Appearance
Final adversarial review — execution decisions
Reviewed 2026-09-20 against the same pinned snapshots, not a new branch audit. This document resolves ambiguity in the original handoff; its explicit decisions take precedence over older suggestions in archived evidence. Verdict: READY WITH DOCUMENTED CAVEATS. Implementation is ready; public release still needs the two owner sign-offs in §18. No application code was modified.
1. Design-system boundary — two identities, not variants of one system
Marketing gets its own design-system layer: surfaces/marketing/styles/{site,creators}.css, components/ui.tsx, and existing app/(marketing)/layout.tsx. Keep Content Rewards' surfaces/content-rewards/components/ui/*, styles/tokens.css, .content-rewards-theme and .dashboard-theme unchanged. Share behavior and brand assets only where visual ownership is not coupled. Do not add variant="marketing" to product Button/Card/Input/PageHeader/Banner/Toggle.
Safest boundary:
- One marketing layout-owned
.cc-rootcontains Navbar, page, Footer, motion and the marketing overlay host. Rubik/Space Mono variables and all--cc-*tokens live on this wrapper, never:root/body or Tailwind's global theme. - Rename every marketing creator
.cr-*class andcr-*animation tocc-cr-*, including JSX, CSS, selectors in browser code/tests and animation references. Also scope every selector branch under.cc-root(except the wrapper rule itself). Do not rename productcr-*classes, route names, storage keys or business roles. - Prefixing alone was insufficient. Dev
tokens.css:501has an unlayered.cr-card; maincreators.css:86places.cr-cardinside@layer components. The unlayered rule can win even against a more specific layered marketing rule. Renaming prevents that reverse leakage; scoping prevents outward leakage. CSS imports in route groups are not a privacy boundary and sheets can coexist after client navigation. - Keep Tailwind's existing reset, utility generation and breakpoint defaults. Preserve source layer order and final unlayered overrides; do not mechanically wrap all CSS in a new layer. Explicit marketing base font, foreground/background, control
font: inheritandcolor-scheme: lightprevent inherited dev defaults from changing the design. Do not useall: unset/revertor a second reset. - Keep marketing containers free of transforms/containment that trap fixed overlays. A marketing-specific overlay host inside
.cc-root, outside page clipping/reveal elements, preserves font/token inheritance. Use a marketing dialog, not product ConfirmModal/OverlayPortal.BodyPortalis only acceptable with a full marketing scope/font wrapper around portaled content; default plan uses the internal host.
Current dev typography/background/scrollbars/reset/Tailwind and legacy dashboard helpers are global in app/globals.css; Content Rewards tokens are on its wrapper but several component selectors are unlayered. Main Toybox tokens/fonts are wrapper-local, yet many selectors (not only cr-*) are unscoped. Root changes in main add global motion, radii and dark color scheme. None is a mandate to unify identities.
2. Architecture preservation and component decisions
| Area | Main supplies | Dev remains authoritative / exact action |
|---|---|---|
| Public shell/home/secondary pages | Composition, visual geometry, copy subject to §6, transitions | Adapt current (marketing) wrappers and surfaces/marketing; no (site) or app/components resurrection. Server metadata wrappers, client interactivity islands. |
| Toybox buttons/cards/stickers/type/container | Visual primitives, native link behavior | Create marketing-only components/ui.tsx; leave product components/ui/{Button,Card,Input,Select,PageHeader,Banner,Toggle,StatusBadge,ProgressBar,CardSkeleton,EmptyState}.tsx untouched. Small code duplication is preferable to visual coupling. |
| Navbar/header/footer | Public links and appearance | Replace only marketing Navbar/Footer; leave DashboardHeader/Sidebar/AdminNavigation/WhopEnvironmentBadge and ActionAccess untouched. One marketing shell; remove old page-level Nav imports atomically when shell ownership changes. |
| Dialogs | Careers content, close/backdrop/Escape | Marketing-specific CareersRoles.tsx plus MarketingOverlayHost.tsx; explicit focus trap/restore, inert background and nested-safe scroll lock. Dev ConfirmModal is product-styled and does not establish the requested focus behavior; copying its pattern is not an accessibility solution. |
| Forms | Inquiry layout and questionnaire | Native scoped controls; reuse shared/components/common/InvisibleTurnstile.tsx unchanged. Do not wrap product Input/Select/CountryCombobox to impose Toybox. Preserve same-origin contact request. |
| Icons/logos | X icon and client marks | Extend shared/components/ui/PlatformIcons.tsx only with missing X export; previous common/PlatformIcons target was wrong. Reuse Lucide and identical local logos; local marketing logo lockup, not product avatar/auth-control replacement. |
| Loaders/banners | Calendar skeleton, counters, questionnaire animation | Marketing-local; leave ErrorToast/ToastViewport/UserAvatar/product banners unchanged. Cosmetic questionnaire loader must say it is matching answers, not checking an account. |
| Links | Public links, curtain opt-in | Marketing StartLink around Next Link; preserve native modified clicks, downloads, hash links, external target/rel. Never wrap product navigation/auth redirects globally. |
| Cookie controls | Corner placement/appearance | One shared consent state/storage/event owner; a marketing-only presentation boundary, not a second consent store. Preserve compact visible /contact controls and preference reopening. Keep product presentation/behavior unchanged. |
| Audience | Brands default, creator query/persistence | Existing provider location/root instance stays; no nested second provider. Query/storage handling runs only for marketing home. Atomic consumer update if changing clippers to creators; alias remains accepted. Product light/dark and roles are independent. |
| Query/data | Case presentation and static metrics | Keep MarketingQueryProvider, useClipperCount, Roblox query/cache behavior and feature guide ownership. Reuse APIs, not main's obsolete fetching implementations. |
| Auth/profile | Google icon and wording | Google already present. Only M34 feature option-array labels change. LoginCard, session APIs, onboarding validation and profile payloads remain dev. |
3. Route ownership and conflict resolutions
Marketing: /, /campaigns, /campaigns/[slug] (seven editorial cases), /services, /contact, /book-call compatibility redirect, /creator-guides[/slug], /privacy, /terms, new /clipping, /careers, /creators, /creators/apply, /creators/start.
