docs: record dev Google and SMTP verification

This commit is contained in:
SimpleTest 2026-07-24 01:14:12 +03:00
parent c76bc4f5f1
commit 671d056d6d

View File

@ -1,6 +1,6 @@
# Who Need Help — implementation verification # Who Need Help — implementation verification
Observed through 2026-07-23 in the local workspace. This report separates observed Observed through 2026-07-24 in the local workspace. This report separates observed
results from product limits and unknown production properties. results from product limits and unknown production properties.
## Local dev hardening audit on 2026-07-23 ## Local dev hardening audit on 2026-07-23
@ -13,7 +13,7 @@ edit, branch, or tag was made during this audit.
configured threshold, actionlint, every Compose render, Prometheus and configured threshold, actionlint, every Compose render, Prometheus and
Alertmanager validation, Helm lint, Trivy source and image scans, formatting, Alertmanager validation, Helm lint, Trivy source and image scans, formatting,
compilation, xref, strict Credo, Sobelow, Dialyzer, Hex audit, both npm audits, compilation, xref, strict Credo, Sobelow, Dialyzer, Hex audit, both npm audits,
and all 352 ExUnit tests. The configured image scans reported zero and all 353 ExUnit tests. The configured image scans reported zero
vulnerabilities, and the run left no project-scoped quality containers, vulnerabilities, and the run left no project-scoped quality containers,
networks, volumes, or one-run image tags. networks, volumes, or one-run image tags.
- A dedicated Brevo SMTP key and verified sender - A dedicated Brevo SMTP key and verified sender
@ -24,9 +24,14 @@ edit, branch, or tag was made during this audit.
creating application or database data; Brevo's transactional log recorded creating application or database data; Brevo's transactional log recorded
`Sent`, `Delivered`, and `First opening` for that exact subject and sender. `Sent`, `Delivered`, and `First opening` for that exact subject and sender.
The disposable probe container was removed, and no test or production sender, The disposable probe container was removed, and no test or production sender,
key, environment, container, or deployment was changed. The running dev key, environment, container, or deployment was changed. On 2026-07-24 the
replicas deliberately still use their earlier runtime environment until the development application replicas were rebuilt and restarted with the external
remaining Google/Firebase credentials are ready for one controlled rebuild. SMTP and Google configuration. Port 587 produced no SMTP banner from either
the host or application container, while port 2525 completed a verified
STARTTLS handshake from both. The ignored development `.env` therefore uses
port 2525. A real application-generated Google ownership-verification message
was accepted in 853 ms and observed in the Gmail inbox from
`dev@whoneedhelp.com`.
- `./scripts/check-environment-readiness.sh .env` now reports external SMTP, - `./scripts/check-environment-readiness.sh .env` now reports external SMTP,
the support inbox, application secrets, Google sign-in, browser VAPID, the support inbox, application secrets, Google sign-in, browser VAPID,
Android App Links, and Android signing inputs as ready. Its two remaining Android App Links, and Android signing inputs as ready. Its two remaining
@ -117,7 +122,7 @@ edit, branch, or tag was made during this audit.
the full two-user medicine flow, active-node failover, Activity moderation, the full two-user medicine flow, active-node failover, Activity moderation,
notifications/export, localization, accessibility, responsive layouts, and notifications/export, localization, accessibility, responsive layouts, and
reconnect behavior. Evidence is retained at reconnect behavior. Evidence is retained at
`output/e2e/20260723021944-2163466`. A preceding run exposed stale E2E marker `output/e2e/20260723214603-691793`. A preceding run exposed stale E2E marker
text after the map legend improvement; the expectation was corrected to the text after the map legend improvement; the expectation was corrected to the
observed `Helper's live location` accessible name. A fresh focused auth replay observed `Helper's live location` accessible name. A fresh focused auth replay
also passed 3/3 across the same browser engines. All run-scoped containers, also passed 3/3 across the same browser engines. All run-scoped containers,
@ -200,7 +205,7 @@ this audit.
