Separate production Google verification gates
This commit is contained in:
parent
ea099b58ad
commit
5bc02efa7c
|
|
@ -188,8 +188,14 @@ as forward-only rather than receiving an invented database rollback.
|
||||||
|
|
||||||
- [x] Public HTTPS home, liveness, readiness, WebSocket upgrade, manifest, and
|
- [x] Public HTTPS home, liveness, readiness, WebSocket upgrade, manifest, and
|
||||||
`assetlinks.json` return the expected production identity.
|
`assetlinks.json` return the expected production identity.
|
||||||
- [ ] Registration, returning-user login, and settings linking complete against
|
- [ ] A new account completes Google registration against the production OAuth
|
||||||
the production Google OAuth client and exact callback origin.
|
client and exact callback origin.
|
||||||
|
- [x] A linked returning account completes Google sign-in against the production
|
||||||
|
OAuth client and exact callback origin. The real browser flow returned the
|
||||||
|
established account to the application with the `Welcome back!` result;
|
||||||
|
the runtime client ID and callback match the production Cloud client.
|
||||||
|
- [ ] An existing signed-in account links Google from settings against the
|
||||||
|
production OAuth client and exact callback origin.
|
||||||
- [x] A production-generated authentication email reaches an external mailbox
|
- [x] A production-generated authentication email reaches an external mailbox
|
||||||
and is DKIM-signed by the production domain.
|
and is DKIM-signed by the production domain.
|
||||||
- [x] Authentication-email action URLs use the production domain directly.
|
- [x] Authentication-email action URLs use the production domain directly.
|
||||||
|
|
|
||||||
|
|
@ -3765,6 +3765,23 @@ promoted.
|
||||||
shared Caddy configuration, or public Git remote was changed by these
|
shared Caddy configuration, or public Git remote was changed by these
|
||||||
checks.
|
checks.
|
||||||
|
|
||||||
|
# 2026-08-26 production Google and Play identity recheck
|
||||||
|
|
||||||
|
- Read-only Google Cloud inspection found the production Web OAuth client with
|
||||||
|
authorized origin `https://whoneedhelp.com` and callback
|
||||||
|
`https://whoneedhelp.com/auth/google/callback`. The running production release
|
||||||
|
used the same client ID and public endpoint identity.
|
||||||
|
- A read-only production database query found one account and one Google auth
|
||||||
|
identity for the established operator account. Provider UID and credential
|
||||||
|
values were not printed. Together with the headed production callback replay
|
||||||
|
recorded on 2026-08-25, this closes the returning-account sign-in gate. It
|
||||||
|
does not prove a new production Google registration or settings-originated
|
||||||
|
linking flow, so those remain separate unchecked launch gates.
|
||||||
|
- The connected physical phone still reported `org.whoneedhelp.mobile` version
|
||||||
|
`0.1.3 (4)` installed by `com.android.vending`. No package, permission, Play
|
||||||
|
track, production service, frozen hackathon test deployment, shared Caddy
|
||||||
|
configuration, or public Git remote was changed by this recheck.
|
||||||
|
|
||||||
# 2026-08-25 anonymous production support verification and cleanup
|
# 2026-08-25 anonymous production support verification and cleanup
|
||||||
|
|
||||||
- One uniquely addressed anonymous `account_access` request was submitted to
|
- One uniquely addressed anonymous `account_access` request was submitted to
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user