# EventOxygen — local attendee walkthrough

Status: in progress, 24 September 2026. This course is not counted complete.

## Actual local setup

Built the current EventOxygen Android source with compile-time configuration for the review organization and an application registered through the authorized owner registration endpoint. App credentials remain in private review state, outside documentation. Installed `com.appmint.event_app` on the review emulator; the previous stock app remains installed separately. The app talks to the isolated local API and real review data.

The signed-out event list now shows **Tutorial Makers Conference 2026**, November 14–15, Chicago. This closes the investigation's missing-event prerequisite; it does not mean the public stock APK automatically connects to a learner's organization. Organizer build instructions still need updating.

![Published training event in the local attendee app](assets/mobile-local/eventoxygen-browse-local.png)

## Signup navigation — reproduced and fixed; native retest passed

Entered a fresh fictional Lina Tutorial account through **My Account → Sign Up**, completed all five fields, and submitted **Create Account**. Registration returned to Sign In, matching the earlier reported defect. The register screen popped only itself, leaving the login route covering the authenticated root.

Changed `event_app/lib/screens/auth/register_screen.dart` to return to the root route after successful registration, where AuthWrapper selects the authenticated destination. Failed registration retains the form. Rebuilding the local APK; verify with a second fresh practice attendee before marking fixed.

![Actual signup form with concealed passwords](assets/mobile-local/eventoxygen-signup-local.png)

## Still to execute

- Fresh signup with fixed navigation and relaunch persistence.
- Free ticket registration, reopening and staff admission/status refresh.
- Programme and Add to My Schedule persistence.
- People, connection acceptance, messages and meetings.
- Profile sharing and appropriate community post/bookmark behavior.
- Policy links, organizer build instructions, course and production-guide corrections.

Source inspection also found empty callbacks on Add to My Schedule and Share QR Code; these are not functional tests or completed fixes.

## Free registration — native pass

After returning to authenticated My Events, selected Browse Events → Tutorial Makers Conference 2026 → Get Tickets. The holder fields were blank; entered the same Lina attendee email and name explicitly. Selected one Tutorial General Admission, verified total Free, and selected Register once. Actual result: Booking Confirmed, one ticket, booking PAID, total Free, ticket CONFIRMED. No paid ticket selected and no payment provider invoked. Do not repeat registration to obtain another screenshot; the existing ticket is the admission test record. Its code is intentionally excluded from this report.

![One free ticket selected with matching attendee identity](assets/mobile-local/eventoxygen-free-registration-local.png)

The event detail also displays unformatted full date-time strings in narrow programme columns; speaker-card rendering requires investigation. These are newly observed presentation defects, not closed findings.

## Fixed-build signup and persistence — native pass

Installed the rebuilt APK without clearing app data. Lina remained signed in, and My Events displayed the conference with **1 ticket**. Used the normal drawer → Log out action, then My Account → Sign Up to create a distinct fresh Kofi Tutorial account. On successful submission the fixed build went directly to **My Events / No events yet**, with the KT avatar, without Android Back or another sign-in. The second account deliberately has no ticket yet.

![New signup reaches the authenticated destination directly](assets/mobile-local/eventoxygen-signup-fixed.png)

![Existing attendee ticket survives reopening](assets/mobile-local/eventoxygen-my-events-reopened.png)

## Personal schedule — save, readback and delete verified natively

Replaced the empty Add to My Schedule callback with a personal session bookmark using the existing customer-scoped bookmark API. Added explicit loading/retry/error states, paginated saved-state lookup and descriptive notes so Saved identifies the talk. This does not register a seat.

As fresh Kofi, opened Home → Schedule → the 11:00–12:00 talk, selected Add to My Schedule and saw Remove from My Schedule. Left and reopened the session; the saved state remained. Opened the actual drawer → Bookmarks → Session; the talk title, day, time and room appeared. Used the trash control; the filtered list returned No bookmarks. No staff token or author-state write was used for these actions.

![Saved state from the real API](assets/mobile-local/eventoxygen-session-saved.png)

![Identifiable saved session](assets/mobile-local/eventoxygen-saved-session-list.png)

![Actual open drawer](assets/mobile-local/eventoxygen-drawer-open.png)

Build passed. Targeted Dart analysis reported no errors; it retains existing warnings about unused session participant rendering and style-level lint notices. The session participant display is not counted fixed by that analysis.

