Appearance
Acceptance and regression verification
This separates audit evidence from tests the migration must pass. No migration code exists in this package.
Final review adds binding tests below and 11. Counts/checks reported by this audit do not mean the future mixed dev+redesign implementation has passed.
Adversarial acceptance additions
- Load product tokens before marketing creator proof and then reverse order, without full reload. Marketing uses no
cr-*classes/keyframes; computed product.cr-cardand marketing proof border/radius/background/fonts are invariant under ordering. Inspect native controls, scroll and marketing dialogs/portals. Product visual primitives unchanged. - Test no-JS and hydration delay: marketing content readable before reveal initialization; no hidden-mobile phone downloads; switching reduced motion stops/restarts only owned effects and removes scroll markers.
- Careers dialog: active focus starts inside, Tab/Shift-Tab cycle, Escape restores trigger, background inert, close reachable at narrow/short viewport even with cookie UI. Product OverlayPortal and ConfirmModal unchanged.
- Intermediate A–G checkpoints compile; no unresolved StartLink/creator constants imports, duplicate Navbar, dead new routes, stale book-call layout metadata, or half-enabled creator action. Final E activates all acquisition links atomically.
/book-call?a=1&a=2returns307 to fixed/contact?a=1&a=2; malicious redirect-like query cannot change destination. Query not sent to Calendly. No new catch-all/proxy; unknown URL retains dev404; bad case/guide slug returns branded noindex404.- Creator four-config matrix: all absent, partial delivery config, valid delivery+absent invite, both configured. Mock provider only. No config means zero delivery calls, local-mode disclosure, learning-track completion, unavailable private destination with separate Whop alternative. Configured action rejects oversized/unknown answers, recomputes track, verifies token and bounds outbound timeout. NEXT_PUBLIC invite never represented as secret authorization.
- Telemetry: both SDK handlers receive current-report/ordinary-event and ordinary-location/report-event cases; each returns null. Normal nonreport event remains unchanged. Do not assert consent enforcement or invoice filtering absent from current code.
- Marketing metadata does not change login/product/token defaults. Root font/html/provider snapshot unchanged except explicit JSON-LD IDs. MARKETING_INDEXABLE unset/false yields empty sitemap/noindex; true yields22 approved public URLs. All private routes stay excluded regardless of flag.
- Apply11§6 copy substitutions in visible text, schema, metadata and llms. Date relative claims. Legal prose/effective date stays dev; published claims/assets require O2 approval, missing Discord launch setting uses O1 safe default.
- Secondary-page tablet/orientation and iOS/Safari checks, authenticated product baseline, complete lesson states and live widget availability were not established by audit captures; implementation must record them or explicitly classify remaining release caveats.
Audit checks actually performed
- Branch/ref/merge-base/path and patch-equivalence analysis; complete six-commit patch capture and 185-file classification.
- Asset blob/size/dev-existence/consumer/duplicate audit.
- Local main/dev runtimes in independent frontend Treehouse leases, built from their own locked dependencies. Browser capture: 62 route/viewport cases, no page exceptions, no horizontal overflow at the captured 390×844 and 1440×1000 viewports. Expected main /book-call and unknown-route 404s, dev /creators and /careers 404s recorded. Each status/title/headings/links/image-load state lives in
visuals/capture-results.json. - Main mobile nav closes with Escape (aria-expanded false); dev baseline keeps aria-expanded true. Main role dialog captured; full keyboard focus containment was not validated by the initial script.
- Normal-motion supplement: main active phone clip plays, inactive clips pause; audience persists to creators; curtain reaches /creators/apply then disappears; first questionnaire answer advances to multi-platform question without submission. Phone hidden below 1024, desktop nav shown from 768; no overflow at 640/768/820/900/1024/1100.
visuals/interaction-results.jsonrecords observations. - Dev baseline 119 tests passed, zero failed/skipped;
evidence/dev-tests.log. - Main build and dev typecheck completed with observed exit 0. Other completed validation outputs and interruption limits are recorded in
evidence/validation-results.json; complete raw logs are retained. Never infer a deployed release from a local build.
