Sample repair report / Notes
From HOLD
to VERIFIED.
This is a test app built to be broken and fixed, not a client project.
A small Node 22 notes service with login, saving, reading and deleting notes, a health endpoint, JSON storage and zero third-party packages.
Source: Build Guard Customer Zero run, notes-broken and notes-clean fixtures. These are the recorded outcomes; raw command output is not reproduced in this sample.
01 / Procedure
What was run.
In this order, from a clean copy on a fresh checkout with its own data directory.
npm ci --offline --ignore-scriptsInstall exactly what is declared.
npm run setupCreate empty storage and users A, B and admin.
npm testTwo tests must be discovered and pass.
npm startThen /health must answer 200 with ok:true, and must answer 503 with ok:false when the storage file is unreadable.
- Run the journeys as users A and B.
Through the real interface: log in, save a note, read it, delete it, and try to read the other user's note.
- Run the error paths.
A missing route, malformed JSON to /login, and an invalid note id.
02 / Evidence
Before and after.
BG-F-001
Duplicate idempotency mutation
Repeating the same save request created a second note instead of returning the first.
BG-F-002
Cross-user direct read
User B could read user A's note by changing the id in the request.
U03, U04
Documented setup fails
The README's setup command does not exist as documented; the app silently works around it.
J2
Delete journey failed
The interface says the note is deleted; the note is still there after a refresh.
Login and saving (J1) and reading (J3) passed. Health checks passed.
- Release blockers
- 0
- Evidence blockers
- 0
- Health checks
- WORKS
- Both journeys
- WORKS
- Error paths
- WORKS
VERIFIED on the notes-clean test app. The result covers the checks above.
03 / Repeat
How to re-check.
Run the same six steps on the delivered code with a fresh DATA_DIR and PORT.
The repair report lists each command, its exit code, its output tail and the observed HTTP status, so anyone can repeat it.
A report proves what it tested. It isn't a promise that the rest of the app is free of bugs or security problems.
Get a free diagnosis