Skip to content
← All builds
MB-303SoftwareLive2026

Tensor3D Storefront

A self-hosted e-commerce platform that replaced Shopify for my 3D-printer parts shop. It covers storefront, checkout, oversell protection, shipping labels, admin and analytics, and I migrated in four years of order history.

The Tensor3D storefront home page: "Built for the people who build." with a Voron printer photo.
Fig. 1 · The Tensor3D storefront home page: "Built for the people who build." with a Voron printer photo.

The rule for this build: this is not a Shopify clone. Where a purpose-built approach fits a small parts shop better than Shopify’s conventions, take it.

What it does

  • Storefront: faceted listing, fuzzy search, variant picker, structured data, a slide-out cart and a sitemap.
  • Checkout through Stripe with live carrier rates, optional tax, and discount codes with limits, dates and collection scoping.
  • Oversell protection: stock is held when checkout starts, consumed when payment lands, and released when the session expires. The Stripe session expires at 30 minutes and the hold at 45, so a payment can never land after its hold is gone.
  • Admin: inventory with 30-day sales velocity, days of stock left and margin; a ship queue with a combined pick list; label purchase; refunds; roles; and an audit log.
  • Migration: catalog and order history imported from Shopify, safe to re-run, with original dates and order numbers kept.

Security as a design input

  • Admin exists on one host only. Requests for /admin get a 404 unless they arrive on an allow-listed LAN host, before authentication even runs. Then it needs a role, a check in every action, and an audit entry for every change.
  • Claim the order before spending money. Refunds and label purchases first claim the order row with a conditional update, then call Stripe or Shippo with an idempotency key. That fixed a real double-refund race the audit found.
  • Charge the quote the shopper saw. Carrier rates aren’t deterministic, so the quote is stored against the address for 30 minutes and the client never supplies an amount.
  • The audit’s critical finding: without a .dockerignore, the build step copied the live-key environment file into an intermediate image layer. The final image was clean; the layer wasn’t. Easy to miss, and exactly what a line-by-line review is for.
A product page with specifications and a quantity picker.
Fig. 2Product pages are generated from the catalog, with structured data and a variant or quantity picker.
The slide-out cart with two items and the subtotal.
Fig. 3The slide-out cart. Stock is reserved only once checkout starts, and released if it lapses.