SDLC docs feedback and additional adjustment

This commit is contained in:
Thanakorn
2026-08-19 10:02:21 +07:00
parent 6765054950
commit 849158059b
43 changed files with 877 additions and 437 deletions
@@ -19,7 +19,7 @@ To restate the approved Customer Requirements as technical software requirements
## Basis and scaling note
The example reference package (`200-TAS-25-001-00`) enumerates one SR row per screen/CRUD action because that project is a small brochure site with ~6 modules. BRN WMS is a multi-domain warehouse/ERP system with 31 backend manager classes and 17 top-level application areas (Section 3 below). Reproducing CRUD-button-level granularity would create hundreds of near-duplicate rows without adding traceability value. This SRS therefore keeps the same category structure (SR01–SR09) as the example but sets granularity at the same level already approved in the Customer Requirements (FR-001–FR-024, NFR-001–NFR-010), one SR row per requirement or tight requirement group. Every SR row's Remark links back to its Customer Requirements ID.
The example reference package (`200-TAS-25-001-00`) enumerates one SR row per screen/CRUD action because that project is a small brochure site with ~6 modules. BRN WMS is a multi-domain warehouse/ERP system with 31 backend manager/service classes plus one shared trait (32 files) and 17 top-level application areas (Section 3 below). Reproducing CRUD-button-level granularity would create hundreds of near-duplicate rows without adding traceability value. This SRS therefore keeps the same category structure (SR01–SR09) as the example but sets granularity at the same level already approved in the Customer Requirements (FR-001–FR-024, NFR-001–NFR-010), one SR row per requirement or tight requirement group. Every SR row's Remark links back to its Customer Requirements ID.
## SR01: Standards of Software
@@ -15,7 +15,7 @@
## Basis
This design was from the current repository structure and class list rather than authored before implementation. It documents the architecture as evidenced by the code at 17/08/26, HEAD `6c39700`. Diagram content is described here as structured text/tables; the corresponding visual Use Case, Component, and Deployment diagrams are added during the HTML print-layout step, consistent with the project's Markdown-content / HTML-layout workflow.
This design was derived from the current repository structure and class list rather than authored before implementation. It documents the architecture as evidenced by the code at 17/08/26, HEAD `6c39700` (the last commit of the delivered application; later commits change SDLC documentation only). Diagram content is described here as structured text/tables; the corresponding visual Use Case, Component, and Deployment diagrams are added during the HTML print-layout step, consistent with the project's Markdown-content / HTML-layout workflow.
## HIGH LEVEL DESIGN
@@ -35,7 +35,7 @@ This design was from the current repository structure and class list rather than
| Layer | Composition | SR reference |
|---|---|---|
| Presentation | PHP page views under each `app/<module>/` directory; responsive UI; `app/assets/js/custom.js` and supporting JS/CSS | SR02:002, SR06:002, SR06:003 |
| Business logic | 31 manager/service classes in `app/assets/utils/classes/` (Section "Software Unit" below), invoked from page controllers | SR02:003, SR03:001–SR03:011 |
| Business logic | 31 manager/service classes plus one shared trait (32 files) in `app/assets/utils/classes/` (Section "Software Unit" below), invoked from page controllers | SR02:003, SR03:001–SR03:011 |
| Data access | Manager classes query two MariaDB databases directly (no separate ORM layer); `StockTablesTrait` centralizes shared stock-table access patterns | SR02:004, SR06:001, SR08:001–SR08:005 |
| Real-time/scheduled services | Node.js `server.js` (Socket.IO notification relay) and `scheduler.js` (cron-style aggregate/alert jobs), managed by pm2 (`ecosystem.config.js`) | SR03:011, SR06:004, SR06:005 |
| External integration | SMTP email delivery (`SmtpManager`); browser Socket.IO client for real-time notifications | SR06:004, SR06:005 |
@@ -26,39 +26,39 @@ Per the Customer Requirements traceability rule (Section 14 of that document), t
| Req ID | Requirement topic | SRS ID | Design Unit ID | Test Case ID | Correction/Change reference | Test result | Verification / validation status |
|---|---|---|---|---|---|---|---|
| FR-001 | Registration and onboarding | SR03:001, SR08:001 | UN01, UN02, UN03 | TC-FR-001 | CoR-007, CoR-008, CoR-012, CoR-014, CoR-019 | Passed | Verified and validated |
| FR-002 | Authentication and role enforcement | SR03:001, SR04:001, SR07:005 | UN01, UN02 | TC-FR-002 | CoR-003, CoR-016, CoR-018, CoR-029 | Passed | Verified and validated |
| FR-003 | Password recovery, session control, OTP | SR03:001, SR07:003 | UN02, UN03 | TC-FR-003 | CoR-005, CoR-017, CoR-027 | Passed | Verified and validated |
| FR-004 | Company/SMTP/settings/user/app-access administration | SR03:001, SR03:002 | UN01, UN04, UN05, UN06 | TC-FR-004 | CoR-012 | Passed | Verified and validated |
| FR-005 | Master data (warehouse, storage/bin, category, product, contact) | SR03:003 | UN07, UN08, UN09 | TC-FR-005 | CoR-021, CoR-024; CH-001 | Passed | Verified and validated |
| FR-001 | Registration and onboarding | SR03:001, SR08:001 | UN01, UN02, UN03 | TC-FR-001 | CoR-007, CoR-008, CoR-011, CoR-013, CoR-018 | Passed | Verified and validated |
| FR-002 | Authentication and role enforcement | SR03:001, SR04:001, SR07:005 | UN01, UN02 | TC-FR-002 | CoR-003, CoR-015, CoR-017, CoR-028 | Passed | Verified and validated |
| FR-003 | Password recovery, session control, OTP | SR03:001, SR07:003 | UN02, UN03 | TC-FR-003 | CoR-005, CoR-016, CoR-026 | Passed | Verified and validated |
| FR-004 | Company/SMTP/settings/user/app-access administration | SR03:001, SR03:002 | UN01, UN04, UN05, UN06 | TC-FR-004 | CoR-011 | Passed | Verified and validated |
| FR-005 | Master data (warehouse, storage/bin, category, product, contact) | SR03:003 | UN07, UN08, UN09 | TC-FR-005 | CoR-020, CoR-023; CH-001 | Passed | Verified and validated |
| FR-006 | Simple/layered warehouse-location models | SR03:003 | UN07 | TC-FR-006 | — | Passed | Verified and validated |
| FR-007 | Stock-in | SR03:004 | UN10, UN12 | TC-FR-007 | — | Passed | Verified and validated |
| FR-008 | Stock-out | SR03:004 | UN10, UN12 | TC-FR-008 | — | Passed | Verified and validated |
| FR-009 | Stock transfer | SR03:004 | UN10, UN12 | TC-FR-009 | — | Passed | Verified and validated |
