{
  "date": "2026-10-04",
  "scope": "Local platform implementation and actual HTTP/PostgreSQL tests; static documentation publication only",
  "implementationFiles": [
    "services/platform/src/auth.mjs",
    "services/platform/src/runtime.mjs"
  ],
  "regressionFile": "services/platform/tests/referral-registration-recovery.test.mjs",
  "firstCallbackFailure": {
    "before": [
      {
        "loginSucceeded": true,
        "summaryStatus": 200,
        "incoming": null,
        "profileExists": true,
        "registrationFailureCodes": [
          "referral_registration_failed"
        ]
      },
      {
        "loginSucceeded": true,
        "summaryStatus": 200,
        "incoming": null,
        "profileExists": true,
        "registrationFailureCodes": [
          "referral_registration_failed"
        ]
      }
    ],
    "after": [
      {
        "loginSucceeded": true,
        "summaryStatus": 200,
        "incoming": "observed",
        "profileExists": true,
        "registrationFailureCodes": [
          "referral_registration_failed"
        ]
      },
      {
        "loginSucceeded": true,
        "summaryStatus": 200,
        "incoming": "observed",
        "profileExists": true,
        "registrationFailureCodes": [
          "referral_registration_failed"
        ]
      }
    ],
    "injection": "Only one borrowed isolated-PG registration clock query per signup; host clock unchanged"
  },
  "tests": {
    "newFileBefore": {
      "passed": 3,
      "failed": 3,
      "log": "work/existing-project/invite-registration-red.log"
    },
    "targeted": {
      "passed": 16,
      "failed": 0,
      "log": "work/existing-project/invite-registration-targeted.log"
    },
    "platformFull": {
      "passed": 263,
      "failed": 0,
      "log": "work/existing-project/invite-registration-platform-full.log"
    },
    "appFull": {
      "passed": 356,
      "reusedPriorResult": true,
      "sourceUnchangedThisPhase": true
    }
  },
  "publicGo": {
    "publicGoVerifiedSignupPassed": true,
    "publicGoRepeatAttributionPassed": true,
    "signedDeviceProfiles": 2,
    "relationCount": 1,
    "originalRelationUnchanged": true,
    "sharedIPRequiresReview": true,
    "rewardRows": 0,
    "sourceMediaRequests": 0,
    "upstreamTransport": "Requests forbidden; actual Go test child must exit 0",
    "scope": "Actual public Go endpoints, Better Auth and isolated RAM PostgreSQL. OTP captured by fixture; no source or credible viewing acceptance.",
    "goExitCode": 0,
    "log": "work/existing-project/invite-registration-go.log"
  },
  "testSetupCorrection": {
    "bootstrapViewer": false,
    "verifiedLoginPassed": true,
    "incomingState": null,
    "profiles": 2,
    "signedRegistrationDevices": 0,
    "scope": "Diagnostic comparison without the real Web viewer-cookie startup; this does not exercise the shipped login flow."
  },
  "review": {
    "actor": "root",
    "freshIndependentReview": false,
    "checks": [
      "Only framework verified new session supplies account identity",
      "Trusted bridge remains responsible for device/IP, no Go production change",
      "Original registration timestamp and relation/reservation remain unchanged",
      "Temporary business callback failure keeps verified login usable",
      "Same-device, older-than-window and already-qualified bindings still rejected",
      "Repeated verification and unknown committed response create no rewards"
    ]
  },
  "historicalObservation": "The old 210/212 failure did not preserve its cause code. The same symptom is now reproduced under a controlled first-callback rejection and that recovery gap is fixed; this does not establish the original sole cause.",
  "unchanged": [
    "No dependency/schema migration/background job added",
    "No App/native/APK/OTA change",
    "Web10/App50 site/App-only quota and copied-URL scope remain as confirmed"
  ],
  "remaining": [
    "Real SMTP delivery",
    "Credible viewing and installation qualification",
    "Production operations and full project acceptance"
  ]
}
