Antelier/ journeys
2026-09-08 11:40 UTC
JOURNEY REPORT · Northwind Bookings (demo app) · demo app (local) · 2026-09-08 11:40 UTC

5 of 5 journeys passed · access audit not run · repair not evaluated

No action is needed for these 5 journeys. The access audit (who can read which rows, whether keys are exposed) has not been run on this app; ask whoever maintains it to run antelier supabase check before relying on this report.

Since the last run

First run for this app.

Journeys

passedsign up and reach the dashboard
as user a · 6 steps
1 · open /signup
passed
2 · fill Email
passed
3 · fill Password
passed
4 · click Sign up
passed
5 · url matches /dashboard
passed
6 · text "Welcome"
passed
Step 1 of 6
passedmake a booking and see it in the list
as user a · 9 steps
1 · open /signup
passed
2 · fill Email
passed
3 · fill Password
passed
4 · click Sign up
passed
5 · url matches /dashboard
passed
6 · fill Service
passed
7 · fill Date
passed
8 · click Book
passed
9 · text "Beard trim on 2026-09-30"
passed
Step 1 of 9
passedanother customer does not see that booking
as user b · 6 steps
1 · open /signup
passed
2 · fill Email
passed
3 · fill Password
passed
4 · click Sign up
passed
5 · url matches /dashboard
passed
6 · text "No bookings yet"
passed
Step 1 of 6
passedcancel the plan and lose dashboard access
as user a · 9 steps
1 · open /signup
passed
2 · fill Email
passed
3 · fill Password
passed
4 · click Sign up
passed
5 · open /settings
passed
6 · click Cancel plan
passed
7 · text "Plan cancelled"
passed
8 · open /dashboard
passed
9 · url matches /signup
passed
Step 1 of 9
passeda visitor who never signed up cannot open the dashboard
as a signed-out visitor · 3 steps
1 · open /dashboard
passed
2 · url matches /signup
passed
3 · text "Create your account"
passed
Step 1 of 3

Access findings

Audit receipt file not recorded · migration revision not recorded
SeverityWhereWhat we foundEvidence
Access audit not run. If this app runs on Supabase, antelier supabase check with the owner's token checks row-level security, anonymous reads and keys in the client bundle; other backends are not audited in this version. Until it runs, access is unknown, not clear.

Finding → Repair → Verified

Finding

No finding run attached to this repair.

Repair

no repair prepared

The repair is prepared from access findings; run the access audit first.

Verified rerun

no rerun since the repair

What this did not check

The access audit (antelier supabase check) has not been run on this app; who can read which rows, and whether keys are exposed, is unknown. · Only the configured journeys and assertions were checked. Browser visibility does not prove API isolation or physical data erasure. · Payments, other devices, third-party origins and unlisted workflows were not checked. · No migration was applied. Screenshots may contain app data; keep reports private. · Demo app: real browser run against the local Northwind fixture server. · Access audit not available for unknown backend in this version; journeys still apply. · Stack: unknown; backend: unknown. Repository fingerprints do not prove the deployed stack or project ownership.