{
  "schemaVersion": 2,
  "date": "2026.09.18",
  "publishedAt": "2026-09-18T15:38:33-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Verify the correct mobile HTTPS entry point",
  "publicationStatus": "Connection route verified",
  "executiveSummary": [
    "Investigated a mobile browser trust warning and verified that the existing managed HTTPS entry point loads successfully with normal certificate verification.",
    "Provided the correct entry-point URL rather than directing the user to bypass browser validation."
  ],
  "workstreams": [
    {
      "title": "Connection diagnostics",
      "status": "Verified",
      "details": [
        "Read the configured HTTPS launch settings and existing reverse-proxy status. Inspected certificate metadata without exposing private keys.",
        "Verified the existing managed hostname using default TLS trust and hostname checks, followed by a successful HTTP200 response."
      ]
    }
  ],
  "decisions": [
    "Use the existing verified entry point. No new website, listener or public exposure was created.",
    "No source, certificate, service or runtime changes were required for this connection-route correction."
  ],
  "validation": [
    {
      "check": "Managed HTTPS handshake",
      "status": "passed",
      "result": "Default TLS verification and hostname checking succeeded."
    },
    {
      "check": "Application route",
      "status": "passed",
      "result": "Verified HTTPS request to the application root returned HTTP200."
    },
    {
      "check": "Hiro regression tests",
      "status": "not_run",
      "result": "Read-only connection diagnostics; no code changes."
    }
  ],
  "currentState": [
    "The verified managed HTTPS entry point is available."
  ],
  "limitations": [
    "Verification was performed from the Windows host; a subsequent successful load on the phone is not yet confirmed.",
    "Separate maintenance of the alternate direct listener was not performed in this diagnostic session."
  ],
  "nextSteps": [
    "Use the verified entry-point URL on the phone."
  ],
  "disclosureNote": "Public entry omits private hostnames, certificate material and actionable details about unresolved configuration issues."
}
