Cardography UAT Guide
Use this page to test Cardography and submit feedback without creating or using an account. Your submission is saved for the site admin to review.
Submit UAT Feedback
Test Guide
Cardography UAT Guide
Purpose
This guide is for user acceptance testing of Cardography before wider promotion or paid member onboarding.
The aim is to confirm that real users can browse the Pokemon card catalogue, register by email, trial the paid workspace, manage a collection, use membership/payment flows, and access help/legal pages without confusion or broken journeys.
Test Rules
- Test on the live site: https://cardography.co.uk
- Use test accounts only.
- Do not test destructive admin actions against real customer data unless a backup has been taken.
- Do not change SSH, firewall, CyberPanel, DNS, server ports, or hosting access settings during UAT.
- Record every failure with the page URL, browser/device, account used, exact steps, expected result, and actual result.
Recommended Test Accounts
Create or use separate accounts for each access level:
| Account Type | Purpose |
|---|---|
| Public visitor | Tests non-logged-in browsing and paywalls. |
| Free member | Tests magic-link login and limited free collection saves. |
| Trial member | Tests 48-hour full-access behaviour. |
| Paid member | Tests paid-only collection tools, images, values, exports, and completion. |
| Admin | Tests admin panels, imports, image controls, values, analytics, layout, and user management. |
Test Browsers and Devices
Minimum coverage:
| Device | Browser | Required |
|---|---|---|
| Desktop/laptop | Chrome or Edge | Yes |
| Desktop/laptop | Safari or Firefox | Recommended |
| Mobile phone | Safari on iPhone or Chrome on Android | Yes |
| Tablet | Any modern browser | Recommended |
For mobile, test both portrait and landscape where possible.
UAT Sign-Off Summary
Use this table at the end of testing.
| Area | Status | Notes |
|---|---|---|
| Public browsing | Not tested / Pass / Fail | |
| Card pages | Not tested / Pass / Fail | |
| Magic-link registration/login | Not tested / Pass / Fail | |
| Membership/trial | Not tested / Pass / Fail | |
| Paid checkout | Not tested / Pass / Fail | |
| My Collection | Not tested / Pass / Fail | |
| Imports/exports | Not tested / Pass / Fail | |
| Completion views | Not tested / Pass / Fail | |
| Sharing/referrals | Not tested / Pass / Fail | |
| Admin tools | Not tested / Pass / Fail | |
| SEO/help/legal pages | Not tested / Pass / Fail | |
| Mobile/accessibility | Not tested / Pass / Fail |
1. Public Visitor Tests
1.1 Homepage Loads
Steps:
- Open https://cardography.co.uk
- Confirm the page loads without login.
- Confirm the Cardography brand, main navigation, search area, and card results are visible.
Expected:
- Homepage returns normally.
- No browser security warning.
- Search results show card thumbnails.
- Navigation includes Search, Membership, Features, Knowledgebase, Account, and More.
1.2 Public Search
Steps:
- Search for `Charizard`.
- Search for `Espeon`.
- Filter by a known set if available, for example `Base` or `Aquapolis`.
- Change view between grid/list if available.
Expected:
- Search results update.
- Results show relevant card names, set names, numbers, rarity/print details where available.
- Public users can see homepage thumbnail images.
- Layout shows a professional card grid and does not overlap on mobile.
1.3 Public Card Page Restrictions
Steps:
- Open a card page from search results.
- Check image and value areas.
Expected:
- Public users can view basic card data.
- Larger card-page images are hidden/paywalled.
- TCGplayer value references are hidden/paywalled.
- The page explains membership options clearly.
- Card name, set, number, rarity, type, release date, print, holo, promo/error fields are visible where available.
1.4 Public Legal and Help Pages
Steps:
- Open `/features`.
- Open `/membership`.
- Open `/knowledgebase`.
- Open `/switch`.
- Open `/legal`, `/terms`, `/privacy`, `/refunds`, `/takedown`, and `/contact`.
Expected:
- Pages load cleanly.
- Takedown is available publicly, not as an account-management action.
- Content makes clear that Cardography is independent/unofficial.
