# Validation

Tested using PHP 8.3 with PDO SQLite, GD, mbstring, fileinfo and cURL in a disposable database; compiled React/Tailwind production build.

19 backend integration checks passed:

1. Secure owner setup and SQLite initialization.
2. Setup locked after first administrator.
3. Anonymous admin access and missing CSRF rejected.
4. Seller accounts blocked from admin endpoints.
5. New real ads held for moderation and hidden publicly.
6. Upload re-encoding and permanent pixel watermark verified.
7. Approval shows real ads beside demos.
8. Demo OFF hides samples from browse, saved ads and direct URLs while retaining real ads.
9. Demo ON restores samples without deleting real data.
10. Keyword/location/price filtering.
11. Ownership checks on edits and deletion.
12. Buyer messages and seller replies.
13. Listing reports and admin resolution.
14. Executable files disguised as images rejected.
15. Moderation OFF publishes future submissions immediately.
16. Sold ads removed from public browsing.
17. Suspended users lose access.
18. Google authorization redirect, PKCE and invalid-state rejection.
19. Google client secret absent from browser bundle.

Browser checks passed in headless Chromium at 390px, 768px and 1440px:

- React renders without uncaught errors.
- Admin login and demo toggle work through the interface.
- Homepage and admin dashboard do not overflow horizontally.
- Seller form, account Google connection link and listing details render.
- Desktop, phone and admin screenshots were visually inspected.

PHP files passed syntax checks. The package contains no test database, pre-created test accounts or test seller uploads.

Limits: live Google code exchange is not verified because the user's deployed domain and Google callback registration are still required. Actual cPanel filesystem permissions, Apache/LiteSpeed rules, PHP extensions, HTTPS and upload limits must be confirmed on the host. This was functional verification, not a penetration test or load test.

The included tests/integration.py script uses requests and Pillow. Run it only on a disposable empty installation with a separate setup key; it creates accounts and alters data/settings. Do not run it on your live marketplace.
