Skip to content

QA runbook: how to verify BloxClips ​

Guide · last verified 2026-09-27. Scope for any given round comes from the linked GitHub issue — this page is the method, not the test plan.

Golden rules ​

  1. Safe checks first. ./scripts/bloxclips-doctor, ./scripts/bloxclips-status --compact, and the repo test suites touch no providers and no production data. Run these freely inside a Treehouse lease.
  2. Provider-capable startup is a separate, authorized step. dev, start, worker, seed/fresh-database, and migrate/deploy commands can reach real databases and providers. Never run them for routine QA, never reset or touch a production or shared database, and never reuse inherited live financial credentials.
  3. No live financial action during tests. Controlled mocks or Whop sandbox only when specifically authorized, with disposable identities and approved provider scope.
  4. Test against staging like production. The current focus is deployment readiness: full-app behavior on staging, as close to production as possible.

The money checklist (every round) ​

Funding and payouts are Whop-only. Verify these invariants, not just the happy path:

  • Canonical flow holds: CampaignInvoice → CampaignFundingReceipt → CampaignFundingAllocation → exactly-once bridge → CampaignFinanceAccount/payout journal. No second funding architecture.
  • Fee policy is explicit: ABSORB behaves as charge_buyer_fee: false, CHARGE_BUYER as true. No hardcoded percentages.
  • CPM depletes client budget; RPM pays creators; rates are versioned and pinned to earning periods.
  • Pending submissions at budget exhaustion are not paid. Paused views are not paid. Top-up and resume open new earning boundaries.

What "done" looks like per area ​

  • Backend: package tests plus the tracking-contract check pass; integration groups run green against isolated disposable databases; no migration without a fresh disposable-database replay and rollback note.
  • Frontend: lint, test, and build pass; auth/error states and access gating verified — backend remains the authorization authority.
  • Scraper: pnpm test, pnpm typecheck, and pnpm build pass; tracking fixture provenance checks match both sides of the backend/scraper contract. Crawlee retries are execution telemetry, not extra scheduled polls — never revive PV Tracker behavior for submission tracking.

Reporting ​

Report what you actually observed at each evidence level: source inspection, automated tests, database integration, browser acceptance, sandbox payment. "Approved design" is not "implemented behavior", and a merged PR alone does not prove acceptance. Unknown provider behavior stays unknown — never infer a fee or substitute an unrelated payment as evidence.