You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Church/Basketball business milestone was accepted in #289 on 2026-09-15. Platform assurance reconciliation is active, but final closure waits for the deployment, monitoring and recovery receipts.
Execution lane:phase: platform-later. Status: active for documentation reconciliation; waiting on #265/#267/#268 for final evidence.
Completed
PR #338 reconciled current local artifact, TLS, security-scan, test and release-acceptance documentation. PR #339 added the guarded staging-acceptance procedure to README, testing, runbook, release-acceptance, roadmap, documentation-status and tool-inventory sources. Exact head 965fede3d99871679ab4a65430edc079d343cc48 passed 2,019 tests with 21 documented skips, local artifact validation and source/image security validation; make test-docs passed with 189 manual and 138 generated documents. The repository distinguishes local evidence from staging/production proof.
Remaining
As #265, #267 and #268 complete, map their exact deployed source/digest, monitoring receipt, isolated restore and approved policy evidence into the assurance matrix. Run 284.4 only against an explicitly disposable authorized target. Keep every unperformed production claim visibly unverified. Close only when the final documentation agrees with the actual evidence and #271 can consume it.
All tests and code review remain local. GitHub Actions does not run tests, and Ollama is not a code-review provider.
Current Implementation Handoff
Prepared 2026-09-13 for a lower-cost builder at source 21a4a804aa57580451edded04736b1f51aef7e48. No CI checks. All implementation validation and code review run locally.
Use the shared builder contract and this issue's work packages; no xhigh model or automatic model upgrade is required. This is a detailed recommendation, not a claim that a smaller model cannot make mistakes or that tests have passed.
Risk/review focus: Medium/high: false security and operational assurances. Start condition: ACTIVE FOR RECONCILIATION; WAITING ON #265/#267/#268 for final staging and operations evidence.
Do not retain Production-Ready/SOC2/HIPAA/GDPR-ready wording as factual certification. Correct partial fixes too: current billing guards and reset email wiring already exist; remaining acceptance is not the same as the historical defect.
This handoff supersedes stale implementation statements in the background below. Preserve existing successful behavior and tests. Recheck the current branch before editing; the baseline is a source pointer, not permission to discard newer changes.
Shared source/ORM/migration changes are serialized per the master roadmap. Do not start concurrent edits to the same ownership area.
Recommended Decisions
Use implemented/tested/unverified/planned status per control with source and dated evidence; a document cannot certify compliance or externally delivered alerts by itself.
Build a setting-to-reader-to-container-to-test matrix. Commands must match the actual artifact and distinguish local disposable checks from approved staging operations.
Prefer forward-compatible artifact rollback with explicit migration compatibility. Do not present alembic downgrade or restore-over-current-database as a routine safe command without a demonstrated drill.
One canonical current runbook with links from historical docs; no copied percentages, current test-count promises or invented hostnames/secrets.
Small Work Packages
Each item is one reviewable slice, not permission for one giant PR. Add the failing regression first; finish code, tests and affected docs for that slice together. Leave this issue open until all packages and original acceptance criteria are satisfied or explicitly revised by the owner.
284.1: Remove/qualify unsupported current claims and wrong paths in a small first PR; retain historical content with clear supersession.
284.2: Trace every config/health/monitoring/provider statement to source and update current setup/deploy references.
284.3: Integrate actual artifact/alert/restore evidence from their owner issues and write operator preflight, failure, recovery and rollback procedures.
284.4: Run local link/config/command checks and an operator walkthrough against an explicitly disposable target before marking procedures verified.
Required Regression Cases
These are specifications for tests to add/retain, not claimed execution results. Each new negative case must assert unchanged unauthorized state and zero forbidden side effects.
T284-01: A current security claim without implemented control/evidence is labeled unverified rather than silently retained.
T284-02: Every env row matches its runtime reader/default/effective container value; conflicting names fail a local consistency check.
T284-03: Runbook failure/rollback steps preserve original data and name exactly which approved target they affect.
T284-04: Billing/SMS/native enablement and real compliance assessment stay separate owner gates, not inferred from router presence.
Local Commands and Evidence
Existing targeted commands (paths checked against the audit source; run only after the stated safe preflight):
poetry run pytest tests/unit/test_runbook_doc.py tests/unit/test_secret_key_guard.py tests/unit/test_local_validation_policy.py -q
Also run the shared formatting/lint/touched-type/unit/full-suite and local review protocol from #252 for the final pushed revision. Add new targeted tests to these commands when implemented. Run API and browser tiers in separate processes. Native, PostgreSQL, image, provider and operator drills require their explicit environment; an unavailable tool/target is blocked/not run, never a pass.
Schema and Compatibility
No schema work in documentation issue; link actual migrations/drill evidence from implementation owners.
Stop Conditions
Do not invent legal/compliance approval, RPO/RTO, operational recipients or production URLs. Mark missing evidence explicitly and request the needed owner decision.
After two failed focused repair attempts without new diagnostic evidence, stop the affected package and post the exact failure, commands, suspected boundary and needed decision. Do not silently broaden scope, weaken tests or upgrade models. A fresh local reviewer checks: Check factual claims against source plus actual run receipts, especially assertions of completeness, production readiness and successful external delivery.
