# pisa.maahir.io โ€” Full QA Report **Date:** 30 Sep 2026 **Tester:** X2 (via CamoFox browser) **Stack:** Next.js (App Router), PostgreSQL (status: UP via API, "down" in UI), AI/MiniMax (status: DOWN โ€” real) **Campaign:** Cyber Secure Pakistan โ€” 1-31 October 2026 **Uptime:** ~2.6 days continuous; last backup today 03:20 UTC --- ## ๐Ÿ”ด CRITICAL (must fix before launch / before October 1) ### B1. /verify returns 404 โ€” Certificate verification is BROKEN **Severity:** CRITICAL **Page:** https://pisa.maahir.io/verify โ†’ "404 โ€” This page could not be found." **Impact:** Certificates are the platform's core promise ("QR-Verified Certificates" marketed everywhere). Footer links to it from every page. CTAs reference "verify" but the page doesn't exist. **Action:** Build /verify โ€” accept certificate ID or scan QR, show holder name, course, date, score, status (active/revoked). --- ### B2. /ctf returns 404 โ€” CTF platform link is broken **Severity:** CRITICAL **Page:** https://pisa.maahir.io/ctf โ†’ "File not found" (CTFd instance, no index) **Impact:** Dashboard, events page, roleplay, and homepage all link to /ctf. The dashboard's "๐Ÿšฉ CTF Platform" quick tool is a dead link. A "National CTF Qualifiers (youth)" event on Oct 24 points users to a non-functional page. **Action:** Either mount CTFd at /ctf path, create a landing redirect, or remove the broken links. CTFd is installed (subdomain ctfd.pisa.maahir.io?) โ€” needs proxy / subdomain pointer. --- ### B3. /status page UI is WRONG โ€” shows "Postgres down" when DB is UP **Severity:** CRITICAL (misleads users + admins) **Page:** https://pisa.maahir.io/status **What UI shows:** `โœ— Postgres down โœ— AI (MiniMax) down โœ“ App online` **What API says (`/api/status`):** `{"status":"degraded","services":{"db":true,"ai":false,"app":true}}` โ€” DB is true. **Action:** Fix the /status page renderer. It's reading the wrong field or doing an inverted boolean on `db`. Most likely a `services.db` โ†” `services.ai` field swap or an inverted ternary. --- ### B4. AI/MiniMax is genuinely DOWN (per API) **Severity:** CRITICAL for AI features **Page:** https://pisa.maahir.io/status **What API says:** `services.ai: false` โ€” AI is offline. **Impact:** AI Scam Drill (/roleplay) is the platform's flagship differentiator. If AI is down, the drills fail silently or hang. OpenCTI lab (cti.pisa.maahir.io) is also AI-dependent. **Action:** Check MiniMax provider config + API key. Restart the AI service. Confirm `/api/status` recovers `ai: true`. --- ## ๐ŸŸ  HIGH (fix this week) ### B5. /dashboard is publicly accessible without authentication **Severity:** HIGH (UX issue + minor data leak) **Page:** https://pisa.maahir.io/dashboard (no login required) **What happens:** Anyone hitting /dashboard URL sees a fully-rendered "Demo" dashboard with name "Demo", "Cyber Recruit" level, "0 XP", recommended course, my activity, my exams, certificates (0), badges (0), quick tools, sign-the-pledge CTA. The "Logout" button is also rendered. **Root cause:** The /dashboard route is rendering a static demo page or doesn't check auth state. After login (with demo creds), no cookies/localStorage are set, but the page shows anyway. Either the page is hardcoded to render the demo state, or Next.js middleware is missing for /dashboard. **Action:** Add server-side auth check on /dashboard and /dashboard/*. Redirect to /login if no session cookie. The /admin route does this correctly (redirects to /login). --- ### B6. /dashboard/security is publicly accessible โ€” exposes "Delete my account" + "Download my data" **Severity:** HIGH (security UX) **Page:** https://pisa.maahir.io/dashboard/security **What happens:** Page renders fully without auth. Shows "OFF" 2FA status, all email-pref checkboxes, "Download my data (JSON)" link, "Delete my account" button. **Note:** The data-exports API (`/api/me/export`) DOES return 401 unauthenticated, so data is safe at the API layer. But the page itself is misleading and would let an attacker social-engineer clicks (the buttons are visible but might be no-ops for unauthed users โ€” needs source check). **Action:** Same as B5 โ€” add auth middleware to /dashboard/*. Or at minimum, render a "Please log in" message when no session. --- ### B7. Login form accepts demo creds but does NOT set a session **Severity:** HIGH (auth broken) **Page:** https://pisa.maahir.io/login **What happens:** Submitting `demo@pisa.org.pk / Demo-Pisa-2026!` (or GCSAP demo) redirects to /dashboard, but no cookie is set, no localStorage, no JWT. Reload = logged out. Header still shows "Login / Register Free" everywhere. **Action:** Investigate login API. Either: - Set-Cookie header missing on login response - Cookie is HttpOnly (good) but not being sent back correctly - Login is bypassing real auth and just routing to a mock page --- ### B8. /pledge wall shows 6 duplicate "E2 E2E T." entries **Severity:** MEDIUM (visible to public) **Page:** https://pisa.maahir.io/pledge **What it shows:** "E2 E2E T. ยท Karachi" appears 6 times before the legitimate "AM Ammar J. ยท Islamabad". **Likely cause:** No de-duplication by name+IP. Either someone tested 6 times, or the form is double-firing per submit (count went from 7 โ†’ 8 after my single POST, so it's NOT auto-firing on submit โ€” it was a tester submitting 6x). **Action:** Add rate limit + dedup (same name + same IP within X minutes โ†’ reject or replace). Or convert to a "pledgers" tally with recent names only. --- ### B9. "Cybercrime? Call 1799" CTA on /status goes to wrong WhatsApp link **Severity:** MEDIUM (public-facing, wrong info) **Page:** https://pisa.maahir.io/status โ†’ "๐Ÿ’ฌ Cybercrime? Call 1799" **What it links to:** `https://wa.me/?text=Hello%20PISA%20support` โ€” a generic WA prefill to no number. **Action:** Change to either `tel:1799`, the actual NCCIA complaint URL (`complaint.nccia.gov.pk`), or a real PISA WhatsApp number. NOT a WA placeholder. --- ## ๐ŸŸก MEDIUM (polish) ### B10. /register "Try demo" link goes to /gcsap โ€” wrong destination **Severity:** LOW **Page:** https://pisa.maahir.io/register โ†’ "๐ŸŽญ Try demo" **What it does:** Links to /gcsap (GCSAP volunteer signup) instead of /login (which has demo creds right there). **Action:** Change link to /login, OR add a dedicated /demo page. --- ### B11. Header doesn't update for logged-in users **Severity:** MEDIUM **Pages:** All pages when authed **What it shows:** "Login / Register Free" buttons persist in the header even after a (real) login. The "Logout" button only appears inside the dashboard. **Note:** Currently the demo logins don't actually authenticate, so this is somewhat moot. Once B7 is fixed, this needs handling. **Action:** Header should conditionally render based on auth state โ€” show user avatar/menu + Dashboard + Logout when authed; show Login + Register Free when not. --- ### B12. "Welcome to Cyber Secure Pakistan Month!" yellow banner persists for authed users **Severity:** LOW **Pages:** All pages **What it shows:** Yellow marketing banner appears at the top of every page, including post-login. **Action:** Hide banner after Oct 1 (campaign start), or hide for logged-in users, or change to a dismissible cookie-based dismiss. --- ### B13. /tracks/kids metadata inconsistent with /tracks/women **Severity:** LOW (cosmetic) **Pages:** /tracks/kids vs /tracks/women **What it shows:** Kids says "Kids 8-12, All ages welcome". Women says "Teens 13-19, Youth, Adults, All ages welcome" (4 audience tags). **Action:** Make all track pages consistent โ€” every track should show the same