# pisa.maahir.io — QA Report (v2 — Re-Test)

**Date:** 30 Sep 2026, 18:30 PKT (re-test)  
**Original QA:** 30 Sep 2026, 13:00 PKT  
**Tester:** X2 (via CamoFox browser + curl)

---

## 🎉 Fixes Confirmed Since Original Report

The PISA team deployed fixes in the ~5 hours since the original QA report. Verified live now:

| Bug | Original Status | Current Status | Verified |
|---|---|---|---|
| **B1** — /verify returns 404 | 🔴 Critical | ✅ **FIXED** — page exists with cert-ID input + Verify button |
| **B3** — /status UI shows wrong db/ai state | 🔴 Critical | ✅ **FIXED** — now correctly shows ✓/✗ matching API |
| **B4** — AI/MiniMax genuinely down | 🔴 Critical | ✅ **FIXED** — `/api/status` returns `{"ai":true}` |
| **B8** — /status "Cybercrime? Call 1799" CTA goes to generic WA | 🟠 High | ✅ **FIXED** — now correctly links to `tel:1799` |

**Status banner now reads:** "All systems operational · 0h uptime · 0 errors · Last backup 12h ago"

---

## ❌ Bugs Still Open

### B2 — /ctf still returns 404 🔴 CRITICAL
CTFd is installed (footer "Powered by CTFd") but index page is missing. The dashboard, /events, and /roleplay still all link here. The Oct 24 "National CTF Qualifiers (youth)" event points users to a non-functional page. **CTF is the platform's flagship gamification feature and it's still 404.**

---

## 🟠 High Severity — Still Open

### B5 — /dashboard still publicly accessible without authentication
Hitting `/dashboard` with no cookie still renders the full dashboard (now upgraded to "Demo" → "Cyber Cadet" Level 2 with 50 XP). The header still shows "Login / Register Free" instead of a logged-in menu. /dashboard/security also still shows "Delete my account" + "Download my data" to anonymous users.

### B6 — Login form doesn't set a session
Demo creds (demo@pisa.org.pk / Demo-Pisa-2026!) still accept and redirect to /dashboard, but no cookie is set. Reload = logged out.

### B7 — /pledge wall duplicates (untested post-fix)
Could not retest in this window — original finding was 6× "E2 E2E T." entries with no dedup.

### B9 — Header doesn't update for logged-in users
Same root cause as B5/B6.

---

## 🟡 Medium Polish — Untested / Still Open

- **B10** — /register "Try demo" → /gcsap (wrong dest)
- **B11** — Yellow campaign banner persists after launch
- **B12** — /tracks metadata inconsistent across pages
- **B13** — /forms page empty
- **B14** — /dashboard/security exposes "Delete my account" (same fix as B5)

---

## 📊 Updated Scoreboard

- 🔴 Critical: **4 → 1** (B2 still open)
- 🔴 High: **5 → 4** (B8 fixed)
- 🟡 Medium: **5 → 5** (unchanged)
- ✅ Working: **25+** (verified working, no regressions)

**Net: 3 critical + 1 high fixed in ~5 hours. 1 critical + 4 high + 5 medium remaining.**

---

## 🛠️ Remaining Fix Priority (Pre-Oct 1)

1. **B2** — /ctf routing (1 hour, biggest visible issue)
2. **B5+B7+B9** — Auth middleware + login cookie set + header reactivity (3–4 hours)
3. **B10–B14** — Polish (1 hour)

*Report updated 30 Sep 2026 18:30 PKT · Original at /report.md*