External browser requests were blocked, including Calendly, YouTube and remote CDN images. Some local Next Roblox GET routes may make public upstream reads. No real contact/creator submission, email, Discord message, calendar booking, login, payout or financial mutation was performed. Product session flows were inspected in code and existing tests; authenticated end-to-end verification remains an implementation acceptance task.
Verification matrix for the implementation agent
| Area / manifest items | Exact scenarios | Passing result |
|---|---|---|
| Visual parity M01/M02/M07–M25/M35–M39 | 1440×1000 and 390×844 screenshots for both home audiences, campaigns/index + ForgeGUI/Kill Streak, services, contact, careers/dialog, guides/detail, legal, creators/apply/start; 768 and 1024 boundary shots; normal and reduced motion | Matches spec colors, fonts, section order, line wrapping, card geometry, assets and responsive transformations; only documented compatibility/accessibility/copy adaptations differ. |
| Breakpoints | 639/640, 767/768, 819/820, 899/900, 999/1000, 1023/1024, 1099/1100 | No horizontal clipping; nav/phone/proof/stat/service grids change as specified; focus rings stay visible. |
| Nav/footer M05/M06 | Menu closed/open, Escape, navigation/back, modified clicks, focus tab order | Exactly one shell; no hidden CTA tab stop; correct active descendant; no dead footer or cookie-preference link. |
| Audience M04/M07 | Default/no storage; brands/creators/clippers query; valid/invalid stored values; blocked storage; unrelated query/hash; reload/back | Brands SSR/hydration safe; query wins; alias maps; preference persists; product role/theme unchanged. |
| Anchors M07/M11/M22 | How It Works in both audiences; inquiry; legal TOC; guide navigation | Real matching target and sticky-header offset; browser history usable; no creator dead fragment. |
| Motion M03/M29 | Normal/reduced preference including changing it; inactive tab; offscreen videos; public→product navigation; failed route; double/modified clicks | Bounded media work; readable reduced-motion posters; observers/Lenis/timers/html state clean up; curtain disappears by fallback. |
| Cases M15–M17 | Seven named slugs + bad slug; curated versus live metrics; Roblox 200/404/502 | Published metrics/order correct; unknown 404; unavailable live values show --; dev richer API fields intact. |
| Inquiry M20/M46 | Missing/invalid budget/name/email; honeypot; missing site key; invalid token; rejected response; 20s abort; retry/success | No duplicate send; exact body contract; understandable accessible messages; token reset; no secret/client leak. Mock providers. |
| Calendly M19/M21 | Widget loading, valid-origin ready message, foreign-origin message, script failure/timeout, direct fallback; old URL with query | Correct event URL/colors; trusted messages only; fallback usable; /book-call redirects to /contact. Do not make a booking. |
| Careers M24 | Three roles, dialog focus, Tab/Shift-Tab, Escape, backdrop, reopen, mail subject | Focus trapped/restored, scroll lock, correct role details and encoded mailto; no POST. |
| Acquisition M25–M28 | All nine questions; Back; empty links/multi/Other; fast flag with starter; weekly+views10k; starter; return/reset; corrupt JSON/track/negative/fractional/oversize progress | Correct deterministic segmentation; storage never crashes page; no account access granted; truthful completion/delivery wording. |
| Lesson gate M27 | Direct /start without app; starter; private track; read-end observer; wrong/right answers; revisit/reload; final invite absent/present | Five sequential guides; appropriate Whop/invite destination; absent config never emits placeholder; local gate not treated as authorization. |
| Action M28 | Unknown fields/track, excessive lengths, malformed answers, missing verification, unset webhook, mocked 2xx/non-2xx/network timeout | No provider call for invalid request; bounded completion; delivered distinguishable; no raw answers/secrets in logs; no live provider messages. |
| Root/surface isolation M01/M02/M03/M30/M44 | Navigate marketing→login→dashboard light/dark→invoice→report→marketing in same browser; native selects, cards, scroll, toast, modal portal | Product fonts/tokens/control scheme retained; no .cr-card leakage or global styles; root services remain mounted as intended. |
| Auth M33/M34 | Anonymous/signed-in/restricted user, Google/Whop URLs, Discord enabled/disabled, returnTo, logout, onboarding validation, verify email | Current dev behavior and cookie credentials unchanged; copy change never changes field/enum values. Controlled mocks/test accounts only. |
