diff --git a/docs/verification.md b/docs/verification.md index 5ebd11d..c69c7aa 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -38,6 +38,21 @@ edit, branch, or tag was made during this audit. development blockers are the four public Firebase Android values and the FCM service-account credential. No release-readiness claim is made until those credentials are imported and provider/device behavior is exercised. +- Real browser Web Push was exercised on the development origin through the + user's existing dev-port Chrome profile. The exact origin permission was + changed from `Ask (default)` to `Allow`; the application registered a second, + user-owned Web Push device with `POST /mobile/push-devices` returning `201`. + A one-time development notification then created one dispatch job and one + device-delivery job. Both completed on their first attempt without recorded + errors, while the LiveView inbox updated to one unread notification and the + device remained active. Subscription endpoints and key material were not + printed or copied. The operating-system notification surface itself was not + programmatically observable, so no claim is made about its visual appearance. +- The same Chrome session did not expose a WebGL context on the notifications + page. Both the initial map mount and the explicit retry reported + `webgl-context-unavailable` with no server or console error. The location form + remained usable through its documented manual-coordinate fallback. This + records a browser capability observation rather than a map-server failure. - The SSH production release `plan` action was repeated read-only. It observed production commit `921e04b3608007675e22e7e26e0beb3975dbba58`, compact topology, external PostgreSQL 18.4, healthy application containers, and @@ -1463,13 +1478,15 @@ None of the observations below describe the current delivery path. Google OAuth client on its exact HTTPS callback origin after the tested release is explicitly promoted. The test client and callback have already completed real registration and returning-user login. -- Development VAPID is configured. Configure isolated Firebase/FCM credentials, - then verify a real browser subscription and Android device against each - deployed origin. +- Development VAPID is configured, and a real development browser subscription + plus one external adapter delivery completed successfully. Configure isolated + Firebase/FCM credentials, then verify a physical Android development device + before repeating browser and Android delivery against each promoted origin. Direct Web Push/FCM adapters, registration lifecycle, private payload shape, retries, invalid-device cleanup, and Android deep-link handling are - implemented and locally tested; real provider/device delivery is not yet - observed. APNs and iOS are outside the current scope. + implemented and locally tested. Browser provider delivery is now observed on + development; Android FCM delivery is not. APNs and iOS are outside the current + scope. - Load-test representative data and traffic, then set measured pool, resource, autoscaling, and action-limit policies. - Publish jurisdiction-specific emergency contacts, privacy, retention,