- Membership and feature pages do not show admin-only features.
2. Magic-Link Registration and Login
2.1 Register New Free Member
Steps:
- Open `/register`.
- Enter a test email address.
- Optional: tick the newsletter checkbox.
- Submit the form.
- Open the email and click the magic link.
- Press the final "Continue Signing In" button if shown.
Expected:
- Email arrives.
- Link does not immediately expire.
- User is signed in.
- Account is created with free preview access.
- Newsletter wording is collector-focused: weekly progress prompts, set-building ideas, collection tips, and summaries.
2.2 Login Existing Member
Steps:
- Log out.
- Open `/login`.
- Enter the same email.
- Use the magic link.
Expected:
- User signs in without a password.
- No password reset journey is needed.
- Magic link can only be used once.
2.3 Magic-Link Expiry
Steps:
- Request a login link.
- Wait beyond the configured expiry window, or reuse a used link.
- Try to complete sign in.
Expected:
- Expired/used link is rejected.
- Message asks user to request a new link.
- User is not signed in with an invalid link.
3. Account Page
3.1 Account Details
Steps:
- Sign in.
- Open `/account`.
- Update the email preference checkbox.
- Save.
Expected:
- Account page shows email, sign-in method, membership status, legal/account links, membership actions, collection sharing, and referrals.
- Account links include Terms, Privacy, Refunds/Cancellation, and Contact.
- Takedown is not shown as an account-management link.
- Preference saves and remains selected/unselected after refresh.
3.2 Account Navigation
Steps:
- Open Account menu.
- Move between Account, My Collection, Dashboard, Set Completion, Wanted List, and Admin Panel where permitted.
Expected:
- Account menu is not cluttered.
- Mobile menu opens as a proper menu/drawer and does not sit awkwardly above search results.
- Restricted pages show clear login/membership prompts.
4. Membership and Trial
4.1 Membership Page
Steps:
- Open `/membership`.
- Review non-member, free member, and paid member comparison.
- Open the full Features page link.
- Review trial and paid plan cards.
Expected:
- Membership page clearly distinguishes non-member, free member, and paid member access.
- Trial is visible as 48-hour free access.
- Monthly is shown as GBP 3/month.
- Annual is shown as GBP 30/year.
- 5-year access is shown as GBP 60 one-off/fixed term.
- Terms/privacy/refunds checkbox is readable and aligned.
- Page encourages upgrade without looking cluttered.
4.2 Start 48-Hour Trial
Steps:
- Sign in as a free member that has not used a trial.
- Start the 48-hour trial from Account or Membership.
- Open paid-only areas.
Expected:
- Trial starts without payment card.
- Membership status shows trial with expiry date/time.
- Paid member tools become available during the trial.
- Starting a trial does not trigger referral reward days.
4.3 Trial Already Used
Steps:
- Use an account that already started a trial.
- Try to start the trial again.
Expected:
- Trial cannot be restarted.
- User sees a clear status or paid-plan prompt.
5. Stripe and Paid Access
Use Stripe test mode unless live payments have been explicitly approved.
5.1 Terms Acknowledgement
Steps:
- Sign in.
- Try to choose a paid plan without ticking the terms/privacy/refunds checkbox.
Expected:
- Checkout does not begin.
- User is asked to accept Terms, Privacy Policy, and Refunds/Cancellation.
5.2 Monthly Checkout
Steps:
- Choose Monthly.
- Complete Stripe checkout using test card details if in test mode.
- Return to Cardography.
Expected:
- Stripe checkout opens.
- Billing success page loads after payment.
- Membership updates after Stripe webhook confirms payment.
- Paid-only features unlock.
5.3 Annual Checkout
Repeat the Monthly test for Annual.
Expected:
- Annual plan records correctly.
- Membership status and paid access are correct.
5.4 5-Year Access Checkout
Repeat the paid checkout test for 5-Year Access.
Expected:
- Payment is one-off, not recurring.
- Account receives fixed 5-year paid access.
- Copy avoids "lifetime" wording.
5.5 Billing Portal
Steps:
- Sign in as a Stripe customer.
- Open Account.
- Click Manage Billing.