| Whop/support | WhopEnvironmentBadge sandbox/live cases; support embed anonymous/authenticated/failed identity; staff permission combinations | Dev environment selection and support context preserved; no silent switch to live; no unauthorized inbox access. |
| RBAC/private campaigns/groups | Capability loading/stale/denied; creator versus admin; private campaign active group member/nonmember; group rates | Backend access remains authoritative; no unauthorized action exposed by new shells; RPM version behavior unchanged. |
| Funding/invoices/payouts | Existing canonical budget/funding/invoice/readiness/maturity tests; invoice token read and metadata; invalid/expired token | No alternate funding architecture, fee hardcoding or payout rail; accurate current status/error boundaries; token no-store/no-referrer. |
| Submissions/analytics | Manual submission, duplicate platform links, review commands/query, group analytics, charts/sparklines, report API | Existing feature tests remain green; no public marketing query mutates account/business state. |
| Telemetry/private tokens | beforeSend current location and event URL containing /share/report/; navigation into/out of report; invoice no-referrer | Report tokens absent from events. No marketing catch-all or root metadata overwrites token-route protections. |
| Affiliate routing M30 | /r/test-code with controlled backend redirect/Set-Cookie; missing backend/failure | Same-origin cookie/redirect semantics preserved; not swallowed by marketing 404. |
| SEO M30/M31/M39 | Canonical/OG/Twitter/schema for every public route; production vs preview; 22 sitemap entries; noindex apply/start/404; invalid slugs | Correct URLs/updated dates, no duplicate schema IDs, no private/token/search-stage routes listed; no preview indexing. |
| Legal M35 | Extract dev text/version before/after shell, compare headings/anchors and provider/payout passages | No unapproved policy or rate change; known pre-existing inconsistencies explicitly carried to owner review. |
| Assets/build M36–M40 | Hash/consumer manifest, local missing assets, runtime image decode, native video poster, dependency diff, install/build/typecheck | Required assets load, duplicates not reintroduced, no downgrade/missing tooling, successful supported build. |
Existing dev suites to retain
tests/admin-access.test.tsx, admin-review-analytics.test.mjs, admin-review-command.test.mjs, admin-submissions-query.test.tsx, campaign-budget-canonical.test.tsx, campaign-budget-display.test.tsx, campaign-funding-page.test.tsx, campaign-invoice-api.test.tsx, clipper-group-analytics.test.tsx, clipper-group-rates.test.tsx, manual-submission.test.tsx, marketing-query-dedup.test.tsx, overlay-portal.test.tsx, overview-sparklines.test.tsx, payout-financial-errors.test.tsx, payout-maturity.test.tsx, payout-review-navigation.test.mjs, permission-simulator.test.mjs, public-report-api.test.mjs, submission-review.test.tsx, support-resolution.test.tsx, toast.test.tsx, whop-environment.test.tsx, and nested discovery coverage. Paths are relative to tests/ after the first entry.
Suggested new focused suites: marketing scope/audience/content, creator acquisition/scoring/storage/action, contact contract, and a browser route/interaction matrix. Use existing Node/tsx test harness; Playwright is present as a browser library, not necessarily a configured @playwright/test project. Do not invent an npm typecheck or E2E script that package.json lacks.
sh
npm test
npx tsc --noEmit --incremental false
npm run lint
npm run build
npm run test:charts
/home/kirbysmashyeet/Source/BloxClips/scripts/bloxclips-gate "$PWD"Run these in the implementation's verified Treehouse worktree. Use relevant focused Node tests while developing; run the full gate before handoff. Chart/browser provider failures must be classified against the baseline rather than silently skipped. No backend tests/migrations are required unless separately scoped backend changes become necessary.
Package consistency / final audit gate
Run node docs/main-dev-redesign-migration/scripts/check-consistency.mjs from workspace root. It checks document presence, six-commit and 185-path coverage, asset coverage, valid item dependencies, PORT/ADAPT evidence/targets/phases/acceptance, local Markdown links and protected primary state records. Its JSON output is persisted in evidence/consistency-results.json.
Final implementation handoff must include changed files, branch/commit, exact test outputs, visual references, remaining provider/copy/rights decisions and issue/PR linkage. “Looks like main” is insufficient if any protected MVP contract regressed.