You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Last updated: September 22, 2026
Status: Active Current gate: Decide the content-version leaderboard migration and public-product rights posture, then finish Phase 4 trusted room authority
This is the single progress ledger for the project. Every implementation or
design change updates the relevant item in this document.
Status rules
ID
Item
Status
Evidence / next action
DOC-14
Attribute registration links to the source-code campaign
Done
Both tutorial registration links use the supplied URL with all four UTM parameters. Exact URL checks, relative documentation links, and whitespace checks pass. Documentation-only; the game has no registration CTA. Next: preserve this campaign attribution in future registration links.
ID
Item
Status
Evidence / next action
ANALYTICS-01
Track visits to the GitHub Pages demo with PostHog
In progress
Connected source now initializes PostHog asynchronously only at the configured Pages URL, labels the first explicit pageview, and disables unrelated collection. Public project key is supplied through ignored local build configuration. Typecheck, 143 tests including three analytics regressions, and the Pages build pass; focused tests and build passed again after tightening collection settings. The built bundle contains the supplied public key and tracking configuration. Changed code passes formatting and targeted lint; full lint has warnings only, while full formatting reports 59 untouched existing files. A read-only ingestion preflight returns HTTP 200 and permits the Pages origin, POST, and content-type. See docs/11-github-pages.md for release acceptance. Source and compiled Pages snapshots are now published; see docs/verification/2026-09-22-posthog-pages.md. Next: trigger or inspect the pending Pages deployment, verify an actual browser event in the receiving project, and configure the dashboard insight. The live root still served the previous build at the post-push check. This does not block the Functional MVP.
PUB-03
Publish PostHog source and Pages snapshots without development history
In progress
Scanned 185 source files and seven compiled assets, then atomically published parentless main and gh-pages commits with exact remote-head leases. Remote readback and one-commit ancestry checks pass; offline-starter is unchanged. Pages commit 7a793eb is published, but no new Pages workflow or check run was visible and the live root still served the previous build. Next: inspect or trigger Pages using an authenticated repository-admin session, then verify the hosted game and pageview request. This optional analytics release does not block the Functional MVP.
Status
Meaning
Done
Evidence exists and the item's acceptance check passed
In progress
Work has started and has a concrete partial artifact
Next
The next queued item on the current critical path
Needs decision
A product, football, legal, or technical choice is required
Not started
Defined but no implementation artifact exists yet
Deferred
Intentionally outside the current Functional MVP path
Progress is reported by completed checklist items, not subjective percentages.
Items differ in size, so the count is a navigation aid rather than an effort or
schedule forecast.
Current snapshot
Milestone
State
Completed items
Immediate next action
Phase 0 — Design lock
In progress
13 / 14
Decide the player, club, and competition public-product rights posture
Phase 1A — Core mechanics
Done
10 / 10
Validated per-game offer/reroll limits passed the 10,000-seed gate
Phase 1B — Functional MVP
Done
7 / 7
Gameplay, persistence, attribution, and the hosted release are verified
Project communication
In progress
9 / 10
Verify source-repository visibility; the signup, AI-plugin setup, and prompting tutorial is complete
Functional MVP tracker: 30 of 31 defined items Done. This is checklist
completion, not an effort percentage.
Phase 0 — Design lock
ID
Item
Status
Evidence / next action
P0-01
Confirm 4-3-3 slots and per-player position ratings
Done
docs/02-game-design.md defines the slot and eligibility contract
P0-02
Confirm duplicate, virtual-deck, reroll, and cooldown rules
Done
Selected cards leave the run; a rules-v2 reroll changes to a different playable club/era and replaces every visible player, while passed/rerolled cards receive two-round cooldowns
P0-03
Prepare the first reproducible data candidate
Done
Historical StatsBomb and Wyscout candidates proved the replacement boundary; OpenFootball is now the active source
P0-04
Review inferred positions and curate the first playable pool
Done
The 1,041 named 2023/24 squad cards use observed broad roles plus deterministic formation-position inference and pass coverage and completion analysis; later release curation remains optional
P0-05
Decide player/club/competition public-product rights posture
Needs decision
Public-domain source reuse does not independently settle player publicity or club/competition name and mark rights. Review all three before an official public-product release; this does not block the Functional MVP.
