Appearance
6. Quality
6.1 Testing
| Layer | What to test | How |
|---|---|---|
| Business logic | rules reject and set correctly | call the API with good and bad data |
| API | create, list, update, permission refusals | test cases with target api; curl |
| UI | page, form, validation, phone width | designer Preview at three widths |
| Workflow | approve, reject, escalate, delegate | Simulate, then a real request |
| Integration | external call, webhook, email | a test connection and a single-record integration flow run |
| Security | employee cannot read others' rows; wrong tenant gets nothing | Effective permission viewer, two test users |
See Testing. The capstone's own checks are in frontend/e2e/check-capstone-prod.mjs.
6.2 Debugging
| Tool | Use |
|---|---|
| Browser console and network tab | failed calls, status codes |
| Problems tabs | structural errors before publish |
| Audit log and workflow history | who did what |
| Service logs | plugin code (Manage backend service) |
| Jobs run history | failed runs |
| Symptom | Cause |
|---|---|
| Blank page | not published, or no permission |
| 401 / 403 | no session / role lacks the permission |
| Wrong data | filter or data source name mismatch |
| Workflow stuck | stage with no way out, or task for a role nobody holds |
| Event not triggered | wrong trigger event or condition |
| 400 "Cannot order ... and ..." on a rule | the two values are not both numbers or both dates; check the field names |
6.3 Performance
Frontend: paginate, lazy-load heavy rows (deferred), avoid huge tables on phones. Backend: index filtered fields, batch work in jobs, keep rules cheap. Database: composite indexes, partial indexes for common filters. Scale: move heavy logic to a service-mode plugin and size it (CPU, memory); run per region when latency matters.
6.4 Security and compliance review before release
Permissions -> tenant isolation -> secrets -> API security -> dependency scan -> code scan -> container scan -> auditToday: check permissions with the viewer, keep secrets in connectors or service variables (never in metadata), confirm every entity has role grants, read the audit log. Dependency, code and container scans are Planned (Security scanning); until then review manually.
Next: Ship and run.
