Skip to content

Debelu improvement scope and initial audit ​

Requested 2 October 2026. This document tracks every requested item and the initial local source inspection. It is not a completion report, an approved design, or evidence of production behavior.

Goal and constraints ​

Make buyer, vendor, admin, and public marketing experiences consistent with the canonical Debelu UI; complete authentication, payment, support, storage, and notification flows. Use packages/ui components and tokens. Marketing and individual stores must not introduce a separate visual system. Interpret “no custom styling” as no page-specific theme, hardcoded palette, or duplicated primitive; responsive composition still needs layout utilities. Confirm that interpretation during design review.

Baseline findings ​

  • The checkout contains pre-existing tracked deletions. Do not silently restore or discard them.
  • Still-imported deleted files include storefront WelcomeOnboarding, vendor StoreHoursField, marketing AuthPageFrame and authEmailLink, and shared pdfBrand. Establish a compiling baseline before implementation.
  • DESIGN.md names shared UI as the source of truth but also permits application theme overrides. The new strict UI requirement takes precedence for the requested marketing and store work.
  • Storage cutover is incomplete in source: core product/branding services still contain Supabase uploads; avatar cleanup, identity verification, and private-file signing also use Supabase. Current production bucket contents were not queried in this audit.
  • userController.getProfile starts virtual-account provisioning without awaiting it and returns the previously fetched profile. Provider completion, refreshed UI, retry behavior, and failure visibility still need validation.
  • VendorService attempts Paystack subaccount creation/update with a configurable percentage defaulting to 5. It catches provider errors, so successful bank setup does not prove subaccount success.
  • PaymentService uses direct splits only when PAYSTACK_SPLIT_PAYMENTS_ENABLED is true; the documented default is escrow followed by wallet credit and approved payout. Production flag values and settlement behavior were not inspected.
  • WhatsApp notification dispatch and signed delivery-event webhooks exist. Actual delivery failure requires tracing provider message IDs and callback outcomes; request acceptance does not prove delivery.
  • ProfileDropdown explicitly left-aligns some menu buttons but omits justify-start on Profile and Log out, while the shared Button centers content.
  • Shared Button supports loading for native buttons; its asChild branch does not propagate the destructured click handler, disabled state, or pending state. Audit real consumers before changing the shared contract.
  • ResponsiveDialog already owns desktop dialog/mobile drawer behavior. Reproduce support scrolling with its consumers and underlying primitives before deciding where the fix belongs.

Requested scope ​

The table records the full acceptance scope. Progress and production evidence follow below; an implemented shared primitive does not establish that every consumer has been audited.