Completion Receipt
Work-package and regression IDs above map to changed files and actual results.
Commands, versions, dates, pass/fail/skip/not-run counts, logs/screenshots and tested head/base SHAs are linked.
A separate local review records findings and resolution; self-review is labeled if used and is not misrepresented as independent review.
Affected docs/README/playbooks/screenshots and dependency/roadmap status are reconciled, not left as unnamed follow-ups.
If implementation is authorized through PR/merge, GitHub reports mergeable and the shared local-evidence requirements are met; reviewer agents never merge.
No hosted CI check, status attestation, Ollama reviewer, live provider action, deployment, real-data purge or store submission was introduced by implication.
Copyable Builder Prompt
First read this issue's Current Priority Decision and #289. Run only its NOW slice.
If this issue is deferred, report that state instead of starting the older package list.
Implement the next ready work package in tomqwu/SignUpFlow issue #284.
Read its Current Implementation Handoff and #252 Builder Handoff Contract first.
Inspect current source and preserve newer/unrelated changes. Start with the
package's failing regression, then complete code, local tests, local review and
affected docs/assets together. Do not skip acceptance or invent passing evidence.
No CI checks or Ollama code review. Do not deploy, activate providers, purge real
data or submit to stores. Stop and report unmet prerequisites or policy decisions.
Record the package/test IDs and exact reviewed/tested source SHAs before claiming done.
No CI checks. All code review, formatting, lint, types, migrations, tests, security scans and artifact validation run locally. Do not add hosted validation, required CI statuses, synthetic success statuses or an Ollama code reviewer. Pages publication is separate. Record commands, environment, results, skips, limitations and reviewed head/base SHAs. Builders merge only after complete local evidence and GitHub mergeability; reviewers never merge.
This is planned work, not an implementation or production-readiness sign-off. The audit did not rerun the application/test suite, deploy, contact delivery/payment providers or validate a native release.
Findings
docs/SECURITY.md says Production-Ready and SOC 2/HIPAA/GDPR ready without supporting verification, and cites nonexistent api/core/security.py. These claims conflict with open security blockers #253-#258/#261.
docs/RUNBOOK.md treats the production configuration as operational: ENVIRONMENT is documented but not passed by production Compose; SENTRY_DSN is described as reporting even though startup only logs its presence; health/readiness both depend on the database and return raw exception text. Its dump/restore/rollback examples are not a demonstrated recovery procedure.
Immediately replace unsupported security/compliance/production certifications with dated implemented/tested/unverified controls and links to actual open blockers. Do not invent a compliance/legal assessment.
Build a configuration matrix for every runtime setting: canonical reader, default, production rule, Compose/entrypoint propagation, failure behavior and local test. Include provider/billing flags, signing keys, expiry, cookie security, debug flags, proxy/TLS, Redis, CORS and logging.
Add an operator acceptance record: source SHA, image digest, database version, commands, timings, logs, outcome, owner and limitations. Separate local source checks, staging drills, provider delivery, physical devices and public release.
Reconcile all current security/deployment/environment/Docker/SaaS/mobile support references and docs index. Archive misleading historical completion claims through the documentation ledger.
Acceptance
No current security or operational document claims production/compliance readiness without linked evidence and scope.
Config examples match actual readers and effective artifact settings; no real secrets appear.
Deployment, migration, restore and rollback commands are proven on disposable authorized targets or clearly marked blocked.
Monitoring docs distinguish implemented logging, actual error reporting and verified alert receipt.
Recovery and retention promises match measured behavior and owner-approved policy.
Unsupported email/SMS/billing/mobile enablement is visibly separate from the core pilot.
Validation / Dependencies
Local source/config/link tests first; authorized local operator drills only after #258/#260/#265/#266/#267/#268. Documentation correction need not wait for those implementations: state the gaps honestly now. No deployment, real data purge, provider activation or release is authorized here.
Delivery Ownership and Cross-links
Suggested owner: Security/platform documentation owner (not yet assigned). Roadmap order: 0 and final reconciliation in 3. Implement in small locally reviewed PRs; no source changes are made by filing this issue.
Coordinates #277 documentation ledger and #278 public claims; #271 is the final release-evidence consumer, not proof that these corrections already exist.
Current Priority Decision
The Church/Basketball business milestone was accepted in #289 on 2026-09-15. Platform assurance reconciliation is active, but final closure waits for the deployment, monitoring and recovery receipts.
Execution lane:
phase: platform-later. Status: active for documentation reconciliation; waiting on #265/#267/#268 for final evidence.Completed
PR #338 reconciled current local artifact, TLS, security-scan, test and release-acceptance documentation. PR #339 added the guarded staging-acceptance procedure to README, testing, runbook, release-acceptance, roadmap, documentation-status and tool-inventory sources. Exact head
965fede3d99871679ab4a65430edc079d343cc48passed 2,019 tests with 21 documented skips, local artifact validation and source/image security validation;make test-docspassed with 189 manual and 138 generated documents. The repository distinguishes local evidence from staging/production proof.Remaining
As #265, #267 and #268 complete, map their exact deployed source/digest, monitoring receipt, isolated restore and approved policy evidence into the assurance matrix. Run 284.4 only against an explicitly disposable authorized target. Keep every unperformed production claim visibly unverified. Close only when the final documentation agrees with the actual evidence and #271 can consume it.