## Resolved historical finding EO01-004

### EO01-004 — “No session bookmark button” leaves the visible agenda action unexplained

- **Severity/status:** Medium; verified screenshot/text inconsistency, control behavior untested.
- **Exact step:** Part 3 → 1, lines 178–182.
- **Expected:** The screenshot and warning explain which session-saving actions a learner can use and which are absent.
- **Actual:** The text says the practiced Schedule/session detail contains no session bookmark button and says not to hunt for a nonexistent control. The embedded session detail visibly contains **Add to My Schedule**. A beginner cannot tell whether this is an alternative agenda action, an inert button, or distinct from Bookmarks.
- **Effect:** The learner is discouraged from an apparently relevant visible action without understanding its role. This review does not infer that the button works or reserves a seat.
- **Evidence:** [Embedded session detail](../learner-review-records/assets/eventoxygen/embedded-15-session-detail.png), [numbered text](../learner-review-records/assets/eventoxygen/manuscript-numbered.txt), line 182.
- **Proposed correction:** Test Add to My Schedule on a fresh account and explain its observed effect and persistence separately from Bookmarks and seat registration. If untested, say so explicitly instead of broadly implying no relevant control exists.

**Resolution, 24 September:** Implemented and natively verified session save, reopen, Saved → Session list, deletion and return to Add to My Schedule. Course now contains actual steps and new screenshots.

## Resolved historical finding EO01-006

### EO01-006 — Navigation illustration does not show the drawer it promises

- **Severity/status:** Low; verified screenshot/caption mismatch.
- **Exact step:** Part 4 → 2, lines 231–237; reused navigation in Parts 4 and 5.
- **Expected:** “Event drawer with Connections and Meetings” visually locates both menu entries.
- **Actual:** `18-event-drawer.png` shows the event Home and hamburger icon; no open menu or Connections/Meetings entries are visible.
- **Effect:** Written navigation is plausible but the screenshot fails to help a first-time learner find these controls.
- **Evidence:** [Embedded drawer screenshot](../learner-review-records/assets/eventoxygen/embedded-18-event-drawer.png).
- **Proposed correction:** Replace it with a settled, fully open drawer capture showing the named entries; avoid a capture taken during the transition.

**Resolution, 24 September:** Captured the fully open native drawer showing Connections, Meetings and Bookmarks and replaced the misleading closed-drawer course image.

## Profile QR sharing — native chooser pass

Implemented the empty share callback in `qr_profile_screen.dart`: renders a PNG with a white quiet zone and opens the platform share sheet. Signed-in Kofi → Me → QR icon → Share QR Code produced Android **Sharing image** with the explanatory profile text. Captured the real chooser and cancelled; no recipient selected and no external message sent. This is profile sharing, not admission. The changed file analyzes without errors (one style-level lint); APK rebuild/install passed.

![Actual Android image chooser](assets/mobile-local/eventoxygen-profile-share-chooser.png)

## Networking preparation and identity mapping

Prepared confirmed attendee participant records for the two fresh accounts through the organizer course's supported staff API, matching existing customers by their exact training email first. No duplicate signup or ticket was needed. Participant IDs and status are recorded in `assets/mobile-local/eventoxygen-participants.json`.

Actual People initially showed Kofi's own Connect action, while the request toast omitted Lina's name. Kofi → Lina Connect did create Pending successfully. Root cause: cards used enriched customer data, but filtering, search, status comparison and request labels read only participant data. Source now normalizes missing identity fields from `customerData.data` and removes self before grouping; pagination uses raw response length. Native retest remains pending. Do not send the existing request again.

### People mapping native retest

Rebuilt and reopened Kofi's People list: **All (2)** contains Lina and Nia, excludes Kofi, and Lina remains **Pending** after restart. Captured `eventoxygen-people-fixed.png`. The request was not resent.

