From 902079a9ad95bf34e056f9741974ef7d944bc10d Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Fri, 24 Jul 2026 00:13:34 +0300 Subject: [PATCH] docs: record development Android OAuth client --- docs/verification.md | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/docs/verification.md b/docs/verification.md index 18b7099..de6bbf5 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -1379,7 +1379,7 @@ None of the observations below describe the current delivery path. unsubscribe removal remain unverified until the provider enables them and a new delivered MIME is inspected. -## Development Android and provider isolation on 2026-07-23 +## Development Android and provider isolation on 2026-07-23 and 2026-07-24 - The development checkout now owns `org.whoneedhelp.mobile.development`, an independent mode-`0600` signing @@ -1402,6 +1402,13 @@ None of the observations below describe the current delivery path. `https://whoneedhelp.imalto.site` origin and callback, and its ID/secret are present only in the ignored development `.env`. The currently running development containers have not yet been rebuilt with that configuration. +- On 2026-07-24 the same Google Cloud development project was checked through + the user's already-authorized dev-port Chrome profile. It contained only the + expected Web client before a separate Android client was created for + `org.whoneedhelp.mobile.development` and the SHA-1 of the stable development + signing certificate. A read-only return to the Clients page then showed + exactly the development Web and development Android clients. No test or + production client was changed. - The isolated external-boundary drill passed OAuth and Google OIDC success/rejection/replay/timeout cases, SMTP rejection/retry/timeout cases, and provider-neutral push delivery with two healthy worker replicas. Its