P0-06
Freeze the player/content schema and validator
Done
JSON Schema plus cross-record validation covers identity, positions, ranges, provenance, counts, coverage, and hash integrity
P0-07
Create minimum scoring configuration and golden fixture XIs
Done
assessment-v1, league-profile-v1, three valid roster vectors, duplicate rejection, draft/cooldown cases, and match-probability cases
P0-08
Confirm source layout and supported browser matrix
Done
npm workspace package boundaries, React DOM choice, input model, browsers, and viewports recorded in technical architecture
P0-09
Run the Phase 0 exit review
Done
Exit review passed for Phase 1A; public rights and final curation are explicitly nonblocking
P0-10
Prepare the CC BY 4.0 Wyscout data candidate
Done
Historical 2017/18 candidate passed its acceptance checks before being superseded and retired by P0-12
P0-11
Promote Wyscout/Figshare to the active content version
Done
Historical content promotion passed its acceptance checks before openfootball-premier-league-2020-2025-club-role-v1 replaced it
P0-12
Replace Wyscout with five-season OpenFootball content
Done
Pinned 2020/21–2024/25 sources yield 1,900 matches, 27 clubs, and 2,400 fictional role cards. Deterministic regeneration, Python and TypeScript suites, role/age/source-copy checks, 10,000/10,000 complete drafts, all-card exposure, and both production builds pass; ratings 55–87, current mean season points 39.12. Obsolete Wyscout data/tools are removed.
P0-13
Promote named OpenFootball 2023/24 Premier League squads
Done
The active catalogue contains 380 matches, 20 clubs, and 1,041 named squad cards. Observed identities and broad roles remain separate from inferred formation positions and synthetic ratings. Regeneration, 22 Python tests, 127 TypeScript tests, both production builds, the 10,000/10,000 draft analysis, local Worker/live-AGS verification, and the hosted version 17 trusted-route/live-AGS smoke pass.
P0-14
Recalibrate synthetic player ratings
Done
Content v2 applies a tested monotonic curve without changing source evidence: median best-position rating 72, 95th percentile 86, 14/1,041 cards at 90+, and maximum 94. Deterministic regeneration, 24 Python tests, 132 TypeScript tests, catalogue validation, typecheck, lint, production build, refreshed golden fixtures, and a 10,000/10,000 complete-draft analysis with all 1,041 cards exposed pass.
Phase 1A — Core mechanics engine
ID
Item
Status
Evidence / next action
P1A-01
Create framework-free domain package and types
Done
Strict workspace contains domain, contracts, content, and fixture packages; format, lint, typecheck, 2 tests, build, and production audit pass
P1A-02
Implement stable deterministic RNG streams
Done
xmur3 + sfc32, derived streams, unbiased bounded integers, shuffle, four golden-vector cases, and source guard pass in 9 RNG tests
P1A-03
Implement club/era constraint and bounded offers
Done
Stable profiles and derived streams produce 3–15 constraint-matching safe cards according to validated configuration; ordering, cap, exclusion, and unsatisfiable cases pass
P1A-04
Implement selected-card removal, rerolls, and cooldowns
Done
rules-v2 state-machine and integration tests prove that each reroll changes the club/era and players, preserves same-round rejection and two-round cooldown, consumes only on success, and remains deterministic through trusted replay; all 132 tests and the full repository verification pass
P1A-05
Implement forward-feasibility/dead-end prevention
Done
Identity-level maximum matching and safe-slot checks pass; 10,000 randomized complete drafts with 5,791 alternate-team rerolls produced zero dead ends
P1A-06
Implement five-category assessment
Done
Three Phase 0 XI vectors reproduce exact category, axis, composite, and attack/defence/control unit scores; duplicate identity is rejected
P1A-07
Implement deterministic 38-match season simulation
Done
Three probability vectors and one exact 38-outcome golden season pass; W/D/L and points invariants are bounded
P1A-08
Implement structured explanation facts
Done
Deterministic strongest/weakest/context facts and exact rendered text pass traceability tests
P1A-09
Pass golden, invariant, replay, and 10,000-seed checks
Done
The rules-v2 named-pool report records 10,000/10,000 completions, zero failures, points 12–78 (mean 41.40), and all 1,041 cards appearing.
P1A-10
Accept validated per-game offer and reroll limits
Done
Shared domain configuration caps visible safe cards at 3–15 and run-wide rerolls at 0–5; the tested initial values are 15 and 5. The rules-v2 10,000-seed report records offer sizes 3–15 (mean 14.40), five rerolls reached in a run, 0.02% alternate-team reroll unavailability, and zero dead ends. P2-09 owns the authoritative runtime source.
