# issues.md · Tester

Run against the built app (API smoke.py / smoke2.py / smoke3.py, UI web/ui.mjs at 1366px and 390px). Everything below is what still fails or is open after the fix loop; passing checks produce nothing.

- **Google Fonts are the only external call** — severity: low
  - Steps: open any screen with no internet access.
  - Expected: type renders as designed.  Actual: falls back to system serif/sans; layout unaffected. Self-host the four families in `web/public/fonts` before launch.
- **Sandbox reset leaves orphaned chain rows** — severity: low
  - Steps: Company file → "Reset the sandbox".
  - Expected: old practice entries gone.  Actual: the old company row is deleted but its `events` rows stay (the table forbids DELETE by design). They belong to no company and are never shown; the table grows by ~50 rows per reset.
- **DSC and Aadhaar eSign are not signing methods in v1** — severity: low (scope)
  - Steps: any sign step, pick "DSC".
  - Expected per design: signs.  Actual: the option is shown disabled with "not in this version"; a scanned signed page or a typed name (non-statutory paper) is used instead. Same on the founder phone.
- **`totp_last` column on an already-installed database** — severity: medium (upgrade only)
  - Steps: deploy this build over an earlier install of this same app.
  - Expected: sign-in works.  Actual: `Schema::ensure` only creates tables, so the new column is missing and sign-in fails. Fresh installs are fine. Fix before any upgrade path exists: add `ALTER TABLE` migrations to `Schema`.
- **Minutes drafts without KEEL_ASSIST_KEY are template prose** — severity: low
  - Steps: meeting step 4 → "Draft the minutes" with no key configured.
  - Expected: natural minutes.  Actual: correct but formulaic sentences from the agenda; a person edits them (required anyway before signing).
