Next.js 网店套件:商品目录、购物车、Stripe 结账、订单、配送、优惠券、真实评价和账户
代码27 个文件上下文约 1024 个 token扫描通过
安装
$
genpm add @core/kit-store你将获得
- 源代码位于 src/app/(store)/,共 27 个文件。 (57.2 kB)
- AI 规则位于 src/app/(store)/AGENTS.md,另附 IDE 规则文件。
- 添加到 .env.example 的环境变量:STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, CART_COOKIE_SECRET, ORDER_LINK_SECRET, STORE_CURRENCY。
- 自动为你解析 @core/cart, @core/catalog, @core/checkout, @core/discounts, @core/kit-cms, @core/orders, @core/reviews, @core/shipping。
README
此包没有 README。
约 1024 个 token→ src/app/(store)/AGENTS.md→ .cursor/rules/genpm-core-kit-store.mdc
这正是你的 AI 在 src/app/(store) 中工作时读取的内容。不会向其上下文添加其他任何内容。
@core/kit-store — rules for AI agents
Purpose
An online store on top of @core/kit-cms, managed from the same /admin: products with variants and categories,
cart, Stripe Checkout, orders (created only by the Stripe webhook), shipping zones and rates, discount codes,
verified reviews, customer orders page, transactional emails and SEO (Product JSON-LD, sitemap). Every storefront
form is a Next.js Server Action, so it works without JavaScript and never accepts prices from the browser.
Map
_templates/genpm.md— the exact lines this kit adds to the project'ssrc/genpm/*.ts(generated, always current)._lib/maintenance.ts— dailystore.maintenancejob (deletes expired carts).shop/page.tsx,categories/[slug],collections/[slug]— listings.products/[slug]/page.tsx— product page.cart/page.tsx— cart, discount code, shipping country/method, totals and payment.checkout/success— real status.orders/[number]/page.tsx— order for its owner or with the signed email link.account/page.tsx— customer orders.api/stripe/webhook/route.ts— Stripe webhook (@core/stripe)._lib/actions.ts— server actions (add, update, code, shipping, checkout, review)._lib/store.ts— helpers._components/— product card/grid, add to cart,CartLinkfor the header, reviews, order summary,store.css._blocks/products.tsx— "Product grid" and "Buy now" blocks._lib/widgets.ts— sales, orders to ship, low stock._lib/legal.ts+_scripts/seed-legal.ts— legal pages as drafts pending review, with a dashboard warning.
Integration
- @core/kit-cms must be integrated first.
- Env:
STRIPE_SECRET_KEY,STRIPE_WEBHOOK_SECRET,CART_COOKIE_SECRETandORDER_LINK_SECRET(≥ 32 chars),STORE_CURRENCY(e.g.EUR),SITE_URL,EMAIL_FROM. Use Stripe test mode until the end-to-end check passes. If the Stripe MCP server is available and the person agrees, use it to inspect the test account (never live keys). - Migrations for catalog, cart, checkout, orders, shipping, discounts, reviews, comments and stripe.
- Add every line of
_templates/genpm.mdto the project'ssrc/genpm/*.ts(it says which file and where): it createssrc/genpm/commerce.ts(imports that register webhooks, cart steps and the dailystore.maintenancejob), the product sitemap and search sources, theproductGrid/buyNowblocks, and the admin resources and widgets (including comments, where product reviews are moderated). Then run the kit-cmssetup-schedules.tsagain. - Stripe webhook: endpoint
https://<site>/api/stripe/webhookwithcheckout.session.completed,checkout.session.async_payment_succeededandcheckout.session.expired(refunds are started from the admin); locallystripe listen --forward-to localhost:3000/api/stripe/webhook. - Create shipping zones and rates in the admin; put
<CartLink />in the site header and "Shop" in the menu. - The person runs
npx tsx "src/app/(store)/_scripts/seed-legal.ts": terms, shipping, returns/withdrawal, privacy and cookies are created as drafts. They must complete them and have them reviewed before publishing. - Verify in test mode: buy with card 4242 4242 4242 4242, the webhook creates the order, the email arrives, stock decreases, the order page opens from the email link and not without it.
Conventions
- Prices are integers in minor units; the client only sends variant ids, quantities, codes and the shipping choice.
- Orders exist only after Stripe confirms payment (webhook), never from the success page.
- The "before" price is hidden: in the EU it must be the lowest price of the previous 30 days (Omnibus directive).
With @core/pricing installed, show it only through
honestCompareAt.