Phase 1B — Functional MVP
ID
Item
Status
Evidence / next action
P1B-01
Build the React draft and formation flow
Done
Browser flow completed all 11 rounds after a reroll; configured offers, legal slots, exact ratings, roster state, round, and rerolls were visible at desktop, 390×844, and 360×640
P1B-02
Integrate the shared mechanics without duplicating rules
Done
apps/web/src/game/session.ts calls createDraft, applyDraftAction, and resolveRun directly; two integration tests pass and a browser run reached the result
P1B-03
Add stable local guest identity
Done
getOrCreateLocalIdentity creates/restores a versioned random profile without fingerprinting; adapter tests pass
P1B-04
Store and reload a checksummed local run
Done
Full seed, versions, 11 actions, 12 state hashes, result, and authority round-trip; tampering is rejected in adapter tests
P1B-05
Build the result XI, record, and explanation screen
Done
Browser result showed the final pitch XI, 14–6–18/48-point record, five dimensions, units, explanation facts, and player-authoritative replay hash
P1B-06
Pass end-to-end checks and deploy the Sites build
Done
52 tests pass with format, lint, typecheck, vinext verification, and a dedicated static Vite SPA bundle; the existing public Site is live at football-11-play.damar-indra.chatgpt.site, and the Phase 2A build includes branded Open Graph and X preview metadata. The browser-only artifact avoids a Worker for this client-owned identity slice, supplies an explicit index.html with SPA fallback, and returns local HTTP 200 checks for the root, fallback route, and social image
P1B-08
Publish gameplay data credits and license notice
Done
The public gameplay footer in the current Sites release links both pinned OpenFootball repositories and CC0, separates observed squad and club-result facts from synthetic card fields, and states the player/club/competition rights boundary. Source regression, full tests, production build, and deployment pass.
Project communication
ID
Item
Status
Evidence / next action
DOC-10
Clean documentation for the next public source update
Done
Removed the retired documentation application, its local archive, and related instructions/references. Updated the document index, current catalogue description, portable GitHub SSH URL, and checklist counts. Typecheck, whitespace checks, configuration JSON parsing, and relative Markdown links pass. Targeted scan of 196 retained tracked files found no recognized credential patterns or configured private values; this is not a full security audit. Keep apps/web/.openai/hosting.json excluded from the later public mirror. No root software license is selected; that remains an author decision. Next: mirror the reviewed source when requested; no remote or hosted deployment was changed.
ID
Item
Status
Evidence / next action
REPO-02
Commit the accumulated development checkout changes
Done
Local master checkpoint includes the accumulated deployment, demo, and documentation changes across 46 files. Staged whitespace checks passed and the post-commit working tree was clean. No push performed. Next: continue development from the checkpoint; publish through the appropriate separate branch when requested.
ID
Item
Status
Evidence / next action
REPO-01
Expose the public repository remote in the development checkout
Done
git remote -v verifies accelbyte points to AccelByte/f11 via the supplied SSH alias and origin remains the personal development repository. September 22 fetch succeeded; git branch -r lists accelbyte/main and accelbyte/gh-pages, with accelbyte/HEAD pointing to main. Current master still tracks origin/master. Accumulated changes were checkpointed in REPO-02. Next: use a branch based on accelbyte/main for public updates to preserve the clean history; do not push development master over public main.
ID
Item
Status
Evidence / next action
DOC-09
Deliver the team's AGS signup, AI-plugin setup, and prompting tutorial
Done
docs/12-accelbyte-integration-guide.md is a 14-step tutorial covering the actual signup fields/button, game namespace selection, Codex plugin installation, deployment-specific MCP configuration/authentication, and copy-ready setup/login/storage/session/debug prompts with expected results. Public signup and official namespace/client/OpenAI MCP pages were inspected; plugin commands and URL patterns were checked against installed AccelByte AI Plugins 0.6.13 docs. Twelve tutorial/reference documents pass 81 relative-link checks, ordered-step, fence, and whitespace checks. Prior service chapters remain supplementary references under docs/12-accelbyte-integration-guide.md#implementation-reference; README and document index point to the tutorial. No account creation, installation, or live AGS authentication was performed. Next: use the walkthrough for a reader-run onboarding session; project integration blockers remain tracked separately.
ID
Item
Status
Evidence / next action
DOC-08
Expand the integration guide into detailed service chapters
Done
Ten focused chapters now consolidated in docs/12-accelbyte-integration-guide.md#implementation-reference cover setup, login, Player Records, Game Records, trusted backend, Statistics/Leaderboards, Session/Lobby, Saved-XI, planned daily/history, and deployment verification. Chapters include prerequisites, configuration, source-backed flows, troubleshooting, and acceptance checks. Resource names, SDK calls, route methods, settings, and smoke commands were checked against source; links, fences, and whitespace pass. DOC-09 repositions these as supplementary references indexed by docs/12-accelbyte-integration-guide.md#implementation-reference. Documentation-only; no live verification or service changes. Next: consult these references after the onboarding tutorial and complete separately tracked integration/release gaps.
