Skip to content

Browser Test Matrix

Use this checklist when testing the React verifier workbench on real browsers and devices.

Entry points:

  • http://127.0.0.1:5173/
  • GET /verifier/status

Preflight

  1. Start the stack with docker compose up -d --build. For phone testing, prefer API_PUBLISH_HOST=0.0.0.0 FRONTEND_PUBLISH_HOST=0.0.0.0 docker compose up -d --build.
  2. If verifier auth is enabled for local bootstrap, set VERIFIER_ADMIN_TOKENS and VERIFIER_BOOTSTRAP_ADMIN_TOKENS_ENABLED=true, then use the workbench's Access Control panel to issue a verifier API key.
  3. Confirm the Runtime Posture panel shows the expected server state:
  4. verifier auth mode
  5. admin flow enabled or disabled
  6. rate limits
  7. Redis connected or local fallback

Browser Coverage

  • Safari on iPhone
  • confirm the phone can load http://<mac-lan-ip>:5173/
  • if the page is plain LAN HTTP, confirm the workbench reports camera unavailability clearly instead of throwing a JS error
  • if testing over HTTPS with a trusted mkcert CA, confirm camera permission prompt appears at https://<mac-lan-ip>:5173/
  • verify live scan works
  • verify QR image upload works
  • verify payload copy fallback behavior if clipboard access is restricted
  • Chrome on Android
  • confirm environment-facing camera can be selected
  • verify live scan works
  • verify key issue / rotate / revoke flow if admin token is configured
  • Chrome on desktop
  • verify camera enumeration lists more than one source when available
  • verify QR image download and re-upload loop
  • Firefox on desktop
  • verify bundled /verifier/decode-image fallback works when BarcodeDetector is unavailable
  • verify image upload path still reaches accepted

Scenario Pass Criteria

For each browser/device, validate:

  1. Valid scan
  2. repeat verification of one envelope returns accepted again while inside its validity window; an expired envelope returns the freshness block
  3. Expired credential
  4. verification returns time_window
  5. Revoked certificate
  6. verification returns issuer_status
  7. Subdomain allowed
  8. verification returns accepted
  9. Subdomain blocked
  10. verification returns payload_revalidation
  11. Payload mismatch
  12. verification returns payload_revalidation

Trace Checks

  • confirm the lab shows a fresh X-Request-ID after each action
  • confirm the action label matches the request you just triggered
  • confirm the runtime panel still matches the server posture after issuing or revoking API keys

Live HTTP Smoke

After the compose stack is up, you can run:

cd backend
VERIFIER_SMOKE_ADMIN_TOKEN=local-lab-admin ./.venv/bin/python scripts/verifier_live_http_smoke.py

That script exercises the running HTTP server, not TestClient.