Product: /login, /onboarding, /verify-email, /dashboard/**, /dev/content-rewards, all under (content-rewards). Login is public access to the product visual surface, not marketing. No independent /signup exists at the pin; do not invent it. Acquisition is anonymous education, not signup or account onboarding.
Independent public-but-sensitive surfaces: /invoice/[token], (reports)/share/report/[token]. “Public URL” does not mean marketing. /r/:code belongs to dev's same-origin affiliate rewrite. /api/** handlers are not marketing routes. Marketing /campaigns/[slug] and product /dashboard/campaigns/[campaignId] have different meanings; never join their datasets or route params.
Resolved fallback: do not add (marketing)/[...rest]/page.tsx, a root catch-all, a new affiliate proxy, middleware, or rewrite reordering. Add only (marketing)/not-found.tsx for invalid campaign/guide slugs. Globally unknown URLs retain dev's existing 404; universal branded unknown-route parity is explicitly waived to preserve routing. Test /r/test-code redirect/Set-Cookie through a controlled backend, malformed API paths, auth, simulator and token routes. No provider write is needed.
Resolved redirect: use a server 307 /book-call → /contact. Preserve all query pairs verbatim using URLSearchParams, including repeats, with a fixed local pathname (never accept a redirect destination from the query). Do not forward those pairs to Calendly or treat them as authority. Browser fragments do not reach the server; no guarantee of legacy fragment preservation. Remove stale /book-call/layout.tsx metadata in the same change so it cannot compete with the canonical destination. Existing admin booking/support redirects remain unchanged.
4. Complete stylesheet/config disposition
The mechanical selector/variable/media/keyframe index is evidence/adversarial-evidence.json (css). All three source CSS resources have zero url(...) references. This index includes inherited dashboard rules so no stylesheet family is silently omitted.
| Source/resource | Decision |
|---|---|
Main app/(site)/site.css | Adapt into marketing styles/site.css; scope all selectors, preserve --cc-*, geometry and final cascade. Dot grids, gradients, ::before/after, hover/focus and 480/640/768/900/1000/1024 rules remain marketing-only. Keep cc-* keyframe names. |
| Main creator CSS | Adapt into marketing styles/creators.css; rename all cr-* selectors/keyframes to cc-cr-* and scope, including reduced-motion branches. Keep 640/820/900/1100 transforms. Import after site.css in marketing layout; homepage uses this sheet too. |
Main globals :root --background/--foreground/--dashboard-*, body/background transition, html dark scheme and data-surface | Discard. Preserve dev values. Marketing sets its own paper background/min-height and light controls. Do not copy audience effects mutating html/body. |
Main global --ease-*, --dur-*, --stagger, --r-* | Translate only consumed values to local --cc-* (or define local aliases on .cc-root); no global radius/easing changes. Define Toybox's four easing curves literally so inherited global values cannot silently change it. |
Main @theme inline radii/eases | Discard; do not redefine Tailwind rounded-*, font-sans, default colors, spacing or breakpoints globally. No changed Tailwind/PostCSS config is required. |
| Main Geist root-variable change | Defer out of this migration. Rubik/Mono do not need it; it changes every product/auth font baseline. M02 implements marketing fonts only. |
Main generic [data-reveal], [data-reveal-group] | Rename attributes to data-cc-reveal / data-cc-reveal-group in marketing JSX/observer/CSS, scope queries to wrapper, preserve final services 32px/24px amplitude and 80ms stagger overrides. No root observer. Initial/no-JS/reduced-motion content visible; only hide after observer readiness. |
Main .cookie-enter | If used, rename cc-cookie-enter, apply only to marketing consent view with local motion values. Keep v2 storage/events unchanged. |
Main .card-hv*, .hv-arrow, .acc-* | Old global recipes are not a substitute for final .cc-* components. Discard where unconsumed; if a retained consumer needs one, rename/prefix within marketing. No product utility replacement. |
Main reduced-motion universal * / html rule | Do not adopt globally. Scope descendant/pseudo-element overrides to .cc-root; motion runtime handles preference changes. Native document scrolling exception is lifecycle-bound below. |
| Lenis html/classes | Only unavoidable document effect: marketing-mounted runtime owns data-bc-marketing-scroll while active; document selectors require that marker. Save/restore prior inline scroll state on cleanup; destroy instance/RAF/listeners and remove only owned markers/classes. No html color/font/theme mutation. Marketing unmount and reduced-motion change must restore native behavior. |
Curtain html[data-curtain] | Move curtain state to .cc-root[data-cc-curtain] and update paused-entry selector. No root-document attribute or global scroll lock surviving navigation. |
Dev app/globals.css + shared/styles/{toast,review-reason}.css | Leave unchanged; no added marketing import. Existing reset, scrollbars, dashboard helpers and unlayered shared overlays remain baseline. |
Dev surfaces/content-rewards/styles/tokens.css | Leave unchanged. Never map Toybox colors/radii/fonts to --cr-* or --dashboard-*. |
| Fonts | next/font/google Rubik weights 500/700/800, Space_Mono 400/700, latin, swap in marketing layout; font variable classes on .cc-root and any marketing portal scope. No @font-face/binary fonts or global loader changes. |