ID
Item
Status
Evidence / next action
DOC-07
Write an AccelByte integration guide from registration to completion
Done
docs/12-accelbyte-integration-guide.md covers registration, namespaces/clients, SDK configuration, IAM, Cloud Save, trusted Statistics/Leaderboards, Session/Lobby, Saved-XI challenges, remaining daily/history work, and completion checks without gameplay instructions. Resource names and smoke commands were checked against source/plans; all guide relative links resolve and documentation whitespace checks pass. The document index links to the guide. Documentation-only; no fresh live verification or backend changes. Next: follow the guide for a new namespace and close the separately tracked integration/release gaps.
ID
Item
Status
Evidence / next action
DOC-06
Trim public-facing documentation
Done
Reviewed README: removed snapshot/exclusion/history notes and license-selection commentary; retained setup and data attribution, added the live game link, and kept deployment prose focused on verified behavior. Documentation-only diff passes whitespace checks.
ID
Item
Status
Evidence / next action
DOC-05
Deploy AccelByte Pages from a separate compiled branch
Done
docs/verification/2026-09-10-accelbyte-pages.md: gh-pages commit 478c541 serves the compiled game at https://accelbyte.github.io/f11/; remote main remains 8bb7cb0. Sites version 21 is deployed. Typecheck, 140 tests, both builds, static private-value scan, fourteen hosted preflights, auth preservation, and unapproved-origin rejection pass. Browser guest sign-in and Sites-issued first-round draft pass; the rendered draft screen was visually reviewed. Next: use the deployment branch for later frontend releases; the separate prior Cloud Save investigation remains open.
ID
Item
Status
Evidence / next action
DOC-04
Publish a clean public source repository
In progress
README.md and docs/verification/2026-09-10-public-source.md describe the separate source export. All 138 existing tests pass; the export scan found no configured private values or recognized credential patterns. One parentless commit contains 182 files with excluded paths absent. The user supplied AccelByte/f11; SSH confirms an accessible empty remote, but the unauthenticated GitHub API returns 404. Push succeeded; remote HEAD and main match the single root commit 8bb7cb0. Next: verify or enable public visibility before marking Done. The visibility/access issue does not block the Functional MVP.
ID
Item
Status
Evidence / next action
DOC-02
Repeatable draft demonstration and edited trial video
Done
tools/demo/ provides a fixed-seed local harness, Playwright capture, timing cues, and FFmpeg editing. The September 7 trial at artifacts/demo/2026-09-07T05-21-40-233Z/ verified 11 UI placements, a complete XI, no page errors, and no external requests; screenshots and edited contact sheet were visually reviewed. draft-demo.mp4 is 23.37 seconds at 1920×1080/30 fps, with selection zoom, 3× remaining draft, and lineup hold. App/demo typechecks, five session tests, the production build, and full MP4 decoding pass. The companion draft-demo.gif is verified at 351 frames, 1280×720, approximately 15 fps, and 23.39 seconds, meeting the requested fewer-than-1,000-frame limit. Video artifacts are local and Git-ignored; next: review pacing, then scope a separate live AGS recording. This presentation work does not block the Functional MVP.
DOC-03
Record a live two-player friend-room demonstration
Done
tools/demo/capture-friends.mjs and edit-friends.mjs record the public game with two distinct AGS guests and no mocked services. The September 7 capture at artifacts/demo/friends-2026-09-07T06-04-58-351Z/ verifies shared membership/readiness/challenge, 22 real picks, complete XIs, matching 56/35-point results, zero page errors, and both guests leaving. Visual slates calibrate the separate video timelines; the edited views were inspected together. MP4: 42.80 seconds, 1920×1080/30 fps. GIF: 642 frames, 1280×720, below 1,000 frames. Script syntax, formatting, and complete media decoding pass. Next: review pacing for the build-story presentation; room comparison remains cooperative Session state, not proof of trusted multiplayer scoring. Artifacts are local and Git-ignored.
