TAM aiEngineering / Bug report

TAM ai Bug Report: Missing Email Verification on Signup

Medium / High
Authentication & Security
Issue reproductionSCREEN RECORDING · 00:51

Unverified email signup flow · Reproduction recording

01What's happening?

During the manual signup process, users can create an account using any arbitrary email address (e.g., support@tam.ai.in). The system successfully provisions the account, generates a temporary password, and grants immediate access to the candidate dashboard without requiring the user to verify ownership of the inbox.

02Business Impact

This frictionless signup leaves the platform highly vulnerable to automated bot registrations, spam, and database bloat. Allowing the creation of fake candidate profiles severely degrades the data integrity of the platform, ultimately destroying the value proposition for paying recruiters who rely on a verified talent pool.

03Recommended Fix

Implement a mandatory One-Time Password (OTP) or Magic Link verification step immediately after the initial signup form submission.

Require Verification CheckTypeScript
// Require email verification before provisioning dashboard access
if (!user.emailVerified) {
  return redirect("/verify-email");
}

Block access to the core platform and Candidate Portal until the user explicitly confirms their email address via the verification link.

TAM ai Bug Report: Profile Address Update Failure

Medium / High
State Management & Data Persistence
Issue reproductionSCREEN RECORDING · 00:51

Profile address update silent failure · Reproduction recording

01What's happening?

When a candidate attempts to update their address fields (City, State, Country, ZIP) and clicks "Save Changes", the UI displays a green "Profile updated successfully!" toast notification. However, the form data immediately reverts to its previous placeholder state (e.g., "Fetching city", "NY", "10001"). The user data is not persisting, resulting in a silent failure disguised as a success.

02Business Impact

Candidates are unable to successfully set or update their physical location, which will severely degrade the accuracy of the platform's AI geographic job matching. Furthermore, the false-positive success message creates significant user frustration, as candidates will assume their profile is accurate when recruiters are actually seeing outdated or placeholder location data.

03Recommended Fix

Verify that the PUT or PATCH API endpoint is correctly mapping the payload and writing to the database. Ensure the frontend state management (such as React Query or Next.js Router) is properly invalidating the cache and re-fetching the updated user object after a successful mutation, rather than swallowing an error or dropping the state.

Next.js Server Action / API Cache RevalidationTypeScript
// Ensure the cache is invalidated after the database update
import { revalidatePath } from 'next/cache';

export async function updateUserAddress(formData) {
  await database.user.update(formData);

  // Force the UI to fetch the newly saved data
  revalidatePath("/dashboard/profile");
}

Check the browser's Network tab to confirm the API isn't returning a 4xx validation error that is being improperly caught and handled by a generic success toast.

TAM ai Bug Report: Mock Interview Creation Dead-End

Medium / High
UX Flow & Routing
Issue reproductionSCREEN RECORDING · 01:03

Mock interview creation dead-end · Reproduction recording

01What's happening?

When a candidate clicks the "Mock Interview" button on a job card (e.g., AI Developer), the system triggers a green success toast stating: "Mock interview created successfully. You can start the interview now.". However, no redirection occurs. The user is left stranded on the Job Marketplace, the button state does not change, and clicking it again simply triggers duplicate actions without ever launching the actual interview interface.

02Business Impact

This is a severe UI dead-end. Candidates are told the interview is ready, but have no clear path to actually start it. If creating these mock interviews consumes tokens from the user's "Wallet Balance", frustrated candidates repeatedly clicking the unresponsive button could be silently draining their premium credits without receiving the service, leading to immediate churn and support tickets.

03Recommended Fix

The frontend needs to handle the successful API response by either immediately routing the user to the newly created interview room, or explicitly updating the UI state so they know where to go next.

Next.js Router RedirectTypeScript
// Inside the button's onClick / form submission handler
try {
  const response = await createMockInterview(jobId);

  if (response.success) {
    toast.success("Mock interview created successfully.");
    // Immediately redirect the user to the active interview room
    router.push(`/mock-interviews/${response.interviewId}`);
  }
} catch (error) {
  toast.error("Failed to create interview.");
}

If automatic redirection isn't the desired UX, the button state must change from "Mock Interview" to a disabled "Go to Interviews Tab" to prevent duplicate API calls.

TAM ai Bug Report: Payment Gateway Redirection Failure (500 Error)

Critical / P0
Payments & API Integration
Issue reproductionSCREEN RECORDING · 00:16

Wallet recharge payment failure · Reproduction recording

01What's happening?

When a candidate attempts to purchase wallet tokens and clicks the "Pay" button, the button state changes to "Redirecting to payment..." but immediately triggers a red "Internal Server Error" toast notification. Despite the user trying multiple different token quantities (e.g., 1000, 250, 100, 50) and price points, the system repeatedly throws this unhandled error and completely fails to redirect the user to the payment gateway checkout page.

02Business Impact

This is a catastrophic revenue-blocking bug. Candidates are actively attempting to add funds to their wallet, but the system is blocking the transaction. A broken checkout flow completely halts monetization, drains premium credits without a refill path, and severely damages user trust when handling financial data.

03Recommended Fix

The backend API route responsible for initializing the payment session (likely Stripe or Razorpay) is crashing on execution. This is typically caused by missing environment variables (like secret API keys) in the production environment, an invalid payload structure being sent to the payment provider, or a serverless function timeout.

Next.js Payment Session HandlerTypeScript
// Ensure the API handles checkout creation securely and catches errors properly
try {
  const session = await paymentProvider.checkout.sessions.create({
    amount: calculateTotalAmount(tokens),
    currency: 'INR',
    // ... other required payload data
    success_url: `${process.env.NEXT_PUBLIC_BASE_URL}/wallet?success=true`,
    cancel_url: `${process.env.NEXT_PUBLIC_BASE_URL}/wallet?canceled=true`,
  });

  return NextResponse.json({ url: session.url });
} catch (error) {
  // Log the specific provider error to Sentry/Console
  console.error("Payment Session Initialization Error:", error);
  return NextResponse.json({ error: "Failed to initialize checkout" }, { status: 500 });
}

Check the Vercel/Next.js production server logs immediately to identify the exact stack trace of the 500 error during the checkout session creation.

So, when do I join the team?

I find the bugs, diagnose the root architecture, and write the Next.js code to fix them. Let's jump on a quick call and get these production bottlenecks resolved.