Don't
- Don't publish legal pages the person has not reviewed, and never present generated legal text as final.
- Don't show fake reviews, ratings, stock counts or countdowns; review JSON-LD only with real approved reviews.
- Don't expose order pages without the owner session or the signed token; don't put tokens in analytics.
# @core/kit-store — rules for AI agents
## Purpose
An online store on top of @core/kit-cms, managed from the same `/admin`: products with variants and categories,
cart, Stripe Checkout, orders (created only by the Stripe webhook), shipping zones and rates, discount codes,
verified reviews, customer orders page, transactional emails and SEO (Product JSON-LD, sitemap). Every storefront
form is a Next.js Server Action, so it works without JavaScript and never accepts prices from the browser.
## Map
- `_templates/genpm.md` — the exact lines this kit adds to the project's `src/genpm/*.ts` (generated, always current).
- `_lib/maintenance.ts` — daily `store.maintenance` job (deletes expired carts).
- `shop/page.tsx`, `categories/[slug]`, `collections/[slug]` — listings. `products/[slug]/page.tsx` — product page.
- `cart/page.tsx` — cart, discount code, shipping country/method, totals and payment. `checkout/success` — real status.
- `orders/[number]/page.tsx` — order for its owner or with the signed email link. `account/page.tsx` — customer orders.
- `api/stripe/webhook/route.ts` — Stripe webhook (@core/stripe).
- `_lib/actions.ts` — server actions (add, update, code, shipping, checkout, review). `_lib/store.ts` — helpers.
- `_components/` — product card/grid, add to cart, `CartLink` for the header, reviews, order summary, `store.css`.
- `_blocks/products.tsx` — "Product grid" and "Buy now" blocks. `_lib/widgets.ts` — sales, orders to ship, low stock.
- `_lib/legal.ts` + `_scripts/seed-legal.ts` — legal pages as drafts pending review, with a dashboard warning.
## Integration
1. @core/kit-cms must be integrated first.
2. Env: `STRIPE_SECRET_KEY`, `STRIPE_WEBHOOK_SECRET`, `CART_COOKIE_SECRET` and `ORDER_LINK_SECRET` (≥ 32 chars),
`STORE_CURRENCY` (e.g. `EUR`), `SITE_URL`, `EMAIL_FROM`. Use Stripe test mode until the end-to-end check passes.
If the Stripe MCP server is available and the person agrees, use it to inspect the test account (never live keys).
3. Migrations for catalog, cart, checkout, orders, shipping, discounts, reviews, comments and stripe.
4. Add every line of `_templates/genpm.md` to the project's `src/genpm/*.ts` (it says which file and where): it creates
`src/genpm/commerce.ts` (imports that register webhooks, cart steps and the daily `store.maintenance` job), the
product sitemap and search sources, the `productGrid` / `buyNow` blocks, and the admin resources and widgets
(including comments, where product reviews are moderated). Then run the kit-cms `setup-schedules.ts` again.
5. Stripe webhook: endpoint `https://<site>/api/stripe/webhook` with `checkout.session.completed`,
`checkout.session.async_payment_succeeded` and `checkout.session.expired` (refunds are started from the admin); locally `stripe listen --forward-to localhost:3000/api/stripe/webhook`.
6. Create shipping zones and rates in the admin; put `<CartLink />` in the site header and "Shop" in the menu.
7. The person runs `npx tsx "src/app/(store)/_scripts/seed-legal.ts"`: terms, shipping, returns/withdrawal, privacy
and cookies are created as drafts. They must complete them and have them reviewed before publishing.
8. Verify in test mode: buy with card 4242 4242 4242 4242, the webhook creates the order, the email arrives, stock
decreases, the order page opens from the email link and not without it.
## Conventions
- Prices are integers in minor units; the client only sends variant ids, quantities, codes and the shipping choice.
- Orders exist only after Stripe confirms payment (webhook), never from the success page.
- The "before" price is hidden: in the EU it must be the lowest price of the previous 30 days (Omnibus directive).
With @core/pricing installed, show it only through `honestCompareAt`.
## Don't
- Don't publish legal pages the person has not reviewed, and never present generated legal text as final.
- Don't show fake reviews, ratings, stock counts or countdowns; review JSON-LD only with real approved reviews.
- Don't expose order pages without the owner session or the signed token; don't put tokens in analytics.
应用 .genpmignore 后将被注入的确切目录树。固定于
// Páginas legales de comercio electrónico como BORRADORES con la estructura habitual y un aviso de revisión.