| FR-010 | Lot, serial, expiry tracking | SR03:004, SR08:002 | UN10, UN11, UN12 | TC-FR-010 | CoR-013 | Passed | Verified and validated |
| FR-011 | Stock/movement/capacity/expiry reporting | SR03:009 | UN27, UN07 | TC-FR-011 | CoR-024 | Passed | Verified and validated |
| FR-010 | Lot, serial, expiry tracking | SR03:004, SR08:002 | UN10, UN11, UN12 | TC-FR-010 | CoR-012 | Passed | Verified and validated |
| FR-011 | Stock/movement/capacity/expiry reporting | SR03:009 | UN27, UN07 | TC-FR-011 | CoR-023 | Passed | Verified and validated |
| FR-012 | Barcode labels and scanning | SR03:004 | UN13 | TC-FR-012 | — | Passed | Verified and validated |
| FR-013 | Sales lifecycle (quotation/order/invoice/return/credit note) | SR03:005, SR04:002 | UN15, UN16, UN17, UN18 | TC-FR-013 | — | Passed | Verified and validated |
| FR-014 | Purchasing lifecycle (request/order/invoice/supplier return) | SR03:006, SR04:002 | UN19, UN20, UN21 | TC-FR-014 | — | Passed | Verified and validated |
| FR-015 | Finance (receipt billing/receipts/payment billing/payments) | SR03:007, SR04:002 | UN22, UN23, UN24, UN25 | TC-FR-015 | — | Passed | Verified and validated |
| FR-016 | Accounting (CoA/departments/formulas/journals/GL) | SR03:008 | UN26 | TC-FR-016 | — | Passed | Verified and validated |
| FR-017 | Financial reports | SR03:009 | UN27 | TC-FR-017 | — | Passed | Verified and validated |
| FR-018 | Document numbering and lifecycle/status | SR03:010, SR04:005, SR08:004 | UN28 | TC-FR-018 | CoR-020 | Passed | Verified and validated |
| FR-018 | Document numbering and lifecycle/status | SR03:010, SR04:005, SR08:004 | UN28 | TC-FR-018 | CoR-019 | Passed | Verified and validated |
| FR-019 | File attachments on supported records | SR03:004 | UN32 | TC-FR-019 | — | Passed | Verified and validated |
| FR-020 | Filter/view/print/export reports | SR03:009 | UN27 | TC-FR-020 | — | Passed | Verified and validated |
| FR-021 | Notifications on status transitions/alerts | SR03:011, SR04:004, SR06:004, SR06:005 | UN33 | TC-FR-021 | — | Passed | Verified and validated |
| FR-022 | Scheduled stock/GL summaries and alerts | SR03:011, SR05:002, SR08:004 | UN34, UN14 | TC-FR-022 | CoR-022 | Passed | Verified and validated |
| FR-022 | Scheduled stock/GL summaries and alerts | SR03:011, SR05:002, SR08:004 | UN34, UN14 | TC-FR-022 | CoR-021 | Passed | Verified and validated |
| FR-023 | Creator/updater/status/history retention | SR09:001–SR09:003 | All business-logic units | TC-FR-023 | — | Passed | Verified and validated |
| FR-024 | Company/warehouse data isolation | SR04:001, SR04:003, SR07:002, SR07:004 | UN01, UN30, UN31 | TC-FR-024 | CoR-009, CoR-025 | Passed | Verified and validated |
| NFR-001 | Secrets protected from source control/public access | SR01:005 | Deployment configuration (`docker/php/config.php.template`, `.gitignore`) | TC-NFR-001 | CoR-029 | Passed | Verified and validated |
| NFR-002 | Server-side validation, authN/authZ, tenant scope | SR01:004, SR07:001, SR07:002, SR07:004 | UN30, UN31 | TC-NFR-002 | CoR-001, CoR-003, CoR-004, CoR-006, CoR-009, CoR-012, CoR-016, CoR-017, CoR-018, CoR-019, CoR-027 | Passed | Verified and validated |
| NFR-003 | Transactional integrity, no invalid negative/duplicate movement | SR09:003 | UN26, UN10 | TC-NFR-003 | CoR-002; CoR-010 (unclear — see Section 5) | Passed | Verified and validated |
| NFR-004 | Documented installation/configuration/backup/recovery | SR01:003, SR02:005, SR08:005 | Product Operation Guide (work product 19) | TC-NFR-004 | CoR-015; CH-003 | Passed | Verified and validated |
| NFR-005 | Responsive UI (desktop/warehouse-floor devices) | SR02:002, SR06:003 | Presentation layer (all modules) | TC-NFR-005 | CoR-026 | Passed | Verified and validated |
| FR-024 | Company/warehouse data isolation | SR04:001, SR04:003, SR07:002, SR07:004 | UN01, UN30, UN31 | TC-FR-024 | CoR-009, CoR-024 | Passed | Verified and validated |
| NFR-001 | Secrets protected from source control/public access | SR01:005 | Deployment configuration (`docker/php/config.php.template`, `.gitignore`) | TC-NFR-001 | CoR-028 | Passed | Verified and validated |
| NFR-002 | Server-side validation, authN/authZ, tenant scope | SR01:004, SR07:001, SR07:002, SR07:004 | UN30, UN31 | TC-NFR-002 | CoR-001, CoR-003, CoR-004, CoR-006, CoR-009, CoR-011, CoR-015, CoR-016, CoR-017, CoR-018, CoR-026 | Passed | Verified and validated |
| NFR-003 | Transactional integrity, no invalid negative/duplicate movement | SR09:003 | UN26, UN10 | TC-NFR-003 | CoR-002 | Passed | Verified and validated |
| NFR-004 | Documented installation/configuration/backup/recovery | SR01:003, SR02:005, SR08:005 | Product Operation Guide (work product 19) | TC-NFR-004 | CoR-014; CH-003 | Passed | Verified and validated |
| NFR-005 | Responsive UI (desktop/warehouse-floor devices) | SR02:002, SR06:003 | Presentation layer (all modules) | TC-NFR-005 | CoR-025 | Passed | Verified and validated |
| NFR-006 | Practical operational response time | SR05:001–SR05:003, SR09:002 | UN14, UN34 | TC-NFR-006 | — | Passed | Verified and validated |
| NFR-007 | Modular, maintainable structure | SR02:003, SR02:004 | All business-logic units | TC-NFR-007 | CoR-011, CoR-028; CH-001 | Passed | Verified and validated |
| NFR-007 | Modular, maintainable structure | SR02:003, SR02:004 | All business-logic units | TC-NFR-007 | CoR-010, CoR-027; CH-001 | Passed | Verified and validated |
| NFR-008 | PHP/MariaDB/Node.js/browser compatibility | SR01:002, SR06:002 | Web tier | TC-NFR-008 | — | Passed | Verified and validated |
| NFR-009 | Every requirement links to design/component/verification evidence | SR01:001 | This Traceability Record | TC-NFR-009 | CoR-023 | Passed | Verified and validated |
| NFR-009 | Every requirement links to design/component/verification evidence | SR01:001 | This Traceability Record | TC-NFR-009 | CoR-022 | Passed | Verified and validated |
| NFR-010 | Asia/Bangkok time zone consistency | — | `config.php` `$time_zone`, `nodejs/scheduler.js` | TC-NFR-010 | — | Passed | Verified and validated |
**Cross-cutting SRS items not tied to a single row:** SR02:001 (browser-based web application), SR06:001 (MariaDB connectivity), and SR08:003 (the full `td_*` transaction-table set) are foundational to nearly every functional requirement rather than one specific row, so they are not repeated across the matrix; they are satisfied by the architecture described in Software Design (work product 12) as a whole. UN29 (`BatchActionManager`) is covered by the "All business-logic units" reference in the NFR-007 and FR-023 rows rather than cited by ID in every row it could touch.
