Live preview of the Stage 1 NestJS scaffold. Every action below is a real same-origin API call.
Renders the real 40-question instrument from GET /growth-audit/questions.
Submissions now persist (GET /growth-audit/:tenantId below the form).
POST /nps — categorizes one response, persists it, and shows any
triggered notification. Submissions now count toward a real tenant-wide NPS score.
POST /customers — a rating's customerId must reference a
real row here (Postgres mode enforces this with a foreign key; in-memory mode never did).
POST /ratings — starts 'pending'; moderate to 'public' before it counts.
POST /consent/grant and the DSAR export endpoint.
POST /auth/login against a demo account seeded for this preview only.
POST /auth/register exists but isn't demoed here — it requires an
authenticated owner-role caller (see "Auth/RBAC" in the README), and
the seeded demo account is staff.
POST /auth/mfa/enroll/start and /confirm — both now require a real
access token (log in above first). tenantId/userId are no longer
request fields at all: they come only from whatever account your access token actually
belongs to, computed here with the browser's own Web Crypto API (RFC 6238 TOTP,
HMAC-SHA1) — the same algorithm src/modules/auth/totp.ts uses server-side,
no authenticator app needed to click through this demo.
PATCH /auth/tenants/notification-phone — where real WhatsApp
notifications (Growth Audit bands, NPS detractors, moderated ratings) for this
tenant are actually sent, owner-only. Needs a real access token (Auth card above).
GET /social/:tenantId/connect — a real Facebook Login OAuth flow (not a
manually-pasted Graph API Explorer token — Meta's own App Review requirement is that
this happen "on your app platform"). Once connected, create/edit/delete a real post on
your connected Page via POST/PATCH/DELETE /social/:tenantId/posts.
If that Page has a linked Instagram professional account, post there too via
POST /social/:tenantId/instagram-posts (image required — Instagram has no
text-only post).