### Logout and Home card defects — reproduced, source repairs awaiting retest

Logging out through the event drawer cleared authentication but left EventShell on top, still displaying the former attendee's ticket card. Captured `eventoxygen-logout-debug.png`. Both drawer logout handlers now await logout, clear event/ticket caches and pop to the authentication root. EventProvider invalidates in-flight reads so they cannot restore the previous account's cache after logout.

The same unbounded horizontal PersonCard layout also exists on event Home; applied explicit width and sufficient height to the speaker, sponsor and attendee rows. These source repairs are not yet counted verified.

## Meeting submission — reproduced, repairs under test

As Lina, accepted Kofi's request and sent the harmless materials message through native Chat. On Kofi's profile selected Meet, entered Tutorial materials coffee, and submitted. Actual native result: **At least one participant is required**; no meeting was created. Screenshot `eventoxygen-meeting-failed.png`.

Repaired `participants` → `participantIds` and `notes` → `description`; attached event identity/timezone. The form now identifies the event timezone, converts the chosen wall clock to an unambiguous UTC timestamp, and the list converts it back to the stored named timezone. Recipient actions now follow their own pending participant response, including the API's `proposed` status; previously the app looked only for a nonexistent `pending` meeting state. Organizer cancellation uses the organizer identity.

Added timezone 0.11.1 using the [package's documented IANA conversion API](https://pub.dev/packages/timezone). Four tests pass: Chicago winter roundtrip, summer offset, nonexistent spring hour rejection, and legacy wall-clock input independent of device timezone. Native meeting creation/acceptance remains pending.

Connection acceptance succeeded but summary counts remained stale. The source now reloads lists and totals after an accepted/rejected request; bulk acceptance snapshots IDs before those reloads. Fresh native counter retest remains pending.

### Home layout and accepted-connection readback

On the rebuilt app, Lina's event Home now renders Nia's speaker card with name and biography instead of an empty block. Captured `eventoxygen-home-speaker-fixed.png`. Reopened Connections from the drawer: actual totals **1 Connected / 0 Received** match the single connected Kofi row (`eventoxygen-connections-reopened.png`). This verifies readback; testing the new immediate post-accept refresh remains separate.

Latest documentation build passes at 227 pages. Chromium opened the EventOxygen course and fetched all 46 image URLs successfully (HTTP 200).

### Meeting creation and organizer readback — native pass

The fixed form created **Tutorial materials coffee** for November 14, 2026, **12:15 PM America/Chicago**, **15m**, with Main hall stage in Notes. Native success returned to Kofi's profile. Staff readback found exactly one matching meeting: `startTime: 2026-11-14T18:15:00.000Z`, timezone America/Chicago, duration15, status proposed, Kofi pending. No API creation workaround was used.

Drawer → Meetings initially shows Upcoming (0), because Upcoming contains confirmed meetings. **All (1)** displays PROPOSED and **14/11/2026 12:15 America/Chicago · 15min**, plus the saved notes. Recipient acceptance is still pending.

![Actual corrected form](assets/mobile-local/eventoxygen-meeting-form-fixed.png)

![Actual proposal and local venue time](assets/mobile-local/eventoxygen-meeting-proposed.png)

### Immediate connection totals — native regression passed

Prepared one additional Nia → Lina request with Nia's normal app/customer authentication (existing review-owned account), then accepted it in Lina's native Connections screen. Without reopening or pulling to refresh, summary totals changed from **1 Connected / 1 Received** to **2 Connected / 0 Received** and the list showed both Nia and Kofi. Captured `eventoxygen-connection-counts-fixed.png`. The previously accepted Kofi connection was preserved.

### Event-drawer logout — native pass

From Lina's authenticated event Home opened the drawer and selected Log out. The fixed build immediately returned to public **Events / My Account**; the authenticated event shell and ticket card no longer remained on top. Captured `eventoxygen-logout-fixed.png`. This is the explicit repaired-handler test, not an app restart used as a workaround.