All tests and code review remain local. GitHub Actions does not run tests, and Ollama is not a code-review provider.
Current Implementation Handoff
Prepared 2026-09-13 for a lower-cost builder at source
21a4a804aa57580451edded04736b1f51aef7e48.No CI checks. All implementation validation and code review run locally.
Use the shared builder contract and this issue's work packages; no
xhighmodel or automatic model upgrade is required. This is a detailed recommendation, not a claim that a smaller model cannot make mistakes or that tests have passed.Risk/review focus: Medium/high: false security and operational assurances.
Start condition: ACTIVE FOR RECONCILIATION; WAITING ON #265/#267/#268 for final staging and operations evidence.
Source of Truth and Current State
docs/SECURITY.mddocs/RUNBOOK.mddocs/DEPLOYMENT_GUIDE.mddocs/DOCKER_DEVELOPMENT.mddocs/ENVIRONMENT_SETUP.mddocs/INDEX.mdapi/core/config.pyapi/main.pydocker-compose.ymldocker-entrypoint.shDo not retain Production-Ready/SOC2/HIPAA/GDPR-ready wording as factual certification. Correct partial fixes too: current billing guards and reset email wiring already exist; remaining acceptance is not the same as the historical defect.
This handoff supersedes stale implementation statements in the background below. Preserve existing successful behavior and tests. Recheck the current branch before editing; the baseline is a source pointer, not permission to discard newer changes.
Dependencies and Ownership
Recommended Decisions
Small Work Packages
Each item is one reviewable slice, not permission for one giant PR. Add the failing regression first; finish code, tests and affected docs for that slice together. Leave this issue open until all packages and original acceptance criteria are satisfied or explicitly revised by the owner.
Required Regression Cases
These are specifications for tests to add/retain, not claimed execution results. Each new negative case must assert unchanged unauthorized state and zero forbidden side effects.
Local Commands and Evidence
Existing targeted commands (paths checked against the audit source; run only after the stated safe preflight):
Also run the shared formatting/lint/touched-type/unit/full-suite and local review protocol from #252 for the final pushed revision. Add new targeted tests to these commands when implemented. Run API and browser tiers in separate processes. Native, PostgreSQL, image, provider and operator drills require their explicit environment; an unavailable tool/target is blocked/not run, never a pass.
Schema and Compatibility
No schema work in documentation issue; link actual migrations/drill evidence from implementation owners.
Stop Conditions
Do not invent legal/compliance approval, RPO/RTO, operational recipients or production URLs. Mark missing evidence explicitly and request the needed owner decision.
After two failed focused repair attempts without new diagnostic evidence, stop the affected package and post the exact failure, commands, suspected boundary and needed decision. Do not silently broaden scope, weaken tests or upgrade models. A fresh local reviewer checks: Check factual claims against source plus actual run receipts, especially assertions of completeness, production readiness and successful external delivery.
Completion Receipt
Copyable Builder Prompt
Earlier Audit and Acceptance Context
Parent roadmap: #252. Audit baseline:
21a4a804aa57580451edded04736b1f51aef7e48(2026-09-13).No CI checks. All code review, formatting, lint, types, migrations, tests, security scans and artifact validation run locally. Do not add hosted validation, required CI statuses, synthetic success statuses or an Ollama code reviewer. Pages publication is separate. Record commands, environment, results, skips, limitations and reviewed head/base SHAs. Builders merge only after complete local evidence and GitHub mergeability; reviewers never merge.
This is planned work, not an implementation or production-readiness sign-off. The audit did not rerun the application/test suite, deploy, contact delivery/payment providers or validate a native release.
Findings
docs/SECURITY.mdsays Production-Ready and SOC 2/HIPAA/GDPR ready without supporting verification, and cites nonexistent api/core/security.py. These claims conflict with open security blockers #253-#258/#261.docs/RUNBOOK.mdtreats the production configuration as operational: ENVIRONMENT is documented but not passed by production Compose; SENTRY_DSN is described as reporting even though startup only logs its presence; health/readiness both depend on the database and return raw exception text. Its dump/restore/rollback examples are not a demonstrated recovery procedure.docker-compose.yml,Dockerfile,docker-entrypoint.sh,api/core/config.pyand runtime env readers must be the source of truth, not a historical plan.Plan
Acceptance
Validation / Dependencies
Local source/config/link tests first; authorized local operator drills only after #258/#260/#265/#266/#267/#268. Documentation correction need not wait for those implementations: state the gaps honestly now. No deployment, real data purge, provider activation or release is authorized here.
Delivery Ownership and Cross-links
Suggested owner: Security/platform documentation owner (not yet assigned). Roadmap order: 0 and final reconciliation in 3. Implement in small locally reviewed PRs; no source changes are made by filing this issue.
Coordinates #277 documentation ledger and #278 public claims; #271 is the final release-evidence consumer, not proof that these corrections already exist.