#RequestStarting points / acceptance evidence
1Change-password pageMarketing auth routes and buyer security settings; authenticated change and recovery flows, invalid/expired link handling, validation, successful reauthentication behavior.
2Signup and first-login onboardingAuthGate, deleted welcome component, vendor OnboardingWizard; persistence, interrupted flow, returning-user behavior, role-specific next actions.
3Individual stores strictly use Debelu UILocate store route and compose canonical page, product, navigation and dialog components; mobile/desktop and light/dark review.
4Interactive product-image zoomProduct details/gallery; click, pan, zoom bounds, reset, touch gestures and keyboard dismissal without interfering with image navigation.
5Global app/admin headers and footersApp shells and public/legal routes; consistent legal/support links and responsive navigation appropriate to each shell.
6Marketing strictly uses Debelu UIShared components/tokens; remove custom primitive/theme divergence.
7Nduzi efficiency and performanceChatOrchestrator, ConversationMemory, NduziCache, tool-access/token tests; measure latency, token use, cache behavior and tool correctness before redesign.
8Live tracking redesignShared tracking timeline/modal and order consumers; truthful statuses, accessible progression and mobile layout.
9Automatic real bank accounts on profilePayment DVA service, profile controller and webhook; provisioning lifecycle, eligibility failures, retry, profile refresh and idempotent wallet credits.
10Wallet and profile wallet header redesignBuyer WalletView, ProfileOverview, vendor VendorWalletPage; balances, account details, transactions and actions with clear financial states.
11Skeletons match contentShared and app skeletons; map each loading branch to its loaded page/card dimensions.
12WhatsApp notifications failingNotification function and WhatsApp webhook; trace queued, accepted, delivered and failed states using actual provider evidence.
13Dark-theme white hover buttonsShared button variants and consumer overrides; contrast in default, hover, focus, pressed, disabled and pending states.
14Separate support new-ticket/history buttonsSupportCenterView; distinct creation and history actions with loading, empty and error states.
15Marketplace profile context and menu alignmentProfileDropdown and app header; correct account identity and left-aligned actions across viewport sizes.
16Proper state management for all buttonsInventory async actions; pending, duplicate-submit prevention, success, failure and retry, including links rendered as buttons.
17Considered optimistic loadingInventory mutation ownership and cache keys; reversible updates with rollback and race handling. Financial success stays server-confirmed.
18Check all storage migration to R2Audit all uploads, reads, deletes and durable references, then production inventory; authorized private access, verified copies and rollback before retirement.
19Dynamic Explore filters and cleaner copyExplore state/header/sections and catalogue API; data-driven tabs/counts, URL state, empty results, removal of unnecessary promotion explanations.
20End-to-end wallet transaction disputesBuyer/vendor wallet, transaction detail, dispute service/controller and admin resolution; eligible transaction binding, ownership, evidence, replies and final state.
21Unified mobile modal scrollingResponsiveDialog, Drawer/Dialog, support chat and related consumers; constrained scroll regions, keyboard/safe-area behavior and agreed bottom-nav placement.
22Spacious vendor dispute pageVendorDisputesPage, list and chat; readable desktop list/detail and mobile navigation without crowded action rows.
23Vendor settings follows buyer profileVendor settings sidebar/panel/subviews and buyer profile navigation; direct subpage URLs, back behavior and unsaved edits.
24Validation across input typesFrontend forms and backend validators; required fields, bounds, whitespace, phone/email/URL, dates, files and financial numbers; accessible field errors.
25Debelu tooltips replace raw HTMLShared Tooltip; audit title uses, preserve accessible labels, support keyboard/touch and avoid redundant tooltip text.
26Facebook, WhatsApp and other store social linksSocialSettingsView, public store rendering and persistence; normalize/validate supported URLs and phone links.
27Store SEO and indexingStore routes, storefront SEO and marketing sitemap; public crawlable content, canonical URLs, per-store metadata and valid structured data. Indexing itself is controlled by search engines.
28Admin granular control and missing featuresAdmin routes, middleware, permissions and UI; feature/permission matrix with server-side authorization, audit records and buyer/vendor workflow coverage.
29Validate bank subaccount and 5% splitVendor bank service, payment initialization, delivery settlement, wallet and payout paths; verify fee basis, single/multi-vendor handling and no duplicate settlement.
30Marketing content and sophisticated interactionsPublic pages and home page; truthful content, working links, useful interactions, reduced-motion behavior and canonical UI. Combine visual-system migration with item 6.
  1. Establish the baseline and shared UI behavior: resolve still-imported missing modules after confirming deletion intent; modal scrolling, button states/contrast, tooltips, profile menu and support navigation. Shared changes reduce repeated page repairs.
  2. Authentication, onboarding and account experience: password flows, onboarding, wallet/profile, vendor settings and validation.
  3. Financial and operational correctness: DVA lifecycle, split/escrow audit, end-to-end transaction disputes, WhatsApp evidence, storage migration and admin capability audit.
  4. Storefront and discovery: stores, gallery zoom, tracking, dynamic Explore and page-specific skeletons.
  5. Marketing and store SEO: shared public chrome, all marketing pages/content/interactions and crawlable stores.
  6. Nduzi performance: use measured baseline and agreed response-quality criteria to select changes; validate independently of visual redesign.

An all-at-once rewrite makes financial and shared-component regressions harder to isolate. UI-only work first improves visible behavior sooner but leaves financial dependencies unresolved longer. The sequence above starts with shared foundations and follows with explicit financial verification.

Verification boundaries ​

Baseline check: npm run type-check completed with exit code 1 on 2 October 2026. Errors include missing marketing auth modules, missing shared pdfBrand, unresolved @debelu/ui / @debelu/core imports and downstream typing errors. These findings predate product implementation in this session. Diagnose workspace resolution separately from the tracked deletions; do not assume all reported errors share one cause.