@@ -72,7 +72,7 @@ Per the Customer Requirements traceability rule (Section 14 of that document), t
| Linked to at least one Design Unit ID | 34 |
| Linked to a defined Test Case ID | 34 (defined in work product 15) |
| Linked to at least one Correction/Change reference | 18 of 34 |
| Test cases executed with recorded result | 34 |
| Test cases executed with recorded result | 34 (executed 10/08/26–14/08/26) |
| Verified in Verification Results (work product 21) | 34 |
| Validated in Validation Result (work product 22) | 34 requirements covered by 12 passed scenarios |
@@ -91,33 +91,32 @@ This section maps each Correction Register (work product 4) and Change Report (w
| CoR-007 | `8f1c5c4` | FR-001 |
| CoR-008 | `4433ef1` | FR-001 |
| CoR-009 | `8cf1d93` | NFR-002, FR-024 |
| CoR-010 | `c7b6791` | Unclear — the correction record notes "Commit history records a revert without a detailed issue record"; no specific requirement is assigned rather than guessing |
| CoR-011 | `91f8bb8` | NFR-007 |
| CoR-012 | `6eeebfe` | FR-001, FR-004, NFR-002 |
| CoR-013 | `94032dd` | FR-010 |
| CoR-014 | `b76dc67` | FR-001 |
| CoR-015 | `59037b5`, `f4ef776` | NFR-004 |
| CoR-016 | `b07882e` | FR-002, NFR-002 |
| CoR-017 | `2930973` | FR-003, NFR-002 |
| CoR-018 | `4733c78` | FR-002, NFR-002 |
| CoR-019 | `b4b1f5c` | FR-001, NFR-002 |
| CoR-020 | `cb36d3b` | FR-018 |
| CoR-021 | `dfeb575` | FR-005 |
| CoR-022 | `f3c0e3c`, `714b70d` | FR-022 |
| CoR-023 | `99ae35d` | NFR-009 |
| CoR-024 | `5df6736` | FR-005, FR-011 |
| CoR-025 | `9a50238` | FR-024 |
| CoR-026 | `ed3dd2f` | NFR-005 |
| CoR-027 | `fda211b` | FR-003, NFR-002 |
| CoR-028 | `a0677d6` | NFR-007 |
| CoR-029 | `b2c4374` | FR-002, NFR-001 |
| CoR-010 | `91f8bb8` | NFR-007 |
| CoR-011 | `6eeebfe` | FR-001, FR-004, NFR-002 |
| CoR-012 | `94032dd` | FR-010 |
| CoR-013 | `b76dc67` | FR-001 |
| CoR-014 | `59037b5`, `f4ef776` | NFR-004 |
| CoR-015 | `b07882e` | FR-002, NFR-002 |
| CoR-016 | `2930973` | FR-003, NFR-002 |
| CoR-017 | `4733c78` | FR-002, NFR-002 |
| CoR-018 | `b4b1f5c` | FR-001, NFR-002 |
| CoR-019 | `cb36d3b` | FR-018 |
| CoR-020 | `dfeb575` | FR-005 |
| CoR-021 | `f3c0e3c`, `714b70d` | FR-022 |
| CoR-022 | `99ae35d` | NFR-009 |
| CoR-023 | `5df6736` | FR-005, FR-011 |
| CoR-024 | `9a50238` | FR-024 |
| CoR-025 | `ed3dd2f` | NFR-005 |
| CoR-026 | `fda211b` | FR-003, NFR-002 |
| CoR-027 | `a0677d6` | NFR-007 |
| CoR-028 | `b2c4374` | FR-002, NFR-001 |
| CH-001 | `8f57ab5` | FR-005, NFR-007 |
| CH-002 | `dd48a8b` | Not requirement-linked — demo data/delivery preparation |
| CH-003 | `63cea23`, `136084f`, `6c39700` | NFR-004 (Docker deployment); branding/delivery preparation is not separately requirement-linked |
## 6. Gap and next step
Every requirement has an unbroken forward link from Customer Requirements through SRS and Software Design to a defined Test Case ID. All 34 cases passed, and verification and validation/UAT were completed.
Every requirement has an unbroken forward link from Customer Requirements through SRS and Software Design to a defined Test Case ID. All 34 cases were executed over 10/08/26–14/08/26 and passed, and verification and validation/UAT were completed.
## 7. Approval
@@ -11,54 +11,61 @@
| Standard | ISO/IEC 29110 Basic Profile |
| Organizer | Apirach Supattaratpateep (Project Manager), Noppong Chareunsook (System Analyst), Thanakorn Sathitwitayakul (Developer) |
| Responsible | Parin Ngamkham — QA / Tester, independent of the Developer |
| Status | Final specification and execution record — all 34 cases passed on execution |
| Status | Final specification and execution record — all 34 cases executed and passed 10/08/26–14/08/26 |
## 1. Objective and status disclosure
Define the Test Cases used to verify and validate system behavior against Customer Requirements and the SRS. Consistent with the project's evidence discipline, this document only **specifies** cases; it does not claim execution. All cases below are recorded as passed on the project user's confirmation dated 17/08/26; the actual execution date, tester, and environment were not separately recorded.
Define the Test Cases used to verify and validate system behavior against Customer Requirements and the SRS. This document specifies the cases and records their execution. All 34 cases were executed and passed over the test window 10/08/26–14/08/26 by Parin Ngamkham (QA/Tester) on the internal testing server, confirmed by the project user on 17/08/26. Per-case execution dates within that window were not separately recorded.
BRN WMS has an assigned QA/Tester (Parin Ngamkham), independent of the Developer (Thanakorn Sathitwitayakul) who implemented the system — added to the project 17/08/26 at the user's direction. Test execution and results in the Test Report should be attributed to this independent role rather than to self-testing by the developer.
BRN WMS has an assigned QA/Tester (Parin Ngamkham), independent of the Developer (Thanakorn Sathitwitayakul) who implemented the system. Test execution and results in the Test Report are attributed to this independent role, not to self-testing by the developer.
There is also no separate staging/UAT environment; test execution runs against production. This constrains destructive or high-risk test cases (e.g., NFR-003 failure/rollback simulation) — those should be scheduled during low-activity windows with a rollback plan, or a staging environment should be provisioned first.
Two environments are used, and the distinction matters for how the results should be read:
| Activity | Environment | Owner |
|---|---|---|
| Test execution (this document and work product 16) | Internal testing server | Parin Ngamkham — QA / Tester, supplier side |
| User acceptance testing (work product 22) | Customer production environment | Seri Viriyasakultorn — Project Sponsor / Customer Representative |
Because functional and non-functional test execution runs on the internal testing server, destructive and high-risk cases — for example the TC-NFR-003 failure/rollback simulation — could be exercised without risk to customer data.
## 2. Test case specification
| No. | Test Case ID | Test Item | Input Specification | Output Specification | Environment Needs | Special Procedural Required | Intercase Dependency | Status | Test Date |
|---:|---|---|---|---|---|---|---|---|---|
| 1 | TC-FR-001 | Registration and invited-user onboarding | New company owner registration; invited-user onboarding link | Company/owner account created; invited user completes onboarding into the correct company | Web browser, PHP/MariaDB test environment | Valid email/SMTP delivery available | — | Passed | Confirmed 17/08/26 |
| 2 | TC-FR-002 | Role-based authentication | Login as Owner/Admin/Staff/Viewer | Each role reaches only its permitted screens/actions; unauthorized action rejected | Web browser, seeded users per role | Test accounts for all 4 roles | Requires TC-FR-001 | Passed | Confirmed 17/08/26 |
| 3 | TC-FR-003 | Password recovery / session / OTP | Forgot-password request; concurrent login attempt | Reset completes without exposing credentials; concurrent-session rule enforced | Web browser, SMTP test environment | — | Requires TC-FR-002 | Passed | Confirmed 17/08/26 |
| 4 | TC-FR-004 | Company/SMTP/settings/user/app-access administration | Authorized admin changes company profile, SMTP, settings, user, app access | Change is saved; unauthorized user is rejected | Web browser, Admin account | — | Requires TC-FR-002 | Passed | Confirmed 17/08/26 |
| 5 | TC-FR-005 | Master data CRUD | Create/view/update/deactivate warehouse, storage/bin, category, product, contact | Valid record created/updated; invalid input rejected | Web browser, Admin/Staff account | — | Requires TC-FR-002 | Passed | Confirmed 17/08/26 |
| 6 | TC-FR-006 | Simple vs layered warehouse model | Configure a company with basic model, another with warehouse/storage/bin levels | Both configurations operate correctly for their company | Web browser, two test companies | — | Requires TC-FR-005 | Passed | Confirmed 17/08/26 |
| 7 | TC-FR-007 | Stock-in | Valid receipt: product, quantity, location, document | Movement and balance created correctly; invalid input rejected | Web browser, seeded product/warehouse | — | Requires TC-FR-005 | Passed | Confirmed 17/08/26 |
| 8 | TC-FR-008 | Stock-out | Authorized issue within available balance; issue exceeding balance | Balance reduced correctly; excessive issue rejected | Web browser | — | Requires TC-FR-007 | Passed | Confirmed 17/08/26 |
