Reproduce before repair
Confirm the repository, lockfile, environment contract, database schema, audit version, and a clean local or staging build before changing financial behavior.
Next.js 15 · Prisma · PostgreSQL · audit-led repair
An existing audit is evidence, not a fixed scope. This sprint converts the highest-risk findings into named code changes, targeted tests, a client-owned staging release, and a defensible decision on the remaining platform.
CONTROLLED REMEDIATION
Confirm the repository, lockfile, environment contract, database schema, audit version, and a clean local or staging build before changing financial behavior.
Convert the existing audit into three agreed critical fixes with affected routes, abuse case, expected behavior, and observable acceptance criteria.
Test authentication, authorization, webhook replay, idempotency, balance mutation, scheduled jobs, and audit logging in sandbox or test data.
Deploy to a client-owned staging environment, document changed files and limitations, and keep live withdrawals disabled until acceptance evidence is signed off.
THE $800 BOUNDARY
Deposits, withdrawals, balances, admin controls, bots, migrations, and production deployment cannot responsibly be treated as one unknown fixed-price task. The first milestone proves the codebase and removes a defined critical slice.
ACCEPTANCE EVIDENCE
Reproducible commands, environment requirements, and known setup exceptions.
Finding-to-file map, abuse case, changed behavior, and explicit remaining risk.
Targeted automated checks plus manual evidence for the agreed financial and admin paths.
Client-owned staging URL, configuration checklist, rollback note, and fixed continuation quote.
READY INPUTS