Design principle: This sandbox never silently replaces missing backend capability with fake data. If a required Vendora API feature is not available in Phase 1A, the limitation is documented here and the corresponding UI feature is either absent or shows an explicit "not yet available" state.

Ticket Hold Management

Limitations related to hold lifecycle management.

Backend dependency

Hold status polling (GET /ticket-holds/{reference})

The Vendora Phase 1A API does not expose an endpoint to poll hold status. The hold reference can be used only to release a hold or reference it in a sale.

Workaround: The hold expiry time is returned in the POST /ticket-holds response. The storefront countdown timer uses this authoritative expiry from Vendora.
Backend dependency

Modifying an existing hold

PATCH /ticket-holds/{reference} is not available. To change ticket selection, the existing hold must be released and a new one created.

Workaround: The storefront releases the old hold on cart item removal and creates a new hold.
Partial

Guaranteed hold release on browser close

The storefront sends a best-effort DELETE /ticket-holds/{ref} on cart removal. Holds that expire naturally (e.g. if the browser is closed mid-flow) are released automatically by the Vendora backend when they expire.

Workaround: Hold expiry is the authoritative mechanism. The UI best-effort release is supplementary only.
In scope

Duplicate ticket sale prevention

Atomic locking, final ticket-status validation, idempotency and duplicate-sale protection are Vendora backend responsibilities. This sandbox does not implement or simulate these guarantees — they are provided by the Vendora API.

E-Ticket Delivery

Limitations related to PDF e-ticket generation and delivery.

Backend dependency

PDF sandbox watermark

Vendora does not currently stamp sandbox PDFs with a "SANDBOX — NOT VALID FOR DRAW" watermark. In production, PDFs are authoritative draw tickets.

Workaround: The sandbox label banner on this portal makes the environment context visible. Do not use sandbox e-tickets as proof of entry.
Backend dependency

E-ticket resend

There is no Phase 1A endpoint to trigger a re-send of an e-ticket to the customer email. E-ticket delivery status is read-only.

Partial

E-ticket download when status is QUEUED or FAILED

The PDF download endpoint returns a 404 or 502 if the e-ticket has not yet been generated by Vendora. The storefront shows the e_ticket.status field to indicate availability.

Workaround: Wait for e_ticket.status to be "SENT" before attempting download.

Authentication and Sessions

Limitations related to portal and storefront session management.

P1 — Deferred

Redis-backed session storage

The current sandbox uses in-process memory for session storage. This means sessions are lost on server restart and do not work in multi-process deployments.

Workaround: Set NUXT_SESSION_DRIVER=redis and NUXT_REDIS_URL before deploying to a shared/hosted environment. The rate limiter and session store are structured for Redis drop-in.
P1 — Deferred

Portal session persistence across restarts

Because sessions are in-process, users must log in again after a server restart. This is acceptable for a controlled sandbox but not for a production deployment.

Rate Limiting

P1 — Deferred

Shared Redis-backed rate limiting

Login rate limiting (5/min/IP) uses an in-process sliding window store. In a multi-process or horizontally scaled deployment this does not enforce limits across processes.

Workaround: Configure a Redis-backed rate limiter (NUXT_REDIS_URL) before hosting the sandbox for multiple concurrent users.

Reporting and Analytics

Backend dependency

Aggregate financial reports

The reports:read permission scope and aggregate endpoint are not available in Vendora Phase 1A. The dashboard shows transaction and ticket lists only.

Backend dependency

SMS delivery status

SMS delivery tracking (Vectramind or equivalent) is not available in Phase 1A.

Branding and UI

In scope

Vendor-specific branding

All branding (title, vendor name, colours, labels) is configurable via environment variables (NUXT_PUBLIC_DEMO_*). No third-party logos or trademarks are used in the default configuration.