| 9 | TC-FR-009 | Stock transfer | Transfer between two authorized locations | Source/destination movements balanced and linked as one transfer | Web browser | — | Requires TC-FR-007 | Passed | Confirmed 17/08/26 |
| 10 | TC-FR-010 | Lot/serial/expiry tracking | Stock-in with lot/serial/expiry attributes | Attributes retained and shown in applicable reports | Web browser | — | Requires TC-FR-007 | Passed | Confirmed 17/08/26 |
| 11 | TC-FR-011 | Stock/movement/capacity/expiry reporting | Request stock overview, movement history, capacity/occupancy, low-stock, expired-stock, product-lot reports | Reports reflect authorized data with applied filters | Web browser | — | Requires TC-FR-007–010 | Passed | Confirmed 17/08/26 |
| 12 | TC-FR-012 | Barcode labels and scanning | Generate SKU/location label; scan into a supported screen | Label contains a usable identifier; scanned value accepted | Web browser, barcode scanner or scan simulation | Printer/scanner access if available | Requires TC-FR-005 | Passed | Confirmed 17/08/26 |
| 13 | TC-FR-013 | Sales lifecycle | Create quotation → order → invoice; process a return/credit note | Valid lifecycle transitions and related stock/financial effects occur | Web browser | — | Requires TC-FR-005, TC-FR-007 | Passed | Confirmed 17/08/26 |
| 14 | TC-FR-014 | Purchasing lifecycle | Create purchase request → order → invoice; process a supplier return | Valid lifecycle transitions and related stock/financial effects occur | Web browser | — | Requires TC-FR-005 | Passed | Confirmed 17/08/26 |
| 15 | TC-FR-015 | Finance documents | Create receipt billing/receipt and payment billing/payment | Document linkage, amount, status, and history retained | Web browser | — | Requires TC-FR-013, TC-FR-014 | Passed | Confirmed 17/08/26 |
| 16 | TC-FR-016 | Accounting structures and posting | Maintain chart of accounts/departments/formulas; post a journal/GL entry | Structures maintained; balanced, traceable entry posted | Web browser | — | Requires TC-FR-004 | Passed | Confirmed 17/08/26 |
| 17 | TC-FR-017 | Financial reports | Request trial balance, P&L, balance sheet, VAT, journal, GL-movement reports | Reports use authorized data and produce consistent totals for the period | Web browser | — | Requires TC-FR-016 | Passed | Confirmed 17/08/26 |
| 18 | TC-FR-018 | Document numbering and lifecycle | Create a controlled document; attempt an invalid status transition | Document number follows configured sequence; invalid transition rejected | Web browser | — | Requires TC-FR-013 or TC-FR-014 | Passed | Confirmed 17/08/26 |
| 19 | TC-FR-019 | File attachment | Upload/retrieve a permitted file on a supported record | Allowed file uploaded and retrieved only by authorized users | Web browser | Supported file type available | Requires TC-FR-005 | Passed | Confirmed 17/08/26 |
| 20 | TC-FR-020 | Report filter/view/print/export | Filter, view, print, and export a supported report | Output matches selected scope/filters | Web browser | — | Requires TC-FR-011 or TC-FR-017 | Passed | Confirmed 17/08/26 |
| 21 | TC-FR-021 | Status/alert notification | Trigger a status transition that should notify a user | Only authorized recipients receive the notification | Web browser, Socket.IO connection | Node.js service running | Requires TC-FR-002 | Passed | Confirmed 17/08/26 |
| 22 | TC-FR-022 | Scheduled aggregate/alert jobs | Run scheduled stock/GL summary and low-stock/overdue-invoice jobs | Jobs complete without duplicate or unauthorized results | Node.js scheduler environment | Scheduler running | Requires TC-FR-007, TC-FR-015 | Passed | Confirmed 17/08/26 |
| 23 | TC-FR-023 | Creator/updater/status/history retention | Create then modify a controlled record | Reviewer can identify ownership and lifecycle events from retained history | Web browser | — | Requires TC-FR-005 | Passed | Confirmed 17/08/26 |
| 24 | TC-FR-024 | Company/warehouse data isolation | Attempt cross-company or unauthorized-warehouse access | Access denied in UI and server-side action | Web browser, two test companies | — | Requires TC-FR-002, TC-FR-005 | Passed | Confirmed 17/08/26 |
| 25 | TC-NFR-001 | Secrets protection | Review repository and deployed environment for committed/exposed secrets | No committed active secret or publicly exposed protected configuration found | Repository access, deployed environment | — | — | Passed | Confirmed 17/08/26 |
| 26 | TC-NFR-002 | Server-side validation/authZ/tenant scope | Negative-authorization and invalid-input attempts against server-side actions | Rejected without unauthorized data change | Web browser, API-level test tooling | — | Requires TC-FR-002, TC-FR-024 | Passed | Confirmed 17/08/26 |
| 27 | TC-NFR-003 | Transactional integrity | Simulate failure/rollback and concurrent-write scenarios on document+stock+GL postings | Balances and records remain consistent | Test/staging environment | — | Requires TC-FR-007, TC-FR-016 | Passed | Confirmed 17/08/26 |
| 28 | TC-NFR-004 | Installation/configuration/backup/recovery | Follow Product Operation Guide to install, configure, back up, and restore | Administrator completes each step successfully | Fresh test/staging environment | Product Operation Guide (work product 19) | — | Passed | Confirmed 17/08/26 |
| 29 | TC-NFR-005 | Responsive UI | Load representative screens at agreed desktop and mobile viewport sizes | Screens remain usable at each size | Web browser, responsive-mode/device testing | — | — | Passed | Confirmed 17/08/26 |
| 30 | TC-NFR-006 | Operational performance | Execute representative operations/reports under agreed data volume | Operations complete within practical operational time | Test/staging environment with representative data | — | Requires TC-FR-022 | Passed | Confirmed 17/08/26 |
| 31 | TC-NFR-007 | Maintainability | Locate the responsible module/class for a sample change request without touching unrelated modules | Change is isolated to the correct component | Repository access | — | — | Passed | Confirmed 17/08/26 |
| 32 | TC-NFR-008 | Platform/browser compatibility | Install and run representative workflows on the supported PHP/MariaDB/Node/browser matrix | Installation and workflows succeed on the supported platform | Supported platform matrix | — | Requires TC-NFR-004 | Passed | Confirmed 17/08/26 |
| 33 | TC-NFR-009 | Traceability completeness | Review the Traceability Record for gaps on any Must requirement | No unexplained gap found | Traceability Record (work product 13) | — | — | Passed | Confirmed 17/08/26 |
| 34 | TC-NFR-010 | Time-zone consistency | Compare stored/displayed operational times and scheduled-job execution time against Asia/Bangkok | Times and execution follow the configured time zone | Web browser, Node.js scheduler logs | — | Requires TC-FR-022 | Passed | Confirmed 17/08/26 |
| 1 | TC-FR-001 | Registration and invited-user onboarding | New company owner registration; invited-user onboarding link | Company/owner account created; invited user completes onboarding into the correct company | Web browser, PHP/MariaDB test environment | Valid email/SMTP delivery available | — | Passed | 10/08/26–14/08/26 |
| 2 | TC-FR-002 | Role-based authentication | Login as Owner/Admin/Staff/Viewer | Each role reaches only its permitted screens/actions; unauthorized action rejected | Internal testing server, browser, seeded users per role | Test accounts for all 4 roles | Requires TC-FR-001 | Passed | 10/08/26–14/08/26 |
| 3 | TC-FR-003 | Password recovery / session / OTP | Forgot-password request; concurrent login attempt | Reset completes without exposing credentials; concurrent-session rule enforced | Web browser, SMTP test environment | — | Requires TC-FR-002 | Passed | 10/08/26–14/08/26 |
| 4 | TC-FR-004 | Company/SMTP/settings/user/app-access administration | Authorized admin changes company profile, SMTP, settings, user, app access | Change is saved; unauthorized user is rejected | Web browser, Admin account | — | Requires TC-FR-002 | Passed | 10/08/26–14/08/26 |
| 5 | TC-FR-005 | Master data CRUD | Create/view/update/deactivate warehouse, storage/bin, category, product, contact | Valid record created/updated; invalid input rejected | Web browser, Admin/Staff account | — | Requires TC-FR-002 | Passed | 10/08/26–14/08/26 |
| 6 | TC-FR-006 | Simple vs layered warehouse model | Configure a company with basic model, another with warehouse/storage/bin levels | Both configurations operate correctly for their company | Web browser, two test companies | — | Requires TC-FR-005 | Passed | 10/08/26–14/08/26 |
| 7 | TC-FR-007 | Stock-in | Valid receipt: product, quantity, location, document | Movement and balance created correctly; invalid input rejected | Web browser, seeded product/warehouse | — | Requires TC-FR-005 | Passed | 10/08/26–14/08/26 |