## Resolved historical finding EO01-002

### EO01-002 — The tutorial build and event are described, not provided

- **Severity/status:** Blocker; prerequisite/document sufficiency finding, not a live event lookup result.
- **Exact step:** “What you need,” lines 17–22; Part 2 → 1, lines 103–105; Part 6 → 2, lines 352–362.
- **Expected:** After installing the specified app, browse Tutorial Makers Conference 2026 and use its free ticket, programme and People entries.
- **Actual:** The document says the stock app uses `eventos`, while its captures use a separate EventOxygen Tutorial build. No installable training build or enrollment/access route is supplied. The linked organizer lesson can describe making one's own event, but cannot connect a stock attendee app to that organization. The developer appendix expressly says source distribution and license were not established.
- **Effect:** A working stock download alone would not resolve the exercise prerequisite. A newcomer cannot assume the fictional event/accounts are available or silently substitute the author's private environment.
- **Evidence:** [Numbered manuscript](../learner-review-records/assets/eventoxygen/manuscript-numbered.txt), lines 17–22, 103–105 and 352–362; [organizer course](../course-content/appmint-run-an-event.md), “What you need” and Part 6.
- **Proposed correction:** Give a concrete supported training enrollment/build distribution route, or state a strict instructor preparation requirement with a readiness checklist and learner-specific event/build/partner information before Part 1. State clearly how to substitute an organizer's own event throughout.

**Resolution, 24 September:** Added strict organizer preparation, actual application registration and private compile-time build/install instructions. Built the configured app, verified its published event, fresh signup and free registration with two separate attendees. The lesson explicitly requires an organizer-supplied build/event and does not promise that the public stock APK includes these private fixtures.

## Resolved historical finding EO01-003

### EO01-003 — The documented developer meeting workaround lacks executable authentication/setup instructions

- **Severity/status:** High; blocked by missing instructions/prerequisites, requests not attempted.
- **Exact step:** Part 6 → 2–3, especially lines 356 and 364–391; invoked by Part 4 → 5 at line 283.
- **Expected:** An authorized developer follows the provided repair and creates/accepts a meeting for the actual practice accounts.
- **Actual:** The lesson supplies relative endpoints and JSON, but no API origin acquisition procedure, application-registration steps, customer sign-in request, required application/customer authorization headers, or a linked complete integration prerequisite. “Normal authorized … flow” and “ordinary sign-ins” do not tell a first-time developer how to form these requests. The fixed `kofi.community@example.invalid` payload also needs explicit substitution with the actual partner's identity. The organizer prerequisite describes staff headers; it does not supply the customer/application authentication procedure required here.
- **Effect:** The “supported request” is illustrative rather than independently executable. Using a staff token or recovering a token from author state would be an undocumented and inappropriate shortcut.
- **Evidence:** [Numbered manuscript](../learner-review-records/assets/eventoxygen/manuscript-numbered.txt), lines 352–391; [organizer prerequisite](../course-content/appmint-run-an-event.md), Part 6 introduction and request helper.
- **Proposed correction:** Link a complete authorized developer setup prerequisite with public origin selection, application registration, customer authentication and exact request headers; use explicit placeholders for actual account identities and meeting ID. Otherwise label this as an API payload reference and retain chat agreement as the attendee fallback.


**Resolution, 24 September:** Repaired the native meeting request, timezone display and recipient actions. Actual native creation and recipient acceptance passed with the two fresh accounts; stored record is confirmed. Rewrote Part 4 as executable native steps. The API contract remains an explicitly optional developer reference with authentication links, not a required workaround.

### Meeting recipient acceptance — native and persisted pass

Kofi → Meetings → All showed the same proposal with Decline/Accept. Selected Accept once. The card became CONFIRMED; Upcoming changed from0to1. Staff readback confirms the same record, correct original timestamp/timezone/duration, and Kofi status accepted. Screenshot `eventoxygen-meeting-confirmed.png`; readback `eventoxygen-meeting-readback.json`.

Recipient Inbox also showed Lina's full materials message. Opened it as Kofi and sent the fictional reply naming Main hall stage and12:15Chicago. Lina-side reply readback remains to be checked. Incoming chat timestamp displayed UTC while a new outgoing message displayed local time; `chat_screen.dart` now converts parsed timestamps toLocal, awaiting rebuild/native retest.

## Profile save — reproduced; repair awaiting native retest

Kofi → Me → Edit Profile: entered **Materials researcher** in Job Title, selected Save and reopened the form. Job Title was empty again. Source confirmed Save only waited one second and closed without an API request.

