{"packetVersion":"2026-08-03.tg-zip.media-proof-rehearsal","status":"owner_media_approval_required","canonicalPage":"/activation/media-proof","packetRoute":"/activation/media-proof/packet","sourceRoutes":["/activation","/activation/evidence","/activation/records","/activation/session","/activation/session/closeout","/activation/handoff"],"storageBoundary":"No-store media proof rehearsal only. This packet does not submit, persist, seed, mutate, authorize, upload, expose media, mint grants, call APIs, run load, request secrets, or create public inventory.","checks":[{"label":"Approved gallery aliases","goal":"Confirm the public, unlisted, private, and protected gallery samples are owner-approved before live media proof starts.","requiredInputs":["Gallery aliases only, with raw bucket object keys excluded from durable notes.","Owner, non-owner, and optional super-admin account aliases for each visibility mode.","Approval window, allowed device/browser targets, and exact read-only or mutation scope."],"evidence":["Alias-to-route mapping for public list, gallery detail, manifest, ZIP, and denial checks.","Owner approval timestamp or handoff reference without credentials or private identifiers.","Explicit list of checks that are excluded until a later proof session."],"stop":"Stop if the proof would require raw media keys, owner credentials, unapproved uploads, or broader access than the approval window names."},{"label":"Protected grant rehearsal","goal":"Prepare protected-delivery proof without minting or exposing grants before the owner approves the exact sample.","requiredInputs":["Protected gallery alias and expected grant claim or header name without secret values.","Authorized owner or granted-account alias and denied non-owner alias.","Signed read URL expiry window and expected fail-closed response after expiry."],"evidence":["Header presence or absence with secret values redacted.","Authorized read, denied read, and expired read results recorded separately.","Provider or app logs checked for unexpected 4xx/5xx during the approved window."],"stop":"Do not create, persist, forward, paste, or screenshot reusable grant secrets, signed URLs, cookies, or tokens."},{"label":"Export quota concurrency rehearsal","goal":"Turn the atomic gallery_export_windows source behavior into a live load script plan that can run only after owner media approval.","requiredInputs":["Public or owner-accessible gallery alias approved for repeated manifest/ZIP requests.","Maximum burst size, expected success count, expected throttled count, and client-key strategy.","Owner-approved log window and rollback or revoke action if the run behaves unexpectedly."],"evidence":["Concurrent request summary with total, allowed, rate-limited, revoked, forbidden, and failed counts.","Retry-After values and CORS-exposed export headers captured from live responses.","Database row count or owner-approved readback proving one gallery/client hash row when provider access is approved."],"stop":"Do not run load against production media, bypass quota, or read database rows unless the owner approves the exact gallery and timing."},{"label":"ZIP integrity and native save","goal":"Verify manifest count, ZIP SHA-256, and browser save/share behavior against approved real media without redistributing originals.","requiredInputs":["Approved media count, expected visibility set, and safe filenames or aliases.","Desktop and mobile device/browser targets for share, copy, save, or download behavior.","Evidence storage location that excludes raw media when thumbnails or filenames are private."],"evidence":["Manifest photo count and expiry compared with the expected approved media set.","ZIP filename, content count, SHA-256 header, and client-side hash verification result.","Native share, copy, save, or download result recorded per device/browser."],"stop":"Do not upload, transform, merge, delete, publish, or redistribute originals while proving export behavior."},{"label":"Closeout classification","goal":"Keep passed, failed, contradicted, and still-gated media proof separate before updating the launch ledger.","requiredInputs":["Source commit, deployed revisions, route timestamps, account aliases, and approved media aliases.","Failed or contradicted checks with exact response code, route, and next action.","Still-gated checks that require broader owner approval or provider access."],"evidence":["Launch closeout packet updated with media proof results and follow-up gates.","Status page and repo ledger updated only for evidence that actually passed.","Rollback or revocation action recorded if the proof session changed access state."],"stop":"Do not mark TG-PRIV or TG-ZIP launch-proven from a checklist, source test, HTTP 200, or unapproved media interaction alone."}]}