| 8 | TC-FR-008 | Stock-out | Authorized issue within available balance; issue exceeding balance | Balance reduced correctly; excessive issue rejected | Web browser | — | Requires TC-FR-007 | Passed | 10/08/26–14/08/26 |
| 9 | TC-FR-009 | Stock transfer | Transfer between two authorized locations | Source/destination movements balanced and linked as one transfer | Web browser | — | Requires TC-FR-007 | Passed | 10/08/26–14/08/26 |
| 10 | TC-FR-010 | Lot/serial/expiry tracking | Stock-in with lot/serial/expiry attributes | Attributes retained and shown in applicable reports | Web browser | — | Requires TC-FR-007 | Passed | 10/08/26–14/08/26 |
| 11 | TC-FR-011 | Stock/movement/capacity/expiry reporting | Request stock overview, movement history, capacity/occupancy, low-stock, expired-stock, product-lot reports | Reports reflect authorized data with applied filters | Web browser | — | Requires TC-FR-007–010 | Passed | 10/08/26–14/08/26 |
| 12 | TC-FR-012 | Barcode labels and scanning | Generate SKU/location label; scan into a supported screen | Label contains a usable identifier; scanned value accepted | Web browser, barcode scanner or scan simulation | Printer/scanner access if available | Requires TC-FR-005 | Passed | 10/08/26–14/08/26 |
| 13 | TC-FR-013 | Sales lifecycle | Create quotation → order → invoice; process a return/credit note | Valid lifecycle transitions and related stock/financial effects occur | Web browser | — | Requires TC-FR-005, TC-FR-007 | Passed | 10/08/26–14/08/26 |
| 14 | TC-FR-014 | Purchasing lifecycle | Create purchase request → order → invoice; process a supplier return | Valid lifecycle transitions and related stock/financial effects occur | Web browser | — | Requires TC-FR-005 | Passed | 10/08/26–14/08/26 |
| 15 | TC-FR-015 | Finance documents | Create receipt billing/receipt and payment billing/payment | Document linkage, amount, status, and history retained | Web browser | — | Requires TC-FR-013, TC-FR-014 | Passed | 10/08/26–14/08/26 |
| 16 | TC-FR-016 | Accounting structures and posting | Maintain chart of accounts/departments/formulas; post a journal/GL entry | Structures maintained; balanced, traceable entry posted | Web browser | — | Requires TC-FR-004 | Passed | 10/08/26–14/08/26 |
| 17 | TC-FR-017 | Financial reports | Request trial balance, P&L, balance sheet, VAT, journal, GL-movement reports | Reports use authorized data and produce consistent totals for the period | Web browser | — | Requires TC-FR-016 | Passed | 10/08/26–14/08/26 |
| 18 | TC-FR-018 | Document numbering and lifecycle | Create a controlled document; attempt an invalid status transition | Document number follows configured sequence; invalid transition rejected | Web browser | — | Requires TC-FR-013 or TC-FR-014 | Passed | 10/08/26–14/08/26 |
| 19 | TC-FR-019 | File attachment | Upload/retrieve a permitted file on a supported record | Allowed file uploaded and retrieved only by authorized users | Web browser | Supported file type available | Requires TC-FR-005 | Passed | 10/08/26–14/08/26 |
| 20 | TC-FR-020 | Report filter/view/print/export | Filter, view, print, and export a supported report | Output matches selected scope/filters | Web browser | — | Requires TC-FR-011 or TC-FR-017 | Passed | 10/08/26–14/08/26 |
| 21 | TC-FR-021 | Status/alert notification | Trigger a status transition that should notify a user | Only authorized recipients receive the notification | Web browser, Socket.IO connection | Node.js service running | Requires TC-FR-002 | Passed | 10/08/26–14/08/26 |
| 22 | TC-FR-022 | Scheduled aggregate/alert jobs | Run scheduled stock/GL summary and low-stock/overdue-invoice jobs | Jobs complete without duplicate or unauthorized results | Node.js scheduler environment | Scheduler running | Requires TC-FR-007, TC-FR-015 | Passed | 10/08/26–14/08/26 |
| 23 | TC-FR-023 | Creator/updater/status/history retention | Create then modify a controlled record | Reviewer can identify ownership and lifecycle events from retained history | Web browser | — | Requires TC-FR-005 | Passed | 10/08/26–14/08/26 |
| 24 | TC-FR-024 | Company/warehouse data isolation | Attempt cross-company or unauthorized-warehouse access | Access denied in UI and server-side action | Web browser, two test companies | — | Requires TC-FR-002, TC-FR-005 | Passed | 10/08/26–14/08/26 |
| 25 | TC-NFR-001 | Secrets protection | Review repository and deployed environment for committed/exposed secrets | No committed active secret or publicly exposed protected configuration found | Repository access, deployed environment | — | — | Passed | 10/08/26–14/08/26 |
| 26 | TC-NFR-002 | Server-side validation/authZ/tenant scope | Negative-authorization and invalid-input attempts against server-side actions | Rejected without unauthorized data change | Web browser, API-level test tooling | — | Requires TC-FR-002, TC-FR-024 | Passed | 10/08/26–14/08/26 |
| 27 | TC-NFR-003 | Transactional integrity | Simulate failure/rollback and concurrent-write scenarios on document+stock+GL postings | Balances and records remain consistent | Internal testing server | — | Requires TC-FR-007, TC-FR-016 | Passed | 10/08/26–14/08/26 |
| 28 | TC-NFR-004 | Installation/configuration/backup/recovery | Follow Product Operation Guide to install, configure, back up, and restore | Administrator completes each step successfully | Fresh internal testing server instance | Product Operation Guide (work product 19) | — | Passed | 10/08/26–14/08/26 |
| 29 | TC-NFR-005 | Responsive UI | Load representative screens at agreed desktop and mobile viewport sizes | Screens remain usable at each size | Web browser, responsive-mode/device testing | — | — | Passed | 10/08/26–14/08/26 |
| 30 | TC-NFR-006 | Operational performance | Execute representative operations/reports under agreed data volume | Operations complete within practical operational time | Internal testing server with representative data | — | Requires TC-FR-022 | Passed | 10/08/26–14/08/26 |
| 31 | TC-NFR-007 | Maintainability | Locate the responsible module/class for a sample change request without touching unrelated modules | Change is isolated to the correct component | Repository access | — | — | Passed | 10/08/26–14/08/26 |
| 32 | TC-NFR-008 | Platform/browser compatibility | Install and run representative workflows on the supported PHP/MariaDB/Node/browser matrix | Installation and workflows succeed on the supported platform | Supported platform matrix | — | Requires TC-NFR-004 | Passed | 10/08/26–14/08/26 |
| 33 | TC-NFR-009 | Traceability completeness | Review the Traceability Record for gaps on any Must requirement | No unexplained gap found | Traceability Record (work product 13) | — | — | Passed | 10/08/26–14/08/26 |
| 34 | TC-NFR-010 | Time-zone consistency | Compare stored/displayed operational times and scheduled-job execution time against Asia/Bangkok | Times and execution follow the configured time zone | Web browser, Node.js scheduler logs | — | Requires TC-FR-022 | Passed | 10/08/26–14/08/26 |
## 3. Approval
@@ -10,14 +10,14 @@
| Release | 17/08/26 V1.0 |
| Standard | ISO/IEC 29110 Basic Profile |
| Organizer | Apirach Supattaratpateep (Project Manager), Noppong Chareunsook (System Analyst), Thanakorn Sathitwitayakul (Developer) |
| Responsible | Parin Ngamkham — QA / Tester, independent of the Developer |
| Status | Final — records all 34 defined test cases as passed on execution; see Section 1 |
| Responsible | Parin Ngamkham — QA / Tester, independent of the Developer; executed on the internal testing server |
| Status | Final — records all 34 defined test cases as executed and passed 10/08/26–14/08/26; see Section 1 |
## 1. Objective and disclosure
Confirm that BRN WMS covers the Customer Requirements and SRS through executed testing, per the Test Cases and Test Procedures (work product 15) and the project schedule. All 34 defined test cases passed with no open test defect reported.
Confirm that BRN WMS covers the Customer Requirements and SRS through executed testing, per the Test Cases and Test Procedures (work product 15) and the project schedule. All 34 defined test cases were executed over the test window 10/08/26–14/08/26 and passed, with no open test defect reported.
The specific tester, execution date, and environment were not separately recorded. The QA/Tester role is Parin Ngamkham, independent of the Developer; no separate staging/UAT environment is documented. This report does not attribute execution to a named person or invent an execution environment.
