GLMCHAT V2.2.1 — NEW-CHAT HANDOVER Created: 22 July 2026 16:54:05 BST AUTHORITATIVE CURRENT RELEASE - Version: 2.2.1 - Deployable ZIP: release/GLMCHAT_V2.2.1_SERVER_DIRECT_DEPLOY_CONTINUED_22072026154516.zip - Deployable ZIP SHA-256: b67db56f204c6131fea9f046601d02b39cf4f8e365237ef661c21328aa50176e - Expanded application: app/ - Architecture: React PWA + PHP 8.2+ + SQLite on LiteSpeed/Apache-compatible shared hosting. - Target: Android mobile, installable PWA, domain root or nested subdirectory. CURRENT DISPOSITION CONDITIONAL STAGING CANDIDATE — NOT PRODUCTION-PROVEN. COMPLETED REMEDIATION - Sensitive offline records protected with AES-GCM after PIN unlock. - Existing plaintext records migrate after successful unlock. - Seven-day offline-credential maximum age. - Controlled service-worker update flow and corrected fallback behaviour. - No-cache handling for non-fingerprinted runtime scripts. - Production preview bypass removed. - Mock provider restricted to APP_ENV=test. - Light-only production palette. - New-chat manifest shortcut added; unused Workbox asset removed. - SBOM, deployment manifest and third-party notices corrected. - Direct-deploy ZIP flattened for extraction at web-root level. - README corrected to describe the actual direct-deploy package. LATEST VERIFIED CHECKS - PHP syntax: 44/44 passed. - JavaScript syntax: 7/7 passed. - Structural/security/PWA/SQLite assertions: 281 passed. - Deployment manifest: 81/81 verified. - SBOM runtime inventory: 80/80 verified. - Precache entries: 15/15 present. - Fresh, repeated and 12-to-13 migration scenarios: passed. - Apache-compatible domain-root and nested-path routing: passed. - Protected paths: 403 confirmed. - ZIP integrity, traversal, duplicate and symlink checks: passed. NOT YET VERIFIED - Successful backend execution with all required PHP extensions. - Live LiteSpeed hosting acceptance. - Upgrade and rollback using cloned real production storage. - Live Together GLM-5.2 text, vision, tools and TTS requests. - Production streaming/cancellation through the real proxy/server stack. - Concurrency, long-running workflows and SQLite contention. - IndexedDB quota, storage eviction and low-connectivity conditions. - Physical Android Chrome, Samsung Internet and TalkBack acceptance. - Source build, type-check, lint and original automated suites: source repository is absent. SERVER REQUIREMENTS - PHP 8.2 or newer. - Extensions: sqlite3, curl, json, openssl, mbstring, fileinfo and zip. - HTTPS. - .htaccess overrides enabled. - storage/ writable by PHP but denied from public HTTP access. UPGRADE WARNING Back up and preserve the existing storage/ directory. Do not overwrite, delete or replace production storage/ unless a separately verified migration/restore plan says so. WORKING RULE Before any future modification, snapshot the actual app and compare every final file against that baseline. Make only the smallest task-specific change and generate the required timestamped unified-diff record.