{
  "schemaVersion": 1,
  "project": "Dice it Yourself",
  "developer": "Seol Youngwoong",
  "dateKST": "2026-09-30",
  "startedAt": "2026-09-30T05:56:21.485Z",
  "endedAt": "2026-09-30T05:56:22.825Z",
  "sourceRevision": "4c3047d34ec481c3626b1a07449c47eb49240e65",
  "sourceTrackedClean": true,
  "sourceFilesUnchanged": true,
  "environment": {
    "platform": "win32",
    "node": "v24.19.0",
    "tsx": "4.23.13"
  },
  "method": "Focused local regression tests using synthetic fixtures, in-memory SQLite and mocked provider/transport boundaries.",
  "command": [
    "node",
    "node_modules/tsx/dist/cli.mjs",
    "--test",
    "--test-reporter=tap",
    "tests/auth-google-policy.test.ts",
    "tests/auth-options.test.ts",
    "tests/media-access-index.test.ts",
    "tests/moderation.test.ts",
    "tests/private-room-link.test.ts",
    "tests/public-room-access.test.ts"
  ],
  "result": {
    "tests": 25,
    "passed": 25,
    "failed": 0,
    "skipped": 0,
    "cancelled": 0,
    "todo": 0,
    "exitCode": 0
  },
  "testCases": [
    "same-email Google sign-in cannot silently link; authenticated explicit link preserves user and password",
    "new Google users can sign up and explicit links cannot change an existing account email",
    "3100 preview origins are accepted only when auth is configured for loopback development",
    "Google is absent unless both credentials are configured",
    "membership migration backfills and uses indexed participant/code lookup across unrelated rooms",
    "leave, rejoin, replacement, delete and rollback keep membership projection atomic",
    "gameplay-only writes do not rewrite membership rows; stale projection cannot grant media",
    "trusted private room batches reuse current membership without global media lookups",
    "canonical SHA256 ignores object key order but commits every media, text, setting and array edit",
    "submission stays pending; admin approval binds exact content; installer entitlement cannot authorize edits or revoked content",
    "official public eligibility needs exact current content, not officialId marker",
    "private media requires owner, acquired entitlement or active private-room reference; kick/leave/public room revoke peer access",
    "relay permission follows registered recipient, expiry and current membership",
    "moderator can view submitted media only; anonymous visibility follows live approval",
    "reports preserve server-resolved names/content and database trigger prevents later snapshot mutation",
    "workshop report snapshots approved content; later withdrawal does not alter it",
    "migration preserves legacy skin/media IDs, hides unreviewed listings and keeps installs/likes",
    "admin pages reach submissions and reports beyond 50 and preserve status filters",
    "solo rooms never start peer signaling; another human starts it lazily",
    "PeerJS channels wait for signaling registration before dialing",
    "incoming game negotiation survives a pulse before its data channel exists",
    "a private RoomLink never resumes HTTP polling, cursor relay or heartbeat after bootstrap",
    "account-change invalidation deduplicates notifications and detaches cleanly",
    "admission denied at link closes transport and stops retries",
    "admission denied at sync closes transport and stops retries"
  ],
  "sourceFilesSha256": {
    "tests/auth-google-policy.test.ts": "ae227a62832dc9ebaf28e15706d53b54bc350c89fa7fbdc3d5b2b7ec2996576a",
    "tests/auth-options.test.ts": "434ac510de4db3dbb70fb849d4e6a0f0c9edc42067da3ee625cdd56d95ccee6d",
    "tests/media-access-index.test.ts": "24b36f28c8c6a4532773da7d32fb8d0045968ec54e51426ab89ebfcbccd5e254",
    "tests/moderation.test.ts": "ed9ef50920ce1bb20d802b129353fc616b315f4210267c567f6c53fa2f8bf139",
    "tests/private-room-link.test.ts": "8460b4e1a16bc630ae47764079c669bbf4e583a3818211dd759a960e8f00a82b",
    "tests/public-room-access.test.ts": "6b64fbddf4004c8e4a2dc4ac3748732b7be9767530628ed9784433cddf156fa2",
    "lib/auth-options.ts": "e465cb6aa791711a486cebdadb65f00792d91edee2fbd259f367600ec222137c",
    "lib/media-access.ts": "3702ef9b18a97a65fe8f667ded90d2faed467b22d6c42b2cb4c32622f4bb38ee",
    "lib/relay-access.ts": "3d45ce09abcb0bf4a4f0c170c1004b244f019e49bd90eb8642d66636689b09c8",
    "lib/moderation-server.ts": "0228317d601d0bd787f2a8f0469d0fd601950621cf0af4a300bc744d89936436",
    "lib/skin-provenance.ts": "dd31dc6aa19ae14e6ae82c509a22837c0cf2279c53da98f7ef5bd2c56fa1f92a",
    "lib/server.ts": "69ce77dfa72586f66c5976c7d01cc9484eaf584b2cfb33b4576fae6f378f8561",
    "package.json": "43025577ae141688142e5db2939d90f3c9dc7c8b5e69528ea4f24a60a09936a0",
    "package-lock.json": "aff74b110175edb82e9de8eb27a0a9910982d51418ff1b1eb5cc262733b1b137"
  },
  "tapSha256": "0140fb96026d5e7f799694c58442b9e9c016920394d9ad5e98ed78b196029046",
  "stderrSha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
  "relatedImplementationHistory": [
    {
      "commit": "75efad92572024641d017eebb656078432a86c85",
      "committedAt": "2026-09-05T15:23:30+09:00",
      "subject": "Prepare Public Beta auth moderation and private Cloudflare migration",
      "classification": "existing implementation change; not a newly discovered vulnerability"
    },
    {
      "commit": "397fca107a6c5f6609c412747adfd80bb20681d1",
      "committedAt": "2026-09-06T00:20:29+09:00",
      "subject": "Add authorized peer media transport and reduce resource loading work",
      "classification": "existing implementation change; not a newly discovered vulnerability"
    }
  ],
  "newCodeChangesInThisReview": false,
  "limitations": [
    "No production or staging HTTP tests.",
    "No live Google OAuth provider verification.",
    "No real WebRTC peer negotiation.",
    "No browser/mobile UI verification.",
    "No independent audit, full penetration test or new vulnerability finding."
  ]
}
