Please enable JavaScript.
Coggle requires JavaScript to display documents.
WaltonPlaza QA view · 2026-10-04 · 182 test cases in 32 files · DEF…
WaltonPlaza QA view · 2026-10-04 · 182 test cases in 32 files · DEF-001…049
Lives inside order-service. Discounts surface only through cart calculation.
-Customer
-Shipping Address
-Payment
-Product
-Discount
-Promocode
✅ QA coverage
✅ cart_formula.test.js (6, 2 locked)
✅ vat_calculation.test.js (3)
✅ cash_handling.test.js (2, 1 locked)
✅ mixed_discounts.test.js (2)
suite: feature:cart
Gotchas
fingerPrint: increase/decrease/setCartShippingAddress use server uuid
request full price block or formula reads ৳0
🐞 Shipping charge
🐞 DEF-016 weight-based bucket hardcoded 'STEADFAST'
🐞 DEF-039 shipping rates hardcoded, config model unread
🐞 DEF-040 delivery discount multiplied twice
🐞 DEF-047 getShippingCharge can't quote cross-area
🐞 Defects
🐞 DEF-001 promo drops to ৳0 on add/remove/qty
🐞 DEF-007 EMI gateway hidden forever after isEmiDisable item
🐞 DEF-008 COD cashHandlingCharge never added to payable
🐞 DEF-017 campaign stock released on any cart action
🐞 DEF-028 unbounded cart trace-log document
🐞 DEF-030 setCartShippingAddress silent null on fingerPrint
🐞 DEF-043 raw TypeError shown to customer
🐞 DEF-044 regular discount overwrites campaign rate
🐞 DEF-049 increase/decrease not atomic
✔️ DEF-004 addProductToCart null platform-wide
✔️ DEF-029 P0 addProductToCart null (out-of-lockstep deploy)
✔️ DEF-032 DEF-029 fix introduced new null
promotion-service. Never bake a live discount into a golden-master test.
-Zone
-Product
-Seller
-Campaign
-Category
-Customer
✅ QA coverage
✅ product_discount.test.js (6, 1 locked)
✅ category_discount.test.js (7, 2 todo)
✅ delivery_discount.test.js (4)
suite: feature:discount
Free delivery: payable STRICTLY > minimumOrderValue, same area
🐞 Defects
🐞 DEF-022 discount upTo cap never enforced
🐞 DEF-046 no role can soft-delete a discount
Tier A — reference/campaign-service. FLASH_SALE pricing + precedence.
-Product
-Zone
-Promocode
-Time
-Flash Sale
-Seller
-Category
✅ QA coverage
✅ campaign_discount.test.js (6, 3 locked)
suite: feature:campaign
🐞 Defects
🐞 DEF-017 campaign stock released on any cart action
🐞 DEF-044 regular rule overwrites campaign rate
🐞 DEF-045 campaign date window not enforced
Tier A — reference/inventory-service. Normal stock covered only through cart/order paths.
⚠️ -Stock Management
⛔ -Return Management
✅ Old Stock (aged inventory)
✅ old_stock.test.js (6, 2 todo)
✅ k6: load:old-stock:* (smoke→soak)
🐞 Defects
🐞 DEF-009 COD cancel keeps holdQuantity
🐞 DEF-020 hold-quantity stock guard disabled (precedence bug)
🐞 DEF-033 Old Stock POS sync wipes holds (hQyt: 0)
🐞 DEF-034 Old Stock check ignores age key
🐞 DEF-035 cancel never releases Old Stock hold
reference/search-service present; no API suite.
⚠️ -Product
⛔ -Seller
covered only via e2e-guest storefront search
user-service (Tier A).
⛔ -Seller Follow
✅ -Shipping Address
✅ -Customer Info
⚠️ -Order History
⛔ -Voucher
✅ -Product Wishlist
✅ -Reward point
⚠️ QA coverage
✅ customer_account.test.js (4)
✅ wishlist.test.js (5)
suite: feature:account
🐞 Defects
🐞 DEF-005 updateCustomerProfile null no-op
Tier A source, read-only dependency (getOrderForSystem). Not tested.
⛔ -Sms
⛔ -Email
⛔ -Push
⛔ -Inapp
Tier B; order-service calls applyComission.
⛔ -Category
⛔ -Seller
⚠️ Cache Service*
✅ redis_product_cache.test.js (1 locked)
⛔ Log Service*
Pub/Sub*
⛔ -Event log
⛔ -Access Log
⛔ -Activity Log
⛔ -Matrix log
⛔ Account Service*
⛔ -Stock
⛔ -Payment
⛔ -Sales
⛔ -Delivery
⛔ -Seller
⛔ -Category
⛔ -Inventory
⛔ -Vat/Tax
⛔ -Discount
⛔ -Commission
⛔ -Refund
⛔ -Ledger
⛔ -Trial Balance
⛔ -Profit&Loss
⛔ -Balance Sheet
Gateway & platform
GraphQL superset: 253 ops, 39 wired for this instance
always HTTP 200 — check statusCode in body
✅ rate limits: test:ratelimit
Mongo standalone — no multi-doc transactions
~28 services under PM2
Tier A — reference/order-service. Checkout orchestrator; 43 proxy files call nearly every other service.