// Nunca se publican solas ni contienen texto legal inventado: el titular las completa y revisa con un profesional.
import { createEntry } from '@/lib/content';
import { getDb } from '@/lib/db';
import type { AdminWidget } from '@/lib/admin';
import { contentEntries } from '@/lib/content';
import { and, eq, inArray, ne } from 'drizzle-orm';
export const LEGAL_PAGES = [
{ slug: 'terms', title: 'Terms of sale', sections: ['Seller identification', 'Products and prices (taxes included)', 'Ordering process', 'Payment', 'Delivery', 'Right of withdrawal', 'Legal guarantee (2 years in the EU)', 'Complaints and online dispute resolution', 'Applicable law'] },
{ slug: 'shipping', title: 'Shipping', sections: ['Destinations', 'Costs', 'Delivery times', 'Tracking', 'Failed deliveries'] },
{ slug: 'returns', title: 'Returns and withdrawal', sections: ['14-day right of withdrawal (EU consumers)', 'How to withdraw (model withdrawal form)', 'Return costs', 'Refund timing and method', 'Exceptions'] },
{ slug: 'privacy', title: 'Privacy policy', sections: ['Controller', 'Data we collect and why', 'Legal basis', 'Recipients (payments, shipping, email, analytics)', 'International transfers', 'Retention', 'Your rights', 'Contact'] },
{ slug: 'cookies', title: 'Cookie policy', sections: ['What cookies are', 'Cookies we use (necessary, analytics, marketing)', 'How to change your choice'] },
] as const;
const doc = (sections: readonly string[]) => ({
type: 'doc',
content: [
{ type: 'paragraph', content: [{ type: 'text', marks: [{ type: 'bold' }], text: 'PENDING REVIEW: this page is a template. Complete it with your real details and have it reviewed by a legal professional before publishing.' }] },
...sections.flatMap((s) => [
{ type: 'heading', attrs: { level: 2 }, content: [{ type: 'text', text: s }] },
{ type: 'paragraph', content: [{ type: 'text', text: '[To be completed]' }] },
]),
],
});
/** Crea las páginas legales que falten como BORRADORES (nunca publica; `seedEntry` sí lo haría). Idempotente. */
export async function seedLegalPages(): Promise<string[]> {
const created: string[] = [];
for (const p of LEGAL_PAGES) {
const [existing] = await getDb()
.select({ id: contentEntries.id })
.from(contentEntries)
.where(and(eq(contentEntries.collection, 'pages'), eq(contentEntries.slug, p.slug)));
if (existing) continue;
await createEntry({ collection: 'pages', slug: p.slug, data: { title: p.title, blocks: [{ id: 'legal', type: 'rich-text', data: { doc: doc(p.sections), width: 'narrow' } }], seo: { noindex: true } } });
created.push(p.slug);
}
return created;
}
/** Aviso del panel mientras alguna página legal siga sin publicar (= sin revisar). */
export const legalPagesWidget: AdminWidget = {
name: 'legal-pending',
title: 'Legal pages pending review',
permission: 'pages:read',
async load() {
const rows = await getDb()
.select({ slug: contentEntries.slug, id: contentEntries.id })
.from(contentEntries)
.where(and(eq(contentEntries.collection, 'pages'), inArray(contentEntries.slug, LEGAL_PAGES.map((p) => p.slug)), ne(contentEntries.status, 'published')));
return { rows: rows.map((r) => ({ label: `/${r.slug}`, value: 'draft', href: `/admin/pages/${r.id}` })) };
},
};
此包未声明 MCP 服务器。
| 版本 | 提交 | 发布时间 | 扫描 |
|---|---|---|---|
| 1.0.1 | 6a45dae | 3小时前 | 扫描通过 |
- 扫描
- 扫描通过 · 0 个问题
- 提交
- v1.0.1 → 6a45dae248ce17fbd95b5f3b2b61c68f66236041 · 获取后已校验
- 脚本
- 无。GenPM 从不运行包中的代码。
- 许可证
- MIT
- 质量
- 100/100
- 可识别的许可证已满足
- AGENTS.md 说明了用途已满足
- AGENTS.md 包含集成步骤已满足
- AGENTS.md 列出约定或禁止事项已满足
- 包含测试已满足
- 通过安全扫描已满足
- 最近 6 个月内发布已满足
- 已验证的发布者已满足
- 摘要和关键词已满足
- 举报
- 发现问题了吗?