Use non-identifying test data only. Test the exact release-signed candidates, not debug builds. A simulator is useful during development but does not replace any required physical device.
Required Devices
Complete the full test set on:
- iPhone.
- iPad.
- Android phone.
- Android tablet.
- supported desktop browser.
- supported mobile browser.
Record the device model, operating-system version, app/build version, browser version where relevant, tester, date, result, and a private evidence reference.
Test Set
- Sign in through the system browser and return through the verified link.
- Cancel sign-in and confirm that no session is created.
- Reject a wrong state, wrong verifier, reused code, and expired code.
- Sign out and confirm the native bearer session is revoked.
- Let a session expire and confirm the app returns to a clear signed-out state.
- Revoke the device from My Account on another platform.
- Remove a school role and confirm the school disappears after refresh.
- Disable the account and confirm every platform loses access.
- Deny camera permission, then recover through normal device settings.
- Scan both a QR profile code and a Code 128 card locally.
- Confirm no camera frame or scan image is saved or uploaded.
- Open approved Universal Links and Android App Links in the app.
- Confirm unapproved and privileged paths do not bypass normal authentication.
- Save and share a PDF through the operating-system controls.
- Interrupt the network during sign-in, session loading, scanning, and sign-out.
- Reset the password and confirm existing sessions follow the approved revocation rule.
- Change a fictional test record on one platform and confirm it appears on all others after refresh.
- Confirm the app remains usable with larger text, screen reader, keyboard, and tablet rotation.
Store Channels
- upload the signed Apple build to TestFlight internal testing.
- upload the signed Android build to Play internal testing.
- correct every finding and document the retest.
- repeat the complete critical path with the exact release candidates intended for review.
Prepare the ignored private records with pnpm store:evidence:init. Complete release-evidence/device-tests.json, then run pnpm store:evidence:check. Only a fully passing matrix supports BAND_LICENCE_NATIVE_DEVICE_TESTS_PASSED=true.