Proof requires same-session navigation both ways, not isolated screenshots: creator proof → product light/dark cards/native selects/modal → marketing proof. Compare computed font, background, radius, border, shadow, color-scheme and scroll behavior. CSS import ordering must not affect results.
5. Shared primitives policy
Legitimate shared pieces: Next Link, Lucide SVGs, brand asset bytes, InvisibleTurnstile, consent state/events, Telemetry, toast service and pure utilities with no product CSS assumptions. Marketing can use those services without inheriting product visual components. Do not extract a new universal design system during migration. Existing product OverlayPortal intentionally selects .content-rewards-theme .dashboard-theme or falls back to body; it is not a neutral marketing portal. Keep its tests and implementation intact.
Root CookieConsent is outside .cc-root; descendant CSS will not style it. Implement a marketing-only presentation wrapper/CSS module in surfaces/marketing/components/MarketingCookiePresentation.tsx, retaining shared state in CookieConsent.tsx. Select it using an explicit known marketing route classifier, never “everything not /dashboard.” Use a scoped wrapper with its own supplied font variables, or keep its existing font as an explicitly accepted shared-control exception. Default decision: preserve its current font; only corner geometry/palette change on marketing. No new consent library/provider or independent banner instance.
6. Copy authority and exact adaptations
Priority: current implemented product/financial invariants → current dev legal text pending legal review → final main owner visual/editorial intent → old research comments. A main sentence is not authorization for policy changes. Apply wording changes consistently to visible text, JSON-LD, metadata and llms.txt.
| Copy family / evidence | Classification and execution instruction |
|---|---|
| Brand headline, service distinction, five-step process, careers roles, clipping definition, footer identity | Owner editorial intent; reuse final wording/layout, not earlier service version or unused Why/Objection copy. |
“every view” / “from the second it's posted” (main content.ts, creator FAQ) | Stale finance explanation. Replace with: “Earn through Whop from eligible views on approved submissions, subject to campaign rules, earning periods and payout requirements.” Never modify finance behavior. |
| “Anyone can start earning today”; “as many videos as you want”; “same video once on each platform” | Overbroad eligibility promises. Use “Creators who meet the campaign and account requirements can participate.” and “Submit videos that meet the campaign's supported-platform, content and submission rules.” Do not infer X or cross-platform eligibility from marketing icons. |
| “3 to 7 days after approval”; request payout/balance wording | Unsupported timing/manual-cashout implication. Use “Eligible earnings are paid through Whop when maturity, verification and other payout requirements are met. Check your dashboard for current status.” No new numeric SLA. |
| “You only pay for results”; guarantee/50K+ review stamp | Commercial marketing, not a promise of no invoice/provider fees. Use “Campaign usage is measured from eligible approved views; funding and fees follow your campaign agreement.” Preserve guarantee heading as commercial copy pending owner publication approval, not executable billing behavior. |
| “exact people most likely to watch”, invalid-view filtering, all submissions manually reviewed, platform list | Marketing/service claims, not proof of current automation/platform support. Qualify unsupported absolutes; list platform availability as campaign-dependent. Never add unsupported backend platform/status handling to make copy true. |
| 100K+/1B+/1M+/$600K+, ForgeGUI 250M+/50K+/460K+, creator $1K+ and proof captions | Editorial/historical evidence, not live counters. Keep source/provenance dates. “100M+ in the last 30 days” must become “100M+ views in the 30-day period reported September 15, 2026” unless owner supplies refreshed dated evidence. No claim that it updates daily. Similar summer/relative-time testimonials stay dated. |
| Creator “You're in”, checking handle/private team | Only educational segmentation is verified. Replace with “Your learning track is ready”; explain browser-local progress and independent account/campaign eligibility. Cosmetic loader: “Matching your answers to a learning track…”, no verified-handle claim. |
| Legal provider/fee/payout prose | Keep dev body and effective date byte-/text-equivalent; do not run historical generator. Existing 7%/5% discrepancy and sponsor example are pre-existing legal-release questions, not implementor choices. |
| CTA destinations | Book a Call → /contact; Start Creating/Get started → /creators/apply; starter → existing Whop. Keep existing public-community and guide Discord URLs distinct; no substitution for private invite. Omit placeholder invite entirely. |
| “Step 1/2 of 3” / nonexistent lesson video | Presentation can describe questionnaire→lessons→optional external destination, but missing destination must be disclosed. No invented training video or membership approval. |
Do not fabricate replacement metrics/testimonials to obtain parity. For release without owner claim/rights sign-off, omit disputed proof/claims rather than silently presenting them as verified; retain their geometry in non-public review fixtures only.
