Record production launch verification
This commit is contained in:
parent
c56c2cebd3
commit
4fd340d705
|
|
@ -129,10 +129,10 @@ as forward-only rather than receiving an invented database rollback.
|
||||||
- [ ] The production Android build signs in, opens verified App Links, receives
|
- [ ] The production Android build signs in, opens verified App Links, receives
|
||||||
FCM, and performs user-started foreground location sharing on a physical
|
FCM, and performs user-started foreground location sharing on a physical
|
||||||
device.
|
device.
|
||||||
- [ ] The full two-person help flow passes: create, discover, accept, chat,
|
- [x] The full two-person help flow passes: create, discover, accept, chat,
|
||||||
optional tracking, start, handover code, both confirmations, blind review,
|
optional tracking, start, handover code, both confirmations, blind review,
|
||||||
report/block, and notification delivery.
|
report/block, and notification delivery.
|
||||||
- [ ] The Activity flow passes: create, request to join, approve/decline,
|
- [x] The Activity flow passes: create, request to join, approve/decline,
|
||||||
withdraw, rejoin, group chat, exact-location disclosure only after
|
withdraw, rejoin, group chat, exact-location disclosure only after
|
||||||
approval, and reporting.
|
approval, and reporting.
|
||||||
- [ ] Support, privacy/data, account-deletion, general content-removal, and
|
- [ ] Support, privacy/data, account-deletion, general content-removal, and
|
||||||
|
|
|
||||||
|
|
@ -3,6 +3,64 @@
|
||||||
Observed through 2026-08-03 in the local workspace. This report separates observed
|
Observed through 2026-08-03 in the local workspace. This report separates observed
|
||||||
results from product limits and unknown production properties.
|
results from product limits and unknown production properties.
|
||||||
|
|
||||||
|
## Public/mobile and Android candidate check on 2026-08-03
|
||||||
|
|
||||||
|
- A headed Chrome audit captured the production home at desktop and 390 × 844
|
||||||
|
mobile viewports, the signed-out requests handoff, support, account deletion,
|
||||||
|
general content removal, and the dedicated TAKE IT DOWN form. No record was
|
||||||
|
submitted. The accepted screenshots showed no confirmed horizontal overflow,
|
||||||
|
clipped primary action, blank state, or public navigation dead end. DOM
|
||||||
|
snapshots contained skip links, semantic landmarks, visible field labels,
|
||||||
|
and explicit safety/privacy guidance. The ignored evidence and audit notes
|
||||||
|
are retained under `output/playwright/production-launch-audit-20260803/`.
|
||||||
|
- The authorised physical device exposed both the production and an obsolete
|
||||||
|
development package. The exact development package
|
||||||
|
`org.whoneedhelp.mobile.development` was removed; the production package and
|
||||||
|
its data were not changed. The remaining `org.whoneedhelp.mobile` reports
|
||||||
|
version code `1`, version name `0.1.0`, target SDK `37`, and launches without
|
||||||
|
an Android fatal exception in the sampled log.
|
||||||
|
- Pulling the installed production base APK produced SHA-256
|
||||||
|
`d079a42809155faa86da72281c985f01d4134097e4410cdfbf244869b3027d21`,
|
||||||
|
exactly matching the source-bound universal APK in
|
||||||
|
`android/dist-release-20260803-162910/`. Notification and fine/coarse location
|
||||||
|
permissions remain denied until user opt-in; the foreground-service location
|
||||||
|
permission is declared/granted by the platform.
|
||||||
|
|
||||||
|
This verifies the sideloaded candidate and its visible launch state. It does
|
||||||
|
not replace a Play-delivered internal-track test or prove FCM and verified App
|
||||||
|
Links under the Play App Signing certificate.
|
||||||
|
|
||||||
|
## Production browser E2E on 2026-08-03
|
||||||
|
|
||||||
|
The production verifier first confirmed the exact target as detached commit
|
||||||
|
`b80bf6e9a551ff49a6201f0d2c726b1b8a63e95a`, Compose project
|
||||||
|
`who_need_help_production`, database `who_need_help_production`, and the single
|
||||||
|
healthy compact application container with zero restarts. The run did not
|
||||||
|
deploy source, reset or migrate the database, change real-user roles, send
|
||||||
|
email, edit Caddy, touch the frozen test project, or push Git.
|
||||||
|
|
||||||
|
- Chromium passed both production scenarios in 46.0 seconds. The mutual-aid
|
||||||
|
scenario exercised two users, medicine discovery and acceptance, private
|
||||||
|
realtime chat, consent-based tracking, helper replacement, handover-code
|
||||||
|
verification, both-party completion, reporting signals, and blind reviews.
|
||||||
|
The Activity scenario exercised creation, join request, organizer approval,
|
||||||
|
exact-location privacy, participant chat, reporting, moderation, withdrawal,
|
||||||
|
and rejoining.
|
||||||
|
- The verifier created six confirmed run-scoped synthetic users and only their
|
||||||
|
manifest-owned records. Its cleanup removed the exact fixture after success.
|
||||||
|
Before and after snapshots both contained 14 users, 1 audit event, 1,441 Oban
|
||||||
|
jobs, and zero help requests, assignments, messages, activities, activity
|
||||||
|
participants/messages, reports, reviews, tracking sessions/positions,
|
||||||
|
notifications, category proposals, and category votes. The run-prefix count
|
||||||
|
was zero after cleanup.
|
||||||
|
- The throwaway local and remote verifier images, containers, remote output,
|
||||||
|
and run-scoped fixture were absent after cleanup. Evidence is retained at
|
||||||
|
`output/production-full-e2e/prod-launch-20260803/`.
|
||||||
|
|
||||||
|
This proves the tested web workflow against the deployed production commit. It
|
||||||
|
does not prove production SMTP delivery, Web Push, Play-delivered Android FCM,
|
||||||
|
or Google Play review completion.
|
||||||
|
|
||||||
## Independent production backup and monitoring on 2026-08-03
|
## Independent production backup and monitoring on 2026-08-03
|
||||||
|
|
||||||
This verification changed only the independent backup repository, operator
|
This verification changed only the independent backup repository, operator
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user