ClaraWideFounder / admin QA
PRODUCTION FOUNDATION · IDENTITY + OWNERSHIP

The server decides who you are—and which records you are allowed to touch.

v0.12.8 keeps the D1-backed identity/session ownership boundary and adds a separate staging-only QA Maker session so the real Maker Listings workflow can exercise authenticated catalog APIs. A server profile is keyed to the session account, cross-account targets are rejected, and profile writes cannot smuggle role or capability changes.

TEST NOW — SESSION + OWNERSHIP FOUNDATIONApply migration 0005, deploy, run identity and ownership self-tests, create one QA shopper session, load/update its server profile, run the tamper test, revoke the session, and confirm the expected post-logout state reads PASS.
PRODUCTION AUTH LATERDo not mark password/magic-link/passkey credentials, real email verification, account recovery, rate limiting, admin MFA, or all-platform API authorization complete yet. v0.12.6 proves the authorization pattern on the account profile endpoint; it does not mean every ClaraWide record has migrated.
SERVER HEALTH

Identity schema + automated contract

These calls hit the real Pages Function and D1. The self-test creates temporary server identity data, verifies shopper-only capability ownership, and deletes the fixture afterward.

SESSION QA

Short-lived staging server sessions

The Shopper button still proves client privilege requests are ignored. The Maker button is a separate server-authorized staging fixture: it grants exactly Shopper + Maker so the real catalog editor can be tested, never Admin.

QA sessions expire automatically after 30 minutes. The raw session token is stored only in an HttpOnly cookie; D1 stores its SHA-256 digest, not the raw token.

OWNERSHIP AUTHORIZATION

Prove one account cannot act as another

The automated test creates two disposable QA accounts, confirms the owner can target itself, rejects a different account ID, rejects role/capability fields, and confirms the second account record stayed untouched.

The live tamper test requires an active QA shopper session. It intentionally sends a fake different account ID and Admin/Maker-style privilege fields; rejection is the PASS condition.

SESSION-OWNED PROFILE

Read and update only “my” server record

No trusted owner ID is taken from the browser. The endpoint derives the account from the HttpOnly session cookie, then reads or updates that account’s D1 profile.

TEST NOW

Identity foundation checks

Only record tests you actually perform on clarawidetest.

PRODUCTION LATER

Real authentication + authorization gates

Leave these Not Checked until each control exists and has real evidence.

IDENTITY ISSUE LOG

Record auth/session/ownership defects

OPEN FINDINGS

Identity blockers & defects

RECENT SERVER RUNS
EVIDENCE BACKUP

Export or reset this QA layer

Export captures manual/production checks, findings and server-run evidence from this browser.

Identity boundaryPassing this QA proves ClaraWide can maintain a server-owned identity/session and enforce ownership on the first authenticated account-profile API. It does not make the current public browser-demo sign-in flow production authentication, and it does not prove authorization on listings, orders, messages, events or other user-owned records yet.