop on Shopend. I decided that it belongs to one shop. A shopper creates an account at a merchant’s storefront, so the shopper is that merchant’s customer, and their carts and orders belong to that shop. An account at mugshop has no meaning at threadline, and a person who buys from both shops has two accounts. The other option is one Shopend account that works at every shop. It is convenient for a person who buys from many shops, but then one shopper’s data would be spread across many shops.
The performance, correctness, reliability, and availability targets apply to every shop. A shop’s requests must meet them even when another shop is busy with a sale. The load assumption was about 500 products and 200 orders a day. That assumption describes one merchant. Shopend holds the products and orders of every shop, so the assumption does not hold for Shopend.