NoumenonGet a free diagnosis

From HOLD
to VERIFIED.

This is a test app built to be broken and fixed, not a client project.

A small Node 22 notes service with login, saving, reading and deleting notes, a health endpoint, JSON storage and zero third-party packages.

Source: Build Guard Customer Zero run, notes-broken and notes-clean fixtures. These are the recorded outcomes; raw command output is not reproduced in this sample.

What was run.

In this order, from a clean copy on a fresh checkout with its own data directory.

  1. npm ci --offline --ignore-scripts

    Install exactly what is declared.

  2. npm run setup

    Create empty storage and users A, B and admin.

  3. npm test

    Two tests must be discovered and pass.

  4. npm start

    Then /health must answer 200 with ok:true, and must answer 503 with ok:false when the storage file is unreadable.

  5. Run the journeys as users A and B.

    Through the real interface: log in, save a note, read it, delete it, and try to read the other user's note.

  6. Run the error paths.

    A missing route, malformed JSON to /login, and an invalid note id.

Before and after.

Before / notes-broken

Four release blockers.

HOLD
  1. BG-F-001

    Duplicate idempotency mutation

    Repeating the same save request created a second note instead of returning the first.

  2. BG-F-002

    Cross-user direct read

    User B could read user A's note by changing the id in the request.

  3. U03, U04

    Documented setup fails

    The README's setup command does not exist as documented; the app silently works around it.

  4. J2

    Delete journey failed

    The interface says the note is deleted; the note is still there after a refresh.

Login and saving (J1) and reading (J3) passed. Health checks passed.

After / notes-clean

The same six steps.

VERIFIED
Release blockers
0
Evidence blockers
0
Health checks
WORKS
Both journeys
WORKS
Error paths
WORKS

VERIFIED on the notes-clean test app. The result covers the checks above.

How to re-check.

Run the same six steps on the delivered code with a fresh DATA_DIR and PORT.

The repair report lists each command, its exit code, its output tail and the observed HTTP status, so anyone can repeat it.

A report proves what it tested. It isn't a promise that the rest of the app is free of bugs or security problems.

Get a free diagnosis