Phase 2 — AGS foundation
ID
Item
Status
Evidence / next action
P2-01
Replace local guest identity with AGS Device ID
Done
@accelbyte/sdk 4.3.3 and @accelbyte/sdk-iam 6.3.6 are pinned; the development Device ID provider is active; Sites records the browser-safe base URL, namespace, and public client ID as non-secret environment values. The Sites release build now fails before packaging when those public values are absent, preventing a deployable bundle from silently losing AGS browser configuration while the confidential client secret remains server-only. The redacted live smoke verifies token minting, authenticated current-user lookup, same-device restoration, and clean-device separation; browser QA verifies first-use login, draft enablement, visible retry, same-guest reload, and isolated-origin separation. Focused adapter tests and the full verification suite pass, with tokens retained only in SDK memory.
P2-02
Sync replayable game data through AGS Cloud Save
Done
@accelbyte/sdk-cloudsave is integrated behind a stable private player-record key with schema/owner/version/checksum/replay validation, 250 KB guard, readback-before-success, restore, retry, and visible recovery states. A redacted live smoke proved write/readback, same-device restored-session readback, deterministic replay, and an 8,661-byte payload in the development namespace
P2-03
Add trusted replay and authenticated user binding
Done
The Sites Worker validates the AGS current user and namespace, accepts an exact 64 KB-bounded seed/version/action contract, replays through shared domain/content code, rejects illegal or unsupported evidence, ignores client totals, and stores a private SERVER Cloud Save receipt. Focused tests and redacted local-Worker and hosted-route smokes pass; the public root returns HTTP 200, legal replay is accepted, duplicate replay is idempotent, and tampered or unsupported evidence is rejected
P2-04
Server-owned AGS Statistics updates
Done
The live football11bestpoints definition is public, SERVER-set, bounded 0–114, and feeds retry-safe MAX settlement. Confidential-client permissions remain limited to Cloud Save player records and Statistics user values; the hosted smoke verifies settlement/readback, duplicate handling, rejection without mutation, and the private SERVER receipt
P2-05
Player-facing AGS Leaderboard query and UI
Done
The live descending all-time football11-best-points leaderboard is tied to the trusted statistic. Authenticated player reads return a sanitized nearby view, and the UI covers loading, ranked, unranked, empty, stale, success, and retryable-error states. The public Sites route returns the materialized AGS value, rank, and nearby view in the hosted end-to-end smoke
P2-06
Decide production guest upgrade and account-loss policy
Deferred
Account upgrade/linking is explicitly deferred. Device ID remains development-only, and the unrecoverable account-loss warning remains visible. This does not block the Functional MVP or the completed Phase 2 technical foundation, but it blocks an official connected-product release until account linking is implemented or the account-loss risk is explicitly accepted
P2-07
Retire durable local run saving
Done
Completed runs now remain only in memory while the client writes the private AGS Cloud Save latest-record slot and verifies its readback. New completions replace or repair the prior cloud latest value, reload recovery reads Cloud Save directly, and legacy local-run values are ignored. All 110 tests, typecheck, lint, the product build pass. The aggregate verify wrapper remains blocked only by 23 pre-existing formatting mismatches outside this change.
P2-08
Isolate rankings across the content-version migration
Needs decision
OpenFootball recalibration changes draft offers and season-point distribution (12–73 versus the retired version's 22–93), so existing football11bestpoints values are not comparable. Choose a new Statistic/Leaderboard or a deliberate reset/migration before publishing the replacement; this blocks fair connected ranking, not the standalone Functional MVP.
P2-09
Resolve draft configuration from an AGS Game Record
Done
The server-owned football11_game_config_v1 record uses numeric schema 1, active revision 1, 15 offers, and 5 rerolls. The Confidential Sites client has only m_cloud_save/g_game_records READ. Every solo start and room round now receives a Sites-issued frozen challenge plus private server-owned player receipt; trusted replay binds player, challenge, seed, versions, room, and config and rejects tampering. Environment defaults are removed. Five Game Record tests, 127 total TypeScript tests, 22 Python tests, typecheck, formatter, lint, the 10,000/10,000 analysis, both builds, redacted local-Worker and hosted-route/live-AGS smokes, and Sites version 17 deployment pass.