7. Non-static behavior ownership
| Behavior | Authority / required result |
|---|---|
| Public nav active state/mobile disclosure | Main appearance + dev route-change cleanup; Escape, link click and navigation close it; closed content inert/not tabbable. |
| Audience radio/query/storage | Main product intent, dev provider; query wins, legacy clippers alias, unrelated params/hash survive. Never sets product role/theme. |
| FAQ | Main single-open disclosure, keyboard/aria; hidden answer links unfocusable; visible approved FAQ and schema identical. |
| Phone/headline/logo rail/counters | Main presentation; active/tab-visible media only, stable word width, duplicate rail entries aria-hidden, hover/focus pause, one-shot counters, reduced-motion final values/poster. |
| Reveal/Lenis/curtain | Main presentation, new marketing lifecycle boundary; clean unmount, modified-click fallback, no-JS visibility, 4s curtain escape. |
| Card hover/focus | Main presentation with keyboard equivalent; coarse-pointer CTA visible without hover, no content only discoverable by hover. |
| Inquiry/Calendly | Main form/widget presentation, existing dev contact contract; validation, loading/error/retry, 20s form abort, origin-checked provider messages, direct fallback. No real sends in tests. |
| Careers | New main role state/mailto; explicit marketing dialog accessibility implementation. |
| Intake/lessons | Main scoring/sequence; safe local-mode, validation and configuration decisions in §8. No auth transition or backend grant. |
| Auth links/returnTo/logout | Current dev only. A public CTA must not mutate session or bypass onboarding. |
| Case links/live Roblox | Editorial routes + existing dev queries; live counts remain contextual, not attributed campaign results. |
| Private report links/telemetry | Dev token API/metadata/filter only; no main reporting redesign exists. |
| Consent/external links | Existing consent semantics; safe rel/target, no placeholder/private credential URL. New marketing click analytics are not authorized. |
8. Creator intake: resolved default and configuration truth table
The new public questionnaire and education are in scope, not optional. Only external delivery to a private Discord webhook is optional. The invite is a separate optional destination; it is not a webhook, OAuth flow or durable application system. Current dev has neither public funnel nor an application backend; guide bodies and Turnstile component/verification pattern already exist.
| Configuration | Required UX and network behavior |
|---|---|
| No webhook | Enable local questionnaire/lessons. State before collection: answers/progress stay in this browser and are not sent to the team. Do not call the delivery action. Completion says learning track ready, not application received. |
| Webhook present but verification config absent/invalid | Fail closed for delivery; continue explicit local mode. Never let presence of a secret alone enable an unprotected endpoint. |
| Valid webhook + existing public/server Turnstile configuration | Enable delivery only after bounded validation/verification. Explain answers go to the BloxClips team's Discord intake. Await result; success only means delivered, not accepted. Failure is retryable and local education may continue without sending. |
| Private invite missing/invalid/placeholder | Keep lessons available. Final step says “Private-team applications are not available yet.” No clickable placeholder, no implied admission, no automatic public Discord substitution. Offer existing Whop as a clearly separate public alternative. Disclose this limitation before starting the questionnaire. |
| Valid public invite configured | Enable final external link after local lessons; tell user Discord/team access is managed separately. A public NEXT_PUBLIC URL can be read from the client bundle: it is not secret or enforceably gated. |
Use the source env names. Validate invite as HTTPS discord.gg or discord.com/invite/... without credentials/placeholder text. Webhook server-only, HTTPS discord.com/api/webhooks/..., never accepted from client input. Proposed frontend schema: ≤16 KiB serialized payload, exactly the nine known question keys/options, links ≤2,000 characters, Other editor ≤120, token ≤2,048; reject unknown keys and duplicate/malformed multi-values. Recompute track server-side from answers; don't trust client track. Server verify/fetch timeouts ≤10s each; no automatic webhook retry or PII/provider-body logs; single-flight client submit. Turnstile is not a substitute for durable rate limiting, but fail-closed verification + bounds is required minimum before optional delivery. Use existing provider verification pattern without moving the contact endpoint.