Expected:
- Stripe billing portal opens if configured.
- User can manage subscription/payment method in Stripe.
6. My Collection
6.1 Free Member Save Limit
Steps:
- Sign in as a free member.
- Save cards to Owned/Wanted.
- Continue until reaching the free save limit.
Expected:
- Free users can save up to the configured limit.
- Limit is currently expected to be 25 unless changed in admin.
- Further saves show upgrade prompt.
- Free users do not get paid-only import/export/value/completion tools.
6.2 Paid Member Collection Management
Steps:
- Sign in as a paid or trial member.
- Add several cards to Owned.
- Add several cards to Wanted.
- Set quantity, condition, grade, and notes.
- Save and refresh.
Expected:
- Rows persist.
- Card name links open the full card page.
- Quantity, condition, grade, notes, and updated date display correctly.
- Owned/wanted filtering works.
6.3 Large Collection Usability
Steps:
- Add or import enough rows to require pagination.
- Test filters: keyword, list, set, condition, grade, group, sort, rows per page.
- Save a view if paid.
Expected:
- Page remains usable with many rows.
- Filters do not lose entered values unexpectedly.
- Pagination works.
- Saved views can be loaded.
6.4 Bulk Actions
Steps:
- Select multiple rows.
- Use bulk action to set Owned/Wanted, condition, grade, or delete.
Expected:
- Only selected rows are updated.
- Deletion requires intentional action.
- Data remains consistent after refresh.
7. Card Pages
7.1 Card Data
Steps:
- Open `/card/3023-aquapolis-espeon-h9-h32`.
- Confirm card details.
Expected:
- Card is Espeon.
- Set is Aquapolis.
- Number is H9/H32.
- Rarity/print/holo data shows where available.
7.2 Related Cards and Variants
Steps:
- Open a card with known variants.
- Review Same Pokemon Across Sets.
- Review Variants.
Expected:
- Related cards link to full card pages.
- Variants are same-set related records.
- Clicking card names and images leads consistently to the full card page or image expansion according to the current design.
7.3 Seed Workbook Holdings
Steps:
- Open a card with seed workbook data, for example a Base2 card.
- Open a card without seed workbook data.
Expected:
- Cards with seed workbook data show "Seed Workbook Holding".
- Cards without seed workbook data do not show a misleading empty table.
- The message "No collection rows matched this card." should not appear.
8. Images and Values
8.1 Public Images
Steps:
- Browse homepage search results as a public visitor.
- Open a card page as a public visitor.
Expected:
- Homepage thumbnails show where image URLs exist.
- Larger card-page images are hidden for non-paying users.
8.2 Paid Images
Steps:
- Sign in as paid/trial.
- Open several card pages.
- Click images to expand.
Expected:
- Larger images display where available.
- Expand interaction works.
- Images have sensible source/identification wording.
8.3 Values
Steps:
- Sign in as paid/trial.
- Open cards known to have TCGplayer data.
- Check My Collection value columns/filtering where available.
Expected:
- Values display only where synced.
- Values are described as reference data, not appraisals.
- Missing values do not break the page.
9. CSV Audit, Import, and Export
9.1 Free Audit
Steps:
- Open `/audit`.
- Upload a clean CSV sample with columns like card name, set name, card number, quantity, condition, grade, notes.
- Run audit.
Expected:
- Audit shows matched and unmatched counts.
- Audit does not save rows to the collection.
- Matched sample links to card pages.
- Unmatched rows are shown without failing the whole process.
9.2 Paid CSV Import Preview
Steps:
- Sign in as paid/trial.
- Open My Collection.
- Upload a CSV through collection import.
- Review preview.
Expected:
- Preview shows matched/unmatched rows.
- User can cancel before import.
- Matched rows show the target card.
- List type and quantity are recognised where provided.
9.3 Confirm CSV Import
Steps:
- Confirm a valid import preview.
- Return to My Collection.
Expected:
- Matched rows are added.
- Unmatched rows are skipped or reviewed according to the preview.
- Imported rows include quantity, condition, grade, notes, and list type where supplied.
