Refresh remaining production launch gates

This commit is contained in:
SimpleTest 2026-08-03 21:35:17 +03:00
parent 645ff3eed9
commit da19893b36

View File

@ -1978,40 +1978,46 @@ separates repository-verifiable evidence from external provider, staffing, and
jurisdiction-specific decisions; an unchecked or unknown item is not claimed jurisdiction-specific decisions; an unchecked or unknown item is not claimed
complete. complete.
- Promote the tested release from `test.whoneedhelp.com` to the independent - Production is already an independent checkout, Compose project, database,
production project only after explicit approval. Recheck the production secrets set, and public origin; it is not promoted from or coupled to the
health endpoints, migrations, Google callback, and authentication-email flow frozen `test.whoneedhelp.com` deployment. The production web workflows and
after that promotion; the current test origin still depends on its configured public/mobile pages were verified on 2026-08-03 as recorded above. The
workstation/VPN/gateway path. remaining external checks are the real production Google callback,
authentication-email receipt, Web Push delivery, and Play-delivered Android
paths listed in the public launch checklist.
- The final Android application ID is `org.whoneedhelp.mobile`. The application - The final Android application ID is `org.whoneedhelp.mobile`. The application
publishes environment-specific `/.well-known/assetlinks.json`. The online publishes environment-specific `/.well-known/assetlinks.json`. The online
development response now agrees with development response now agrees with
`org.whoneedhelp.mobile.development` and its signed certificate, and the `org.whoneedhelp.mobile.development` and its signed certificate, and the
verified implicit same-origin App Link rendered in the API 37 smoke. Before verified implicit same-origin App Link rendered in the API 37 smoke. Before
a Play release, register the application, add the Play App Signing a Play release, publish the already accepted source-bound AAB from the
certificate fingerprint alongside any sideload/upload fingerprint, repeat internal-testing draft, record the Play App Signing certificate fingerprint
domain verification with that Play certificate, and complete store alongside the existing upload fingerprint, repeat domain verification with
policy/release work. A dedicated upload key and signed APK/AAB exist, but no that Play certificate, and complete store policy/release work. The Play
Play application has been registered. application and internal draft exist, but a Play-delivered build has not yet
- Operate PostgreSQL/PostGIS with off-site backups, recovery testing, monitoring, been tested.
and the availability model selected for real usage. - The independent encrypted off-site backup, isolated restore, daily timer, and
- The development Brevo SMTP transport and sender have completed both an external readiness monitor passed their mechanical checks on 2026-08-03.
external release-container probe and an application-generated authentication Key custody, retention, recovery objectives, alert ownership, and the intended
delivery observed in Gmail. Repeat the same post-deploy application flow for PostgreSQL availability model remain operator decisions rather than inferred
production only after the final release scope is reviewed and explicitly properties of those checks.
approved. - The development Brevo SMTP transport and sender completed both an external
release-container probe and an application-generated authentication delivery
observed in Gmail. Production configuration readiness is not equivalent to
mailbox delivery; repeat the application-generated authentication flow on the
exact production origin and observe receipt before checking that launch gate.
- Exercise registration, sign-in, and settings linking against the production - Exercise registration, sign-in, and settings linking against the production
Google OAuth client on its exact HTTPS callback origin after the tested Google OAuth client on its exact HTTPS callback origin. The production
release is explicitly promoted. The test client and callback have already configuration passes the repository readiness check, but that does not prove
completed real registration and returning-user login. the external browser callback flow.
- Development VAPID and isolated Firebase/FCM are configured. Real development - Development VAPID and isolated Firebase/FCM are configured. Real development
browser Web Push, emulator FCM, and physical-device FCM delivery all browser Web Push, emulator FCM, and physical-device FCM delivery all
completed successfully. The physical development replay also covered completed successfully. The physical development replay also covered
foreground tracking while the native service was active and verified Stop foreground tracking while the native service was active and verified Stop
cleanup. Before a public mobile release, repeat browser/Android delivery cleanup. Before a public mobile release, repeat browser/Android delivery
against each explicitly promoted production origin. Unattended background against the production origin and the Play-delivered Android build.
location was not requested or verified. APNs and iOS are outside the current Unattended background location was not requested or verified. APNs and iOS
scope. are outside the current scope.
- Google Analytics for Firebase is intentionally deferred rather than silently - Google Analytics for Firebase is intentionally deferred rather than silently
enabled by the Firebase project wizard. Before enabling it, implement the enabled by the Firebase project wizard. Before enabling it, implement the
consent, privacy-notice, event allow-list, sensitive-field exclusions, and consent, privacy-notice, event allow-list, sensitive-field exclusions, and