| Consent-driven live tracking | Implemented and cross-client verified | On API 37, Android started `TrackingService` as a location foreground service with a persistent Stop notification. After Home minimized the Activity, an emulator coordinate change reached PostGIS. Notification Stop removed the service, notification, active session, and raw position. | Browsers stop with the page. Android has no `ACCESS_BACKGROUND_LOCATION`, unattended start, or route history. | | Consent-driven live tracking | Implemented and cross-client verified | On API 37, Android started `TrackingService` as a location foreground service with a persistent Stop notification. After Home minimized the Activity, an emulator coordinate change reached PostGIS. Notification Stop removed the service, notification, active session, and raw position. | Browsers stop with the page. Android has no `ACCESS_BACKGROUND_LOCATION`, unattended start, or route history. |
| Privacy settings | Implemented and browser-verified | The profile exposed hidden, approximate public, exact for active match, and explicit exact-public options. Blocking and current-position cleanup have automated tests. | Exact public location remains a user opt-in; legal privacy and retention text still requires jurisdiction-specific review before launch. | | Privacy settings | Implemented and browser-verified | The profile exposed hidden, approximate public, exact for active match, and explicit exact-public options. Blocking and current-position cleanup have automated tests. | Exact public location remains a user opt-in; legal privacy and retention text still requires jurisdiction-specific review before launch. |
| Reputation and anti-abuse | Implemented at MVP level | Handover codes, two-party completion, double-blind reviews, unique-counterpart ranking, optional movement/proximity evidence, reports, blocks, abuse signals, and moderator audit paths have automated tests. | The system is not bot-proof and does not claim identity verification. No punitive numeric policy is enabled without measured and approved thresholds. | | Reputation and anti-abuse | Implemented at MVP level | Handover codes, two-party completion, double-blind reviews, unique-counterpart ranking, optional movement/proximity evidence, reports, blocks, abuse signals, and moderator audit paths have automated tests. | The system is not bot-proof and does not claim identity verification. No punitive numeric policy is enabled without measured and approved thresholds. |
| Account registration and sign-in | Implemented and browser-verified | Email registration is a single passwordless flow: it records the display name and acceptance once, sends a confirmation link, and does not duplicate a user on subsequent sign-in. Confirmed users can keep using magic links or add a password in settings. Google OpenID Connect registration, sign-in, link, unlink, replay prevention, verified-email enforcement, and account-ownership rules are covered by the 337-test suite. Earlier public-test-domain verification exercised the real Google provider without creating a duplicate row; the final local headed-Chrome replay exercised isolated Mailpit registration again. | Local test email is deliberately captured in Mailpit. The current delivery code is provider-neutral SMTP; no production SMTP delivery or production Google callback was exercised by the 2026-07-22 local audit. | | Account registration and sign-in | Implemented and browser-verified | Email registration is a single passwordless flow: it records the display name and acceptance once, sends a confirmation link, and does not duplicate a user on subsequent sign-in. Confirmed users can keep using magic links or add a password in settings. Google OpenID Connect registration, sign-in, link, unlink, replay prevention, verified-email enforcement, and account-ownership rules are covered by the 353-test suite. Real headed Chrome on the development origin exercised the Google callback, existing-account ownership email, one-time identity connection, and subsequent one-click Google login without creating a duplicate user. The application-generated authentication email was observed in Gmail from the development sender. | Production SMTP delivery and the production Google callback remain unverified. |
| Notifications and nearby alerts | Implemented and browser-verified | Users can configure push/email preferences, quiet hours, category/urgency/day/time filters, a private matching center, and 1/3/5/10/25 km radii. Durable inbox notifications and Oban delivery jobs are tested; public notification payloads omit chat text, exact coordinates, and the private saved-area label. The focused Chromium replay completed subscription, matching request, inbox delivery, navigation, and export. | External Web Push/FCM delivery depends on deployment credentials and real registered devices; those external boundaries were not exercised in the final local audit. | | Notifications and nearby alerts | Implemented and browser-verified | Users can configure push/email preferences, quiet hours, category/urgency/day/time filters, a private matching center, and 1/3/5/10/25 km radii. Durable inbox notifications and Oban delivery jobs are tested; public notification payloads omit chat text, exact coordinates, and the private saved-area label. The focused Chromium replay completed subscription, matching request, inbox delivery, navigation, and export. | External Web Push/FCM delivery depends on deployment credentials and real registered devices; those external boundaries were not exercised in the final local audit. |
| Social profiles | Manual links implemented; optional GitHub verification implemented and automated-tested | Manual links cannot set verification fields. The optional GitHub flow uses state, PKCE, a user-bound one-time session, unique provider ownership, and an audit record. The local protocol drill also performs real HTTP token/user exchanges without returning an access token to the application. | GitHub OAuth credentials are intentionally absent and are not required for registration or the help flow. The real external provider redirect/callback remains disabled and unverified; other providers remain manual/unverified. | | Social profiles | Manual links implemented; optional GitHub verification implemented and automated-tested | Manual links cannot set verification fields. The optional GitHub flow uses state, PKCE, a user-bound one-time session, unique provider ownership, and an audit record. The local protocol drill also performs real HTTP token/user exchanges without returning an access token to the application. | GitHub OAuth credentials are intentionally absent and are not required for registration or the help flow. The real external provider redirect/callback remains disabled and unverified; other providers remain manual/unverified. |
| Support and content removal | Implemented and browser-verified | Public support, account deletion, general removal, and TAKE IT DOWN forms create separate audited queues; private email status links verify public contacts; authenticated submissions use the account email; moderator-only operations can update status and notify verified contacts. TAKE IT DOWN accepts URLs/text only and records a 48-hour review due time. Authenticated users can download an allowlisted JSON export, and moderators can run a read-only deletion relationship preflight. | The current product hosts no user media and does not claim TAKE IT DOWN coverage. Staffing, jurisdiction-specific legal classification, final retention rules, destructive account erasure/anonymisation, and identical-media-copy handling remain operational/legal work. | | Support and content removal | Implemented and browser-verified | Public support, account deletion, general removal, and TAKE IT DOWN forms create separate audited queues; private email status links verify public contacts; authenticated submissions use the account email; moderator-only operations can update status and notify verified contacts. TAKE IT DOWN accepts URLs/text only and records a 48-hour review due time. Authenticated users can download an allowlisted JSON export, and moderators can run a read-only deletion relationship preflight. | The current product hosts no user media and does not claim TAKE IT DOWN coverage. Staffing, jurisdiction-specific legal classification, final retention rules, destructive account erasure/anonymisation, and identical-media-copy handling remain operational/legal work. |
@ -209,7 +214,7 @@ this audit.
