Skip to content

Acceptance and regression verification ​

This separates audit evidence from tests the migration must pass. No migration code exists in this package.

Final review adds binding tests below and 11. Counts/checks reported by this audit do not mean the future mixed dev+redesign implementation has passed.

Adversarial acceptance additions ​

  • Load product tokens before marketing creator proof and then reverse order, without full reload. Marketing uses no cr-* classes/keyframes; computed product .cr-card and marketing proof border/radius/background/fonts are invariant under ordering. Inspect native controls, scroll and marketing dialogs/portals. Product visual primitives unchanged.
  • Test no-JS and hydration delay: marketing content readable before reveal initialization; no hidden-mobile phone downloads; switching reduced motion stops/restarts only owned effects and removes scroll markers.
  • Careers dialog: active focus starts inside, Tab/Shift-Tab cycle, Escape restores trigger, background inert, close reachable at narrow/short viewport even with cookie UI. Product OverlayPortal and ConfirmModal unchanged.
  • Intermediate A–G checkpoints compile; no unresolved StartLink/creator constants imports, duplicate Navbar, dead new routes, stale book-call layout metadata, or half-enabled creator action. Final E activates all acquisition links atomically.
  • /book-call?a=1&a=2 returns307 to fixed /contact?a=1&a=2; malicious redirect-like query cannot change destination. Query not sent to Calendly. No new catch-all/proxy; unknown URL retains dev404; bad case/guide slug returns branded noindex404.
  • Creator four-config matrix: all absent, partial delivery config, valid delivery+absent invite, both configured. Mock provider only. No config means zero delivery calls, local-mode disclosure, learning-track completion, unavailable private destination with separate Whop alternative. Configured action rejects oversized/unknown answers, recomputes track, verifies token and bounds outbound timeout. NEXT_PUBLIC invite never represented as secret authorization.
  • Telemetry: both SDK handlers receive current-report/ordinary-event and ordinary-location/report-event cases; each returns null. Normal nonreport event remains unchanged. Do not assert consent enforcement or invoice filtering absent from current code.
  • Marketing metadata does not change login/product/token defaults. Root font/html/provider snapshot unchanged except explicit JSON-LD IDs. MARKETING_INDEXABLE unset/false yields empty sitemap/noindex; true yields22 approved public URLs. All private routes stay excluded regardless of flag.
  • Apply11§6 copy substitutions in visible text, schema, metadata and llms. Date relative claims. Legal prose/effective date stays dev; published claims/assets require O2 approval, missing Discord launch setting uses O1 safe default.
  • Secondary-page tablet/orientation and iOS/Safari checks, authenticated product baseline, complete lesson states and live widget availability were not established by audit captures; implementation must record them or explicitly classify remaining release caveats.

Audit checks actually performed ​

  • Branch/ref/merge-base/path and patch-equivalence analysis; complete six-commit patch capture and 185-file classification.
  • Asset blob/size/dev-existence/consumer/duplicate audit.
  • Local main/dev runtimes in independent frontend Treehouse leases, built from their own locked dependencies. Browser capture: 62 route/viewport cases, no page exceptions, no horizontal overflow at the captured 390×844 and 1440×1000 viewports. Expected main /book-call and unknown-route 404s, dev /creators and /careers 404s recorded. Each status/title/headings/links/image-load state lives in visuals/capture-results.json.
  • Main mobile nav closes with Escape (aria-expanded false); dev baseline keeps aria-expanded true. Main role dialog captured; full keyboard focus containment was not validated by the initial script.
  • Normal-motion supplement: main active phone clip plays, inactive clips pause; audience persists to creators; curtain reaches /creators/apply then disappears; first questionnaire answer advances to multi-platform question without submission. Phone hidden below 1024, desktop nav shown from 768; no overflow at 640/768/820/900/1024/1100. visuals/interaction-results.json records observations.
  • Dev baseline 119 tests passed, zero failed/skipped; evidence/dev-tests.log.
  • Main build and dev typecheck completed with observed exit 0. Other completed validation outputs and interruption limits are recorded in evidence/validation-results.json; complete raw logs are retained. Never infer a deployed release from a local build.