Run targeted behavior tests and workspace type checks for each batch, then responsive visual checks at phone, tablet and desktop sizes in light/dark themes. Test actual failure/retry paths, keyboard focus and long content. Financial workflows need webhook replay/idempotency and authorization tests; migration needs checksums and authorized private reads. Record local, deployed and provider-confirmed evidence separately. This audit makes no live configuration, message, payment, migration or deployment changes.

Progress verified on 2 October ​

Shared Button now guards pending/disabled native and slotted actions, including nested dialog controls. Shared modals have explicit body scrolling, separate footers, navigation/safe-area clearance, opener focus restoration and nested mobile drawers. Support conversation updates preserve initial history, confirmed replies and newer drafts across request races. Support creation/history actions are separate, with accessible validation and shaped loading states. Profile menu actions align consistently. Canonical tooltips replace native DOM titles in the audited consumers. Shared button variants pass light/dark hover contrast checks.

Product galleries now open the shared image viewer with bounded wheel, keyboard, pan and pinch controls. Closing a nested mobile viewer preserves the parent drawer and page scroll lock. The latest focused suite passes 25 tests; nested drawer browser checks pass in system Chrome and Edge. All workspace type checks and production builds pass. Earlier full suites passed storefront 219, backend 213, admin 63, marketing 25 and notification functions 29 tests. Existing lint and large-bundle warnings remain. Physical Safari and mobile keyboard behavior are not verified. These working-tree changes are not claimed deployed.

Read-only production audit, 2 October ​

The user's confirmed Railway account contains discerning-exploration; its service is debelu-backend at api.debelu.com, with Redis. The backend deployment is active and has R2 configuration variable names present. Values were not revealed. Absence of the direct-split flag from the visible service variables agrees with the source default of escrow, but does not prove provider settlement settings. Four virtual accounts are persisted and three seller bank rows have subaccount codes; their Paystack fee settings still require verification.

Cloudflare R2 contains one observed bucket, debelu-product-images, with four objects (134.73 kB). Its custom domain cdn.debelu.com is active and enabled. Supabase still contains 40 objects across seven buckets: product-images 13, vendor-branding 2, avatars 12, identity-verification 4, dispute-evidence 6, attachments 3, products 0. Migration is incomplete. Private identity, evidence and attachment files require authenticated delivery; they cannot be moved into the public product bucket. No objects were copied or deleted.

The correct Supabase project is havugmqmyplqgbrlthhs. deliver-notification is deployed and its overview reports two invocations without function errors. The Meta Debelu app is live, all four English utility templates are active with quality pending, and the messages webhook field is subscribed at v26.0 to https://api.debelu.com/api/whatsapp/webhook. Old runbook statements about pending templates or an unpublished app are superseded by this observation.

Two WhatsApp delivery rows are marked sent and have provider IDs, but neither matches a stored status callback. The sole delivered callback has a different message ID. Provider acceptance therefore does not establish delivery to those recipients. The sampled profiles have three WhatsApp opt-ins and 35 opt-outs. The function intentionally limits WhatsApp to opted-in order/payment/dispute/security notifications and respects quiet hours. No live messages, account registrations, tokens, billing changes or deployments were made during these checks.

Subsequent approved production repair: the WABA-level “Subscribe webhooks” switch was off despite the app-level messages subscription. The user explicitly approved enabling this connection. The switch now shows on for the Debelu account. This permits real account events to reach the configured callback; a future matching delivery receipt remains required to verify message delivery. No messages were sent.

Subsequent local financial repairs: provisioning now withholds bank details when durable account mapping fails, rejects malformed accounts, avoids creating a new account after a failed provider lookup, and shares simultaneous requests for the same user within one backend process. This is not a distributed provisioning lock. Focused backend durability and existing split/DVA tests pass (19 tests). The account hook ignores stale/disabled/previous-owner responses and rejects incomplete data (four tests). Buyer profile overview now requests and displays the real wallet bank account with loading, retry and copy states; these changes are not deployed.

Released under Proprietary Enterprise License.