Skip to content
Paid-path report · Stripe TEST mode

Tested NoteNest (our local demo app)

From the outside, no code access · run demo-20261003215838 · Oct 3, 2026, 5:58:38 PM ET → Oct 3, 2026, 5:58:46 PM ET · runner v0.1.0

Human review pending

4/7
passed · 2 failed · 1 not run
01A new customer can sign upA brand-new account was created and landed in the free area.✓ Pass
started Oct 3, 2026, 5:58:38 PM ET · finished Oct 3, 2026, 5:58:38 PM ET · 2 steps
1.1 Open the sign-up page✓ Pass
Expected
A sign-up form is shown
Observed
Sign-up form visible
Time
Oct 3, 2026, 5:58:38 PM ET
URL
http://localhost:4400/signup
Evidence: Open the sign-up page
1.2 Create a new account✓ Pass
Expected
Account created and the free area shows "FREE-AREA"
Observed
Signed up as pp-demo-20261003215838-free@paywallproof.test; free area visible
Time
Oct 3, 2026, 5:58:38 PM ET
URL
http://localhost:4400/dashboard
Evidence: Create a new account
02A successful test payment goes throughPaid with the success test card and returned to the app.✓ Pass
started Oct 3, 2026, 5:58:38 PM ET · finished Oct 3, 2026, 5:58:39 PM ET · 4 steps
2.1 Open the sign-up page✓ Pass
Expected
A sign-up form is shown
Observed
Sign-up form visible
Time
Oct 3, 2026, 5:58:38 PM ET
URL
http://localhost:4400/signup
Evidence: Open the sign-up page
2.2 Create a new account✓ Pass
Expected
Account created and the free area shows "FREE-AREA"
Observed
Signed up as pp-demo-20261003215838-payer@paywallproof.test; free area visible
Time
Oct 3, 2026, 5:58:38 PM ET
URL
http://localhost:4400/dashboard
Evidence: Create a new account
2.3 Open checkout from the upgrade button✓ Pass
Expected
The upgrade button leads to a checkout page
Observed
Checkout form at /checkout
Time
Oct 3, 2026, 5:58:39 PM ET
URL
http://localhost:4400/checkout
Evidence: Open checkout from the upgrade button
2.4 Pay with test card 4242 4242 4242 4242✓ Pass
Expected
Payment completes and returns to the app
Observed
Returned to the app at /success
Time
Oct 3, 2026, 5:58:39 PM ET
URL
http://localhost:4400/success?session_id=cs_test_fixture_0eef4b23af23
Evidence: Pay with test card 4242 4242 4242 4242
03A declined card is handled properlyThe decline card showed a clear message and nothing unlocked.✓ Pass
started Oct 3, 2026, 5:58:39 PM ET · finished Oct 3, 2026, 5:58:39 PM ET · 5 steps
3.1 Open the sign-up page✓ Pass
Expected
A sign-up form is shown
Observed
Sign-up form visible
Time
Oct 3, 2026, 5:58:39 PM ET
URL
http://localhost:4400/signup
Evidence: Open the sign-up page
3.2 Create a new account✓ Pass
Expected
Account created and the free area shows "FREE-AREA"
Observed
Signed up as pp-demo-20261003215838-decliner@paywallproof.test; free area visible
Time
Oct 3, 2026, 5:58:39 PM ET
URL
http://localhost:4400/dashboard
Evidence: Create a new account
3.3 Open checkout from the upgrade button✓ Pass
Expected
The upgrade button leads to a checkout page
Observed
Checkout form at /checkout
Time
Oct 3, 2026, 5:58:39 PM ET
URL
http://localhost:4400/checkout
Evidence: Open checkout from the upgrade button
3.4 Pay with test card 4000 0000 0000 0002✓ Pass
Expected
A clear decline message; no unlock
Observed
Decline message shown ("declined")
Time
Oct 3, 2026, 5:58:39 PM ET
URL
http://localhost:4400/checkout
Evidence: Pay with test card 4000 0000 0000 0002
3.5 Check access after the decline✓ Pass
Expected
Still locked: no paid access
Observed
Still locked
Time
Oct 3, 2026, 5:58:39 PM ET
URL
http://localhost:4400/dashboard
Evidence: Check access after the decline
04Paid features unlock after payingCharged but still locked: the payment went through, but the paid features did not unlock.✕ Fail
started Oct 3, 2026, 5:58:39 PM ET · finished Oct 3, 2026, 5:58:45 PM ET · 3 steps
4.1 Look for paid access after paying✕ Fail
Expected
paid-only status "Plan: Pro" (the paid page itself is open to everyone, see check 7) within 6s
Observed
Still locked after 6s of retries (at /dashboard)
Time
Oct 3, 2026, 5:58:45 PM ET
URL
http://localhost:4400/dashboard
Evidence: Look for paid access after paying
4.2 Reload✕ Fail
Expected
Paid access still visible
Observed
Locked after reload
Time
Oct 3, 2026, 5:58:45 PM ET
URL
http://localhost:4400/dashboard
Evidence: Reload
4.3 Log out, log back in, check again✕ Fail
Expected
Paid access still visible
Observed
Locked after a fresh login (at /dashboard)
Time
Oct 3, 2026, 5:58:45 PM ET
URL
http://localhost:4400/dashboard
Evidence: Log out, log back in, check again