9.4 Export Collection
Steps:
- Sign in as paid/trial.
- Export My Collection CSV.
- Open the CSV.
Expected:
- CSV downloads.
- Columns include Cardography card ID, card name, set, number, list type, quantity, condition, grade, notes, and value fields where available.
- Export can be used as an external backup.
10. Set Completion
10.1 Paid Access
Steps:
- Open `/sets` as public/free.
- Open `/sets` as paid/trial.
Expected:
- Public/free users see a membership prompt.
- Paid/trial users see set completion.
10.2 Completion Modes
Steps:
- Review Master Completion.
- Review Set Checklist Completion.
- Review Artwork Completion text/status.
Expected:
- Master Completion counts every variant/print/holo row.
- Set Checklist Completion collapses duplicates by set + card number + card name.
- Artwork Completion is presented as future/reserved unless implemented.
- Percentages and totals are understandable.
11. Sharing and Referrals
11.1 Collection Sharing
Steps:
- Sign in.
- Open Account.
- Enable Public Collection Share.
- Choose whether to show estimated values and wanted count.
- Save.
- Open the generated share URL in a private/incognito browser.
Expected:
- Collection Sharing is separate from Referrals.
- Share URL is generated.
- Public share page is read-only.
- Private notes and email address are not shown.
- Show/hide values and wanted count settings work.
11.2 Referral Link
Steps:
- Open Account.
- Copy referral link.
- Open referral link in a private/incognito browser.
- Register a new test account.
Expected:
- Referral signup count increases.
- New account records the referrer.
- No reward is granted for simply registering or starting a free trial.
11.3 Paid Referral Reward
Steps:
- Use a referred test account.
- Complete a paid checkout in Stripe test mode.
- Allow webhook to process.
Expected:
- Referrer receives configured bonus access days only after confirmed paid membership.
- Free trials do not trigger referral rewards.
- Account page copy says reward is for referred paid members.
12. Knowledgebase
Steps:
- Open `/knowledgebase`.
- Review sections for getting started, sign-in/security, collection, importing, membership/billing, privacy/support.
- Click relevant links from answers.
Expected:
- Knowledgebase is easy to scan.
- Details expand/collapse.
- Links go to correct pages.
- Copy explains workflows in plain language.
13. SEO and Public Indexing
13.1 Robots and Sitemap
Steps:
- Open `/robots.txt`.
- Open `/sitemap.xml`.
Expected:
- Public catalogue, features, membership, knowledgebase, switch, guide, compare, set, Pokemon, and card URLs are allowed/indexable.
- Private account/admin/collection routes are not indexed.
- Sitemap uses `https://cardography.co.uk`.
13.2 Metadata
Steps:
- View page source for homepage, features, membership, a set page, a Pokemon page, and a card page.
Expected:
- Page titles are specific.
- Meta descriptions are relevant.
- Canonical URLs use `https://cardography.co.uk`.
- Structured data is valid enough not to block indexing.
14. Admin UAT
Only admin users should run this section.
14.1 Admin Access
Steps:
- Sign in as non-admin.
- Try `/admin`.
- Sign in as admin.
- Open `/admin`.
Expected:
- Non-admin is redirected/blocked.
- Admin sees Admin Panel.
- Admin menu includes Overview, Imports, Unmatched Rows, Site Copy, Layout, Security, Analytics, Members, Retention, Images, Values.
14.2 Layout Settings
Steps:
- Open `/admin/layout`.
- Review settings.
- Change a harmless display setting such as card columns.
- Save and check homepage.
- Restore if needed.
Expected:
- Settings save.
- Homepage layout updates.
- Paid Referral Reward Days wording is used.
14.3 Site Copy
Steps:
- Open `/admin/content`.
- Adjust a small test phrase.
- Save.
- Confirm public page updates.
- Restore original text.
Expected:
- Copy saves.
- No HTML/script injection occurs.
14.4 Unmatched Rows
Steps:
- Open `/admin/unmatched`.
- Export unmatched CSV.
- Review manual link form.
Expected:
- Unmatched rows are visible if any exist.
- Export CSV downloads.
- Admin can use card IDs to manually link rows.
