# Final Release Validation — TELSPAY Education v2026.9.5.1

Build date: 2026-09-08
Upgrade basis: validated TELSPAY Education v2026.9.5 plus Student Login Access v2026.9.5.1.

This document is finalized from the automated release gate immediately before ZIP packaging. Live MariaDB/provider/SMTP/cPanel behavior remains an environment-stage validation and is not represented as an offline guarantee.


## v2026.9.5.1 Student Login Access validation

The Student Login Access module adds no direct password-retrieval capability. Existing password hashes remain one-way and the Student Wallet transaction PIN remains independent.

Static validation checks include:

- Admin permission gate: `education.student_wallet.credentials`.
- CSRF validation on SACCO Admin resend actions.
- Student Wallet must be ACTIVE or LOCKED and the linked student/school must remain operational.
- Email/SMS route validation before token issuance.
- Cryptographically random single-use token; only a keyed HMAC hash is stored in the token registry.
- Previous ACTIVE links for the same wallet are revoked when a replacement is issued.
- Default token expiry: 30 minutes; default resend cooldown: 300 seconds.
- Public reset page uses a local POST + CSRF flow and does not display the existing password.
- Replacement password requires 10–200 characters with at least one letter and one number.
- Consumed tokens become USED atomically with the password update.
- Student Login notification bodies are redacted after successful send.
- Expired/revoked Student Login notification retries are cancelled and scrubbed.
- New migration is additive and does not alter balances, loan amounts, existing passwords or transaction PIN hashes.
