# Exact URL storage reproduction, revision 4

Synthetic data only. Credentials and real contact details are omitted. No vendor message has been sent.

## Required behavior

An integration sends a normal source URL with two query parameters. The exact JSON string, after ordinary JSON parsing, must be stored in custom text field `forrasoldal-url-je-49`, returned by the same API readers and shown on the opened request.

```text
https://example.invalid/landing/?utm_source=qa&utm_campaign=raw-url
```

## Public v2 object writer

```http
PUT /api/v2/objects/{synthetic_object_id}
AuthToken: [existing tenant API key, omitted]
Content-Type: application/json
```

```json
{"name":"SYNTHETIC DIAGNOSTIC","category_id":0,"forrasoldal-url-je-49":"https://example.invalid/landing/?utm_source=qa&utm_campaign=raw-url"}
```

Observed: accepted write, followed by literal `&amp;` through both `GET objects/single/{id}` raw custom-field rows and `GET objects/customfields/{id}`. A standard JSON `\u0026` transport variant on the synthetic memo field also stored `&amp;`, with no unrelated change.

## Official CF7 module writer

The released vendor plugin maps flat metadata keys into JSON and uses AuthToken. Current `GET /api/v2/cf7/fields/module/1` exposes `m_name`, `m_description` and the source49 slug.

```http
POST /api/v2/cf7/send/module/1
AuthToken: [existing tenant API key, omitted]
Content-Type: application/json
```

```json
{"m_name":"SYNTHETIC DIAGNOSTIC","m_description":"Official writer test, not a website enquiry","forrasoldal-url-je-49":"https://example.invalid/landing/?utm_source=qa&utm_campaign=raw-url"}
```

Observed: HTTP 200/data ok and one exact-name request. Raw, formatted and native response plus the opened card contain `?utm_source=qa&amp;utm_campaign=raw-url`. This example substitutes example.invalid for the actual public test URL. Exact original bytes, hashes and values are retained in the linked receipts.

## Native control

A normal native edit gave source49 with `&` on the existing synthetic card 1914, and identical API readers subsequently returned it correctly. [Earlier native write/read receipt](crm-native-url-readback.json), [earlier public source49 controls](url-encoding-correction-v5.json). Normal existing native Bearer-session access is confirmed HTTP 200. The public AuthToken key was rejected as native Bearer credentials. The native client submits a numeric custom-field map in a whole-form save. No public repeatable service authentication lifecycle or documented narrow writer has been established.

## Official CF7 modulepartner variant

The supported `GET /api/v2/cf7/fields/modulepartner/1` exposes the same module source49 key plus partner lastname, firstname and email. A distinct one-attempt POST to `cf7/send/modulepartner/1` supplied those exposed flat keys with a fresh controlled synthetic QA address and the normal source URL. HTTP 200/data ok created one labelled request 1917 and one correctly linked QA partner 3705, newsletter false. Raw-detail and formatted responses again contain literal `&amp;`. The opened-card result is recorded separately.

These are observed API/read/card values. There was no direct CRM database inspection and no protected website submission. The example.invalid URL above is a sanitized substitution, not a claim that the exact supplied wire used that domain.

## Exact evidence

- [Unicode JSON wire and stored value](r4-json-hex-amp-probe.json)
- [Official CF7 writer, exact outbound and stored source](r4-cf7-writer-probe.json)
- [Native response and opened card](r4-native-route-readback.json)
- [Official partner variant](r4-cf7-modulepartner-probe.json)
- [Opened partner variant](r4-modulepartner-opened-card.json)
- [Null storage versus formatted default values](r4-native-storage-comparison.json)
- [Official source and endpoint investigation](vendor_raw_storage_recovery.md)

HTML entity decoding in a reader, `%26` query separators and manual per-request edits do not meet the required persisted-string behavior.