External browser requests were blocked, including Calendly, YouTube and remote CDN images. Some local Next Roblox GET routes may make public upstream reads. No real contact/creator submission, email, Discord message, calendar booking, login, payout or financial mutation was performed. Product session flows were inspected in code and existing tests; authenticated end-to-end verification remains an implementation acceptance task.

Verification matrix for the implementation agent ​

Area / manifest itemsExact scenariosPassing result
Visual parity M01/M02/M07–M25/M35–M391440×1000 and 390×844 screenshots for both home audiences, campaigns/index + ForgeGUI/Kill Streak, services, contact, careers/dialog, guides/detail, legal, creators/apply/start; 768 and 1024 boundary shots; normal and reduced motionMatches spec colors, fonts, section order, line wrapping, card geometry, assets and responsive transformations; only documented compatibility/accessibility/copy adaptations differ.
Breakpoints639/640, 767/768, 819/820, 899/900, 999/1000, 1023/1024, 1099/1100No horizontal clipping; nav/phone/proof/stat/service grids change as specified; focus rings stay visible.
Nav/footer M05/M06Menu closed/open, Escape, navigation/back, modified clicks, focus tab orderExactly one shell; no hidden CTA tab stop; correct active descendant; no dead footer or cookie-preference link.
Audience M04/M07Default/no storage; brands/creators/clippers query; valid/invalid stored values; blocked storage; unrelated query/hash; reload/backBrands SSR/hydration safe; query wins; alias maps; preference persists; product role/theme unchanged.
Anchors M07/M11/M22How It Works in both audiences; inquiry; legal TOC; guide navigationReal matching target and sticky-header offset; browser history usable; no creator dead fragment.
Motion M03/M29Normal/reduced preference including changing it; inactive tab; offscreen videos; public→product navigation; failed route; double/modified clicksBounded media work; readable reduced-motion posters; observers/Lenis/timers/html state clean up; curtain disappears by fallback.
Cases M15–M17Seven named slugs + bad slug; curated versus live metrics; Roblox 200/404/502Published metrics/order correct; unknown 404; unavailable live values show --; dev richer API fields intact.
Inquiry M20/M46Missing/invalid budget/name/email; honeypot; missing site key; invalid token; rejected response; 20s abort; retry/successNo duplicate send; exact body contract; understandable accessible messages; token reset; no secret/client leak. Mock providers.
Calendly M19/M21Widget loading, valid-origin ready message, foreign-origin message, script failure/timeout, direct fallback; old URL with queryCorrect event URL/colors; trusted messages only; fallback usable; /book-call redirects to /contact. Do not make a booking.
Careers M24Three roles, dialog focus, Tab/Shift-Tab, Escape, backdrop, reopen, mail subjectFocus trapped/restored, scroll lock, correct role details and encoded mailto; no POST.
Acquisition M25–M28All nine questions; Back; empty links/multi/Other; fast flag with starter; weekly+views10k; starter; return/reset; corrupt JSON/track/negative/fractional/oversize progressCorrect deterministic segmentation; storage never crashes page; no account access granted; truthful completion/delivery wording.
Lesson gate M27Direct /start without app; starter; private track; read-end observer; wrong/right answers; revisit/reload; final invite absent/presentFive sequential guides; appropriate Whop/invite destination; absent config never emits placeholder; local gate not treated as authorization.
Action M28Unknown fields/track, excessive lengths, malformed answers, missing verification, unset webhook, mocked 2xx/non-2xx/network timeoutNo provider call for invalid request; bounded completion; delivered distinguishable; no raw answers/secrets in logs; no live provider messages.
Root/surface isolation M01/M02/M03/M30/M44Navigate marketing→login→dashboard light/dark→invoice→report→marketing in same browser; native selects, cards, scroll, toast, modal portalProduct fonts/tokens/control scheme retained; no .cr-card leakage or global styles; root services remain mounted as intended.
Auth M33/M34Anonymous/signed-in/restricted user, Google/Whop URLs, Discord enabled/disabled, returnTo, logout, onboarding validation, verify emailCurrent dev behavior and cookie credentials unchanged; copy change never changes field/enum values. Controlled mocks/test accounts only.
Whop/supportWhopEnvironmentBadge sandbox/live cases; support embed anonymous/authenticated/failed identity; staff permission combinationsDev environment selection and support context preserved; no silent switch to live; no unauthorized inbox access.
RBAC/private campaigns/groupsCapability loading/stale/denied; creator versus admin; private campaign active group member/nonmember; group ratesBackend access remains authoritative; no unauthorized action exposed by new shells; RPM version behavior unchanged.
Funding/invoices/payoutsExisting canonical budget/funding/invoice/readiness/maturity tests; invoice token read and metadata; invalid/expired tokenNo alternate funding architecture, fee hardcoding or payout rail; accurate current status/error boundaries; token no-store/no-referrer.
Submissions/analyticsManual submission, duplicate platform links, review commands/query, group analytics, charts/sparklines, report APIExisting feature tests remain green; no public marketing query mutates account/business state.
Telemetry/private tokensbeforeSend current location and event URL containing /share/report/; navigation into/out of report; invoice no-referrerReport tokens absent from events. No marketing catch-all or root metadata overwrites token-route protections.
Affiliate routing M30/r/test-code with controlled backend redirect/Set-Cookie; missing backend/failureSame-origin cookie/redirect semantics preserved; not swallowed by marketing 404.
SEO M30/M31/M39Canonical/OG/Twitter/schema for every public route; production vs preview; 22 sitemap entries; noindex apply/start/404; invalid slugsCorrect URLs/updated dates, no duplicate schema IDs, no private/token/search-stage routes listed; no preview indexing.
Legal M35Extract dev text/version before/after shell, compare headings/anchors and provider/payout passagesNo unapproved policy or rate change; known pre-existing inconsistencies explicitly carried to owner review.
Assets/build M36–M40Hash/consumer manifest, local missing assets, runtime image decode, native video poster, dependency diff, install/build/typecheckRequired assets load, duplicates not reintroduced, no downgrade/missing tooling, successful supported build.

