Paid-path report · Stripe TEST mode
Tested NoteNest (our local demo app)
From the outside, no code access · run demo-20261003215838 · Oct 3, 2026, 5:58:38 PM ET → Oct 3, 2026, 5:58:46 PM ET · runner v0.1.0
Human review pending
4/7
passed · 2 failed · 1 not run
01A new customer can sign upA brand-new account was created and landed in the free area.✓ Pass
02A successful test payment goes throughPaid with the success test card and returned to the app.✓ Pass
2.1 Open the sign-up page✓ Pass
- Expected
- A sign-up form is shown
- Observed
- Sign-up form visible
- Time
- Oct 3, 2026, 5:58:38 PM ET
- URL
- http://localhost:4400/signup

2.2 Create a new account✓ Pass
- Expected
- Account created and the free area shows "FREE-AREA"
- Observed
- Signed up as pp-demo-20261003215838-payer@paywallproof.test; free area visible
- Time
- Oct 3, 2026, 5:58:38 PM ET
- URL
- http://localhost:4400/dashboard

03A declined card is handled properlyThe decline card showed a clear message and nothing unlocked.✓ Pass
3.1 Open the sign-up page✓ Pass
- Expected
- A sign-up form is shown
- Observed
- Sign-up form visible
- Time
- Oct 3, 2026, 5:58:39 PM ET
- URL
- http://localhost:4400/signup

3.2 Create a new account✓ Pass
- Expected
- Account created and the free area shows "FREE-AREA"
- Observed
- Signed up as pp-demo-20261003215838-decliner@paywallproof.test; free area visible
- Time
- Oct 3, 2026, 5:58:39 PM ET
- URL
- http://localhost:4400/dashboard

3.3 Open checkout from the upgrade button✓ Pass
- Expected
- The upgrade button leads to a checkout page
- Observed
- Checkout form at /checkout
- Time
- Oct 3, 2026, 5:58:39 PM ET
- URL
- http://localhost:4400/checkout

04Paid features unlock after payingCharged but still locked: the payment went through, but the paid features did not unlock.✕ Fail
4.1 Look for paid access after paying✕ Fail
- Expected
- paid-only status "Plan: Pro" (the paid page itself is open to everyone, see check 7) within 6s
- Observed
- Still locked after 6s of retries (at /dashboard)
- Time
- Oct 3, 2026, 5:58:45 PM ET
- URL
- http://localhost:4400/dashboard

4.2 Reload✕ Fail
- Expected
- Paid access still visible
- Observed
- Locked after reload
- Time
- Oct 3, 2026, 5:58:45 PM ET
- URL
- http://localhost:4400/dashboard

4.3 Log out, log back in, check again✕ Fail
- Expected
- Paid access still visible
- Observed
- Locked after a fresh login (at /dashboard)
- Time
- Oct 3, 2026, 5:58:45 PM ET
- URL
- http://localhost:4400/dashboard

Fix prompt: paste into your AI builder
In this Lovable project: A customer paid successfully in Stripe but the paid features stayed locked ('charged but still locked'). Unlock access only from a server-side source of truth: handle the Stripe webhook events checkout.session.completed and customer.subscription.updated, verify the webhook signature, look the user up by client_reference_id (not by email alone), and save their subscription status and current_period_end. On every page load, read access from that saved status on the server. After the change, a paying user must see paid features after a refresh and after logging out and back in. If the app uses Supabase, put the check in a Supabase Edge Function or a row-level-security policy, not in the React component. Show me the changes before applying them, then keep everything else working.05The customer can cancel on their ownCancelled online without contacting anyone.✓ Pass
06Access ends when the paid period endsNot run: paid access was never granted (see check 4), so there is nothing to revoke.– Not run
07Paid pages can't be reached without payingPaid content was reachable without paying (5 probes failed).✕ Fail
7.1 Logged out: open /pro directly✕ Fail
- Expected
- Redirected or locked; no paid content
- Observed
- Paid content visible while logged out
- Time
- Oct 3, 2026, 5:58:45 PM ET
- URL
- http://localhost:4400/pro

7.2 Unpaid account (free): open /pro and reload✕ Fail
- Expected
- Locked; no paid content
- Observed
- Paid content visible to an account that never paid
- Time
- Oct 3, 2026, 5:58:46 PM ET
- URL
- http://localhost:4400/pro

7.3 Unpaid account (decliner): open /pro and reload✕ Fail
- Expected
- Locked; no paid content
- Observed
- Paid content visible to an account that never paid
- Time
- Oct 3, 2026, 5:58:46 PM ET
- URL
- http://localhost:4400/pro

7.4 Success-URL replay: open /success?success=true&session_id=cs_test_fake, then /pro✕ Fail
- Expected
- Visiting the success page without paying unlocks nothing
- Observed
- Replaying the success URL unlocked paid content
- Time
- Oct 3, 2026, 5:58:46 PM ET
- URL
- http://localhost:4400/pro

7.5 Passive scan: did any response sent to an unpaid browser contain paid content?✕ Fail
- Expected
- No response contains the paid marker
- Observed
- Paid marker found in 7 response(s): visitor: /pro; free: /pro; decliner: /pro
- Time
- Oct 3, 2026, 5:58:46 PM ET
Screenshot slot: none captured for this step
Fix prompt: paste into your AI builder
In this Lovable project: Paid content can be reached without paying (for example by opening the paid page while logged out, with a free account, or by visiting the success URL directly). Protect every paid route and every paid data query on the SERVER: check that the user is logged in and has an active paid status saved from Stripe webhooks before returning anything. Hiding things in the UI is not enough. Never unlock because of a URL parameter like ?success=true. If the app uses Supabase, put the check in a Supabase Edge Function or a row-level-security policy, not in the React component. Show me the changes before applying them, then keep everything else working.
Notes
- Local demo fixture: fake checkout on localhost, Stripe test card numbers only. Not Stripe.
- Test account created: pp-demo-20261003215838-visitor@paywallproof.test (persona "visitor"). Delete it from your test data when you're done.
- Test account created: pp-demo-20261003215838-free@paywallproof.test (persona "free"). Delete it from your test data when you're done.
- Test account created: pp-demo-20261003215838-payer@paywallproof.test (persona "payer"). Delete it from your test data when you're done.
- Test account created: pp-demo-20261003215838-decliner@paywallproof.test (persona "decliner"). Delete it from your test data when you're done.
Point-in-time test in Stripe test mode. Not a security certification, legal or tax advice, or a guarantee of any outcome. Test date: Oct 3, 2026, 5:58:38 PM ET.







