Lumitaris
DEMO · JAY

QA / Diagnostics Center

Read-only quality checks. No learner data is modified here.

Open the Platform Troubleshooting Center

Release decision

BLOCKED — do not invite outside families

Safe for owner-only testing in the current single household. Two Critical Blockers (creator-rule gap and self-service link creation) mean a signed-in account could create or link records for an unlinked learner; live cross-account enforcement is also not yet observed. Re-evaluate after the next-action list is complete — a public launch is not recommended in this validation pass.

Verified automatically

Pass

Default-deny RLS policy present on all 19 protected collections (creator / viewers / exact-owner-identity branches).

Pass

Diagnostics, QA reset, ErrorLog, and QA collections are admin-role only in live mode.

Pass

Break-return idempotency: one return event, one +5 Focus award (Resilience tab, automated run).

Pass

Readiness upsert: one record per local day (Resilience tab, automated run).

Pass

Memory Vault replay guard: a review graded twice within the replay window is a no-op.

Pass

Ownership immutability: app write paths strip student_email from every update.

Pass

Logged-out sessions never issue entity requests (demo store only).

Verified manually

Manual

None recorded yet — human checks are pending (see A11y Manual and Resilience tabs).

Not testable here

Not Testable

Live multi-account RLS enforcement (R-01–R-10, R-15): Base44 accounts exist only via dashboard invites; a human must complete the Identity Plan wizard and run the matrix from each account. Builder tooling cannot sign in as other users.

Not Testable

Direct API request simulation with learner/parent tokens: no token impersonation exists in this environment.

Not Testable

Durable offline write queue: the platform has no offline queue primitive — documented, not simulated.

Failed or needs remediation

Critical · Creator-rule gap (T-1/T-2/T-3)

Why it matters: RLS templates cannot verify a ParentLearnerLink at create time, so a signed-in account can create records naming another learner while listing itself in viewers.

Safest corrective action: Move parent-side record creation behind a service-role backend function that validates the explicit link before writing.

Retest status: open — re-run after remediation.

Critical · Self-service link creation (T-8)

Why it matters: Any signed-in account can create a ParentLearnerLink naming itself the parent of any learner; links feed viewer resolution.

Safest corrective action: Require admin-approved invite/consent or service-role validation for link creation.

Retest status: open — re-run after remediation.

Multi-account RLS matrix

5 Pass (code)

Route/admin gates (R-11–R-14) and logged-out denial (R-16) verified in code.

11 Not Testable

Allow/deny cases R-01–R-10, R-15 require the six live QA identities; policy config is in place and verified.

Write-path tampering results

6 Pass

created_by_id unforgable (platform); foreign-record updates and viewer edits denied; admin records protected; URL params carry no data authority.

2 Fail

Creator-rule and link-creation gaps — Critical Blockers, remediation defined.

Creator-rule review

Finding

A bypass is possible within invited accounts: the create rule accepts any owner identity when the creator lists itself in viewers. RLS cannot express link verification at create time. Policy left unchanged (narrowing it would break the parent write flows); documented as the release blocker with the service-role remediation.

Legacy migration results

Ready

Migration Lab built with disposable QA records, link-derived stamps, fail-closed ambiguity, idempotent reruns, audit trail, and confirmed rollback. Execute it from the Migration Lab tab with the live admin session to record outcomes.

Resilience results

3 automated

Break-return double tap, duplicate readiness, and review replay — run from the Resilience tab in demo mode; results recorded with XP before/after and duplicate counts.

11 manual

UI-level scenarios (S1–S4, S6–S12) carry exact tester steps; not yet verified.

Manual accessibility status

0 of 12

No human-verified checks yet — the pack records tester, device, route, notes, and pass/fail per check, and never auto-fills.

Next action list

1

Route parent-side record creation and ParentLearnerLink creation through a service-role function that validates the explicit link (clears both Critical Blockers).

2

Complete the QA identity wizard (six invited accounts), then execute the RLS Matrix and Write Path panels live and record evidence.

3

Have a human tester complete the 12-check accessibility pack and the manual resilience scenarios.

4

Run the Migration Lab end-to-end: create, migrate, rerun (idempotency), rollback — confirm the audit trail.

5

Re-run the creator-rule and link tests after the fix, then re-issue this report with live evidence.

Report generated 2026-09-14 · labels use text, never color alone · no learner reflections, free text, uploads, or raw logs are included.

Integrity checks are non-destructive and detection-only. Fixes marked "auto-fixed: no" are intentionally left for review so no learner data is ever silently changed.