From 27bcb7188e3ffe90b71084b72da633253a2b2794 Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Thu, 23 Jul 2026 22:22:28 +0300 Subject: [PATCH] Document isolated development SMTP verification --- docs/verification.md | 25 ++++++++++++++++++++++--- 1 file changed, 22 insertions(+), 3 deletions(-) diff --git a/docs/verification.md b/docs/verification.md index f424f76..61f853c 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -16,6 +16,23 @@ edit, branch, or tag was made during this audit. and all 341 ExUnit tests. The configured image scans reported zero vulnerabilities, and the run left no project-scoped quality containers, networks, volumes, or one-run image tags. +- A dedicated Brevo SMTP key and verified sender + `Who Need Help Development ` were configured only in the + ignored local development `.env`. Brevo reported the sender domain as + authenticated with DKIM and DMARC. A release-container delivery probe sent one + non-authentication verification message to the operator inbox without + creating application or database data; Brevo's transactional log recorded + `Sent`, `Delivered`, and `First opening` for that exact subject and sender. + The disposable probe container was removed, and no test or production sender, + key, environment, container, or deployment was changed. The running dev + replicas deliberately still use their earlier runtime environment until the + remaining Google/Firebase credentials are ready for one controlled rebuild. +- `./scripts/check-environment-readiness.sh .env` now reports external SMTP, + the support inbox, application secrets, browser VAPID, Android App Links, and + Android signing inputs as ready. Its three remaining development blockers are + the Google OAuth client pair, the four public Firebase Android values, and the + FCM service-account credential. No release-readiness claim is made until those + credentials are imported and provider/device behavior is exercised. - Two web and two worker replicas, PostGIS, Mailpit, Traefik, and the scoped Docker socket proxy were running after the audit. Both web replicas and both workers were healthy; public liveness and readiness returned `ok` and @@ -1310,9 +1327,11 @@ None of the observations below describe the current delivery path. been registered. - Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring, and the availability model selected for real usage. -- After provider approval, verify that delivered MIME contains neither open nor - link tracking and omits the unsubscribe block, then exercise registration and - magic-link delivery through the deployed application to a real mailbox. +- The development Brevo SMTP transport and sender have completed an external + delivery probe. After the controlled dev rebuild, exercise registration and + magic-link delivery through the deployed application itself and inspect the + received message. Repeat the same post-deploy application flow for production + only after the final release scope is reviewed and explicitly approved. - Exercise registration, sign-in, and settings linking against the production Google OAuth client on its exact HTTPS callback origin after the tested release is explicitly promoted. The test client and callback have already