14.5 Image Controls
Steps:
- Open `/admin/images`.
- Review missing/hidden/active image lists.
- Do not bulk sync large batches during UAT unless agreed.
Expected:
- Page loads.
- Missing images are listed.
- Admin can approve/hide/replace images.
- API failure or missing key should not break catalogue browsing.
14.6 Value Controls
Steps:
- Open `/admin/values`.
- Review synced/missing values.
- Do not bulk sync large batches during UAT unless agreed.
Expected:
- Page loads.
- Values are shown as TCGplayer reference data.
- Missing values are listed without breaking pages.
14.7 Users
Steps:
- Open `/admin/users`.
- Review user list.
- Change a test account membership/role only.
Expected:
- Admin can update user email, membership status, and role.
- Do not modify real users during UAT unless intended.
14.8 Analytics
Steps:
- Open `/admin/analytics`.
- Review top pages, searches, referrers, events, member/trial counts.
Expected:
- Analytics are aggregate.
- Raw IP addresses are not shown.
- Admin traffic is separated/skipped as designed.
15. Mobile and Accessibility
15.1 Mobile Navigation
Steps:
- Open homepage on mobile.
- Use Account and More menus.
- Open search filters.
Expected:
- Menus open cleanly.
- Search filters do not sit awkwardly above results.
- No text overlaps or clipped buttons.
15.2 Keyboard Navigation
Steps:
- Use Tab and Shift+Tab through homepage, membership, account, and collection pages.
- Activate buttons with Enter/Space.
Expected:
- Focus is visible.
- Controls are reachable.
- Skip link works if present.
15.3 Screen Reader/Labels
Steps:
- Inspect form fields and buttons.
- Check image alt text on visible images.
Expected:
- Inputs have labels or clear accessible names.
- Buttons describe their action.
- Card images have useful alt text.
16. Security and Access Checks
These tests must avoid any server firewall/SSH changes.
16.1 HTTPS
Steps:
- Open https://cardography.co.uk
- Check browser lock/security indicator.
Expected:
- HTTPS works.
- No mixed-content warnings in normal browsing.
16.2 Private Routes
Steps:
- Open `/account`, `/my-collection`, `/dashboard`, `/sets`, `/wanted`, `/admin` while signed out.
Expected:
- Private routes require login and/or membership.
- Admin requires admin role.
16.3 Direct App Port
Only run this if server access has been agreed.
Expected:
- Public users should use `https://cardography.co.uk`.
- The app should not require exposing the Node app port directly.
- Do not change firewall, SSH, CyberPanel, or network rules during this check.
17. Regression Checklist
Before sign-off, retest:
- Homepage search.
- Card page.
- Register/login magic link.
- Membership page.
- Account page.
- My Collection.
- Features page.
- Knowledgebase.
- Mobile menu.
- Admin overview.
18. Defect Log Template
Use this format for every issue:
```text
ID:
Date:
Tester:
Device/browser:
Account type:
URL:
Steps to reproduce:
Expected result:
Actual result:
Severity: Critical / High / Medium / Low
Screenshot/video:
Notes:
```
19. Severity Guide
| Severity | Meaning | Examples |
|---|---|---|
| Critical | Blocks launch or paid access | Site down, checkout broken, admin exposed, users cannot log in. |
| High | Major workflow broken | Collection save fails, paid features not unlocked, import corrupts rows. |
| Medium | Important issue with workaround | Filter bug, confusing paywall, layout issue on one device. |
| Low | Cosmetic/content issue | Typo, spacing, minor copy improvement. |
20. UAT Exit Criteria
Cardography is ready for launch/promotion when:
- Critical issues: 0 open.
- High issues: 0 open, unless explicitly accepted.
- Medium issues: accepted or scheduled.
- Public browsing works on desktop and mobile.
- Magic-link registration/login works.
- Membership/trial messaging is clear.
- Paid checkout has been tested in Stripe test mode or live mode as appropriate.
- My Collection works for free and paid access levels.
- Admin tools are restricted to admin users.
- Legal/help/SEO pages are live and consistent.
- A fresh backup exists before any major launch or data import.