🚨 CRITICAL: All core infrastructure tests must pass before any other module testing
.envContent-Security-Policy header presentGeneric Database
Catalog Database
Bot Database
Session Redis (DB 0)
redis-cli -n 0 ping → PONGCatalog Redis (DB 1)
redis-cli -n 1 ping → PONGBot Redis (DB 2)
redis-cli -n 2 ping → PONGBasic Health Check
/health → 204 No ContentReadiness Check
/ready → 204 No Content/api/core/* routes load without 404Index Page
/ → Serves index.htmlSPA Fallback
/nonexistent-route → Serves index.html (not 404)Static Assets
/robots.txt → Serves robots.txt/sitemap.xml → Serves sitemap.xml/favicon.ico → Serves favicon or 404/../../../etc/passwd → 404 or safe response/..%2f..%2f..%2fetc%2fpasswd → 404 or safe response404 Handling
/api/nonexistent → Clean 404 JSON response500 Error Handling
Health Endpoint Performance
/health → Response time < 50ms/ready → Response time < 50msStatic File Performance
/ → Response time < 200ms/api/*