QA / Diagnostics Center
Read-only quality checks. No learner data is modified here.
Open the Platform Troubleshooting CenterRelease decision
BLOCKED — do not invite outside families
Safe for owner-only testing in the current single household. Two Critical Blockers (creator-rule gap and self-service link creation) mean a signed-in account could create or link records for an unlinked learner; live cross-account enforcement is also not yet observed. Re-evaluate after the next-action list is complete — a public launch is not recommended in this validation pass.
Verified automatically
Default-deny RLS policy present on all 19 protected collections (creator / viewers / exact-owner-identity branches).
Diagnostics, QA reset, ErrorLog, and QA collections are admin-role only in live mode.
Break-return idempotency: one return event, one +5 Focus award (Resilience tab, automated run).
Readiness upsert: one record per local day (Resilience tab, automated run).
Memory Vault replay guard: a review graded twice within the replay window is a no-op.
Ownership immutability: app write paths strip student_email from every update.
Logged-out sessions never issue entity requests (demo store only).
Verified manually
None recorded yet — human checks are pending (see A11y Manual and Resilience tabs).
Not testable here
Live multi-account RLS enforcement (R-01–R-10, R-15): Base44 accounts exist only via dashboard invites; a human must complete the Identity Plan wizard and run the matrix from each account. Builder tooling cannot sign in as other users.
Direct API request simulation with learner/parent tokens: no token impersonation exists in this environment.
Durable offline write queue: the platform has no offline queue primitive — documented, not simulated.
Failed or needs remediation
Critical · Creator-rule gap (T-1/T-2/T-3)
Why it matters: RLS templates cannot verify a ParentLearnerLink at create time, so a signed-in account can create records naming another learner while listing itself in viewers.
Safest corrective action: Move parent-side record creation behind a service-role backend function that validates the explicit link before writing.
Retest status: open — re-run after remediation.
Critical · Self-service link creation (T-8)
Why it matters: Any signed-in account can create a ParentLearnerLink naming itself the parent of any learner; links feed viewer resolution.
Safest corrective action: Require admin-approved invite/consent or service-role validation for link creation.
Retest status: open — re-run after remediation.
Multi-account RLS matrix
Route/admin gates (R-11–R-14) and logged-out denial (R-16) verified in code.
Allow/deny cases R-01–R-10, R-15 require the six live QA identities; policy config is in place and verified.
Write-path tampering results
created_by_id unforgable (platform); foreign-record updates and viewer edits denied; admin records protected; URL params carry no data authority.
Creator-rule and link-creation gaps — Critical Blockers, remediation defined.
Creator-rule review
A bypass is possible within invited accounts: the create rule accepts any owner identity when the creator lists itself in viewers. RLS cannot express link verification at create time. Policy left unchanged (narrowing it would break the parent write flows); documented as the release blocker with the service-role remediation.
Legacy migration results
Migration Lab built with disposable QA records, link-derived stamps, fail-closed ambiguity, idempotent reruns, audit trail, and confirmed rollback. Execute it from the Migration Lab tab with the live admin session to record outcomes.
Resilience results
Break-return double tap, duplicate readiness, and review replay — run from the Resilience tab in demo mode; results recorded with XP before/after and duplicate counts.
UI-level scenarios (S1–S4, S6–S12) carry exact tester steps; not yet verified.
Manual accessibility status
No human-verified checks yet — the pack records tester, device, route, notes, and pass/fail per check, and never auto-fills.
Next action list
Route parent-side record creation and ParentLearnerLink creation through a service-role function that validates the explicit link (clears both Critical Blockers).
Complete the QA identity wizard (six invited accounts), then execute the RLS Matrix and Write Path panels live and record evidence.
Have a human tester complete the 12-check accessibility pack and the manual resilience scenarios.
Run the Migration Lab end-to-end: create, migrate, rerun (idempotency), rollback — confirm the audit trail.
Re-run the creator-rule and link tests after the fix, then re-issue this report with live evidence.
Report generated 2026-09-14 · labels use text, never color alone · no learner reflections, free text, uploads, or raw logs are included.
Integrity checks are non-destructive and detection-only. Fixes marked "auto-fixed: no" are intentionally left for review so no learner data is ever silently changed.