Sprint 1 evidence index
The issue #20 validation run included the complete 11-file API database integration selection: all 106 tests passed against uniquely named temporary databases derived from the ignored disposable test configuration. This remains local evidence and does not replace operator-run production release evidence.
This index supports #20. A linked procedure is evidence of a method, not evidence that its unrecorded manual steps passed.
| Requirement / claim | Evidence | Source | Status | Manual follow-up |
|---|---|---|---|---|
| Release scope and checklist | Release validation and demonstration script | #20 | Repository procedure | Link final reviewed evidence and post-merge runs from #20. |
| Deterministic integrated journey | E2E design, apps/web/playwright/sprint1.deterministic.spec.ts, npm run test:e2e:sprint1 | #50, merged PR #136 | Automated/local | Attach two consecutive release-branch results; CI enablement remains a separate prerequisite. |
Protected API returns 401 | apps/api/tests/authentication.integration.test.ts, events.integration.test.ts, cors.integration.test.ts; public GET /api/v1/events smoke | #20, #45 | Automated/local and public smoke | Repeat after merge and record timestamp/SHA. |
| Event discovery and PostGIS eligibility | apps/api/tests/event-database.integration.test.ts; deterministic E2E | #20, #48, #50 | Automated/local | Production DB release evidence remains operator-run. |
| Reachable, unreachable, denied, retry, API failure | apps/web/tests/explore-page.test.tsx; deterministic E2E for reachable, unreachable, denied | #20, #50 | Automated/local | Attach deployed/manual outcomes. |
| Map-independent text fallback | apps/web/tests/exploration.test.tsx; trust boundaries | #20, #44 | Automated/local | Attach deployed browser map-failure evidence. |
| Field calibration | Field-test protocol and player journey | Closed #43, merged protocol PR #57 | Gitea closed; repository results unrecorded | MANUAL — link/review the actual external #43 evidence, confirm threshold interpretation, and update the repository record if appropriate or record the discrepancy as follow-up work before closing #20. |
| Accessible/mobile journey | Explore semantic tests and responsive implementation; #44 dependency | #44 | Partial automated evidence | MANUAL — attach/link reviewed keyboard, focus, 360/390/768/desktop evidence before closing #20. |
| Auth0, CORS, and location privacy | Auth/API/CORS tests; trust boundaries; deployment guide | #45 | Automated configuration evidence | MANUAL — link deployed allowed/denied-origin, Auth0, storage/log, and privacy review evidence. |
| Repeatable database release | Database release procedure | #47, merged PR #53 | EVIDENCE FROM DEPENDENCY | Operator approval and sanitised production execution evidence are required. |
| PostGIS recovery | Recovery rehearsal, event-database.integration.test.ts | #48, merged PR #54 | Automated/local rehearsal design | MANUAL — attach/link reviewed sanitised #48 result from #20. |
| Visual identity and presentation | Campus seal/branding history and current UI | #51, PR #55, PR #83, PR #86, PR #90 | EVIDENCE FROM DEPENDENCY | Link external screenshots/review if they are required release evidence. |
| Public Web/API deployment | Azure guide, .gitea/workflows/ci.yml, public read-only smoke | #17, #20 | Public availability can be checked | Authenticated Web-to-API journey and release-SHA deployment proof remain manual/post-merge. |
| Public documentation | apps/docs, .gitea/workflows/docs-deploy.yml, CI guide, public docs site | #15, PR #91, PR #95 | Public site exists | Verify this new package after its main deployment. |
| CI and deployment | .gitea/workflows/pr-validation.yml, ci.yml, docs-deploy.yml | #17, #20 | Workflow definitions | MANUAL — link successful PR and exact main/release-SHA runs after merge. |
| Four contributors | git shortlog -sne --all and commit history | #20 | Four apparent names, multiple aliases | MANUAL — map aliases to the four humans and review meaningful non-merge commits. |
| Severe-defect gate | Current Gitea issue list | #20 | Not available from repository history | MANUAL — confirm no open P0/P1/severe issue immediately before release closure. |
| Decisions and limitations | Known limitations, ADR-005, map architecture, and location documents | #20 and linked dependencies | Repository evidence | Record any release finding as a linked defect/decision. |
| Meetings, recordings, and screenshots | No concrete repository URL discovered | #20 and dependency discussions | MANUAL | Attach/link only real reviewed Gitea evidence; do not invent identifiers. |
| AI attribution | Declarations in changed release documents and eventual commit trailer | Course policy and #20 | Repository declaration | Reviewer confirms final declaration matches material tools/models. |
Public deployment locations
Record release-specific results in #20 rather than editing historical claims into this index. Evidence must exclude credentials, complete tokens, connection strings, and unnecessary precise coordinates.
AI declaration
This document was planned and reviewed with assistance from ChatGPT-Web[GPT-5.6 Sol] and generated and edited with assistance from Codex[GPT-5].