Skip to content

API, provider and configuration dependency audit ​

Frontend pins in 00. Backend remote refs were independently verified with GitHub branch API: dev 03da862e70c67e461ee2e0e15ab5fd649171e908, main d2ba30c3d5facae4420a2a2b8c24b819bb44911b. Backend repository inspected read-only. No backend or scraper change is required for the evidenced redesign.

Final challenge: no Express/scraper code changes, not “no server work.” All39 PORT/ADAPT items have manifest backendAssessment. New Next action needs frontend server validation/config; contact/provider settings already exist. Binding mode matrix and bounds are in 11§8–10. Questionnaire/lessons are required; only Discord delivery optional. Default local mode remains enabled, with no send and no receipt claim. Missing private invite yields an explicit unavailable final step, not a placeholder. No catch-all/affiliate proxy changes are planned.

Contract ledger ​

Consumer / sourceRequest or assumptionCurrent dev supportMigration instruction
_components/InquiryForm.tsx:14,82–101Same-origin POST /api/contact, JSON {name,email,message,company,turnstileToken}; 20s AbortController; non-2xx error JSON; generic successFrontend app/api/contact/route.ts identical in main/dev, blob cefd3b337b9901c408b67ffddafc74370debcf1aReuse route and dev shared/components/common/InvisibleTurnstile. No new Bloxclips-backend endpoint or CORS change. Test handler with provider mocks.
Existing Next contact handlerTrims/validates name ≤100, email ≤254, message ≤3000; company honeypot; Turnstile verification then ResendAlready present. Requires server TURNSTILE_SECRET_KEY, RESEND_API_KEY; optional sender/recipient. Browser key NEXT_PUBLIC_TURNSTILE_SITE_KEYKeep contract. Do not call it with valid real credentials during audit tests. Existing provider-body error logging is not justification to include raw bodies in new logging.
Backend src/api/routes/contact.tsExpress POST /api/contact; Zod schema, rate limiting, duplicate suppression/contact attempts and emailPresent on backend dev and main; selected files have no main/dev diffDistinguish backend origin route from same-origin Next route. Do not move the new form to Express as accidental cleanup; that changes suppression/error behavior and deployment requirements.
Contact CalendlyInlineLoads https://assets.calendly.com/assets/external/widget.js; embeds https://calendly.com/bloxclips/on-boarding, listens only to https://calendly.com messagesNo BloxClips API neededPort widget lifecycle/fallback. Existing backend src/api/routes/bookings.ts remains in use by other flows; do not delete it or migrate its schema. No real booking was submitted.
_components/Roblox.tsx:33GET /api/roblox/game/:placeId → {title,playing,visits}Frontend dev supports subset plus universeId, description, mediaImages, mediaVideosKeep dev handler. Main handler is smaller and would regress game detail/gallery consumers. Validation is numeric placeId; upstream/cache semantics are already implemented.
_components/Roblox.tsx:55GET /api/roblox/thumbnail/:placeId → {imageUrl}Identical main/dev handler blob 011dc918845fb09472ad468601688dc326262869Reuse; network failure gives text/art fallback. Remote Roblox CDN images are ordinary img elements, not a reason to change API.
New creator submitApplicationNext server action payload `{track:string,links:string,answers:Record<string,stringstring[]>}`; optional Discord webhook POST embedNo equivalent feature/action/backend route on dev; no matching backend creator-application symbol was found
Creator action returnUnset webhook, fetch error, or non-2xx still returns ok:true, delivered:false; client fires without awaitingThis is a source gap, not a working intake guaranteeEducation continues in explicit local mode. Delivery mode awaits truthful result; missing webhook makes no send and no receipt claim. Test success/failure/timeout with mocks.
Creator _progress.tslocalStorage application + lesson count, no account/sessionNew public browser-only stateValidate parsed object, known track and finite integer progress 0..5. Never use it for RBAC, verification, private campaign eligibility or earnings.
Creator final DiscordPublic build-time invite environment variable, placeholder fallbackNot configured in repository; deployed value unknownAdd documented env name and safe unavailable UI; never publish literal REPLACE-WITH invite. Public community, guide Discord and private-team Discord are distinct destinations.
Marketing network stats100k+/1B+/1M+/$600K+ sourced from owner presentation, static source recordsDev existing live-count hook uses another meaning: provider membershipsTreat as editorial claims. Retain /api/live/clipper-count and useClipperCount; no Whop API change follows from using a static marketing band.
Affiliate links/r/:code rewritten by current next.config to backend to set cookie on browser-visible originPresent in devBroad main catch-all may win before fallback rewrite. Require integration test using controlled backend redirect/Set-Cookie. Do not delete referral behavior because main lacks equivalent new architecture.

New configuration versus preserved configuration ​

New frontend keys to document (names only; do not commit values):

  • ROBLOX_GAMING_UGC_DISCORD_WEBHOOK_URL: server secret, optional delivery integration. Never NEXT_PUBLIC_, never sent to client.
  • NEXT_PUBLIC_ROBLOX_GAMING_UGC_DISCORD_INVITE_URL: public invite URL for completed private-track education. Required only to enable that destination.
  • MARKETING_INDEXABLE: new server-only indexing opt-in; only literal true on authorized production enables public marketing indexing/sitemap. Default false, including staging/preview; do not infer it from NODE_ENV.

Keep existing NEXT_PUBLIC_API_URL, NEXT_PUBLIC_WHOP_ENVIRONMENT, NEXT_PUBLIC_DISCORD_OAUTH_ENABLED, contact settings, Whop server settings and documented aliases. NEXT_PUBLIC_WHOP_ENVIRONMENT=live is the explicit live discriminator in dev; everything else resolves sandbox. Marketing migration must not switch that value, authenticate a live account or remove its UI badge.

No new auth cookies, request credentials, API base URL, server actions for campaigns, file-upload contract, CORS configuration, financial status values, account fields, funding APIs or scraper queue messages are introduced by the marketing design. The Google logo patch is already represented by dev LoginCard. Main's other dashboard edits are terminology inside old implementations, not useful new product contracts.

Why backend-main migration is unnecessary ​

The only relevant public API reads are served by current frontend Next routes; contact is identical and Roblox is supported by a newer dev superset. Backend main/dev contact and booking route files were compared directly and are identical at the pinned refs. The optional application integration calls a provider from a new Next action, with no evidence of missing Express implementation or data schema. Therefore there is no reason to inspect unrelated backend branches or metric-scraper, or recommend backend changes based on old frontend code. Reopen this conclusion only if implementation uncovers a new requirement (for example durable applications or real private-team approvals); that is product scope expansion, not an implicit redesign dependency.

Verification limits ​

Source contracts and local public render paths were verified. Third-party availability, Turnstile, real mail delivery, Discord membership/delivery, Calendly scheduling and production cookie/CORS configuration were not exercised. Browser capture blocked external resources; local server-side Roblox GETs may still reach public upstreams. No provider write operation was performed. Tests for future implementation must mock these boundaries or use an explicitly authorized controlled environment.