Owner question is narrowly about launch configuration, not architecture: Will launch enable the Discord intake, and what approved public invite/destination should be used? Until supplied, the above local/unavailable mode is the decided behavior. Durable storage, real admission, secret invites, rate-limit infrastructure or approvals would be separately scoped backend work.
9. Telemetry/privacy: precise protection, not a blanket claim
Main keeps existing @vercel/analytics/next and @vercel/speed-insights/next directly in root; it did not introduce a new analytics vendor. At dev shared/components/common/Telemetry.tsx:6–25, beforeSend returns null if either current pathname or event URL pathname starts /share/report/. The URL's final segment is a bearer token granting report access; pageview/performance event URLs can disclose it. Preserve both checks for late events during navigation, for both SDKs; never instantiate either SDK again in marketing.
The guard is path-specific, not general token sanitization. It does not by itself establish consent enforcement or invoice telemetry exclusion; Telemetry.tsx does not read hasConsent. Do not describe v2 cookie controls as proof analytics waits for consent. Those are pre-existing limitations, not reasons to weaken the report guard or silently expand this migration. Preserve invoice/report noindex/no-referrer/no-store contracts. Use synthetic tokens in mocks and avoid real tokens/answers in screenshots, console, event properties and logs.
10. Backend conclusion challenged
All 39 PORT/ADAPT items now have an explicit backendAssessment in the manifest. No Bloxclips-backend or scraper CODE change is required for this bounded migration.
- M17/M20 use existing frontend Next Roblox/contact contracts, not newly required Express APIs.
- M19 uses Calendly deployment/network availability; no booking schema change. M21 is frontend redirect compatibility.
- M26/M27 local state and existing guide data need no account API. M28 adds frontend server-side code and optional env/provider delivery; “no backend code” must never be read as “no server code/security work.”
- M30/M31 require frontend deployment indexing configuration, not data APIs. Fixed editorial metadata must not fetch protected campaign/report information.
- M04/M32 use browser state; M34 keeps existing payload/enum values; auth/session semantics do not change.
- Remaining items are presentation/content/assets/dependency adaptation. Dev report APIs, campaign APIs and funding flows remain untouched and regression-tested.
Provider readiness is not established by source inspection. Contact still needs existing Turnstile/Resend env, Roblox outbound reads, Calendly external access and optional Discord settings. No real delivery was tested. Durable intake/admission would change this conclusion and requires separate scope.
11. Assets and dependency completeness
41 changed public assets, 22 inherited consumed assets, five raw docs logos and three CSS resources remain accounted for. Review script checks exact case of every literal local media reference in final marketing/data sources against the Git tree; no missing case-sensitive path was found. Preserve Itsukashi, NapsBlox, Sammical, SenpaiUnlimited capitalization; Linux will not repair it. CSS contains no indirect URL assets, Lottie or font-face resources.
Hero: five inherited canonical MP4s + new stills (use kaiserflows.jpg first paused frame). Logos: 10 rendered marks (eight image marks plus two text marks), inherited variants plus new marks/Rush; skip unconsumed CR replacement. Implementation evidence correction (2026-09-20): pinned final content.trustedBy and LogoWall.tsx contain 10, while the earlier audit count of 11 implicitly included the explicitly unconsumed CR mark. Cases: local game icons, inherited clip/poster art, ForgeGUI avatar/chart; remote Roblox images keep fallback. Creator proof: five JPGs + UI/SVG-built cards. Services: six MP4/JPG pairs + four inherited hero clip/still pairs. Contact/careers/legal/guides: CSS/Lucide/media already listed; no missing mobile art or training video. Social preview: 1200×630 PNG. Icons/favicons unchanged.
No supplied alternate-resolution/mobile-specific files: use responsive layout/cropping, not invented duplicates. Preserve native video posters/muted/playsInline; preload metadata only where visible/needed and do not eagerly download hidden mobile phone sources. Pause is not equivalent to stopping preload. Static images keep width/aspect ratio, meaningful alt, and source object-fit. Next Image conversion is optional, not a reason to broaden remotePatterns/config. Font preload stays route-local through next/font; no global video preload.
Package review: only direct base→main addition is lenis ^1.3.26, lock resolves 1.3.26. Other changed lock records are metadata at unchanged versions (full list in review evidence), not requested upgrades. Keep dev Next 16.3.3, React, Tailwind/PostCSS override, React Query, Whop, tsx and Playwright. Do not import main lock, main Next 16.2.4, new UI/dialog/font libraries or GSAP. Existing Framer Motion/native APIs cover other effects. Lenis is a deliberate small runtime addition for source scroll fidelity; disable under reduced motion, load only marketing. Compatibility on the mixed dev+Lenis target remains an implementation build/runtime gate, not a claim established by separate snapshot builds.