Existing dev suites to retain ​

tests/admin-access.test.tsx, admin-review-analytics.test.mjs, admin-review-command.test.mjs, admin-submissions-query.test.tsx, campaign-budget-canonical.test.tsx, campaign-budget-display.test.tsx, campaign-funding-page.test.tsx, campaign-invoice-api.test.tsx, clipper-group-analytics.test.tsx, clipper-group-rates.test.tsx, manual-submission.test.tsx, marketing-query-dedup.test.tsx, overlay-portal.test.tsx, overview-sparklines.test.tsx, payout-financial-errors.test.tsx, payout-maturity.test.tsx, payout-review-navigation.test.mjs, permission-simulator.test.mjs, public-report-api.test.mjs, submission-review.test.tsx, support-resolution.test.tsx, toast.test.tsx, whop-environment.test.tsx, and nested discovery coverage. Paths are relative to tests/ after the first entry.

Suggested new focused suites: marketing scope/audience/content, creator acquisition/scoring/storage/action, contact contract, and a browser route/interaction matrix. Use existing Node/tsx test harness; Playwright is present as a browser library, not necessarily a configured @playwright/test project. Do not invent an npm typecheck or E2E script that package.json lacks.

sh
npm test
npx tsc --noEmit --incremental false
npm run lint
npm run build
npm run test:charts
/home/kirbysmashyeet/Source/BloxClips/scripts/bloxclips-gate "$PWD"

Run these in the implementation's verified Treehouse worktree. Use relevant focused Node tests while developing; run the full gate before handoff. Chart/browser provider failures must be classified against the baseline rather than silently skipped. No backend tests/migrations are required unless separately scoped backend changes become necessary.

Package consistency / final audit gate ​

Run node docs/main-dev-redesign-migration/scripts/check-consistency.mjs from workspace root. It checks document presence, six-commit and 185-path coverage, asset coverage, valid item dependencies, PORT/ADAPT evidence/targets/phases/acceptance, local Markdown links and protected primary state records. Its JSON output is persisted in evidence/consistency-results.json.

Final implementation handoff must include changed files, branch/commit, exact test outputs, visual references, remaining provider/copy/rights decisions and issue/PR linkage. “Looks like main” is insufficient if any protected MVP contract regressed.