# Revision 2 website screenshot comparison Reviewer: fresh gpt-6-luna high, `/root/rev2_blind_web`, report `rev2-blind-web.md`. Root read the finished report once and compared it with the contract and receiving records. | Scope | Literal observation | Root comparison | |---|---|---| | D4 amount and nights | Summary shows 1 000 000 Ft including international flights, 7 Bali nights. | Matches D4.1 and D4.2. Exact receiving descriptions and night custom field are checked separately. | | Five quote mappings, first/repeat | All end on the visible thank-you page. Distinct form fields and checked existing consent are visible where supplied by that form. | Matches visible submission result. This is combined with exact request/partner IDs, not treated as backend proof alone. | | Main repeat validation | Empty required fields produced visible errors before correction. A corrected submission then reached the thank-you page. | Validation failure is retained as a genuine intermediate failure. Only corrected request1779 counts as accepted. | | Newsletter first/repeat | Populated form, checked consent and thank-you state. | Website delivery happened under the authorized temporary CAPTCHA exception. Source metadata defects found in receiving readback were corrected separately before final acceptance. | | Clipped long field values | Long names/emails are horizontally clipped within their inputs. | No data loss inferred. Full values are preserved in payload/CRM evidence. | | Floating call/chat controls | Some scroll positions overlap the right side of mobile controls. | Final reachable-control evidence and actual click/submission are required, not inferred from these positions. | ## Evidence classification corrections The names `d4-mobile-*` are inaccurate: their images are desktop width1270/1280, so root uses them as desktop form evidence. The reviewer’s mobile label is not accepted as a measured viewport statement. The initial protected thank-you image is746×969. A tab-scoped CDP experiment measured390×844 in DOM but the browser screenshot surface generated tiny390×219 captures; those `measured-390-*` images are retained as diagnostic artifacts, not legible mobile acceptance proof. Final mobile evidence is captured from the correctly selected in-app browser at390×844 under `mobile-verified-*`, with actual screenshot dimensions checked. The newsletter reviewer inferred first/last names from position. Payload and CRM fields are authoritative: lastnameCodex, firstnameHirlevel926. This is not a backend name reversal. ## Protection boundary Initial protected request1768 used the CAPTCHA Matt completed. Other named test submissions were made with a narrow, exact synthetic-address exception. Both completed exception windows restored the exact original CAPTCHA bytes. Negative CF7 missing/invalid-token tests returned spam and no CRM contact. Newsletter negative requests were rejected upstream with406, and the ordinary UI without a completed challenge showed failure and created no contact. These checks do not assert a successful restored protected newsletter submission.