# Mobile completion: release and acceptance

## Scope

PR #167 now includes Assigned search and project-role authorization (previous
checkpoint `dec231a5b`), plus read-only WhatsApp send reconciliation, matched F2F
recording/report endpoints and a voice-note readiness command. The accompanying
Flutter changes belong to `property-lab/propertylab-b2b-app`, `codex/native-ui`.
This is not an automatic production deployment or App Store/TestFlight release.

## Deployment order

1. Review/merge #167 into master through the normal release process. Apply its
   original F2F session migration if not already applied. These completion
   additions introduce **no further migration**. Do not seed/reset production.
2. Deploy code, refresh route/config caches and restart workers through the
   existing operations procedure. Preserve existing WhatsApp credentials,
   company settings, Lead ownership and vendor-ingestion configuration.
3. Enable microphone voice notes in the production environment, after verifying
   ffmpeg with libopus is executable by the PHP application user:

   ```dotenv
   AGENT_APP_VOICE_NOTES_ENABLED=true
   AGENT_APP_VOICE_FFMPEG_BINARY=ffmpeg
   ```

   An absolute binary path may be needed in PHP-FPM's environment. Rebuild config
   cache via normal deployment and run `php artisan agent-app:check-voice-notes`
   as the application user, in the application container if applicable. Require
   exit 0/PASS. This converts generated silence locally and sends no message.
   Verify effective PHP-FPM `upload_max_filesize`, `post_max_size`, proxy body
   limits and timeouts, not just CLI PHP. Raw voice is at most 9,600,000 bytes
   plus multipart overhead; normal document uploads still allow up to 25 MB.
4. Validate authenticated conversation capabilities (`supports_voice` and
   `supports_send_lookup`), F2F endpoints and Assigned search in the deployed
   company workspace. A missing endpoint is not an empty successful result.
5. Release the updated Flutter build separately. Existing APKs/TestFlight builds
   do not acquire the new displays merely by deploying this backend.

## Physical acceptance after deployment

Use an explicitly approved internal Lead/recipient (Zhang Youchen was approved
for this thread), never a live customer by default:

- iPhone + Android: request microphone permission, record, stop, explicitly send
  and play back at recipient. Check permission denial, interruption/background,
  BLE recording contention, Cloud API closed-window refusal and QR/Bridge.
- After a deliberately uncertain send, reopen and check the original UUID. Show
  persisted delivery status without another POST, including when voice cache is
  missing. Unknown results stay unresolved; removed sends expose no content.
- F2F: assigned independent lanyard starts/stops physically, uploads via its
  existing vendor path, matches within the declared meeting and appears in the
  App. Verify transcript, analysis, Meeting Report and next steps. Test multiple
  chunks and both upload/completion arrival orders, manual unlink and revocation.
- Lead/WhatsApp: project-only Caller/Closer appears in Assigned/search, role and
  project labels are visible, selected-BD filters never widen permissions.

If a gate fails, retain the existing voice flag off / previous App release until
resolved. Do not delete pending messages or recordings to make acceptance pass.

## Automated evidence

September 15, PHP 8.4, isolated local MySQL test DB:

- Agent API + F2F ingestion + Manage/F2F + engagement visibility: **399 tests,
  2,727 assertions passed**. One pre-existing PHPUnit XML deprecation.
- Real ffmpeg/libopus conversion and bounded voice probe passed locally. No
  provider messages or production configuration changes were made.
- New tests cover original-sender/conversation scope, expired-window lookup,
  deleted messages, voice attachments, session/report ownership, current Lead
  access, manual unlink, pagination and safe report fields.
- Final list query reads metadata only (not 25 full transcripts/AI payloads).
  F2F regression rechecked after this projection: 18 tests / 120 assertions.
- Pint and test-double signature checks passed (56 overridden methods).

Production configuration, physical lanyard ingestion and dual-provider microphone
delivery are release gates, not claims implied by these automated checks.