Fix prompt: paste into your AI builder

In this Lovable project: A customer paid successfully in Stripe but the paid features stayed locked ('charged but still locked'). Unlock access only from a server-side source of truth: handle the Stripe webhook events checkout.session.completed and customer.subscription.updated, verify the webhook signature, look the user up by client_reference_id (not by email alone), and save their subscription status and current_period_end. On every page load, read access from that saved status on the server. After the change, a paying user must see paid features after a refresh and after logging out and back in. If the app uses Supabase, put the check in a Supabase Edge Function or a row-level-security policy, not in the React component. Show me the changes before applying them, then keep everything else working.
05The customer can cancel on their ownCancelled online without contacting anyone.✓ Pass
started Oct 3, 2026, 5:58:45 PM ET · finished Oct 3, 2026, 5:58:45 PM ET · 2 steps
5.1 Find the manage/cancel option✓ Pass
Expected
A self-serve way to manage the subscription
Observed
Cancel control found (localhost:4400/portal)
Time
Oct 3, 2026, 5:58:45 PM ET
URL
http://localhost:4400/portal
Evidence: Find the manage/cancel option
5.2 Cancel the subscription✓ Pass
Expected
Cancellation confirmed on screen
Observed
Cancellation confirmed
Time
Oct 3, 2026, 5:58:45 PM ET
URL
http://localhost:4400/portal
Evidence: Cancel the subscription
06Access ends when the paid period endsNot run: paid access was never granted (see check 4), so there is nothing to revoke.– Not run
started Oct 3, 2026, 5:58:45 PM ET · finished Oct 3, 2026, 5:58:45 PM ET · 0 steps
07Paid pages can't be reached without payingPaid content was reachable without paying (5 probes failed).✕ Fail
started Oct 3, 2026, 5:58:45 PM ET · finished Oct 3, 2026, 5:58:46 PM ET · 5 steps
7.1 Logged out: open /pro directly✕ Fail
Expected
Redirected or locked; no paid content
Observed
Paid content visible while logged out
Time
Oct 3, 2026, 5:58:45 PM ET
URL
http://localhost:4400/pro
Evidence: Logged out: open /pro directly
7.2 Unpaid account (free): open /pro and reload✕ Fail
Expected
Locked; no paid content
Observed
Paid content visible to an account that never paid
Time
Oct 3, 2026, 5:58:46 PM ET
URL
http://localhost:4400/pro
Evidence: Unpaid account (free): open /pro and reload
7.3 Unpaid account (decliner): open /pro and reload✕ Fail
Expected
Locked; no paid content
Observed
Paid content visible to an account that never paid
Time
Oct 3, 2026, 5:58:46 PM ET
URL
http://localhost:4400/pro
Evidence: Unpaid account (decliner): open /pro and reload
7.4 Success-URL replay: open /success?success=true&session_id=cs_test_fake, then /pro✕ Fail
Expected
Visiting the success page without paying unlocks nothing
Observed
Replaying the success URL unlocked paid content
Time
Oct 3, 2026, 5:58:46 PM ET
URL
http://localhost:4400/pro
Evidence: Success-URL replay: open /success?success=true&session_id=cs_test_fake, then /pro
7.5 Passive scan: did any response sent to an unpaid browser contain paid content?✕ Fail
Expected
No response contains the paid marker
Observed
Paid marker found in 7 response(s): visitor: /pro; free: /pro; decliner: /pro
Time
Oct 3, 2026, 5:58:46 PM ET
Screenshot slot: none captured for this step

Fix prompt: paste into your AI builder

In this Lovable project: Paid content can be reached without paying (for example by opening the paid page while logged out, with a free account, or by visiting the success URL directly). Protect every paid route and every paid data query on the SERVER: check that the user is logged in and has an active paid status saved from Stripe webhooks before returning anything. Hiding things in the UI is not enough. Never unlock because of a URL parameter like ?success=true. If the app uses Supabase, put the check in a Supabase Edge Function or a row-level-security policy, not in the React component. Show me the changes before applying them, then keep everything else working.
Notes
  • Local demo fixture: fake checkout on localhost, Stripe test card numbers only. Not Stripe.
  • Test account created: pp-demo-20261003215838-visitor@paywallproof.test (persona "visitor"). Delete it from your test data when you're done.
  • Test account created: pp-demo-20261003215838-free@paywallproof.test (persona "free"). Delete it from your test data when you're done.
  • Test account created: pp-demo-20261003215838-payer@paywallproof.test (persona "payer"). Delete it from your test data when you're done.
  • Test account created: pp-demo-20261003215838-decliner@paywallproof.test (persona "decliner"). Delete it from your test data when you're done.

Point-in-time test in Stripe test mode. Not a security certification, legal or tax advice, or a guarantee of any outcome. Test date: Oct 3, 2026, 5:58:38 PM ET.