Public Visitor
- Home
- Discover events
- Host events CTA
- Sign in/Register
- Events listing
- Search/filter/sort
- Open event detail
- Event detail
- About
- Booking tab
- Seat-map tab
- Checkout entry
Home is the central brain. Each branch shows role entry points, menu items, and workflows testers must verify.
Brand header, Discover, Sign in/Register, Host events, public navigation, role routing.
Create venue -> create reusable seat map -> create reserved/non-reserved sections -> upload seat-map PDF/image -> create future event -> attach exact seat map -> configure event ticket prices -> publish.
Discover event -> choose Booking tab -> select reserved seat or non-reserved quantity -> assign ticket types -> checkout -> signed Stripe webhook -> ticket/QR issued.
Review organiser application -> approve -> configure non-conflicting fee rules -> monitor Stripe/readiness -> verify no secrets or unsafe states.
Try role escalation, ID swapping, forged payment redirects, unsigned webhooks, XSS labels, unsafe uploads, and cross-tenant access.