QA report: external/profile.polymedia.app at hosted
No application defects were confirmed during testing, though test environment network restrictions prevented full verification of profile queries.
Testing covered the primary navigation tabs, home page call-to-action links, network badge displays, wallet connection triggers, and profile search input handling with valid, invalid, empty, and whitespace formats across nine scenarios.
Input validation and static interface navigation performed as expected across seven passing scenarios. Two scenarios failed when attempting to query live Sui profile data, but both associated findings were withdrawn by the audit after identifying that sandbox CORS policy restrictions to the public Sui testnet fullnode blocked backend communication.
Because the external RPC fullnode could not be reached from the test environment, end-to-end profile retrieval on the Sui testnet remains unverified, though no actionable defects in the application codebase were identified.
Run summary
| Metric | Count |
|---|
| Scenarios executed | 9 |
| Passed | 7 |
| Failed | 2 |
| Blocked | 0 |
| Findings raised | 2 |
| Issues after the audit | 0 |
| Withdrawn by the audit | 2 |
| Critical / high / medium / low | 0 / 0 / 0 / 0 |
Target: https://profile.polymedia.app/?network=testnet · Testing level: deep_feature · Stack: unknown
Issues
No issues survived the audit.
Environment limitations
These failures came from the test environment, not from the application: a credential the sandbox does not hold, a demo nobody may write to, a resource it cannot reach. They are not counted as issues. They record what this run could not exercise.
- Search address query fails with unhandled TypeError Failed to fetch (S1, high): The search fails because requests to the third-party Sui testnet fullnode are blocked by CORS, which is an environment limitation rather than an application defect. The audit recorded the test environment as the cause, so this is a limit of the run rather than a defect of the application. The page reported 2 console errors during the scenario.
- S7 could not exercise this: CORS policy blocks fetch to Sui testnet fullnode on page load. Requests to the fullnode fail due to a CORS policy block, rendering network-dependent features unusable. The audit recorded the test environment as the cause, so it is not counted as an issue.
Withdrawn findings
The Critic re-examined these claims and found the evidence did not support them. They are kept here rather than deleted.
- Search query fails with unhandled 'TypeError: Failed to fetch' error (S4, high): The same defect on the same control is already reported as F1. One defect is counted once, however many scenarios met it. The page reported 2 console errors during the scenario.
Scenario results
| Scenario | Priority | Result | Issues |
|---|
| S1 Search Profile with valid Sui address | high | fail | none |
| S2 Search Profile with invalid address format | high | pass | none |
| S3 Connect Wallet on Manage Page | high | pass | none |
| S4 Search Profile with multiple valid addresses | medium | fail | none |
| S5 Search Profile with empty input | medium | pass | none |
| S6 Search Profile with whitespace only | medium | pass | none |
| S7 Navigation across primary tabs | medium | pass | none |
| S8 Home page call-to-action links | low | pass | none |
| S9 Network badge verification | low | pass | none |
The audit
The Critic reviewed 2 findings and ran 0 live replays in the browser, each on a fresh page.
- The test run was broadly limited by a third-party CORS policy issue with the public Sui testnet fullnode, restricting true functional test coverage.
- Finding F2 was recorded in S4's record but was not presented in the findings list for review.
- F2 reports the same defect on the same control as F1, so it is recorded as a duplicate.
Coverage and caveats
In scope: Search functionality and input validation; Wallet connection workflow via the Manage page; Primary navigation and call-to-action links; Network indication badge.
Not covered: Profile creation or on-chain mutations (needs an account, out of scope for a hosted run).
- A dummy 66-character hex string is used to represent a valid Sui address during search testing.
- RPC errors such as CORS or rate limits are treated as environmental; the UI is expected to handle them gracefully rather than crashing.
By the numbers
| Metric | Value |
|---|
| Scenarios | 7 passed, 2 failed, 0 blocked of 9 (31 planned steps) |
| Browser actions | 138 (17 clicks, 18 inputs, 18 navigations, 85 snapshots) |
| Screenshots | 28 (4 explore, 24 scenario, 0 critic), 24 captioned |
| Coverage | 4 pages, 1 forms, 2 flows, 2 console errors |
| Audit | 2 findings, 0 re-verified live, 0 confirmed, 0 promoted, 2 withdrawn |
| Model calls | 142 |
| Tokens | 750,586 input, 7,289 output, 15,681 thinking |
| Time | 7 min |
| Wallet | 0 transactions, 0 signatures, 0 refusals on chain sui:testnet |
| Stage | Calls | Input | Output | Thinking | Seconds |
|---|
| explore | 22 | 106,445 | 1,400 | 2,128 | 57 |
| plan | 1 | 3,488 | 1,527 | 3,714 | 34 |
| test | 117 | 633,485 | 3,766 | 6,044 | 317 |
| critique | 1 | 5,575 | 403 | 3,390 | 28 |
| report | 1 | 1,593 | 193 | 405 | 7 |