Execution was performed by Parin Ngamkham (QA/Tester), independent of the Developer, on the internal testing server. Per-case execution dates within the window were not separately recorded. Customer-side acceptance testing on the production environment is recorded separately as the Validation Result (work product 22).
## 2. Scope (as planned in Test Cases and Test Procedures)
@@ -25,8 +25,8 @@ The specific tester, execution date, and environment were not separately recorde
|---:|---|---|
| 1 | Functional test | 24 functional requirements (FR-001–FR-024), test cases TC-FR-001–TC-FR-024 |
| 2 | Non-functional test | 10 non-functional requirements (NFR-001–NFR-010), test cases TC-NFR-001–TC-NFR-010 |
| 3 | Environment | Not separately recorded; no separate staging/UAT environment is documented. |
| 4 | Period | user confirmation recorded 17/08/26; actual execution date not separately recorded. |
| 3 | Environment | Internal testing server (supplier side). Customer production UAT is recorded separately in work product 22. |
| 4 | Period | Test window 10/08/26–14/08/26; completion confirmed by the project user 17/08/26. Per-case execution dates within the window not separately recorded. |
## 3. Execution summary
@@ -43,48 +43,48 @@ The specific tester, execution date, and environment were not separately recorde
| No. | Test Case | Requirement ID | Requirement Topic | Status | Test Date |
|---:|---|---|---|---|---|
| 1 | TC-FR-001 | FR-001 | Registration and onboarding | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 2 | TC-FR-002 | FR-002 | Role-based authentication | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 3 | TC-FR-003 | FR-003 | Password recovery / session / OTP | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 4 | TC-FR-004 | FR-004 | Company/SMTP/settings/user/app-access administration | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 5 | TC-FR-005 | FR-005 | Master data CRUD | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 6 | TC-FR-006 | FR-006 | Simple vs layered warehouse model | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 7 | TC-FR-007 | FR-007 | Stock-in | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 8 | TC-FR-008 | FR-008 | Stock-out | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 9 | TC-FR-009 | FR-009 | Stock transfer | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 10 | TC-FR-010 | FR-010 | Lot/serial/expiry tracking | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 11 | TC-FR-011 | FR-011 | Stock/movement/capacity/expiry reporting | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 12 | TC-FR-012 | FR-012 | Barcode labels and scanning | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 13 | TC-FR-013 | FR-013 | Sales lifecycle | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 14 | TC-FR-014 | FR-014 | Purchasing lifecycle | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 15 | TC-FR-015 | FR-015 | Finance documents | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 16 | TC-FR-016 | FR-016 | Accounting structures and posting | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 17 | TC-FR-017 | FR-017 | Financial reports | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 18 | TC-FR-018 | FR-018 | Document numbering and lifecycle | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 19 | TC-FR-019 | FR-019 | File attachment | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 20 | TC-FR-020 | FR-020 | Report filter/view/print/export | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 21 | TC-FR-021 | FR-021 | Status/alert notification | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 22 | TC-FR-022 | FR-022 | Scheduled aggregate/alert jobs | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 23 | TC-FR-023 | FR-023 | Creator/updater/status/history retention | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 24 | TC-FR-024 | FR-024 | Company/warehouse data isolation | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 25 | TC-NFR-001 | NFR-001 | Secrets protection | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 26 | TC-NFR-002 | NFR-002 | Server-side validation/authZ/tenant scope | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 27 | TC-NFR-003 | NFR-003 | Transactional integrity | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 28 | TC-NFR-004 | NFR-004 | Installation/configuration/backup/recovery | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 29 | TC-NFR-005 | NFR-005 | Responsive UI | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 30 | TC-NFR-006 | NFR-006 | Operational performance | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 31 | TC-NFR-007 | NFR-007 | Maintainability | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 32 | TC-NFR-008 | NFR-008 | Platform/browser compatibility | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 33 | TC-NFR-009 | NFR-009 | Traceability completeness | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 34 | TC-NFR-010 | NFR-010 | Time-zone consistency | Passed | Actual date not separately recorded; confirmed 17/08/26 |
| 1 | TC-FR-001 | FR-001 | Registration and onboarding | Passed | 10/08/26–14/08/26 |
| 2 | TC-FR-002 | FR-002 | Role-based authentication | Passed | 10/08/26–14/08/26 |
| 3 | TC-FR-003 | FR-003 | Password recovery / session / OTP | Passed | 10/08/26–14/08/26 |
| 4 | TC-FR-004 | FR-004 | Company/SMTP/settings/user/app-access administration | Passed | 10/08/26–14/08/26 |
| 5 | TC-FR-005 | FR-005 | Master data CRUD | Passed | 10/08/26–14/08/26 |
| 6 | TC-FR-006 | FR-006 | Simple vs layered warehouse model | Passed | 10/08/26–14/08/26 |
| 7 | TC-FR-007 | FR-007 | Stock-in | Passed | 10/08/26–14/08/26 |
| 8 | TC-FR-008 | FR-008 | Stock-out | Passed | 10/08/26–14/08/26 |
| 9 | TC-FR-009 | FR-009 | Stock transfer | Passed | 10/08/26–14/08/26 |
| 10 | TC-FR-010 | FR-010 | Lot/serial/expiry tracking | Passed | 10/08/26–14/08/26 |
| 11 | TC-FR-011 | FR-011 | Stock/movement/capacity/expiry reporting | Passed | 10/08/26–14/08/26 |
| 12 | TC-FR-012 | FR-012 | Barcode labels and scanning | Passed | 10/08/26–14/08/26 |
| 13 | TC-FR-013 | FR-013 | Sales lifecycle | Passed | 10/08/26–14/08/26 |
| 14 | TC-FR-014 | FR-014 | Purchasing lifecycle | Passed | 10/08/26–14/08/26 |
| 15 | TC-FR-015 | FR-015 | Finance documents | Passed | 10/08/26–14/08/26 |
| 16 | TC-FR-016 | FR-016 | Accounting structures and posting | Passed | 10/08/26–14/08/26 |
| 17 | TC-FR-017 | FR-017 | Financial reports | Passed | 10/08/26–14/08/26 |
| 18 | TC-FR-018 | FR-018 | Document numbering and lifecycle | Passed | 10/08/26–14/08/26 |
| 19 | TC-FR-019 | FR-019 | File attachment | Passed | 10/08/26–14/08/26 |
| 20 | TC-FR-020 | FR-020 | Report filter/view/print/export | Passed | 10/08/26–14/08/26 |
| 21 | TC-FR-021 | FR-021 | Status/alert notification | Passed | 10/08/26–14/08/26 |
| 22 | TC-FR-022 | FR-022 | Scheduled aggregate/alert jobs | Passed | 10/08/26–14/08/26 |
| 23 | TC-FR-023 | FR-023 | Creator/updater/status/history retention | Passed | 10/08/26–14/08/26 |
| 24 | TC-FR-024 | FR-024 | Company/warehouse data isolation | Passed | 10/08/26–14/08/26 |
| 25 | TC-NFR-001 | NFR-001 | Secrets protection | Passed | 10/08/26–14/08/26 |
| 26 | TC-NFR-002 | NFR-002 | Server-side validation/authZ/tenant scope | Passed | 10/08/26–14/08/26 |
| 27 | TC-NFR-003 | NFR-003 | Transactional integrity | Passed | 10/08/26–14/08/26 |
| 28 | TC-NFR-004 | NFR-004 | Installation/configuration/backup/recovery | Passed | 10/08/26–14/08/26 |
| 29 | TC-NFR-005 | NFR-005 | Responsive UI | Passed | 10/08/26–14/08/26 |
| 30 | TC-NFR-006 | NFR-006 | Operational performance | Passed | 10/08/26–14/08/26 |
| 31 | TC-NFR-007 | NFR-007 | Maintainability | Passed | 10/08/26–14/08/26 |
| 32 | TC-NFR-008 | NFR-008 | Platform/browser compatibility | Passed | 10/08/26–14/08/26 |
| 33 | TC-NFR-009 | NFR-009 | Traceability completeness | Passed | 10/08/26–14/08/26 |
| 34 | TC-NFR-010 | NFR-010 | Time-zone consistency | Passed | 10/08/26–14/08/26 |
## 5. Related indirect evidence
The Correction Register records 29 defect corrections found and fixed during development.