Phase 3 — Sharing and daily
ID
Item
Status
Evidence / next action
P3-01
Daily seed lifecycle
Deferred
Begins after the Phase 2 AGS identity/trust foundation
P3-02
Public immutable result route
Deferred
Project only trusted public-safe result fields from Phase 2 records
P3-03
Landscape social preview
Deferred
Render result-specific metadata and imagery from the trusted public projection
P3-04
Vertical share card
Deferred
Use the same approved public result contract as the landscape preview
P3-05
Synced result history
Deferred
Use AGS-backed durable history with a bounded browser cache
Phase 4 — Friend rooms
ID
Item
Status
Evidence / next action
P4-01
Create AGS game session
Done
The football11-friend-room-v1 template reads back as no-server NONE, nonpersistent, OPEN, minimum 1, maximum 8, 24-hour TTL, and code-enabled. A Device user creates, restores, and leaves the visible room; Session 5.3.6 is instantiated only after the shared SDK token is installed. The full repository verification and redacted live lifecycle probe pass.
P4-02
Discover/join open session; retain optional native code
Done
Isolated browser users discover only compatible non-full OPEN rooms and join by the displayed room action/session ID. The live probe passes join-by-ID, join-by-code, revoke, regenerate, reopen, and closed rejection. Browser QA proves the room disappears while CLOSED, reappears during COUNTDOWN, and reports a safe combined closed/permission 403 message.
P4-03
Membership, readiness, and start rules
In progress
Two Device users converge to 2/8 through Lobby messageSessionNotif refresh hints plus four-second polling, ready independently, and the leader locks the participant set by changing AGS joinability to CLOSED. Unreal SDK source confirms OnSessionJoined, OnSessionMembersChanged, OnGameSessionUpdated, and OnSessionEnded; the TypeScript SDK exposes the raw envelope. The cooperative browser guards pass; next route leader/start mutations through the completed P2-03 trusted boundary.
P4-04
Per-player deterministic simultaneous drafting
In progress
New rounds publish one immutable challenge ID/base-seed/version bundle plus per-player-v1; each client derives a compact deterministic seed from that base, challenge ID, and authenticated AGS user ID. Cloud Save records and in-memory submissions retain optional room context, and ranked room submissions now bind to a canonical AGS Session read: the Sites server checks namespace/template, active membership, locked participation, challenge, versions, and its own player-seed derivation before replay. Tests cover different-player offers, reconnect and next-cycle stability, wrong seeds/members, legacy shared seeds, Cloud Save restore, safe legacy-draft migration, incompatible future strategies, and Phase 5 interoperability. Hosted room-context verification remains before this item can be called done.
P4-05
Progress, comparison, and automatic next round
In progress
Browser QA shows private counts converging to 11/11, a deterministic 68-point/62-point comparison, OPEN reveal/countdown, and automatic round 2→3 replay in the same session. Each new ordinal creates a fresh random base seed before deriving a new stream for every participant. Ranked room replay is now player/session-bound, but comparison still reads the compact Session-attribute development aggregate; any member with update permission can alter that aggregate, so comparison must consume trusted receipts before competitive acceptance.
P4-06
Leave, reconnect, timeout, and host behavior
In progress
Mid-draft reload restores the accepted prefix, Lobby reconnection reaches CONNECTED, polling covers missed events, and the live probe passes native leader migration plus leave cleanup. Unit tests cover deadline/terminal transitions. Explicit abandon, timeout, and host-loss behavior still need visible browser exit evidence; this does not invalidate the working primary flow.
P4-07
Multi-browser room verification
In progress
Three isolated origins pass create, discovery/join, 2/8 roster convergence, readiness, CLOSED start, hidden discovery and rejected code join, divergent 11-pick drafts, mid-draft reload, comparison, OPEN countdown discovery, and automatic fresh-ordinal restart in the same session. Desktop and 375px QA show no horizontal overflow. Sites version 17 preserves the verified merged Phase 4/Phase 5 build and server-issued Game Record challenges while promoting the named 2023/24 catalogue. The guarded release build embeds canonical browser-safe AGS connection values, and the Session SDK remains behind hydration. Remaining exit work is the P4-06 recovery matrix and hosted room-context exit verification.
Phase 5 — Saved-XI competition
ID
Item
Status
Evidence / next action
P5-01
Save and replace an eligible XI
Done
The Worker replays the exact submission, binds it to the authenticated AGS user and trusted receipt, requires equality with current best points, and explicitly creates or replaces one public SERVER-owned Saved XI. Unit tests cover first publish, replacement, and rejection; the redacted live smoke reads the published record back from AGS.
P5-02
Query nearby leaderboard entries
Done
Trusted discovery reads the existing football11-best-points all-time Leaderboard at ±10 ranks, expands once to ±50, and bulk-loads only public Saved XIs with the authenticated player token. The browser never supplies the authoritative candidate set; focused filtering tests and the two-player live smoke pass.
