diff --git a/docs/verification.md b/docs/verification.md index 853c572..5ffa9ac 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -3,6 +3,52 @@ Observed through 2026-07-25 in the local workspace. This report separates observed results from product limits and unknown production properties. +## Live development deployment verification on 2026-07-25 + +The local development Compose project was rebuilt and restarted from exact +local commit `7a54477a308181768469bb1012b1ec561400b9fe`. This was a +development-domain deployment only. The hackathon test deployment, production +deployment, Git remote, Devpost entry, branches, and tags were not changed. + +- The ordinary development Compose project runs two healthy web replicas, two + healthy worker replicas, a healthy PostgreSQL/PostGIS container, and the + development proxy. The four BEAM nodes passed the repository's realtime + cluster check. +- Both direct proxy readiness on `127.0.0.1:4010` with the configured host + header and public readiness at + `https://whoneedhelp.imalto.site/healthz/ready` returned HTTP 200 with + `{"status":"ready"}`. The public home page returned HTTP 200 and the title + `Who Need Help`. +- `./scripts/check-environment-readiness.sh .env --require-release` reported + zero blocking items and zero local-only warnings. The check found the + development origin, independent application secrets, external SMTP, + support inbox, web and Android Google sign-in, VAPID, Firebase client, + FCM service account, Android App Links, and development signing inputs + present and internally consistent; it did not print their secret values. +- A headed Chrome inspection of the public development domain confirmed the + real MapLibre demo map, localized English and Russian navigation and page + content, the searchable compact language menu, the authentication redirect + for protected request discovery, and the 390 by 844 mobile navigation + layout. The inspected page reported zero browser console errors or warnings. + A mobile viewport capture is retained at + `output/playwright/dev-live-mobile-menu-20260725.png`. +- `./scripts/staging-e2e-run.sh` passed the real public HTTPS mutual-aid flow + against `https://whoneedhelp.imalto.site`: two users, medicine request, + helper replacement, realtime private chat, consent-based tracking, + handover, both-party completion, reporting signals, and blind reviews. + Evidence is `output/staging-e2e/20260725212537-291190`. +- Exact fixture cleanup removed 3 synthetic users, 2 requests, 3 assignments, + 2 messages, 1 tracking session, 2 reviews, 2 abuse signals, and 13 audit + events. The before/after application-table snapshots have the same SHA-256 + (`e0effacce81c9662c448d4d073578d54c5f779bd1d9f6f9188c7911afbd55659`) + and the cleanup diff is empty. The two unreferenced temporary E2E image tags + were removed explicitly after the run. +- The full public auth/email staging drill was not run against this + development topology because its required local Mailpit endpoint at + `127.0.0.1:8027` was not running. Auth and email behavior remains covered by + the isolated 45-scenario browser matrix and 390-test local quality gate + below; this observation is not represented as a live external-email check. + ## Cross-browser and release rehearsal follow-up on 2026-07-25 The observations below apply to local commit