# SafeCircle Community Alerts — Release Candidate v5 Test Report

Date: 2026-10-09

## Additional v5 fix

- Community report text-length validation no longer fatals when PHP `mbstring` is absent; it uses Unicode-aware counting when available and a safe fallback otherwise.

## Passed locally

- PHP syntax validation for all three new PHP endpoint/admin files.
- JavaScript syntax validation for `frontend/app.js` and `frontend/sw.js`.
- HTML parser check: no duplicate IDs; all required community-alert UI elements are present.
- Regression assertions for server-side moderation transitions.
- Local PHP development server smoke checks: unauthenticated GET requests to both new API endpoints return HTTP 401 with a JSON `Unauthorized` response; OPTIONS preflight returns HTTP 200.
- ZIP integrity check.

## Fix included in v4

A moderation workflow bug was found during review: a pending report could be marked resolved, and the feed returns resolved reports, which could expose an unreviewed report. The server now only permits `pending → verified`, `verified → resolved`, and rejection of pending/verified/resolved reports. The UI buttons match those transitions. Only the first pending-to-verified transition sends a community notification.

## Not yet tested / release blockers for production certification

- MySQL migrations have not been run against the production schema or a compatible live MySQL instance.
- Authenticated report submission, feed filtering, and admin moderation have not been exercised end-to-end against MySQL. This test container has PDO but no PDO MySQL driver or cURL extension. The report endpoint now has a fallback when `mbstring` is absent.
- Actual Web Push delivery to real subscribed devices has not been tested. Delivery also depends on browser permission, subscription validity, and server PHP extensions/configuration.
- The package has not been tested on the running SafeCircle production host, nor have the existing SOS/check-in/trip/family-circle flows been regression-tested against a live server.

## Before production use

Back up the site/database; verify the exact production schema and required PHP extensions (`pdo_mysql`, `mbstring`, `curl`, `openssl`); deploy to a staging copy first; run both SQL migrations there; test reporting/moderation/push on real devices; and only then promote the same tested build to production. Do not expose configuration files, database exports, or credentials.