P5-03
Select a valid opponent through the trusted application boundary
Done
The Worker excludes self, recent, absent, invalid, and incompatible records, selects from the surviving trusted set, stores a private seed and full XI snapshots, and returns only an anonymous preview plus opaque ten-minute token. The live flow reaches discovery and exposes neither raw opponent user ID nor seed.
P5-04
Define and implement head-to-head simulation
Done
head-to-head-v1 implements a symmetric neutral match, canonical deterministic sampling, draws, and +3/0/-2 zero-floor Challenge Score; golden, reversal, replay, and 10,000-seed distribution tests pass. Public match projections remove the private simulation evidence.
P5-05
Store settlement and update approved statistic
Done
The live private football11challengescore definition is SERVER-set with a zero minimum and no Leaderboard. Resolution stores pending immutable history before an absolute OVERRIDE, reads the result back, finalizes history, and repairs the same settlement idempotently after failure or reload. The live smoke proves duplicate replay and that the selected opponent's score is unchanged.
P5-06
Add anti-farming and version-safety rules
Done
Exact version equality, single-use ten-minute tokens, 24-hour same-opponent exclusion, a rolling 20-match/day ceiling, bounded 20-match history, expired/no-opponent states, and retryable pending settlement are enforced. Focused tests, the combined 111-test suite, production build, desktop UI fixture review, and live AGS cooldown readback pass; Phase 4 remains separately unfinished.
Phase 6 — Connected release hardening
ID
Item
Status
Evidence / next action
P6-01
Freeze release content, rules, and simulation versions
Deferred
Release work
P6-02
Security and permission review
Deferred
The merged September 3 dependency audit reports 22 advisories: 1 critical, 16 high, 4 moderate, and 1 low. Triage, upgrade without a forced breaking rewrite, and re-audit before public release. This does not block the Functional MVP or Phase 4 development verification.
P6-03
Migration, backup, and rollback rehearsal
Deferred
Release work
P6-04
Accessibility and supported-browser verification
Deferred
Release work
P6-05
Performance and budget verification
Deferred
The production client build passes but reports a chunk over 500 KB; measure and code-split before the connected public release
P6-06
Operations, monitoring, and incident ownership
Deferred
Release work
P6-07
Production go/no-go review
Deferred
Final release gate
P6-08
Replace development-facing gameplay copy
Done
The player-facing apps/web UI now removes the development footer, backend product labels, replay hashes, raw room states, session diagnostics, and settlement jargon while preserving the guest account-loss warning and data credits. Unexpected authentication, save, ranking, and competition errors no longer pass service messages through to players. A three-surface source regression plus the updated error-sanitization tests pass within all 114 tests; the changed-file format check, typecheck, lint, and production build also pass.
P6-09
Restore the repository-wide formatter baseline
Done
The previously reported 20-file drift was normalized while integrating the Game Record work. Repository-wide format:check and the complete npm run verify release wrapper now pass.
P6-10
Optimize catalogue delivery
Next
The OpenFootball catalogue still triggers the production build's >500 kB chunk warning. Measure transfer/parse cost and move catalogue loading behind a split or server boundary before performance-sensitive release; this does not block the Functional MVP.
P6-11
Simplify and align the player UI with AccelByte's theme
Done
Approved Superdesign hybrid draft 05d39d3d-545d-49ce-b9b1-0300e7305f18 version 2 is implemented in apps/web: the original dark-green/lime shell, pitch, and panels remain, while the card grid is now a compact vertical fifteen-entry selector. Every legal-position rating remains visible; orderOfferCardsForSelection uses their arithmetic mean only as a descending presentation sort key, never renders it, preserves source order for ties, and does not mutate the domain offer. Two focused ordering tests pass within all 129 tests; web and repository typechecks, changed-file formatting, lint, and the production build pass. Headless Chrome QA at 1440×1100 and 390×844 confirms 15 rows, correct order, no public average text, no horizontal overflow, visible ratings, and a clear selected-row/legal-slot state.
P6-12
Emphasize ratings in the primary selector line
Done
The approved selector revision is implemented in apps/web: team/season metadata is removed from each row, player names stay left aligned, and every exact position rating is right aligned in a compact rounded badge. Forward, midfield, defender, and goalkeeper badges use distinct role colors with explicit selected-row contrast; the ordering average remains undisclosed. All 132 tests, web and repository typechecks, changed-file formatting, lint, and the production build pass. Compiled-CSS browser QA at 1280×720 and 390×844 confirms right alignment, all role treatments, no team/season text, no horizontal overflow, and readable active-state badges.
