All projects

Demo · Multi-vendor marketplace · 2026

NeuroBlend

A coffee marketplace where several roasters sell their products: get in with one click and play the customer, the seller, then the admin, with no sign-up and no real money.

Visit site

Home page of the NeuroBlend demo
automated tests
226
to play, no sign-up
3 roles
of real money: Stripe in test mode
€0

Context

NeuroBlend is not a real shop: it is a technical demo, and its code is public on GitHub. The idea: several roasters sell their capsules on the same site. The customer pays once, the money goes to the seller and the platform keeps its commission. The brand, the shops and the reviews are fictional, and payments go through Stripe in test mode. The demo is in French.

Challenges

  • Show a marketplace from all three sides (buying, shipping, administering) to someone who has no account.
  • Keep a real payment split between the seller and the platform, refunds included, without any real money being able to move.
  • Give an admin account to any visitor without them being able to see another visitor’s orders or damage the catalogue.

What was built

  • One-click entry, three roles

    One button creates three disposable accounts: customer, seller and admin. A banner switches between them to follow the same order from start to finish.

  • Split payment

    The customer pays by card in the Stripe form. The amount goes to the seller, and the commission (10 or 15% depending on the shop) stays with the platform.

  • Order tracking

    The seller sees the order come in, prepares it and ships it. An order only moves in one direction, and only once it is paid.

  • Refunded cancellation

    The admin cancels an order: the customer is refunded, the transfer to the seller is reversed, the commission is returned and the stock comes back.

Under the hood

  • Each visitor has their own sandbox: they see the seeded data (three shops, nine products, fictional orders and reviews) and what they create themselves, never another visitor’s data. A single SQL condition enforces this rule.
  • The seeded data is read-only, regular sign-up and login are closed, entries are capped per IP address and accounts are deleted after 24 hours.
  • An order is recorded before payment and then validated in a single SQL query: a payment confirmed twice only removes the stock once. Amounts are calculated in cents.
  • Before opening, the code was reviewed by an agent with no context, tasked with playing the attacker: no leak between visitors, but two ways to overload the demo, fixed since.