PureStats documentation
Verification and Local Testing
Test PureStats installations, proxies and isolated browser sessions without polluting real visitors or conversion reports.
Automated integration tests must use local fixtures and mocked HTTP, not invented visits sent to production. Documentation and OpenAPI checks are pure reads; no registration, token exchange, DNS mutation or analytics writes are needed to validate them.
Documentation Contract
From the repository root, run the documentation tests:
vendor/bin/phpunit --configuration phpunit.laravel.xml --filter AgentDocumentation tests/Laravel/Agents
The suite checks that every discovery URL resolves through the local Laravel kernel, Markdown bodies have no YAML frontmatter or Inertia wrappers, complete sources appear in llms-full.txt, ETags support conditional GET/HEAD, and responses set no session cookies. OpenAPI checks use canonical contracts, not production accounts. The HTTP workflow test uses in-memory SQLite, ephemeral signing keys and mocked DNS/HTTPS proof to follow discovery, registration, token exchange, idempotent site creation, snippet retrieval and isolated test start/status/stop. It blocks outgoing HTTP and does not publish DNS or fetch a production tracker. Future-only integration requirements must not become live paths or full-documentation features.
Tracker Harness
Before deploying a snippet, inspect the generated HTML or layout for exactly one core tag and the canonical domain. In a local browser harness, intercept tracker, configuration, module and ingestion requests with deterministic fixtures. Assert the initial pageview and each ordinary route transition occur once, consent-required mode sends nothing before consent, excluded paths are suppressed and disabled modules are not loaded.
For a proxy, assert the upstream destination is fixed, raw bodies and queries are retained, asset caching respects validators, and ingestion or authenticated responses are never cached. Test trusted-IP and signature handling locally with fixture secrets that are never production credentials. Reject spoofed forwarding headers at the first trusted ingress.
Real Deployment Evidence
Use the isolated installation-test operations from the quickstart. Start returns a private test_url containing a 64-hex #purestats-test= fragment, a test id, a token, an expiry and isolated: true. The supported real core tracker (version 1.7.2) uses that fragment to send a test pageview through the real ingestion checks with transaction rollback. Test pageviews must not create production visitors, sessions or rollups. Optional replay is skipped, and a passing test is not evidence that every optional module works. Poll the site/client-bound status with the returned id, then stop the test and close its isolated browser profile. Never paste the token-bearing URL into public output or analytics fields.
The token remains scoped to that browser tab through page reloads and navigation. Expired or stopped tests are rejected and never fall through to ordinary tracking. Close the test tab to leave test mode; do not reuse it for normal browsing.
Keep normal production first-hit evidence distinct from isolated test success:
For a real authorized site, distinguish these checks:
- The deployed HTML contains the intended tag and canonical
data-domain. - A normal browser loads the tracker JavaScript without CSP or network errors.
- Tracker configuration and enabled optional modules load successfully.
- A legitimate owner-approved browser visit is accepted by ingestion.
- Installation health or analytics reflects that accepted visit after processing.
A successful script download is not proof of an accepted pageview. A successful ingestion HTTP status is not by itself proof that filtering accepted the event. Do not disable consent, exclusions, DNT or bot filtering to force a pass. A headless automation may be correctly filtered. Report exactly which checks passed and which require an authorized human visit.
Existing verification source and Troubleshooting provide dashboard context. Query installation state through a machine operation only if that operation exists in the live catalog; never infer a private route.