P6-13
Make delayed actions visible and duplicate-safe
Done
The full player-control audit distinguishes immediate local actions from delayed guest initialization/login, draft start/restart, Cloud Save retry, trusted ranking, friend-room discovery/create/join/refresh/readiness/start/code/leave operations, clipboard copy, and Saved-XI load/publish/search/resolve actions. Delayed controls now expose action-specific labels, spinners, disabled and aria-busy state, while synchronous refs reject repeat entry before React rerenders; background room refreshes no longer clear a foreground action. A focused regression passes within all 133 tests, full repository verification passes, and browser QA at desktop and 390×844 confirms visible Cloud Save and room-refresh progress with no horizontal overflow. Sites version 19 is deployed from commit e622106d5ac50f51874e27eb234fb6306eda78f4, and the public root returns HTTP 200.
| P6-14 | Host the playable frontend on GitHub Pages with the Sites backend | In progress | Static release bb56a57 is pushed to damarindraab/f11 main. Both builds, typecheck, all 138 tests, and lint (warnings only) pass. Built-Worker checks pass for all seven method/preflight combinations across five API paths, same-origin root HTTP 200, and cross-origin JSON errors. Public bundle private-value scan passes. Sites version 20 is deployed from 074172b40e7c4f6d31fc8a556693cb64b20caeaf. Hosted preflights, same-origin compatibility, unapproved-origin rejection, and the redacted full trusted-replay smoke with the Pages Origin all pass, including idempotency, tamper rejection, private receipts, Statistic, and Leaderboard readback. The user enabled Pages; root and JS/CSS assets return 200. Browser guest login, Sites-issued draft, eleven selections, and trusted 42-point result/ranking pass. A Cloud Save warning appeared before and after drafting; local diagnostics reproduce an Axios Network Error without an HTTP response, while Node reaches the service and both origin preflights pass. Next: diagnose the browser Cloud Save request and verify saving/reload before closing acceptance. That personal-account deployment is separate from AccelByte/f11. Initial September 10 browser inspection found the source README at https://accelbyte.github.io/f11/. DOC-05 subsequently completed the AccelByte deployment: compiled gh-pages publication, URL configuration, Sites version 21 CORS support, and browser guest/draft-start verification pass. See docs/11-github-pages.md and docs/verification/2026-09-09-pages-backend.md. This optional hosting split does not block the Functional MVP. |
Update protocol
For each completed work step:
Change only the affected item statuses.
Replace planned text with concrete evidence: file, test, build, decision, or
deployed behavior.
Promote exactly the next critical-path item to Next when useful.
Update the current snapshot and Last updated date.
Commit the tracker with the work it describes.
Shared tutorial
ID
Item
Status
Evidence / next action
DOC-11
Share the consolidated integration tutorial
Done
The single guide on master includes offline setup, six stages, and service references. Superseded documents are removed and links updated; relative links, stage anchors, fences, and whitespace checks pass. Next: rebase offline-starter onto this documentation update.
Public source hygiene
ID
Item
Status
Evidence / next action
DOC-12
Review public-source contents
Done
Removed obsolete narrative documents and references, updated repository instructions, and untracked local deployment bindings with an ignore rule. Scanned 176 retained tracked files for recognizable credentials and two configured private values: no matches. Reviewed URL hosts; retained public deployment URLs, official references, and examples. All 107 relative documentation links and whitespace checks pass. This targeted scan covers current source, not Git history. Next: rebase the offline starter; public mirroring remains deferred.
| REPO-03 | Rename the offline tutorial branch | Done | Local branch is named offline-starter; the tutorial uses the new name. Branch contents are unchanged by the rename and documentation whitespace checks pass. Next: use offline-starter for the tutorial; remote publication remains deferred. |
| PUB-01 | Publish clean connected and offline source branches | Done | Published connected main as a single root commit and offline-starter as its direct child, with no development ancestry. Both trees match the prepared source; 176 connected files and 110 offline files pass credential/exclusion scans and 107 documentation-link checks each. Atomic push and remote readback passed; gh-pages is unchanged. Next: preserve this source-branch boundary for future updates. |
| DOC-13 | Restore agent-ready integration plans | Done | Six files under docs/ags-plans provide stage scope, prerequisites, execution checklists, original connected design details, acceptance checks, and direct handoff prompts. Tutorial and indexes link to the plans. All 137 relative documentation links pass; plan fences and credential/private-value checks pass. Historical notes are distinguished from unimplemented starter work. Next: give the Stage 1 plan to the implementing agent. |