Separate production Google verification gates

This commit is contained in:
SimpleTest 2026-08-26 00:12:31 +03:00
parent ea099b58ad
commit 5bc02efa7c
2 changed files with 25 additions and 2 deletions

View File

@ -188,8 +188,14 @@ as forward-only rather than receiving an invented database rollback.
- [x] Public HTTPS home, liveness, readiness, WebSocket upgrade, manifest, and
`assetlinks.json` return the expected production identity.
- [ ] Registration, returning-user login, and settings linking complete against
the production Google OAuth client and exact callback origin.
- [ ] A new account completes Google registration against the production OAuth
client and exact callback origin.
- [x] A linked returning account completes Google sign-in against the production
OAuth client and exact callback origin. The real browser flow returned the
established account to the application with the `Welcome back!` result;
the runtime client ID and callback match the production Cloud client.
- [ ] An existing signed-in account links Google from settings against the
production OAuth client and exact callback origin.
- [x] A production-generated authentication email reaches an external mailbox
and is DKIM-signed by the production domain.
- [x] Authentication-email action URLs use the production domain directly.

View File

@ -3765,6 +3765,23 @@ promoted.
shared Caddy configuration, or public Git remote was changed by these
checks.
# 2026-08-26 production Google and Play identity recheck
- Read-only Google Cloud inspection found the production Web OAuth client with
authorized origin `https://whoneedhelp.com` and callback
`https://whoneedhelp.com/auth/google/callback`. The running production release
used the same client ID and public endpoint identity.
- A read-only production database query found one account and one Google auth
identity for the established operator account. Provider UID and credential
values were not printed. Together with the headed production callback replay
recorded on 2026-08-25, this closes the returning-account sign-in gate. It
does not prove a new production Google registration or settings-originated
linking flow, so those remain separate unchecked launch gates.
- The connected physical phone still reported `org.whoneedhelp.mobile` version
`0.1.3 (4)` installed by `com.android.vending`. No package, permission, Play
track, production service, frozen hackathon test deployment, shared Caddy
configuration, or public Git remote was changed by this recheck.
# 2026-08-25 anonymous production support verification and cleanup
- One uniquely addressed anonymous `account_access` request was submitted to