QA report: external/explorer.polymedia.app at hosted
No confirmed application defects. All findings were withdrawn, most due to test environment CORS limits.
Testing evaluated core explorer features on Testnet across 12 scenarios, exercising network switching, header navigation, homepage data tabs, search input resolution, and detail views for addresses, objects, checkpoints, and epochs.
A finding that selecting the Validators tab on the homepage renders no content and unmounts key header links was withdrawn after a hand check. The tabpanel does render its own content, a plain "Validator data could not be loaded" message, the same CORS-driven limitation seen elsewhere in this run, not a rendering failure. The header's Epoch, @juzybits, SOURCE CODE and MORE PROJECTS links were confirmed present and unchanged both before and after clicking the tab, checked twice independently. The harness could not see content inside a tab panel at the time this run was tested (fixed in commit 44cdfe8), which is what produced this finding. Five other findings involving search navigation and detail page rendering were withdrawn by the audit because CORS policy restrictions on fullnode RPCs prevented the test environment from fetching live blockchain data.
The application displayed appropriate empty states and error notices throughout, and no confirmed defect remains from this run.
Run summary
| Metric | Count |
|---|
| Scenarios executed | 12 |
| Passed | 6 |
| Failed | 6 |
| Blocked | 0 |
| Findings raised | 6 |
| Issues after the audit | 0 |
| Withdrawn by the audit | 6 |
| Critical / high / medium / low | 0 / 0 / 0 / 0 |
Target: https://explorer.polymedia.app/?network=testnet · Testing level: deep_feature · Stack: unknown
Issues
No issues survived the audit.
Environment limitations
These failures came from the test environment, not from the application: a credential the sandbox does not hold, a demo nobody may write to, a resource it cannot reach. They are not counted as issues. They record what this run could not exercise.
- Search does not navigate to address detail page when pressing Enter on a valid address (S1, high): The search fails to resolve the address because the test environment's CORS policy blocks requests to the Sui fullnode RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.
- Search for numeric checkpoint sequence returns 'No Results' instead of navigating to checkpoint detail page (S2, high): The search failure is caused by the test environment's CORS policy blocking the application from reaching the Sui RPC. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.
- Object detail view fails to extract data and display object details for 0x2 (S7, high): The application gracefully handles the data extraction failure caused by the test environment's CORS restriction blocking the RPC request. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 3 console errors during the scenario.
- Checkpoint details page fails to render checkpoint summary and timestamp on Testnet (S8, high): The data retrieval issue is due to the test environment's CORS policy blocking access to the RPC, which the application handles by showing an error message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.
- Epoch details page fails to retrieve and render epoch data (S9, high): The environment's CORS restriction prevents the application from fetching epoch data, causing the expected failure message. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 3 console errors during the scenario.
- S4 could not exercise this: Mainnet RPC requests blocked by CORS policy. The Mainnet RPC requests fail due to a CORS policy restriction in the test environment. The audit recorded the test environment as the cause, so it is not counted as an issue.
Withdrawn findings
The Critic re-examined these claims and found the evidence did not support them. They are kept here rather than deleted.
- Validators tab fails to render content and causes homepage elements to unmount (S5, high): I clicked on the Validators tab and observed that no content was rendered in the Validators tab panel. Furthermore, the Epoch link, @juzybits link, SOURCE CODE link, and MORE PROJECTS link all disappeared from the header as reported. The page reported 2 console errors during the scenario. Hand re-check, 2026-09-27: reproduced on the live app in a real browser after the runner's tab-panel snapshot fix (44cdfe8). Clicking the Validators tab shows its own tabpanel with a plain 'Validator data could not be loaded' message (a real, separate CORS-driven limitation, not a rendering failure), and the header's Epoch, @juzybits, SOURCE CODE and MORE PROJECTS links were confirmed present and unchanged both before and after the click, in two independent page loads. The harness could not see content inside a tab panel (fixed 44cdfe8), which is what produced this finding originally.
Scenario results
| Scenario | Priority | Result | Issues |
|---|
| S1 Search for Address | high | fail | none |
| S2 Search for Checkpoint | high | fail | none |
| S3 Search with Invalid Input | high | pass | none |
| S4 Switch Network via Selector | high | pass | none |
| S5 Navigate Homepage Tabs | high | fail | none |
| S6 Render Address Details | medium | pass | none |
| S7 Render Object Details | medium | fail | none |
| S8 Render Checkpoint Details | medium | fail | none |
| S9 Render Epoch Details | medium | fail | none |
| S10 Handle Missing Transaction Block | medium | pass | none |
| S11 Render Validators List | low | pass | none |
| S12 Header Home Link Integrity | low | pass | none |
The audit
The Critic reviewed 6 findings and ran 1 live replay in the browser, each on a fresh page.
- The test environment's origin was blocked by the Sui fullnode RPCs' CORS policies, limiting the run's ability to fetch and assert against live blockchain data.
- The application generally handled RPC network failures gracefully with empty states or error messages, except for the Validators tab on the homepage which crashed the layout.
- Hand correction, 2026-09-27: F3 was re-checked by hand after the tab-panel snapshot fix (44cdfe8) and withdrawn. The tabpanel's own content and the header links both render and persist correctly, the original claim does not reproduce.
What to fix first
No confirmed issue to fix. Every finding from this run was withdrawn, either as a test environment CORS limit or, for the Validators tab claim, as a harness snapshot bug already fixed upstream (44cdfe8).
Coverage and caveats
In scope: Global search functionality for various blockchain entity types; Network switching mechanism via UI; Homepage dashboard tabs (Transaction Blocks, Validators); Detail views for Address, Object, Checkpoint, Epoch, and Transaction Block; Validators list view.
Not covered: Wallet connection and transaction signing (out of scope for read-only hosted explorer run, no UI captured in AppMap).
- The transaction block hash '11111111111111111111111111111111111111111111' from the AppMap is likely a dummy or invalid hash; expected behavior is a graceful 'not found' state.
- Network state is driven by the '?network=' URL parameter, so explicit navigation steps will reset the network context for each scenario.
- Reported CORS errors from public RPC nodes might prevent actual on-chain data from loading; displaying a clean error message rather than crashing is considered a pass.
By the numbers
| Metric | Value |
|---|
| Scenarios | 6 passed, 6 failed, 0 blocked of 12 (32 planned steps) |
| Browser actions | 172 (17 clicks, 15 inputs, 47 navigations, 93 snapshots) |
| Screenshots | 30 (4 explore, 25 scenario, 1 critic), 25 captioned |
| Coverage | 7 pages, 1 forms, 2 flows, 2 console errors |
| Audit | 6 findings, 1 re-verified live, 0 confirmed, 0 promoted, 6 withdrawn |
| Model calls | 143 |
| Tokens | 771,527 input, 10,411 output, 23,751 thinking |
| Time | 8 min |
| Wallet | 0 transactions, 0 signatures, 0 refusals on chain sui:testnet |
| Stage | Calls | Input | Output | Thinking | Seconds |
|---|
| explore | 25 | 135,065 | 1,811 | 2,467 | 70 |
| plan | 1 | 3,697 | 2,122 | 2,900 | 34 |
| test | 112 | 616,065 | 5,321 | 11,283 | 317 |
| critique | 4 | 14,563 | 923 | 6,398 | 58 |
| report | 1 | 2,137 | 234 | 703 | 8 |