12. Responsive contract by section
| Section | Desktop → tablet → mobile |
|---|---|
| Shell/hero | 76px sticky row, nav ≥768; below that in-flow Menu/Close. Phone/stickers absent below1024, not miniature. Hero text/pill/CTAs remain, clamp type with stable cycling-word width. Dot field remains; no phone source loading required on mobile. |
| Logo wall | Continuous repeated rail; touch has no hover dependency. Reduced motion wraps a static single accessible set. No alternate mobile logos. |
| Brand stats/cases | Stats two columns ≥640, one below; mobile stat min-height removed, padding reduced, tilt halved, number clamp(2.4rem,12vw,3rem). Cases1/2/4 at base640/1024, coarse-pointer CTA visible. |
| Process/problem/scorecard/guarantee | Process1/2/5 columns at640/1024; dashed connectors only≥1024. Problem sticky split≥1024 becomes stacked. Scorecard900 switches three columns (dimension + two options) to stacked cells below900: desktop header hidden, each option gains its mobile label. Guarantee splits1024; stamp loses constrained max-width below640. Preserve reading order. |
| FAQ/final CTA | Wide heading/list split → stacked. Final CTA remains brand-only, wraps buttons and reduces sticker size; no hidden primary action on touch. |
| Case index/details | Case narrative/media split/flip at900; mobile source reading order, not alternating CSS order. Published metrics before live context; compact metric rows and 2×2 stacked definition tiles. Founder proof tilt halves <640. |
| Services | Feed1 column with media/text rows;2 columns640–999;4 columns≥1000. UGC/clipping copy/media split≥1000; clipping copy order2 only wide, copy-first mobile. Mass band splits1000, padding shifts768. Included tiles1/2/4 at640/1024. Footer/platform row stacks<768. No generic “all stack at lg” substitution. |
| Contact | Two-column calendar/head≥1024; stack with usable fallback on mobile, inquiry form below. Calendar-specific adjustments≤480; compact consent must not cover form controls or calendar fallback. |
| Creator homepage vs landing | Homepage has separate three-card stat band≥820. /creators cream PageHead has stats in aside, not another band. Both proof→steps→FAQ; landing does not reuse hero/rail. Proof1/2/3 columns at640/1100; desktop manually balanced groups become CSS column flow at tablet. Steps3≥900,1 below. |
| Questionnaire/lessons | Same nine-question order, full usable controls at phone width; no extra mobile question. Lessons sticky300px rail + fluid reading≥1024, rail before body below. Read-end/answer gate must work after viewport/orientation changes. |
| Guides/legal/careers | Reading columns preserve measure; legal260px sticky TOC wide, ordinary flow small. Careers dialog uses viewport-bounded scrolling with focus/close reachable; no desktop-only application control. |
Screenshot limits: all stored screenshots were revisited as contact sheets with DOM evidence; typography detail uses full-size originals. Public desktop/mobile and six home breakpoint observations exist. Authenticated product screenshots, tablet secondary pages, completed five-lesson states, iOS/Safari viewport/scroll behavior and real external widgets were not captured. These remain explicit implementation gates, not inferred parity. See10 for ±1px breakpoint testing.
13. SEO/root-document decisions
Marketing seo.ts/page wrappers own titles/descriptions/canonicals, /bloxclips-embed.png, Twitter identity and Article/FAQ/Breadcrumb schemas. Do not replace root metadata defaults for product/auth/token pages. Retain root lang=en, font class placement, data-scroll-behavior, hydration flag, dynamic export, providers, icons and favicon files. There is no new web-app manifest requirement; do not invent one.
Only permitted root metadata-adjacent edit: add stable @id to existing Organization/WebSite JSON-LD nodes and reference Organization from WebSite publisher; don't emit duplicate company nodes from every page. Marketing-specific descriptions/social data remain marketing-owned. Keep JSON-LD serialization safe for < in editorial strings. Unknown-case/guide404 must noindex; generic unknown URLs retain dev404 (§3).
Use one new server-only MARKETING_INDEXABLE=true opt-in, default false, documented in .env.example; only authorized production deployment sets it. Not NODE_ENV (staging builds are production builds). False: marketing robots metadata noindex/nofollow, sitemap empty, robots disallow all. True:22 public URLs; always exclude apply/start/book-call/product/API/report/invoice/simulator. Preserve existing private-route exclusions. robots is not authorization and does not replace noindex/token safeguards. CONTENT_UPDATED=2026-09-15 applies to imported editorial content only; preserve dev guide/legal actual dates. No automatic date bumps or external indexing calls.
