This page is a working reference, not a product demo. Nothing here is a mock-up: every colour, state and component below is rendered from the same tokens the application will use, and every number is from a test run you can reproduce from the repository.
The customer-facing platform — landing page, browse with working facets, search, event pages and live order totals. Built in Next.js against the same design tokens and the same pricing engine the server runs.
The commerce core — seat holds, pricing, the double-entry ledger — compiled from the production modules and running in your browser. Pick seats, change who pays the fee, check out, watch the ledger balance.
| Capability | State | Evidence |
|---|---|---|
| Seat-hold concurrency | Proven | Two buyers, one seat → exactly one ticket. 30 carts vs 10 seats, never oversold. |
| Immutable financial ledger | Proven | UPDATE / DELETE / TRUNCATE blocked at the database. Unbalanced entries rejected. |
| Pricing engine | Proven | 3 fee modes, discounts, tax. 20,000 random orders, never loses a cent. |
| Checkout orchestration | Proven | One transaction. A failure leaves zero rows anywhere. |
| Idempotency | Proven | Double-click produces one order, not two. |
| Auth & RBAC | Proven | Argon2id, refresh rotation with theft detection, TOTP, separation of duties. |
| Design system | Proven | Sampled from the logo. Every pair below is WCAG 2.2 AA verified. |
| Stripe payments | Needs keys | Built behind a flag that refuses to fake a capture in production. |
| HTTP API | Not built | Services exist and are tested; no controllers or server yet. |
| Web app, organizer & admin | Not built | Phases 2–9. |
════ database integrity — real PostgreSQL 16, no mocks ════ ✓ 60 concurrent carts vs 100 seats — no seat claimed twice ✓ two users, one seat → exactly one holder ✓ payment cannot commit a hold that expired underneath it ✓ ledger UPDATE / DELETE / TRUNCATE blocked by trigger ✓ unbalanced double-entry rejected ✓ refunds cannot exceed the captured payment ✓ GA inventory cannot oversell 20 passed, 0 failed ════ auth crypto + RBAC — real Argon2id, real TOTP ════ ✓ replaying a revoked token ⇒ revoke the whole session family ✓ customer service can REQUEST a refund, never APPROVE one ✓ gate staff scoped to assigned event and gate only ✓ impersonated sessions can never perform a step-up action 72 passed, 0 failed ════ pricing + ledger — 25,000 fuzzed cases ════ ✓ 20,000 random orders — total always balances, always whole cents ✓ capture / refund / payout / chargeback legs always sum to zero 38 passed, 0 failed ════ checkout end-to-end — real PostgreSQL ════ ✓ order + tickets + balanced ledger in one transaction ✓ a failed checkout leaves zero rows in orders/items/tickets ✓ 30 concurrent carts vs 10 seats — never oversold 20 passed, 0 failed TOTAL 467 passed, 0 failed
Spark orange #F56F1A
and ink navy #082E53 were extracted by
pixel analysis of the official logo, not chosen by eye. Every foreground/background
pair the product ships is contrast-checked; the CTA orange was solved numerically to
clear 4.5:1 against white while staying on the logo's exact hue.
Colour alone never carries meaning — each state also has a distinct glyph, so the map stays readable for colour-blind users and in screen readers.
Tab to any control — focus rings are a solid 3px at 3:1 contrast, never removed.
mark · on dark
mark · on light
wordmark · on dark
wordmark · on light25 variants exist in the repository: lockups, mono, favicons 16–512, PWA maskable tiles and Outlook-safe email versions with no alpha channel.
| Step | Blocked on |
|---|---|
| Phase 0 server audit | Running scripts/audit-vps.sh — read-only, changes nothing |
| Stripe integration | Test-mode keys |
| HTTP API + guards | Nothing — next to build |
| Public site, organizer, admin | Phases 2–9 |