Replaced that stub with the authenticated own-customer update endpoint, using only the editable profile fields. The returned customer identity must match the signed-in attendee; saved user state is updated for reopening/restart. Failures retain the form and show an error. Rebuild/native saved-value and restart checks remain pending.

## Profile persistence and chat local time — native passes, 24 September

After installing the repaired APK, Kofi saved **Materials researcher**, reopened Edit Profile, force-stopped/restarted the app and reopened the form again: the job title remained. A fresh customer sign-in and authenticated `GET /client-data/profile` returned the same value. Evidence: [saved form](assets/mobile-local/eventoxygen-profile-saved.png), [sanitized server readback](assets/mobile-local/eventoxygen-profile-readback.json). The old `/profile/customer/profile` refresh URL returns 404; the app refresh method has been corrected to the verified own-profile endpoint.

Reopened the two-message conversation. Both persisted timestamps now display in the emulator's local timezone: Lina06:14 and Kofi06:34. [Native screenshot](assets/mobile-local/eventoxygen-chat-local-time-fixed.png). This also exposed reversed message ordering after reload; a chronological sort is in the next build, awaiting native retest.

## Conversation order and own-post bookmarks — native pass

Conversation now reloads oldest-to-newest, with both timestamps local. [Actual reopened messages](assets/mobile-local/eventoxygen-chat-order-fixed.png).

Kofi created one fictional timber-connector question through Explore → composer → Post. After installing the saved-post repair and reopening Explore, the same question remained. Selected Save under that question, then Home → drawer → Bookmarks → Post. The entry displays the question text; Open saved post returns to its original author/content/comments screen. No unrelated example post is required. Evidence: [draft](assets/mobile-local/eventoxygen-practice-post-draft.png), [published](assets/mobile-local/eventoxygen-practice-post-created.png), [saved](assets/mobile-local/eventoxygen-saved-post-fixed.png), [reopened](assets/mobile-local/eventoxygen-saved-post-reopened.png).

Resolved EO01-007 by replacing the dependency with an actual learner-created post and fixing the application’s generic, non-opening bookmark entry. Historical finding follows.

### EO01-007 — Saving a post depends on an unrelated, unsupplied community fixture

- **Severity/status:** Medium; prerequisite/instruction gap, live feed untested.
- **Exact step:** Part 5 → 1 and 3, lines 303 and 325–329.
- **Expected:** Follow the event course prerequisites and save the specified useful contribution.
- **Actual:** The target is “Zara's joinery question,” which the lesson says came from Studio Circle, a separate community. The front prerequisite list requires an app, event, partner and staff, not that community/post. The organizer course is the event prerequisite; the community course is not required before this step. A fresh organizer event or correctly scoped feed need not contain this post.
- **Effect:** Even with app/event access resolved, the exact Save exercise may have no target. Treating the old author's public feed as learner-provided data would hide the gap.
- **Evidence:** [Numbered manuscript](../learner-review-records/assets/eventoxygen/manuscript-numbered.txt), lines 15–22 and 299–329; embedded feed on [sheet 3](../learner-review-records/assets/eventoxygen/embedded-contact-sheet-3.png).
- **Proposed correction:** Let learners save an actual appropriate visible post, including their own newly created practice question if supported; alternatively provision a named practice post and list its community access as a prerequisite. Give an empty-feed branch and avoid depending on unintended organization-wide fallback.


## Admission QR — native freshness repair under test

Readback of Lina’s existing ticket before opening the repaired screen showed a code older than5,000seconds, while the server verifier defaults to a60second maximum. Both ticket layouts previously rendered the stored booking code. Replaced them with the holder-authorized fresh-QR endpoint,40second renewal, clearing on background and no stale-code fallback on failure. Opening My Tickets in the rebuilt native app produced a7second-old server code, with no new booking or admission. Automatic renewal, offline recovery and staff admission checks follow; physical camera decoding is not claimed.

The earlier compile failed because the full-screen ticket had a second QR renderer. Both layouts now use the new widget; targeted analysis has no warnings/errors and the rebuilt APK installed successfully.

