Baseline Evidence¶
Date: 2026-08-10
/calendarpreviously rendered only Google/Microsoft connection cards.- The dashboard queried active patients separately and rendered hard-coded zeroes for appointments, documents and revenue.
/api/appointmentslacked the bounded, timezone-explicit, patient-display feed contract.- The isolated API had no dashboard summary route or auditable documents/revenue sources.
- CEP/CNPJ performed undeclared browser-side requests; CFP copy implied unavailable validation.
Functional baseline behavior was established from inspected source because local PostgreSQL credentials did not authenticate.