14. Regression matrix: probable blast radius
| Protected dev functionality | Redesign change most likely to damage it | Required invariant/test |
|---|---|---|
| Auth/session/onboarding | Root/provider/audience/CTA changes, M02/M04/M34 | Existing credentials/returnTo/restrictions/validation; provider controls unchanged. |
| Whop/support embed | Global fonts/scroll/overlays, dependency overwrite | Support identity, permissions, iframe interaction; no Lenis interception. |
| Creator experience/campaigns | cr collision, public case-data confusion | Product cards/theme intact; real campaign IDs/visibility/remaining budget untouched. |
| Submissions/verification | Acquisition mistaken for admission; modal reuse | Local progress grants nothing; submission/verification modals retain portals and checks. |
| Staff/admin/RBAC | Marketing catch-all/nav/global UI | AdminAccessBoundary/adminFetch capability gates unchanged; no unknown admin routes exposed. |
| Funding/invoices | Main legal/copy/root metadata | Canonical invoice/receipt/allocation exactly-once architecture, token policies and fee handling untouched. |
| Payouts | “every view”/timing copy/old pages | Whop-only, pinned earning boundaries/maturity/holds; no recreated request-cashout/provider rails. |
| Clipper Groups/private campaigns | Naming or new creator-track mapping | No enum/payload/domain rename; membership/rates/backend access remain authoritative. |
| Analytics/private reports | Direct SDK/root replacement or metadata | Current+event URL suppression, report API untouched, no real tokens in fixtures. |
| Sandbox/live/config | Main lock/next.config/env copying | Explicit dev environment selection/badge/standalone/simulator/affiliate behavior retained. |
| Product overlays/toasts | Marketing portal/global animation/z-index | Existing shared toast/review CSS/OverlayPortal unchanged; no clipping or stray curtain. |
15. Ordering and independent checkpoints
A–G remain review phases, not authorization to deploy partial migration. Every phase must typecheck/build and leave routable controls. Fix these previously implicit dependencies:
- A creates content/assets/fonts/CSS and pure utilities. Source
ui.tsximports StartLink from later B: initially use native Next Link, then wire StartLink atomically in B. Do not introduce unresolved forward imports. Creator content/constants are created in A before curtain consumers. M17's Roblox visual exports also move toA: CampaignArt consumes RobloxThumb inC. Keep dev RobloxLiveStat default export, add LiveStickers/LiveMetricTiles/RobloxThumb there, and rewrite new imports; integrate full case routes inD. Existing Roblox reads use effect-based fetch; React Query pilot applies to other marketing reads, so do not invent a Roblox query refactor. B's audience type update includes existing page/Hero/Navbar/Footer atomically before C's replacement home. - B's shell change removes page-level Navbar from all existing marketing routes in the same commit; Footer remains single. Do not add links to new careers/clipping/creator routes until those pages exist in D/E. Keep existing working links meanwhile. Runtime document side effects and style isolation tests run here, not only G.
- C builds both home compositions and
/creatorslanding. Until E, keep existing public Whop destination for creator actions and omit acquisition curtains; E atomically switches all creator CTAs to/creators/apply. This is a temporary review checkpoint, not final parity. Add the CreatorSteps anchor now; source creator anchor is broken. - D orders M17 beforeM16, M20 beforeM19 beforeM21. Only then install
/book-callredirect; simultaneously remove old nested metadata. Activate careers/clipping nav/footer links once pages build. - E implements schema/progress/action before Apply, then Start. Configure local/unavailable mode by default; atomically activate final creator CTAs/curtain. No half-enabled webhook or placeholder URL checkpoint.
- F uses helper foundations fromA to finish metadata/sitemap; no catch-all work remains. Exact final link and 22-URL checks now apply. G is copy-only product labels/full gate and review; exclusions are constraints fromA, not cleanup deferred untilG.
Each commit: focused behavior tests + typecheck; each phase: build + public/product isolation smoke; full suites/gate inG. Intermediate source screenshots may differ while body/shell updates are staged; do not call a phase visually complete until its consumers are wired. Keep types/data backward-compatible until all current consumers migrate in the same commit. No new feature-flag system is necessary for these sequential review commits.
16. Manifest integrity and coverage
All51 items reviewed. Counts unchanged:8 PORT,31 ADAPT,4 ALREADY PRESENT,8 SKIP. Every PORT/ADAPT record retains source commits/files, current target, semantic intent, phase/dependencies/risk/acceptance and now has concrete implementationInstructions, backendAssessment, and a reference to this review. M18 icon path corrected; M02 global font fix deferred; M30 catch-all target removed; M24 portal destination explicit; M32 contact decision explicit. Phase placement is the first implementation phase; cross-phase completion is recorded separately, especially M30(A,F) and M25 content(A)/presentation(C).
17. Questions the implementor should NOT need to ask
- One design system or two? Two visual systems; share behavior/assets, not styled product controls.
- Can I paste CSS under the route layout? No; rename marketing cr classes, scope every selector/observer and keep final layer order.
- Where do marketing dialogs go? The marketing-owned overlay host inside font/token scope, not product OverlayPortal.
- Does public login get the new appearance? No. Product auth surface remains dev.
- Do I add a signup/application backend? No. Public questionnaire/lessons plus optional bounded frontend action only.
- Do I need the Discord settings to implement? No. Local mode and unavailable final destination are specified; production enablement is separate.
- Does a Discord invite prove private access is protected? No. It's public client configuration, not an authorization gate.
- Should I fix every obsolete finance sentence by changing product behavior? Never. Use §6 safe copy; retain dev legal text for separate approval.
