diff --git a/docs/verification.md b/docs/verification.md index 357ed9f..08a78ed 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -1978,40 +1978,46 @@ separates repository-verifiable evidence from external provider, staffing, and jurisdiction-specific decisions; an unchecked or unknown item is not claimed complete. -- Promote the tested release from `test.whoneedhelp.com` to the independent - production project only after explicit approval. Recheck the production - health endpoints, migrations, Google callback, and authentication-email flow - after that promotion; the current test origin still depends on its configured - workstation/VPN/gateway path. +- Production is already an independent checkout, Compose project, database, + secrets set, and public origin; it is not promoted from or coupled to the + frozen `test.whoneedhelp.com` deployment. The production web workflows and + public/mobile pages were verified on 2026-08-03 as recorded above. The + remaining external checks are the real production Google callback, + authentication-email receipt, Web Push delivery, and Play-delivered Android + paths listed in the public launch checklist. - The final Android application ID is `org.whoneedhelp.mobile`. The application publishes environment-specific `/.well-known/assetlinks.json`. The online development response now agrees with `org.whoneedhelp.mobile.development` and its signed certificate, and the verified implicit same-origin App Link rendered in the API 37 smoke. Before - a Play release, register the application, add the Play App Signing - certificate fingerprint alongside any sideload/upload fingerprint, repeat - domain verification with that Play certificate, and complete store - policy/release work. A dedicated upload key and signed APK/AAB exist, but no - Play application has been registered. -- Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring, - and the availability model selected for real usage. -- The development Brevo SMTP transport and sender have completed both an - external release-container probe and an application-generated authentication - delivery observed in Gmail. Repeat the same post-deploy application flow for - production only after the final release scope is reviewed and explicitly - approved. + a Play release, publish the already accepted source-bound AAB from the + internal-testing draft, record the Play App Signing certificate fingerprint + alongside the existing upload fingerprint, repeat domain verification with + that Play certificate, and complete store policy/release work. The Play + application and internal draft exist, but a Play-delivered build has not yet + been tested. +- The independent encrypted off-site backup, isolated restore, daily timer, and + external readiness monitor passed their mechanical checks on 2026-08-03. + Key custody, retention, recovery objectives, alert ownership, and the intended + PostgreSQL availability model remain operator decisions rather than inferred + properties of those checks. +- The development Brevo SMTP transport and sender completed both an external + release-container probe and an application-generated authentication delivery + observed in Gmail. Production configuration readiness is not equivalent to + mailbox delivery; repeat the application-generated authentication flow on the + exact production origin and observe receipt before checking that launch gate. - Exercise registration, sign-in, and settings linking against the production - Google OAuth client on its exact HTTPS callback origin after the tested - release is explicitly promoted. The test client and callback have already - completed real registration and returning-user login. + Google OAuth client on its exact HTTPS callback origin. The production + configuration passes the repository readiness check, but that does not prove + the external browser callback flow. - Development VAPID and isolated Firebase/FCM are configured. Real development browser Web Push, emulator FCM, and physical-device FCM delivery all completed successfully. The physical development replay also covered foreground tracking while the native service was active and verified Stop cleanup. Before a public mobile release, repeat browser/Android delivery - against each explicitly promoted production origin. Unattended background - location was not requested or verified. APNs and iOS are outside the current - scope. + against the production origin and the Play-delivered Android build. + Unattended background location was not requested or verified. APNs and iOS + are outside the current scope. - Google Analytics for Firebase is intentionally deferred rather than silently enabled by the Firebase project wizard. Before enabling it, implement the consent, privacy-notice, event allow-list, sensitive-field exclusions, and