AppIdea Bangladesh
Icon & evidence library
03 / Validation & known findings

What passed.
What did not.

A clean automated result and a visible UI defect can coexist. This pack preserves both.

143Tests passed / no skips
4JavaScript syntax checks passed
151Source-manifest hashes matched
2Sampled create forms failed

The exact capture method

Network URL navigation is blocked by the managed browser policy in this environment. That policy was left unchanged. The UI was rendered as offline content using the supplied HTML body, unchanged CSS and unchanged JavaScript in headless Chromium 144.0.7559.96.

A small fetch bridge forwards relative API calls through a Python HTTP client to the real local aiohttp server and a fresh synthetic SQLite workspace. App selection is set through the actual UI state and functions. A UUID fallback supports the non-secure about:blank rendering context. API responses are not fabricated; temporary credentials and the database are not distributed.

These are UI-rendering captures, not end-to-end browser-network acceptance. Browser URL routing, native cookie transport, same-origin/CSP enforcement, service workers, PWA installation, physical-device behaviour, full workflows and assistive-technology acceptance are outside this run.

The 37 PNGs comprise the sign-in and portfolio pages plus five captures per app: English overview, Bengali overview, mobile-width overview, record table and create form. The form captures include the two failures. No create form was submitted.

Source: capture record · capture harness (The local test/capture harness remains in the supplied offline ZIP.).

Fresh automated checks

ModuleTestsResult
test_commerce_school.py27PASS
test_frontend_contract.py6PASS
test_healthcare.py23PASS
test_proposals_social.py32PASS
test_reference_safety.py2PASS
test_security_recovery.py45PASS
test_suite_integration.py8PASS
Total143PASS

Environment differs from the release pins

Fresh environment: Python 3.13.5, SQLite 3.46.1, Node v22.16.0, aiohttp 3.13.3, cryptography 46.0.4, tzdata 2026.2.

Supplied candidate evidence records Python 3.12.14 with aiohttp 3.14.4, cryptography 50.0.1 and tzdata 2026.5. The new run is supplemental; it does not reproduce that exact pinned environment.

Started: 2026-10-10T17:26:18.632639+00:00
Finished: 2026-10-10T17:26:50.661181+00:00
No source files changed during the run.

Fresh validation JSON · Test log · Supplied validation JSON (Source snapshots and local paths are not published with this site.)

Finding UI-01 / observed / not repaired

Scalar textarea fields cannot render

Observed in: BriefBunon → Projects → Add record; GolpoShur → Brand voice kit → Add record. Both dialogs display: Cannot set property type of #<HTMLTextAreaElement> which has only a getter.
BriefBunon create form displaying the textarea error
BriefBunon: observed failure, original source.
GolpoShur create form displaying the textarea error
GolpoShur: observed failure, original source.

Source correlation

In suite/static/app.js (Source snapshots and local paths are not published with this site.), scalarField selects a textarea element at line 241 but passes type: inputType at line 245. The E helper at line 50 assigns matching DOM properties directly. The native textarea type property is read-only, so the strict-mode assignment throws.

The DOMless contract suite passed; this native DOM error was not caught by that run. Other scalar textarea forms may share the defect but were not exhaustively sampled. Five other selected create forms rendered without an observed form error.

Suggested repair, not applied: omit the type property when creating a textarea, then rerun native-DOM, form and persistence regressions. The original source and failure screenshots remain unchanged in this pack.

Integrity and release boundaries

All 151 files listed by the supplied release manifest matched their SHA-256 values. The input ZIP SHA-256 is:

67b254adad3e15e46e75704d44b59a4bab3de342daa794fef8a4dbc0421df4b3

The preserved source subset is a reference, not a standalone app distribution. The original manifest includes files not repeated here. Subset mapping and hashes (Source snapshots and local paths are not published with this site.).

The supplied audit retains 44 locally implemented, 29 partial and 15 blocked requirements. Live provider integrations, professional review where applicable, broader browser/device acceptance and target deployment gates remain open. This pack does not certify accounting, clinical, legal, security or accessibility compliance. Supplied release gates (Source snapshots and local paths are not published with this site.).