TELSPAY MEMBER APP v2026.4.0

START HERE:
  deployment/BLANK_SCREEN_RECOVERY.txt
  deployment/telspay_secure.example.php.txt
  docs/SECURITY_OPERATIONAL_UPGRADE_2026_4_0.md

DATABASE:
  1. database/member_app_operational_security_upgrade_2026_4_0.sql
  2. database/member_app_operational_security_postcheck_2026_4_0.sql

SOURCE CHECK:
  tools/release_check_2026_4_0.sh

Do not deploy before rotating historical credentials, setting all private
environment keys, configuring private receipt/KYC storage, and completing the
non-production acceptance tests. The included source archive intentionally
excludes the previous embedded backup ZIP.

v2026.4.1 startup recovery: a missing private configuration or failed database
connection now produces a safe diagnostic page instead of a blank screen.

v2026.4.2 availability recovery: confirmed VPN/proxy/hosting networks remain
blocked, while an external IP-risk-provider outage is logged rather than
locking every legitimate registration, login and transaction out of the app.

v2026.4.3 login recovery: login messages now distinguish a deliberate
fail-closed provider policy from an unrelated critical device-risk block.

v2026.4.4 data-protection recovery: consent SQL preparation failures no longer
produce "bind_param() on bool" fatal errors. Deploy the updated
registration/services/RegistrationService.php, run the full v2026.4.0 database
migration, then run database/data_protection_consent_repair_2026_4_4.sql. Both
repair post-check queries must return PASS before registration is reopened.
