Authenticate & Stabilize Core App Functions
Budget: $30 – $250 NZD
Core Stability, Auth & Early Readiness Phase
Objective:
Ensure the application has a stable, secure foundation by validating authentication, core APIs, and critical data flows, while also addressing a few high-impact areas that reduce risk for later phases.
Scope of Work:
Full testing of user onboarding & authentication
(signup, email verification, login, session handling, password reset)
Validation of core APIs (auth + primary data APIs)
– correct responses, permissions, and no exposure of sensitive data
Review and validation of Row Level Security (RLS) on critical tables
Fixing all auth- and API-related issues identified during testing
Additional (Early Coverage for Future Phases):
Smoke testing of key user flows (dashboard access, data load, basic navigation)
Initial performance sanity check (page load behavior, obvious bottlenecks)
Basic security sanity checks aligned with fintech best practices
(no deep OWASP scan yet, but early risk identification)
Deliverables:
Stable and verified authentication flow
Working and secured core APIs
List of issues found + fixes applied
Clear technical summary confirming readiness to proceed to deeper testing.
Objective:
Ensure the application has a stable, secure foundation by validating authentication, core APIs, and critical data flows, while also addressing a few high-impact areas that reduce risk for later phases.
Scope of Work:
Full testing of user onboarding & authentication
(signup, email verification, login, session handling, password reset)
Validation of core APIs (auth + primary data APIs)
– correct responses, permissions, and no exposure of sensitive data
Review and validation of Row Level Security (RLS) on critical tables
Fixing all auth- and API-related issues identified during testing
Additional (Early Coverage for Future Phases):
Smoke testing of key user flows (dashboard access, data load, basic navigation)
Initial performance sanity check (page load behavior, obvious bottlenecks)
Basic security sanity checks aligned with fintech best practices
(no deep OWASP scan yet, but early risk identification)
Deliverables:
Stable and verified authentication flow
Working and secured core APIs
List of issues found + fixes applied
Clear technical summary confirming readiness to proceed to deeper testing.