docs: record development Android OAuth client

This commit is contained in:
SimpleTest 2026-07-24 00:13:34 +03:00
parent 32cb7945e5
commit 902079a9ad

View File

@ -1379,7 +1379,7 @@ None of the observations below describe the current delivery path.
unsubscribe removal remain unverified until the provider enables them and a
new delivered MIME is inspected.
## Development Android and provider isolation on 2026-07-23
## Development Android and provider isolation on 2026-07-23 and 2026-07-24
- The development checkout now owns
`org.whoneedhelp.mobile.development`, an independent mode-`0600` signing
@ -1402,6 +1402,13 @@ None of the observations below describe the current delivery path.
`https://whoneedhelp.imalto.site` origin and callback, and its ID/secret are
present only in the ignored development `.env`. The currently running
development containers have not yet been rebuilt with that configuration.
- On 2026-07-24 the same Google Cloud development project was checked through
the user's already-authorized dev-port Chrome profile. It contained only the
expected Web client before a separate Android client was created for
`org.whoneedhelp.mobile.development` and the SHA-1 of the stable development
signing certificate. A read-only return to the Clients page then showed
exactly the development Web and development Android clients. No test or
production client was changed.
- The isolated external-boundary drill passed OAuth and Google OIDC
success/rejection/replay/timeout cases, SMTP rejection/retry/timeout cases,
and provider-neutral push delivery with two healthy worker replicas. Its