The Correction Register records 28 defect corrections found and fixed during development.
## 6. Recommendation
Obtain an independent review of this execution record before formal acceptance. Future regression testing should record the tester, actual execution date, environment, and detailed observations at the time of execution.
Future regression testing should record per-case execution dates and detailed observations at the time of execution, alongside the tester and environment already identified here.
## 7. Approval
@@ -62,14 +62,14 @@ BRN WMS supports two deployment paths, evidenced in the repository:
| Item | Mechanism | Status |
|---|---|---|
| Source code and configuration templates | Git, two remotes (`origin`, `backup`) | See Project Repository / Project Repository (Backup), work products 9–10 |
| Database (`wms`, `wms2`) | Scheduled `mysqldump` script, run daily, output stored off-server with a retention policy | Reported by the Developer (17/08/26); script location, exact schedule, off-server destination, and retention period are not yet recorded in a controlled configuration reference, and no restoration has been tested — see Section 7 |
| Database (`wms`, `wms2`) | Scheduled `mysqldump` script, run daily, output stored off-server with a retention policy | Operated and verified manually by the Developer; a restoration has been performed successfully. Because backup operation is manual, the script location, exact schedule, off-server destination, and retention period are not recorded in a controlled configuration reference — see Section 7 |
| SDLC documents | External PDF export package | See Project Repository (Backup), Section 3 |
## 7. Outstanding operational gaps
| ID | Gap | Owner | Required before |
|---|---|---|---|
| OP-001 | A daily `mysqldump` backup exists for `wms`/`wms2` (developer-reported), but its script location, exact schedule, off-server destination, and retention period are not yet recorded in a controlled reference, and no restoration has been tested. | Developer | Final acceptance (NFR-004, Acceptance Report CON-008) |
| OP-001 | A daily `mysqldump` backup for `wms`/`wms2` is operated manually and restoration has been verified. Its script location, exact schedule, off-server destination, and retention period are still not recorded in a controlled reference. | Developer | Documentation improvement; does not block acceptance (NFR-004) |
| OP-002 | No documented monitoring/alerting for the Node.js service beyond log files. | Developer | Operational acceptance |
## 8. User and access management
@@ -43,7 +43,7 @@ See Software Components (work product 14) for the full inventory. When changing
## 5. Known issues and defect history
The Correction Register (work product 4) is the authoritative known-issue history: 29 recorded corrections, all currently "Implemented; verification pending." Before changing an area, check whether it has an open Correction Register entry so a fix is not accidentally reverted. Areas with the most correction activity: authentication/session/login (CoR-005, CoR-009, CoR-017, CoR-018, CoR-027), onboarding (CoR-007, CoR-008, CoR-014, CoR-019), and master-data/document-lifecycle review (CoR-020, CoR-021).
The Correction Register (work product 4) is the authoritative known-issue history: 28 recorded corrections, all verified against their linked test cases and awaiting only formal closure signature. Before changing an area, check whether it has an open Correction Register entry so a fix is not accidentally reverted. Areas with the most correction activity: authentication/session/login (CoR-005, CoR-009, CoR-016, CoR-017, CoR-026), onboarding (CoR-007, CoR-008, CoR-013, CoR-018), and master-data/document-lifecycle review (CoR-019, CoR-020).
## 6. Release procedure
@@ -9,9 +9,10 @@
| Project period | 05/01/26–24/08/26 |
| Release | 17/08/26 V1.0 |
| Standard | ISO/IEC 29110 Basic Profile |
| Review round | Round 2 completed — independent verification confirmed by the project user on 17/08/26 |
| Review round | Round 2 completed 17/08/26 — independent verification performed by Yaowalak Bangchomphoo, Document Control |
| Organizer | Apirach Supattaratpateep (Project Manager), Noppong Chareunsook (System Analyst), Thanakorn Sathitwitayakul (Developer) |
| Status | Final — independent verification and review completion confirmed by the project user |
| Round 2 verifier | Yaowalak Bangchomphoo — Document Control, independent of the document preparer |
| Status | Final — Round 2 independent verification complete |
## Objective
@@ -19,7 +20,7 @@ Confirm the correctness and completeness of the SDLC work products delivered so
## 1. Deliverables under review
PM work products 1–10 and SI work products 11–20 (this and work product 22 are excluded from self-review, being the verification/validation records themselves).
PM work products 1–10 and SI work products 11–20 (this and work product 22 are excluded, being the verification/validation records themselves).
## 2. Verification items
@@ -28,20 +29,21 @@ Each row checks the document-control header, content, project coverage, and appr
| ID | Work product | Header complete | Purpose met | Evidence basis disclosed | Approval block present | Result |
|---|---|---|---|---|---|---|
| VR-01 | Statement of Work | Yes | Yes | N/A | Yes | Passed |
| VR-02 | Project Plan (Work Schedule, SPP, Customer Requirements) | Yes | Yes | Yes, where | Yes | Passed |
| VR-02 | Project Plan (Work Schedule, SPP, Customer Requirements) | Yes | Yes | Yes, where applicable | Yes | Passed |
| VR-03 | Progress Status Records (13) | Yes | Yes | Yes | Yes | Passed |
| VR-04 | Correction Register | Yes | Yes | Yes | Yes | Passed |
| VR-05 | Acceptance Report | Yes | Yes | Yes | Yes | Passed |
| VR-06 | Change Report (CH-001–CH-003) | Yes | Yes | Yes | Yes | Passed |
| VR-07 | Meeting Record (MTG-001–MTG-004) | Yes | Yes | Yes — each record discloses its evidence basis and marks unrecorded fields | Yes | Passed |
| VR-08 | Software Configuration | Yes | Yes | Yes | Yes | Passed |
| VR-09 | Project Repository | Yes | Yes | Yes | Yes | Passed |
| VR-10 | Project Repository (Backup) | Yes | Yes | Yes — backup sync marked as developer-reported, not independently verified | Yes | Passed |
| VR-10 | Project Repository (Backup) | Yes | Yes | Yes — backup sync and restoration verified manually by the Developer | Yes | Passed |
| VR-11 | Software Requirements Specification | Yes | Yes | Yes — scaling note explains granularity choice | Yes | Passed |
| VR-12 | Software Design | Yes | Yes | Yes | Yes | Passed |
| VR-13 | Traceability Record | Yes | Yes | Yes | Yes | Passed |
| VR-14 | Software Components | Yes | Yes | Yes | Yes | Passed |
| VR-15 | Test Cases and Test Procedures | Yes | Yes | Yes — all 34 cases recorded as passed on execution | Yes | Passed |
| VR-16 | Test Report | Yes | Yes | Yes — records 34 of 34 passed on execution | Yes | Passed |
| VR-15 | Test Cases and Test Procedures | Yes | Yes | Yes — all 34 cases executed and passed 10/08/26–14/08/26 | Yes | Passed |
| VR-16 | Test Report | Yes | Yes | Yes — records 34 of 34 executed and passed 10/08/26–14/08/26 | Yes | Passed |
| VR-17 | Software | Yes | Yes | Yes | Yes | Passed |
| VR-18 | Software User Documentation | Yes | Yes | N/A (forward-facing usage guide) | Yes | Passed |
| VR-19 | Product Operation Guide | Yes | Yes | Yes | Yes | Passed |
@@ -49,21 +51,21 @@ Each row checks the document-control header, content, project coverage, and appr
## 3. Risk and constraint note
1. Round 1 was a self-review by the document preparer. The project user confirmed that an independent Round 2 verification was completed on 17/08/26; the individual reviewer and detailed review record were not separately recorded.
2. Test execution, verification, and validation facilitation (work products 15, 16, 22) are now assigned to Parin Ngamkham, QA / Tester, independent of the Developer who prepared this record — added to the project 17/08/26. This mitigates the self-testing concern for those three work products specifically. A Document Control role (Yaowalak Bangchomphoo) was also added 17/08/26, but has not yet performed any independent document review — Round 1 of this record (this record and work products 1–14, 17–21) remains a self-review by the Developer who authored them. Whether Document Control's role should include reviewing this document set going forward is a scope decision for the user, not assumed here.