### QR freshness, failure and recovery — native pass

Opening My Tickets fetched a new code. Removing only the emulator API reverse tunnel caused the next refresh to hide the QR and display **Connect to refresh your admission QR, or ask staff for manual lookup** with **Refresh QR**. Restoring the tunnel and selecting Refresh QR recovered. Leaving the native screen open subsequently rotated the server code again automatically; the latest readback was40seconds old, within the60second server validity window. No admission occurred during these reads. Evidence: `eventoxygen-ticket-before.json`, `eventoxygen-ticket-fresh.json`, `eventoxygen-ticket-recovered.json`, `eventoxygen-ticket-auto-renewed.json` and [actual offline screen without a QR](assets/mobile-local/eventoxygen-ticket-offline-safe.png).

Pin succeeded, but selecting Unpin and reopening the menu still showed Unpin. The callback always wrote the same ticket ID. It now removes the stored preference when already pinned; rebuilt native retest is pending.

### Reciprocal message and meeting readback — native pass

Lina’s Inbox shows Kofi’s actual reply. Lina → Meetings → Upcoming shows the same confirmed **Tutorial materials coffee**,14November12:15America/Chicago,15minutes and matching venue notes. No second meeting or reply was created. Evidence: [received reply](assets/mobile-local/eventoxygen-lina-reply-inbox.png), [organizer confirmed meeting](assets/mobile-local/eventoxygen-organizer-meeting-confirmed.png).

Documentation build passed227pages; Chromium HTTP-checked all46 non-data image URLs in this course and each returned200. Lazy-loaded images were checked by their actual requests, not incorrectly counted as broken before scrolling.

### Unpin — native regression passed

Installed the fix over Lina’s existing pinned ticket. My ticket → Show menu → Unpin, then reopened the menu: **Pin ticket** returned. No ticket was issued or transferred. The saved preference is removed instead of writing the same ticket ID again.

Final targeted native analysis: no errors or warnings, four style/context info notices remain. All four timezone regression tests pass on the final build.

## Staff admission and attendee readback — native pass

Signed into Appmint Mobile normally after its session expired. Opened the selected conference’s Scan, chose **Check In → Main hall → Manual Lookup**, entered Lina’s exact fictional holder email and selected **Check in** once. The staff app showed **CHECKED IN / Lina Tutorial**. Server readback confirms the existing ticket changed to `checked_in` with exactlyone check-in. No duplicate registration, second admission or ticket reset occurred.

Returned to EventOxygen, opened **My ticket** again and read **Tutorial General Admission / CHECKED_IN / Lina Tutorial**, with the live admission QR. The self-check correctly names the holder name, type and status, not an email absent from that card. [Staff result](assets/mobile-local/eventoxygen-staff-admission.png), [sanitized persisted readback](assets/mobile-local/eventoxygen-ticket-admitted.json). Physical camera decoding remains untested; this was the documented holder-email fallback.

## Resolved historical finding EO01-005

### EO01-005 — The ticket self-check requests an email absent from its screenshot

- **Severity/status:** Medium; verified screenshot/instruction mismatch, native behavior untested.
- **Exact step:** Part 2 → 6, “Try it,” line 166, following Part 2 → 5 My ticket.
- **Expected:** Reopen the event/ticket and point to holder email, ticket type and status without registering again.
- **Actual:** The embedded My Tickets card shows Lina Tutorial's name, code, type, status and QR; it does not show her email. The earlier Booking Confirmed screenshot contains an email, but the exercise gives no route back to that view after reopening.
- **Effect:** A beginner cannot satisfy the stated self-check from the illustrated ticket screen and may assume their app is missing data.
- **Evidence:** [Embedded ticket card](../learner-review-records/assets/eventoxygen/embedded-40-lina-ticket.png), [numbered text](../learner-review-records/assets/eventoxygen/manuscript-numbered.txt), lines 146–166.
- **Proposed correction:** Ask the learner to identify the holder name/type/status on the ticket and verify the registration email at a separately documented accessible screen. If the current app can expose email here, show the precise action and screenshot.



Resolution24September: corrected the self-check to visible holder name/type/status and verified native ticket reopening both before and after staff admission.

