Testing your app
Test in three layers, from fastest to most realistic.
| Layer | Tool | Proves |
|---|---|---|
| 1. The handshake | The Playground checks, against the sandbox | Your server issues and burns nonces, verifies tokens, and refuses every bad token |
| 2. Your app's own flows | The list below, signed in as a fake user | Your pages and data behave for a signed-in person |
| 3. The real thing | SuperPreneur on a phone, after registration | Your page works in the container, on mobile data |
1. The handshake#
Open the Playground, enter your server's address and press Run all checks. All sixteen should pass before you register. When one fails it says what it saw and what to change. The checks cover the nonce route, a normal sign-in, a stable user id, a protected route, nonce rules (once only, unknown, mismatched), each kind of bad token, and bad input.
2. Your app's flows#
Use the Playground's Sign in as to get a session for sita, bikash or asha, then walk your app as each of them. Use at least two users, to see that one person never sees another's data.
| # | Flow | Expected |
|---|---|---|
| 1 | Open your page directly, outside SuperPreneur | An "open from SuperPreneur" message; no data is shown, and every data route answers 401 |
| 2 | First sign-in | The page opens already signed in and greets the user by name |
| 3 | Return visit | Signed in at once with the same sub and the same data |
| 4 | Two different users | Each sees only their own data |
| 5 | Session expiry or server restart | The page signs in again silently and the user sees no error |
| 6 | A bad token (expired, revoked) | A plain sentence and a way forward, never a raw code or a blank screen |
| 7 | Empty, loading and error states of every screen | Each is designed, none is blank |
| 8 | Slow or lost connection | The user is told, and nothing is lost or duplicated |
| 9 | Every rule of your business | For example a double booking is refused with a clear message |
| 10 | A very small phone (360 px wide) | Everything fits and every button is easy to tap |
3. On a real phone#
After your app is registered and set to Active, open it from SuperPreneur on one iPhone and one Android phone, on mobile data. This is the last item of the go-live checklist.