| Multiple web/worker instances | Implemented and locally failure/rollout-verified | The final isolated Compose drill passed BEAM crashes and sequential replacement with 3 web/2 worker replicas: all five nodes joined, PubSub passed, and 744/744 readiness requests succeeded. The project-owned kind cluster replaced all 2 web/2 worker pod UIDs under `maxUnavailable=0`; all four replacement pods joined, PubSub passed, and 363/363 samples ultimately succeeded. | Local PostGIS is a single instance. Production database HA, backups, and recovery are operator work and are not claimed complete. | | Multiple web/worker instances | Implemented and locally failure/rollout-verified | The final isolated Compose drill passed BEAM crashes and sequential replacement with 3 web/2 worker replicas: all five nodes joined, PubSub passed, and 744/744 readiness requests succeeded. The project-owned kind cluster replaced all 2 web/2 worker pod UIDs under `maxUnavailable=0`; all four replacement pods joined, PubSub passed, and 363/363 samples ultimately succeeded. | Local PostGIS is a single instance. Production database HA, backups, and recovery are operator work and are not claimed complete. |
| Local observability | Implemented and protocol-verified | Pinned Prometheus scraped the exact 3 web and 2 worker targets with a file Bearer credential; Grafana provisioned a healthy datasource and ten-panel web/worker/BEAM/Ecto/Oban dashboard; Alertmanager delivered firing and resolved webhooks for an induced scoped replica stop. | Local delivery does not establish production retention, notification-provider reliability, on-call policy, or measured alert thresholds. | | Local observability | Implemented and protocol-verified | Pinned Prometheus scraped the exact 3 web and 2 worker targets with a file Bearer credential; Grafana provisioned a healthy datasource and ten-panel web/worker/BEAM/Ecto/Oban dashboard; Alertmanager delivered firing and resolved webhooks for an induced scoped replica stop. | Local delivery does not establish production retention, notification-provider reliability, on-call policy, or measured alert thresholds. |
| Encrypted local backup | Implemented and failure-verified | Pinned Restic streamed PostgreSQL custom format into pinned local MinIO with no host plaintext dump, passed full-data checking and a fresh-database restore, rejected a corrupted repository, and published no snapshot for an interrupted upload. The one-run MinIO project and volume were removed after retaining the non-secret evidence. | The drill proves the local mechanism, not off-site durability, database HA, or a production RPO/RTO/retention policy. | | Encrypted local backup | Implemented and failure-verified | Pinned Restic streamed PostgreSQL custom format into pinned local MinIO with no host plaintext dump, passed full-data checking and a fresh-database restore, rejected a corrupted repository, and published no snapshot for an interrupted upload. The one-run MinIO project and volume were removed after retaining the non-secret evidence. | The drill proves the local mechanism, not off-site durability, database HA, or a production RPO/RTO/retention policy. |
| External protocol boundaries | Implemented and locally failure-verified | Assent/Req and Swoosh/gen_smtp paths have internal success/rejection/retry/replay/timeout coverage. Google OIDC discovery/authorization/token/JWKS with nonce and PKCE and the optional GitHub boundary are locally exercised through mocks; an earlier public test run exercised real Google OIDC. The current push code includes provider-neutral HTTP delivery plus direct standards-based Web Push and FCM adapters with durable Oban retries and invalid-device cleanup. UniSender observations below are retained only as historical evidence and do not describe current wiring. | The real GitHub provider, production Google callback, production authentication-email delivery, external Web Push endpoint, physical-device FCM delivery, and APNs remain unverified. SMTP exactly-once delivery is not claimed. | | External protocol boundaries | Implemented and locally failure-verified | Assent/Req and Swoosh/gen_smtp paths have internal success/rejection/retry/replay/timeout coverage. Google OIDC discovery/authorization/token/JWKS with nonce and PKCE and the optional GitHub boundary are locally exercised through mocks. The development origin additionally exercised the real Google provider and an authenticated Brevo SMTP delivery observed in Gmail. The current push code includes provider-neutral HTTP delivery plus direct standards-based Web Push and FCM adapters with durable Oban retries and invalid-device cleanup. UniSender observations below are retained only as historical evidence and do not describe current wiring. | The real GitHub provider, production Google callback, production authentication-email delivery, external Web Push endpoint, physical-device FCM delivery, and APNs remain unverified. SMTP exactly-once delivery is not claimed. |
## Reproducible checks ## Reproducible checks
@ -1393,15 +1398,15 @@ None of the observations below describe the current delivery path.