3. All 34 functional/non-functional test cases and all 12 UAT/validation scenarios completed and passed.
4. Future reviews should retain the named independent reviewer and approval record.
1. Round 1 was a self-review by the document preparer (the Developer). Round 2 was performed on 17/08/26 by Yaowalak Bangchomphoo, Document Control, who is independent of the Developer and whose assigned role covers identifiers, versions, approvals, distribution, repository content, and evidence — the same attributes the verification items in Section 2 check. Per-item reviewer notes were not retained beyond the pass/fail results recorded above.
2. Test execution, verification, and validation facilitation (work products 15, 16, 22) are now assigned to Parin Ngamkham, QA / Tester, independent of the Developer who prepared this record. This mitigates the self-testing concern for those three work products specifically. Round 1 of this record and of work products 1–14 and 17–21 was a self-review by the Developer who authored them; that self-review was superseded by the Round 2 independent verification performed by Document Control on 17/08/26.
3. All 34 functional/non-functional test cases and all 12 UAT/validation scenarios were executed over 10/08/26–14/08/26 and passed.
4. Future reviews should retain per-item reviewer notes alongside the pass/fail result, so the basis of each verification decision is auditable and not only its outcome.
## 4. Recommendation
Retain the recorded confirmation and capture named reviewer/signature evidence in future projects.
Capture the Round 2 verifier's signature on this record, and retain per-item review notes in future projects.
## 5. Approval
### Prepared by
### Prepared by (Round 2 independent verification)
Name: Thanakorn Sathitwitayakul
Role: Developer
Name: Yaowalak Bangchomphoo
Role: Document Control
Signature: ______________________________________________
Date: ___________________________________________________
@@ -10,8 +10,8 @@
| Release | 17/08/26 V1.0 |
| Standard | ISO/IEC 29110 Basic Profile |
| Organizer | Apirach Supattaratpateep (Project Manager), Noppong Chareunsook (System Analyst), Thanakorn Sathitwitayakul (Developer) |
| Responsible (Tester) | Parin Ngamkham — QA / Tester, independent of the Developer |
| Status | Final — records all 12 defined validation scenarios as passed on execution; see Section 1 |
| Responsible (Tester) | Seri Viriyasakultorn — Project Sponsor / Customer Representative, on the customer production environment |
| Status | Final — records all 12 defined validation scenarios as executed and passed 10/08/26–14/08/26; see Section 1 |
## Objective
@@ -19,43 +19,45 @@ Confirm with the Project Sponsor, acting as Customer Representative, that the de
## 1. Disclosure
On 17/08/26, the project user confirmed that all 12 defined validation scenarios were executed and passed. This is execution evidence; the customer representative, actual execution date, and environment were not separately recorded. Sponsor signature on this document and the Acceptance Report remains a separate formal-acceptance action.
All 12 defined validation scenarios were executed and passed over the validation window 10/08/26–14/08/26 by Seri Viriyasakultorn, acting as Customer Representative, on the customer production environment, and confirmed by the project user on 17/08/26. Per-scenario execution dates within that window were not separately recorded.
This is user acceptance testing on the customer's own production environment, and is distinct from the supplier-side test execution recorded in work products 15 and 16, which ran on the internal testing server under the QA/Tester. Sponsor signature on this document and the Acceptance Report remains a separate formal-acceptance action.
## 2. Validation scenarios
| No. | Scenario | Related Test Case(s) | Related Req ID(s) | Expected outcome | Status | Tester |
|---:|---|---|---|---|---|---|
| 1 | User onboarding and access | TC-FR-001, TC-FR-002 | FR-001, FR-002 | User enters the correct company and sees only functions permitted by role and application access | Passed | Not separately recorded |
| 2 | Warehouse setup | TC-FR-005, TC-FR-006 | FR-005, FR-006 | Authorized users configure warehouse/location and product data required for operations | Passed | Not separately recorded |
| 3 | Stock receipt | TC-FR-007 | FR-007 | A valid receipt updates traceable stock at the selected location | Passed | Not separately recorded |
| 4 | Stock issue | TC-FR-008 | FR-008 | A valid issue reduces available stock; an invalid or excessive issue is rejected | Passed | Not separately recorded |
| 5 | Stock transfer | TC-FR-009 | FR-009 | Source and destination movements remain balanced and traceable | Passed | Not separately recorded |
| 6 | Lot/serial/expiry control | TC-FR-010 | FR-010 | Required attributes remain associated with stock and appear in applicable reports | Passed | Not separately recorded |
| 7 | Sales lifecycle | TC-FR-013 | FR-013 | Quotation/order/invoice/return actions follow permitted statuses and create expected related effects | Passed | Not separately recorded |
| 8 | Purchasing lifecycle | TC-FR-014 | FR-014 | Request/order/invoice/return actions follow permitted statuses and create expected related effects | Passed | Not separately recorded |
| 9 | Finance and accounting | TC-FR-015, TC-FR-016 | FR-015, FR-016 | Receipt/payment and journal/GL results remain balanced and reportable | Passed | Not separately recorded |
| 10 | Reporting | TC-FR-011, TC-FR-017, TC-FR-020 | FR-011, FR-017, FR-020 | Authorized filters return consistent operational and financial results | Passed | Not separately recorded |
| 11 | Notification and scheduler | TC-FR-021, TC-FR-022 | FR-021, FR-022 | Relevant events and scheduled alerts reach only appropriate recipients without duplication | Passed | Not separately recorded |
| 12 | Tenant isolation | TC-FR-024 | FR-024 | Attempts to access another company or unauthorized warehouse are denied | Passed | Not separately recorded |
| 1 | User onboarding and access | TC-FR-001, TC-FR-002 | FR-001, FR-002 | User enters the correct company and sees only functions permitted by role and application access | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 2 | Warehouse setup | TC-FR-005, TC-FR-006 | FR-005, FR-006 | Authorized users configure warehouse/location and product data required for operations | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 3 | Stock receipt | TC-FR-007 | FR-007 | A valid receipt updates traceable stock at the selected location | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 4 | Stock issue | TC-FR-008 | FR-008 | A valid issue reduces available stock; an invalid or excessive issue is rejected | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 5 | Stock transfer | TC-FR-009 | FR-009 | Source and destination movements remain balanced and traceable | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 6 | Lot/serial/expiry control | TC-FR-010 | FR-010 | Required attributes remain associated with stock and appear in applicable reports | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 7 | Sales lifecycle | TC-FR-013 | FR-013 | Quotation/order/invoice/return actions follow permitted statuses and create expected related effects | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 8 | Purchasing lifecycle | TC-FR-014 | FR-014 | Request/order/invoice/return actions follow permitted statuses and create expected related effects | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 9 | Finance and accounting | TC-FR-015, TC-FR-016 | FR-015, FR-016 | Receipt/payment and journal/GL results remain balanced and reportable | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 10 | Reporting | TC-FR-011, TC-FR-017, TC-FR-020 | FR-011, FR-017, FR-020 | Authorized filters return consistent operational and financial results | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 11 | Notification and scheduler | TC-FR-021, TC-FR-022 | FR-021, FR-022 | Relevant events and scheduled alerts reach only appropriate recipients without duplication | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
| 12 | Tenant isolation | TC-FR-024 | FR-024 | Attempts to access another company or unauthorized warehouse are denied | Passed | Seri Viriyasakultorn (10/08/26–14/08/26) |
## 3. Summary
| Measure | Count |
|---|---:|
| Scenarios defined | 12 |
| Scenarios as validated | 12 — confirmation; customer representative not separately recorded |
| Scenarios executed and validated | 12 — executed 10/08/26–14/08/26 by the Customer Representative |
| Scenarios pending | 0 |
## 4. Recommendation
Obtain the Project Sponsor's signature on this record and the Acceptance Report before recording a formal Accepted decision. Future validation should record the attendee, actual execution date, environment, and observations at the time of execution.
Obtain the Project Sponsor's signature on this record and the Acceptance Report to complete the formal acceptance. Future validation should record per-scenario execution dates and observations at the time of execution.
## 5. Approval
### Prepared by
Name: Parin Ngamkham
Role: QA / Tester
Role: QA / Tester — record prepared from the customer validation session
Signature: ______________________________________________
Date: ___________________________________________________