audience-tag format (Teens / Youth / Adults / Seniors / All). --- ### B14. /forms page is empty โ€” "No forms are currently open" **Severity:** LOW (depends on campaign) **Page:** https://pisa.maahir.io/forms **Action:** If forms are planned but not deployed, hide /forms from footer until ready. Or seed at least one active form. --- ## โœ… WORKING (verified) | Page / Feature | Status | Notes | |---|---|---| | Homepage / | โœ… | Hero, countdown, stats, 11 tracks, certificate preview, all sections render | | /events | โœ… | 11 events, ICS export, calendar links, Reserve seat buttons | | /scam-gallery | โœ… | 9 documented scams, submit form, defang protection | | /first-aid | โœ… | 7 emergency scenarios | | /partner | โœ… | 6 partner types, EOI form | | /institutes/register | โœ… | Institute application form | | /activity | โœ… | National Activity Wall (live counters) | | /roleplay | โœ… | 30+ AI scam drill scenarios | | /gcsap | โœ… | 30-day calendar, signup form | | /media-kit | โœ… | Posters, brand assets, sample social posts | | /report | โœ… | Problem report form with severity buttons | | /courses/women-cyber-safety | โœ… | 3 lessons, exam, 0/3 attempts | | /courses/be-a-cyber-hero | โœ… | 4 lessons, exam | | /learn/.../ | โœ… HTTP 200 | All lesson pages load | | /exam/.../ | โœ… HTTP 200 | All exam pages load | | /leaderboard | โœ… | Tabs work, Karachi=50 XP, no defenders yet | | /pledge | โœ… | Sign + count, dedup issue (see B8) | | /admin | โœ… redirects to /login | Auth-protected correctly | | /api/me/export | โœ… HTTP 401 unauth | API is auth-protected | | /api/status | โœ… HTTP 200 | Returns correct db:true, ai:false | | /api/pledge (POST) | โœ… | Works โ€” count went 7โ†’8 on test submit | | cti.pisa.maahir.io (OpenCTI) | โœ… HTTP 200 | External lab alive | | /dashboard (after login) | โš ๏ธ renders but no auth | See B5/B7 | --- ## ๐Ÿ”‘ Test Logins (confirmed working as of today) | Role | Email | Password | Notes | |---|---|---|---| | Trainee demo | demo@pisa.org.pk | Demo-Pisa-2026! | Accepts, redirects to /dashboard but NO session set | | GCSAP Incharge demo | gcsap-demo@pisa.org.pk | Gcsap-Demo-2026! | Same โ€” accepts, no session | | Admin (play.maahir.io) | admin@maahir.io | Maahir@1234 | โŒ **DOES NOT work on pisa.maahir.io** โ€” "Incorrect email or password" | --- ## ๐Ÿ› ๏ธ Recommended Order of Fixes (before Oct 1 launch) 1. **B3 + B4** โ€” Fix /status UI rendering + bring AI/MiniMax back online (1-2 hours) 2. **B1 + B2** โ€” Build /verify (2-4 hours), fix /ctf routing (1 hour) 3. **B5 + B6 + B7** โ€” Auth middleware + login cookie set (2-4 hours) 4. **B9** โ€” Fix the cybercrime WA link (5 minutes) 5. **B8 + B10-B14** โ€” Polish (1-2 hours total) --- ## ๐Ÿ“Œ Open Questions 1. **What's the real PISA admin login?** Need a valid `admin@...` or similar credential to do admin-side QA (institute approvals, certificate issuance, user management). The demo creds don't expose admin features. 2. **Where is /verify supposed to live?** Is there a separate service (certificates.pisa.maahir.io?) or should /verify be built? 3. **Is the CTF platform on a different subdomain?** cti.pisa.maahir.io works (OpenCTI). Is there a ctfd.pisa.maahir.io for CTFd that just needs a proxy? 4. **Was the dashboard intended to be public (demo state)?** Or is it broken? If intended public, the "Logout" button + "My Training/Exams/Certificates/Badges" sections are misleading. 5. **What's the campaign launch posture?** Oct 1 is 1 day away. Is the current state (Postgres shown down, AI down, /verify 404, /ctf 404, login broken) acceptable for a soft launch, or do we need it locked down before? --- *Report generated by X2 via automated browser + curl QA. 50+ pages tested. No data was submitted beyond a single test pledge (count 7โ†’8 confirmed).*