-Customer
-Shipping Address
-Payment
-Product
-Discount
-Promocode
✅ QA coverage
✅ order_creation_contract.test.js (2)
✅ order_lifecycle.test.js (11, 1 locked)
✅ customer_journey.test.js (14) — addProductToCart → createOrder
suites: test:journey · feature:checkout · feature:order-management
Golden-master formula
subTotal = Σ mrpPrice × qty
customerPayable = subTotal − totalDiscounts + payableShipping + vat [+ emiCharge]
orderattempts 5/user/day → JOURNEY_ORDER_BUDGET
🐞 Defects
🐞 DEF-003 order total vs line-item gap (no Mongo transactions)
🐞 DEF-009 COD cancel never releases holdQuantity
🐞 DEF-014 FLAT discount × qty on order recalculation
🐞 DEF-015 post-order edits hardcode COD, no EMI
🐞 DEF-021 updateOrderForInventory empty catch
🐞 DEF-025 reOrder empty catch
🐞 DEF-027 cancelOrder commits before promo-usage rollback
🐞 DEF-035 cancelOrder never releases Old Stock hold
🐞 DEF-036 reOrder bills no delivery charge
🐞 DEF-037 createOrder rollback adds VAT twice
promotion-service. Two-layer model: create/update = config, check/apply = transaction.
-Product
-Seller
-Customer
-Zone
-Campaign
-category
✅ QA coverage
✅ promocode.test.js (19, 6 locked)
suite: feature:promocode
Rule: valid only if isPublic (customer can discover it)
TC-JRNY-003 blocks on invisible code
🐞 Defects
🐞 DEF-024 SUB_TOTAL/DELIVERY codes apply raw config value
🐞 DEF-041 isPublic not enforced on apply
✔️ DEF-042 promocode discounted aged (Old Stock) line
promotion-service reward-config. Referral/Signup earning not covered.
-Referral
-Earning point
-Signup
-Rules
-Purchase amount
✅ QA coverage
✅ reward_points.test.js (4)
suite: feature:reward
earn = round(rewardedAmount × point / expenseAmount) · 1 pt = ৳3
🐞 Defects
🐞 DEF-006 points not persisted after order
🐞 DEF-018 redeem preview lost balance check
✔️ DEF-002 ৳12 silent reward mismatch
Tier A — reference/payment-service. Calls back into order-service (payment-mismatch seam).
-COD
-Nagad
-Brac City
-DDBL
-Bkash
-SEBL (EMI)
-UCB
-TBL
Matrix-collapse: 4 classes
✅ COD — full flow once
⚠️ mobile wallet — delta only
⚠️ card/bank gateway — delta only
✅ EMI — emi_policy.test.js (9)
✅ QA coverage
✅ payment_gateway.test.js (3, 1 locked)
✅ e2e: test:e2e-emi-sebl (MPGS sandbox)
✅ e2e: test:e2e-ucb (CyberSource sandbox)
⚠️ Old Stock × EMI (2026-10-04)
✔️ G-1 fresh aged unit lost EMI — fixed on dev
✔️ G-2 EMI then aged add — createOrder guard added
🐞 G-3 makePayment(EMI) on aged COD order — API only
🐞 G-4 reOrder no stock/EMI checks
🐞 Defects
🐞 DEF-007 EMI gateway permanently hidden
🐞 DEF-019 UCB webhook trusts client signed_field_names
Tier A — reference/category-service. Source of cart's getProductsDiscount. Content/SEO deliberately not tested.
⚠️ Product Service*
-Varient
-Tag
-Category
⛔ Category tree
-Electronic Devices
-Electronic Accessories
-TV & Home Appliances
⚠️ QA coverage
✅ product_reads.test.js (5, 1 locked)
✅ catalog_config.test.js (14, 2 locked) — Full mode
✅ e2e: test:e2e-home · test:e2e-browse · test:e2e-guest
🐞 Defects
🐞 DEF-010 updateAttributeSet throws on partial update
🐞 DEF-011 updatePromotionalCategory slugify crash
🐞 DEF-012 getFilterStockProducts always null
🐞 DEF-038 vatType FLAT unimplemented
🐞 DEF-048 homepage card prints ৳0
Tier A — reference/auth-service. DEF-023 RETRACTED, row kept.
-Operator
-Customer
-Seller
-ACL
⚠️ QA coverage
✅ auth.test.js (2)
✅ rate-limit harness: test:ratelimit
Budget: loginaattempts 10/user/day (binding on prod)
CSRF not operative anywhere (docs/CSRF-FINDINGS.md)
🐞 Defects
🐞 DEF-013 OTP CSRF bypass by omitting field
🐞 DEF-026 REMOVE-PROMO-FROM-ORDER in no seed role
DEF-023 customer role privilege gap
Tier B. Exercised indirectly through delivery-discount and shipping tests.
-Service Zone
-SubZone
-Master Zone
area match drives delivery discount + shipping rate
Tier B.
⛔ -Commission
⛔ -Zone
⛔ -Tag
⛔ -Category
Tier B.
Tier B.
⛔ Report Service*
⛔ -Payment
⛔ -Sales
⛔ -Order
⛔ -Purchase
⚠️ Clients
✅ Client Web+
✅ Playwright: guest, browse, home, buy-now, EMI/UCB pay
✅ prod: test:prod:smoke · prod:calc · prod:roles (read-only)
⛔ Client Ios App+
⛔ Client Android app+
🐞 G-3 EMI repay path unchecked
⛔ content protall+
⛔ BD Portal+
⛔ CS portal+
⚠️ Management Protal+
operator token used for order edits only
⛔ Account Portal+
⛔ Inventory Portal+
Note
'*' Means Microservice
'+' Means Client
'-' Means Component
✅ deep QA coverage
⚠️ partial coverage
⛔ not tested
🐞 open / suspected defect
✔️ fixed (locked regression)
ℹ️ rule / fact