Staging Environment Validation Guide

Real code audit findings - Platform validated 2026-04-20

Audit Status: 34 components audited · 12 backend functions · 8 entities · 28 pages · Critical issues: 3 · Warnings: 7

1Environment & Database

✓ Database & Secrets

  • ✓ All 3 secrets configured (KVK_API_KEY, PostMark, MOLLIE_API_KEY)
  • ✓ Base44 SDK v0.8.26 properly initialized in base44Client.js
  • ✓ 8 entities properly defined with relationships
  • ⚠ CRITICAL: Payout processing assumes bank details stored as plain text — needs encryption
  • ⚠ WARNING: Transaction.platform_revenue calculated inconsistently across codebase

✓ Test Accounts & Data

  • ✓ Demo data fully calibrated: 11.76M passengers, €157.5M annual volume
  • ✓ 35 retailers across 5 airports with realistic metrics
  • ✓ Test QR codes generation working (jsQR library active)
  • ✓ Sample transactions seeded in demoData.js

2Core User Flows & UI/UX

✓ Travel Partner & Agency Flows

  • ✓ AgencyPortal and AgencySignup fully implemented
  • ✓ DemoAgencyDashboard with real data binding and period selector
  • ✓ KVK validation integrated (validateKvk function)
  • ✓ TravelPartnerPresentationFuture (13-slide PPTX) created
  • ⚠ AgencyDashboard relies on real transaction data — demo/staging may diverge

✓ Retailer Flows & Scanning

  • ✓ RetailerDashboard, RetailerPortal, RetailerSignup fully functional
  • ✓ DemoRetailerDashboard synced with real dashboard UI/UX
  • ✓ RetailerScanQR and RetailerScanOnly with jsQR integration
  • ✓ QR code validation, status tracking, redemption logic working
  • ⚠ RetailerCalculator ROI numbers hardcoded — update if tier changes

✓ Components & Reusability

  • ✓ 34 UI components (shadcn/ui) properly used
  • ✓ AggregationView component with period selector (Day/Month/Year)
  • ✓ RedemptionHeatmap SVG visualization working
  • ⚠ DemoProfileTab duplicates logic — consider extraction

3Payment & Billing

✓ Mollie Integration

  • ✓ createMolliePayment function implemented
  • ✓ mollieInvoiceWebhook processes payment confirmations
  • ✓ Invoice status transitions (pending → paid) working
  • ⚠ CRITICAL: Webhook signature validation in mollieInvoiceWebhook must run AFTER auth.me()
  • ⚠ Test payment link generation with sandbox API key

✓ Payout Processing

  • ✓ generateMonthlyInvoices automation creates invoices monthly
  • ✓ executeAgencyPayouts processes Mollie payouts
  • ✓ Commission calculation: 0.5% per transaction (agencies)
  • ⚠ CRITICAL: Bank account data (IBAN) stored unencrypted in SignupApplication
  • ✓ checkOverdueInvoices marks expired invoices as overdue
  • ✓ Retailer payout emails via Postmark working

4Data Integrity & Edge Cases

✓ Voucher & Transaction Logic

  • ✓ Voucher status enum enforced (active, redeemed, expired)
  • ✓ Double redemption prevention via status checks
  • ✓ Expiration date validation in ScanVoucher
  • ✓ Discount tier logic: €50–€99→10%, €100–€299→15%, €300+→20% (€25 cap)
  • ✓ Transaction logging with all fields (value, discount, platform_revenue)

⚠ Known Issues & Warnings

  • ⚠ AuthContext uses localStorage for auth state — consider session-based approach
  • ⚠ No explicit error boundary components — unhandled errors may crash page
  • ⚠ RetailerFeedback.comment field is optional but rating required — ensure data consistency
  • ⚠ Transaction.rejection_reason field unused — either use or remove
  • ✓ Invalid input handled via form validation (react-hook-form)

5Performance & Optimization

✓ Frontend Performance

  • ✓ Vite + React build configured with code splitting
  • ✓ Recharts & Framer Motion for visualizations (lazy-loaded on demand)
  • ✓ React Query for data caching (@tanstack/react-query v5.84.1)
  • ✓ Responsive design with Tailwind CSS (no dynamic class generation)
  • ⚠ DemoRetailerDashboard renders 5 main charts — consider pagination on mobile

✓ Backend Performance

  • ✓ Base44 entities support filtering, pagination, sorting
  • ✓ Deno backend functions optimized (no N+1 queries observed)
  • ✓ Postmark & Mollie API calls use async/await properly
  • ⚠ AdminPanel loads all vouchers/transactions without pagination — may slow for large datasets
  • ✓ Database indexes assumed on Booking.travel_date, Transaction.created_date

6Security & Compliance

✓ Authentication & Authorization

  • ✓ Base44 built-in auth handles token issuance & session management
  • ✓ Role-based access control (admin, user, retailer, agency) implemented
  • ✓ ProtectedRoute component guards private pages
  • ✓ User entity RLS prevents users from viewing other users' data
  • ⚠ CRITICAL: Bank account IBAN stored unencrypted — implement field-level encryption

✓ Data Protection & Compliance

  • ✓ Privacy Policy, Terms of Service, GDPR, DPA pages implemented
  • ✓ CookieConsentBar manages user preferences
  • ✓ Terms accepted before signup (terms_accepted field)
  • ✓ AccountDeletion entity tracks data deletion requests
  • ✓ Email unsubscribe logic in notifyVoucherRedeemed function
  • ⚠ No explicit data retention policy enforced — document & automate cleanup

✓ Input Validation & Sanitization

  • ✓ React Hook Form validates all inputs before submission
  • ✓ KVK number validation via external API (validateKvk function)
  • ✓ Email format validation on signup
  • ✓ No dynamic SQL — Base44 SDK handles query parameterization

Pre-Production Checklist

  • ⚠ MUST FIX: Implement IBAN encryption in SignupApplication (critical)
  • ⚠ MUST FIX: Verify Mollie webhook signature validation order
  • ⚠ SHOULD FIX: Add AdminPanel pagination for large datasets
  • ✓ All 28 pages tested and functional
  • ✓ All 12 backend functions deployed
  • ✓ Demo data calibrated to real market metrics
  • ✓ Email service integration verified (Postmark)
  • ✓ Auth flow tested (signup, approval, dashboard access)

We use cookies to improve your experience. You decide which cookies to allow — essential cookies are always required for the platform to function. Cookie Policy