# AI Web Command: pre-launch validation

Status: not launch-ready. This checklist distinguishes passing local checks from untested or unfinished product flows.

## Verified locally on 2026-09-28

- SaaS production build passes; 13 Vitest tests pass; targeted ESLint passes.
- Site Agent PHP lint passes for 53 files; its three JavaScript files pass syntax checks. WordPress PHPUnit tests could not run because the WordPress test suite/phpunit is unavailable locally.
- Woo Bridge 0.1.1 PHP lint passes. Its product mapping now prioritizes variation IDs and uses the Woo account email before billing email.
- Login renders at `http://localhost:3000/login`; with Docker stopped, the demo login now displays a useful database-unavailable message instead of a parse error.
- Dashboard navigation and overview no longer present browser-only MCP, activity, settings, or site-action controls as live features.

## Must finish before public launch

1. **WooCommerce identity and billing:** configure a real storefront with WooCommerce Subscriptions, six mapped products/variations (monthly and annual for each tier), bridge shared secret, HTTPS SaaS URL, and SSO URL. Test checkout, trial, payment, renewal, cancellation, on-hold, failed payment, refund, upgrade/downgrade, and an email change. Confirm account identity and entitlement in SaaS after each event. Add reliable retry/reconciliation for bridge failures and out-of-order/replayed entitlement events.
2. **Licensing:** the plugin now uses a signed, site-bound entitlement with a 48-hour validity window, and SaaS syncs it on pairing/Woo events plus a production cron. Live-test expiration, cancellation, downgrade/over-limit behavior, credential revocation, and recovery after a WordPress outage. The cron and Woo webhook delivery must be observed on production before launch.
3. **MCP:** implement the hosted, authenticated MCP endpoint and real per-client authorization. Current MCP policy screens are local preview data; no ChatGPT/Claude/Gemini/Grok connection should be advertised as active yet. Test read-only, writes, approval, audit, revocation, and multi-site isolation.
4. **Site lifecycle:** implement server-backed health checks, credential rotation/revocation, and site removal. Current pairing stores a scoped encrypted credential, but its initial Connected state is not a live heartbeat. Verify that disconnecting or changing Woo entitlement actually stops remote actions.
5. **Network security:** pin verified public DNS addresses for outbound WordPress calls, or use equivalent egress controls, to prevent DNS rebinding between validation and connection. Verify redirect rejection, TLS, timeouts, response limits, rate limiting, and malformed responses.
6. **WordPress integration:** install the current Site Agent ZIP on a staging content site and a WooCommerce/Elementor site. Test pairing, read-only/full access, token revocation, checkpoints and restore, snippets, Elementor edits, plugin updates, AI Chat storage/retrieval, and upgrade from an older plugin ZIP without duplicate installation.
7. **Data and UX:** run real browser tests on desktop/mobile after PostgreSQL is available. Confirm login/logout, pairing expiry and retry, site-limit messages, billing display, empty states, slow/unavailable WordPress, and no secrets in browser storage/logs beyond the short-lived pairing code.
8. **Release operations:** configure production secrets, backups, migrations, monitoring, support/recovery procedure, legal billing/guarantee copy, and a staged rollout. Verify the store and SaaS domains and all callbacks over HTTPS.

## Next test sequence

1. Start Docker Desktop, apply checked-in Prisma migrations, and seed the local demo. Recheck the dashboard and pairing UI.
2. Configure a staging WooCommerce store and SaaS bridge; run signed SSO and entitlement tests with a test customer and mapped subscription.
3. Pair one staging WordPress site from the Site Agent plugin. Verify token scope and revoke it from WordPress.
4. Finish licensing, MCP, lifecycle, and network-security blockers above before inviting external customers.