## Final display follow-up

The public event preview now renders Nia’s speaker card and both attendee cards, including Kofi’s saved job title. Its Schedule jump shows11:00 and12:00 in the narrow time column and the correct session/room. Actual captures: [public people](assets/mobile-local/eventoxygen-public-people-fixed.png), [public programme](assets/mobile-local/eventoxygen-public-schedule-clock-fixed.png). Six timezone/clock-format regressions pass.

Home retained its previous CONFIRMED ticket copy after My Tickets had refreshed to CHECKED_IN. EventProvider now refreshes the active event’s tickets and detail when its full ticket list reloads. That fix is built; the state-transition native retest was interrupted and remains explicitly pending.


## Home ticket-state regression — passed 24 September 2026

Kofi's existing fresh attendee account began with CONFIRMED on Home. Staff used Appmint Mobile, Check In, Main hall and Manual Lookup with that fictional holder email. Submitted Check in exactly once. The attendee opened My ticket: CHECKED_IN. Android Back returned to Home, whose cached card now also read CHECKED_IN without logout/restart. This verifies the EventProvider active-ticket synchronization repair. No checkout or duplicate admission was used.

[Before](assets/mobile-local/eventoxygen-kofi-home-confirmed.png) · [After](assets/mobile-local/eventoxygen-kofi-home-checked-in.png). The after image was visually inspected and contains no live admission QR. The staff result toast was not retained; acceptance relies on the actual attendee ticket and Home readbacks, not the later scanner screenshot.

Only the intended signup policy destinations remain open for this course.


## Policy destination investigation — 24 September 2026

**Privacy link fixed and verified locally. Terms remains open.** The [official EventOxygen App Store listing](https://apps.apple.com/us/app/eventoxygen/id6770200026) explicitly publishes `https://appmint.io/privacy-policy` as the developer privacy policy. This is direct product-specific evidence for the destination. Both old `eventos.app/privacy` and `eventos.app/terms` URLs failed normal TLS verification with a self-signed certificate; the warning was not bypassed.

Changed `event_app/lib/config/legal_urls.dart` in the application source and isolated local build to the published privacy destination. Signup, profile and account drawer use that shared constant. The Android debug APK built successfully and installed with `adb install -r`, preserving Kofi's existing attendee account. The existing emulator was restarted without wiping data.

**Actual native check:** Kofi's My Events → account initials → Privacy Policy opened Android Chrome. After choosing Stay signed out and declining optional notifications, the page displayed **Appmint Privacy Policy**, its effective date and readable policy paragraphs at `appmint.io/privacy-policy/`. Chrome reported a secure connection. The [native screenshot](assets/mobile-local/eventoxygen-native-privacy-fixed.png) was visually inspected. No account, registration, ticket or admission was created. Signup's shared URL is corrected in the build, but no new signup submission was performed for this link-only repair.

Desktop Chromium independently returned HTTP 200 for the [published privacy destination](https://appmint.io/privacy-policy/) and the App Store listing: [privacy page](assets/mobile-local/eventoxygen-official-privacy.png), [official listing](assets/mobile-local/eventoxygen-official-store.png). A basic Python request to the privacy page received 403, whereas actual Chromium and native Chrome loaded it; browser acceptance is therefore based on their actual readable results.

**Exact remaining decision:** confirm the Terms of Service URL intended for EventOxygen attendees. The official listing does not publish one. The privacy page's footer links [Appmint Terms](https://appmint.io/terms-and-conditions/), which loads HTTP 200, but describes the app-building platform and includes paid-plan wording and unresolved governing-law placeholders. It is not enough evidence to silently substitute it for attendee terms. The existing Terms constant was left unchanged. [Observed candidate page](assets/mobile-local/eventoxygen-official-terms-candidate.png).

**Related publishing discrepancy for the owner:** the live App Store listing states Data Not Collected, while this native walkthrough created and read persistent attendee identity/profile data. The listed privacy text describes the Appmint website. Matching those published disclosures to EventOxygen's actual data handling requires an owner decision; this link repair does not assert that the legal content or store declaration is complete or correct. No App Store metadata or live legal text was changed.
