Skip to content

6. Quality ​

6.1 Testing ​

LayerWhat to testHow
Business logicrules reject and set correctlycall the API with good and bad data
APIcreate, list, update, permission refusalstest cases with target api; curl
UIpage, form, validation, phone widthdesigner Preview at three widths
Workflowapprove, reject, escalate, delegateSimulate, then a real request
Integrationexternal call, webhook, emaila test connection and a single-record integration flow run
Securityemployee cannot read others' rows; wrong tenant gets nothingEffective permission viewer, two test users

See Testing. The capstone's own checks are in frontend/e2e/check-capstone-prod.mjs.

6.2 Debugging ​

ToolUse
Browser console and network tabfailed calls, status codes
Problems tabsstructural errors before publish
Audit log and workflow historywho did what
Service logsplugin code (Manage backend service)
Jobs run historyfailed runs
SymptomCause
Blank pagenot published, or no permission
401 / 403no session / role lacks the permission
Wrong datafilter or data source name mismatch
Workflow stuckstage with no way out, or task for a role nobody holds
Event not triggeredwrong trigger event or condition
400 "Cannot order ... and ..." on a rulethe two values are not both numbers or both dates; check the field names

6.3 Performance ​

Frontend: paginate, lazy-load heavy rows (deferred), avoid huge tables on phones. Backend: index filtered fields, batch work in jobs, keep rules cheap. Database: composite indexes, partial indexes for common filters. Scale: move heavy logic to a service-mode plugin and size it (CPU, memory); run per region when latency matters.

6.4 Security and compliance review before release ​

Permissions -> tenant isolation -> secrets -> API security -> dependency scan -> code scan -> container scan -> audit

Today: check permissions with the viewer, keep secrets in connectors or service variables (never in metadata), confirm every entity has role grants, read the audit log. Dependency, code and container scans are Planned (Security scanning); until then review manually.

Next: Ship and run.