production pipeline separately passed release tests, lint, R8/resource production pipeline separately passed release tests, lint, R8/resource
shrinking, APK/AAB signing checks, Bundletool validation, and production App shrinking, APK/AAB signing checks, Bundletool validation, and production App
Links identity validation. Links identity validation.
- The complete isolated quality/security gate passed with 352 ExUnit tests, - The complete isolated quality/security gate passed with 353 ExUnit tests,
ShellCheck, Hadolint, actionlint, Compose/Helm validation, format/compiler, ShellCheck, Hadolint, actionlint, Compose/Helm validation, format/compiler,
xref, Credo, Sobelow, Dialyzer, Hex/npm audits, source scanning, and all xref, Credo, Sobelow, Dialyzer, Hex/npm audits, source scanning, and all
configured runtime image scans. Its unique Compose project, volume, and configured runtime image scans. Its unique Compose project, volume, and
temporary image tags were absent after cleanup. temporary image tags were absent after cleanup.
- The development Google Web OAuth client is configured for the exact - The development Google Web OAuth client is configured for the exact
`https://whoneedhelp.imalto.site` origin and callback, and its ID/secret are `https://whoneedhelp.imalto.site` origin and callback, and its ID/secret are
present only in the ignored development `.env`. The currently running present only in the ignored development `.env`. The current development
development containers have not yet been rebuilt with that configuration. replicas were rebuilt with that configuration and remained healthy.
- On 2026-07-24 the same Google Cloud development project was checked through - On 2026-07-24 the same Google Cloud development project was checked through
the user's already-authorized dev-port Chrome profile. It contained only the the user's already-authorized dev-port Chrome profile. It contained only the
expected Web client before a separate Android client was created for expected Web client before a separate Android client was created for
@ -1409,6 +1414,15 @@ None of the observations below describe the current delivery path.
signing certificate. A read-only return to the Clients page then showed signing certificate. A read-only return to the Clients page then showed
exactly the development Web and development Android clients. No test or exactly the development Web and development Android clients. No test or
production client was changed. production client was changed.
- Real headed Chrome verification used only the user's existing dev-port
profile. The Google Web flow reached the exact development callback, required
one email-ownership confirmation before attaching a matching existing local
account, then completed a subsequent Google sign-in without another email.
Read-only PostgreSQL checks observed seven users and exactly one Google auth
identity, and the settings page reported the Google account as connected.
The application-generated confirmation email was observed in Gmail from the
development sender. No test or production OAuth client, sender, deployment,
database, public Git reference, or Devpost entry was changed.
- The isolated external-boundary drill passed OAuth and Google OIDC - The isolated external-boundary drill passed OAuth and Google OIDC
success/rejection/replay/timeout cases, SMTP rejection/retry/timeout cases, success/rejection/replay/timeout cases, SMTP rejection/retry/timeout cases,
and provider-neutral push delivery with two healthy worker replicas. Its and provider-neutral push delivery with two healthy worker replicas. Its
@ -1440,11 +1454,11 @@ None of the observations below describe the current delivery path.
signed APK/AAB exist, but no Play application has been registered. signed APK/AAB exist, but no Play application has been registered.
- Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring, - Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring,
and the availability model selected for real usage. and the availability model selected for real usage.
- The development Brevo SMTP transport and sender have completed an external - The development Brevo SMTP transport and sender have completed both an
delivery probe. After the controlled dev rebuild, exercise registration and external release-container probe and an application-generated authentication
magic-link delivery through the deployed application itself and inspect the delivery observed in Gmail. Repeat the same post-deploy application flow for
received message. Repeat the same post-deploy application flow for production production only after the final release scope is reviewed and explicitly
only after the final release scope is reviewed and explicitly approved. approved.
- Exercise registration, sign-in, and settings linking against the production - Exercise registration, sign-in, and settings linking against the production
Google OAuth client on its exact HTTPS callback origin after the tested Google OAuth client on its exact HTTPS callback origin after the tested
release is explicitly promoted. The test client and callback have already release is explicitly promoted. The test client and callback have already