# Connected-client course — actual local learner walkthrough

19 September 2026. Completed the core course through the running AppEngine API (`http://localhost:3300`, version0.132.0), Studio (`http://localhost:3100`, version0.6.2) and a small browser client (`http://127.0.0.1:4317`). Used the authorized newly created learner organization `ck-local-mu83iwh3`, two new fictional customers and one new free consultation. No author/demo customer or production business record was reused.

## Results

| Course operation | Actual result |
| --- | --- |
| Health, staff sign-in | Health200; staff sign-in201 with matching user/email/org. Public `whoami` returned `Anonymous User` even with this valid staff bearer; corrected the manuscript’s impossible email stop condition to verify the completed sign-in response and protected lookup. |
| Customer prerequisite | Both Lina (`lina.events@example.invalid`) and Kofi (`kofi.events@example.invalid`) created through `/profile/customer/signup`201, then signed in201. No inbox verification challenge appeared. |
| Initial reads | Each profile200 with its own customer ID; reservations/orders200 with empty data arrays; dashboard200. |
| Definition create/reuse | Exact manuscript definition PUT200; fresh raw GET200; exact-name lookup reports one matching definition. Studio Reservation Definitions shows the service,30minutes,$0,09:00–17:00 and capacity1. |
| Booking | Lina POST201, persisted reservation `6aae607128eaa92a3d2a0b45`, status`new`, customer ID matching Lina, Chicago timezone. Studio’s card displays `3d2a0b45`, Oct5,10:00AM and Lina’s email; survives reload. |
| Direct customer reads | Lina list contains1 and own single GET200; Kofi list0 and same single GET404. Generic raw GET gives Lina200 and Kofi403 without booking data. |
| Delegated reads | Staff bearer plus Lina customer bearer gives list1/single200/generic200. Substituting Kofi gives list0/single404/generic403. A primary staff identity does not bypass the effective customer boundary. |
| Profile persistence | Flat PUT200 for Lina’s firstName/lastName/phone; freshGET contains `Tutorial Updated` and fictional phone`+12025550147`. Kofi’s profile remains unchanged. |
| Refresh | POST201 returns usable access token; following authenticated profileGET200 identifies Lina. Existing refresh value retained if response omits replacement. |
| Errors | Missing/invalid bearer401; wrong customer password400. Browser also renders missing-org400 separately from successful empty data. |
| Browser response handling | Actual customer API calls from the local client: Lina Loaded1; Kofi No bookings; invalid-token401; missing-org400; corrected credentials retry recovers Loaded1. Customer tokens masked in captures and never stored in the page’s persistent storage. |
| Browser CORS | OPTIONS204 reflects`http://127.0.0.1:4317`, permits GET and authorization/content-type/orgid. Actual GET responses contain`Access-Control-Allow-Origin: *`; browser requests succeed. This verifies this local origin only. |
| API-key form | Followed Account→API keys→Create New Key. Actual form captured; Permissions remains empty. Cancelled by closing the isolated context; no key created. |
| Dashboard count | After the booking, upcomingReservations remains0 while the customer list and Studio display the booking. Existing course distinction remains correct. |

## Mail boundary used for these records

Configured only this learner-owned organization through supported `POST /upstream/save-integration`: `SMTPProvider`, name`tutorial-local-mail-capture`, priority100, host`127.0.0.1`, port2527, securefalse, sendOutgoingtrue. The organization’s own capable SMTP provider is selected before shared fallback. Explicit upstream sendEmail reached the loopback catcher; both customer welcome messages and both immediate booking messages subsequently reached it too. Future reminder messages exist but were not fired.

The catcher binds only to127.0.0.1 and stores raw messages in private `/tmp/learner-smtp-capture-20260919` files (directory0700/files0600). Raw messages can contain credentials or acceptance links and are not included in the evidence. No shared provider configuration or shared-worker pause was changed. This boundary covers this organization; it does not capture shared-org platform signup notices. The catcher remains running for the parent task’s authorized staff workflows.

## Evidence

- [Sanitized real HTTP transcript](assets/local-connected-client/api-results.json): tokens/password fields removed; actual methods, paths, statuses and owned fixture readbacks preserved.
- [Reloaded staff board](assets/local-connected-client/04-reservations-reloaded.png), [visible text](assets/local-connected-client/04-reservations-reloaded.txt).
- [Reservation Definitions](assets/local-connected-client/05-reservation-definition.png).
- [Unsaved API-key form](assets/local-connected-client/02-api-key-form.png).
- [Browser booking](assets/local-connected-client/06-browser-own-booking.png), [empty state](assets/local-connected-client/07-browser-empty.png), [401](assets/local-connected-client/08-browser-error.png), [400](assets/local-connected-client/09-browser-missing-org.png), [CORS response ledger](assets/local-connected-client/browser-cors.json).
- [Runnable local response-check page](assets/local-connected-client/client.html): no embedded credentials; serve locally and enter a customer session.
- [Owned notification status metadata](assets/local-connected-client/mail-metadata.json); raw mail excluded.

Private credentials and live tokens stay in `/tmp/connected-client-private-20260919.json`, not in the repository. CLI runners are temporary `/tmp/connected-client-*.mjs`; their requests targeted only localhost. Browser contexts were newly created for this task and external requests blocked.

## Changes and limits

Edited the connected-client course, its pending report and this task’s evidence/report only. Added tested two-customer provisioning, current profile patch/readback, working single-read behavior, current ownership results, runnable response UI and browser-origin evidence. Replaced the broken staff-whoami prerequisite and identified historical failure screenshots explicitly.

No application source change was needed. One reservation was created; no duplicate POST was repeated. Historical duplicate submission remains a known concern, not a newly tested current result. No production/deployment, external provider send, API-key creation/scope enforcement, SDK package execution, forced expiry, reservation update/delete, attachment access or public rollout was certified. Read isolation is narrowly proven for the named direct and delegated routes on this local build.
