Prototype — fictional demonstration data only.
Prototype — fictional demonstration data only.

Release safeguards still apply. A completed checklist needs real evidence and authorised sign-off.

Use non-identifying test data only. Test the exact release-signed candidates, not debug builds. A simulator is useful during development but does not replace any required physical device.

Required Devices

Complete the full test set on:

  • iPhone.
  • iPad.
  • Android phone.
  • Android tablet.
  • supported desktop browser.
  • supported mobile browser.

Record the device model, operating-system version, app/build version, browser version where relevant, tester, date, result, and a private evidence reference.

Test Set

  1. Sign in through the system browser and return through the verified link.
  2. Cancel sign-in and confirm that no session is created.
  3. Reject a wrong state, wrong verifier, reused code, and expired code.
  4. Sign out and confirm the native bearer session is revoked.
  5. Let a session expire and confirm the app returns to a clear signed-out state.
  6. Revoke the device from My Account on another platform.
  7. Remove a school role and confirm the school disappears after refresh.
  8. Disable the account and confirm every platform loses access.
  9. Deny camera permission, then recover through normal device settings.
  10. Scan both a QR profile code and a Code 128 card locally.
  11. Confirm no camera frame or scan image is saved or uploaded.
  12. Open approved Universal Links and Android App Links in the app.
  13. Confirm unapproved and privileged paths do not bypass normal authentication.
  14. Save and share a PDF through the operating-system controls.
  15. Interrupt the network during sign-in, session loading, scanning, and sign-out.
  16. Reset the password and confirm existing sessions follow the approved revocation rule.
  17. Change a fictional test record on one platform and confirm it appears on all others after refresh.
  18. Confirm the app remains usable with larger text, screen reader, keyboard, and tablet rotation.

Store Channels

  • upload the signed Apple build to TestFlight internal testing.
  • upload the signed Android build to Play internal testing.
  • correct every finding and document the retest.
  • repeat the complete critical path with the exact release candidates intended for review.

Prepare the ignored private records with pnpm store:evidence:init. Complete release-evidence/device-tests.json, then run pnpm store:evidence:check. Only a fully passing matrix supports BAND_LICENCE_NATIVE_DEVICE_TESTS_PASSED=true.