- Can I copy root SEO/font fix to get parity? No; marketing metadata and fonts are local; root only gets stable entity IDs if needed.
- Should I add an affiliate proxy to make the catch-all work? No. Omit the catch-all and preserve current rewrite.
- Are all third-party integrations verified? No. Captures intentionally blocked them; mocks/fallbacks and separately authorized staging checks remain.
- Where is the implementation source? Pinned Git main objects, with exact files in the manifest; audit patches provide historical context. Do not execute historical generator/cleanup scripts.
18. ASSUMPTIONS THE IMPLEMENTOR MUST NOT HAVE TO GUESS
| Assumption | Classification | Resolution |
|---|---|---|
| Pins/merge-base/history coverage are immutable audited snapshots | VERIFIED | 01; rebase target authority to fresh origin/dev only after reviewing its delta. |
| Two visual surfaces already have separate route/feature ownership | VERIFIED | Dev layouts/token/component tree; preserve it. |
| Prefix alone prevents both CSS leakage directions | VERIFIED FALSE | Rename creator classes plus scope; unlayered product rule overrides layered marketing. |
| Route-group stylesheet import isolates CSS | VERIFIED FALSE | Explicit selector/token/portal boundaries required. |
| Shared OverlayPortal/ConfirmModal is neutral and accessible enough | VERIFIED FALSE | Product-specific target/styling; separate marketing dialog with tested focus. |
| Root CookieConsent currently reads AudienceTheme | VERIFIED FALSE | Dev component does not; avoid implying that requirement. New marketing presentation may read audience without moving/root-duplicating state. |
| Global Geist correction is required for redesign | HIGH CONFIDENCE: no | Defer; marketing fonts independent. |
| Catch-all is necessary to deliver redesign safely | INFERRED: no | Explicit bounded parity exception for global unknown URLs, no routing rewrite. |
| /book-call should survive owner removal | INFERRED compatibility choice | Fixed local307 to/contact, query retained, old metadata removed. |
| Main runtime, not comments, defines landing composition | VERIFIED | Landing cream hero/stat aside→Proof→CreatorSteps→FAQ; home differs. |
| Questionnaire scoring is membership approval | VERIFIED FALSE | Browser-local segmentation only, cannot authorize. |
| Invite remains secret because lessons hide its button | VERIFIED FALSE | NEXT_PUBLIC value is public; no access-control guarantee. |
| Optional intake means entire creator funnel can be omitted | VERIFIED FALSE | Funnel in scope; only Discord delivery optional. |
| Missing config may truthfully show “application received” | VERIFIED FALSE | Local-mode disclosure/unavailable destination; no false delivery. |
| No backend code means no server work/config | VERIFIED FALSE | New optional Next action plus env/security; no Express/scraper change. |
| Main stats and testimonials are current/approved | INFERRED, not proven | Dated editorial evidence only; publication approval below. |
| Main copy proves new financial/product policy | VERIFIED FALSE | Current dev semantics win; safe wording in§6. |
| Existing legal text is internally consistent | VERIFIED FALSE | Known fee discrepancy; retain text during visual work, owner/legal resolves publication. |
| Cookies enforce telemetry consent or protect all token URLs | VERIFIED FALSE | Exact report-only guard; don't broaden assurance. |
| Main dependencies must replace dev versions | VERIFIED FALSE | Only Lenis direct addition; dev graph retained. |
| Local assets resolve with exact Linux case / CSS hides extra assets | VERIFIED | Mechanical exact-case reference check, CSS url list empty; remote assets unverified. |
| Separate snapshot builds prove mixed migration compatibility | VERIFIED FALSE | New mixed build/runtime tests mandatory. |
| Source screenshots prove tablet, authenticated and provider behavior | VERIFIED FALSE | Explicit capture gaps in§12 and10. |
| Production indexing can depend on NODE_ENV alone | VERIFIED FALSE | Server MARKETING_INDEXABLE explicit production opt-in. |
| Main private Discord destination/delivery launch settings are known | NEEDS OWNER DECISION (O1) | Supply approved invite and choose webhook enablement; default local/unavailable works meanwhile. |
| Claims, personal media rights and legal publication terms are approved | NEEDS OWNER DECISION (O2) | One publication sign-off covering dated metrics/testimonials/asset permissions and current fee/timing clauses; no invented legal policy. |
These are the only owner decisions. They block the affected publication/enablement, not architectural implementation. External indexing/deploy operations still require their usual authorization, not another redesign design decision.
19. Readiness and review limitations
Ready with documented caveats: architectural choices, safe defaults and concrete implementation boundaries no longer require guessing. The artifact verification is not a post-migration test. No current production availability, refreshed branch integration, real provider delivery, authenticated E2E or legal permission is asserted. Archived raw evidence remains historical; this review and amended manifest/plan are execution authority.
Read-only state verification observed another task creating backend task/analytics-001; that task ref is outside this review and was left untouched. Primary HEADs, worktree status and local main/dev refs are compared separately and remain protected. No repository/application edits, commits, leases or provider mutations were performed by this review.