VALIDATION
Tested locally with PHP 8.3 and MariaDB 10.11.
PHP syntax validation passed for all PHP source files.
End-to-end HTTP and database tests passed for:
- Installer and chosen admin credentials; provider login; owner registration.
- Pet creation and ownership checks.
- Per-adoption WhatsApp number formatting and link update after editing.
- Adoption applications and approval status.
- Appointment creation, duplicate-slot rejection and availability endpoint.
- COD checkout, stock deduction, full rollback of an invalid cart, and
  idempotent stock restoration when cancelling an order.
- Community questions and replies.
- Passport redemption with a signed-in provider; owner isolation.
- CSRF rejection and denial of owner-to-admin actions.
- Pledge recording, receipt confirmation accounting and volunteer persistence.
- Site contact settings; rendering of all role pages; logout.
- Actual adoption image upload and HTTP image delivery.
- Completed-appointment review persistence and duplicate-review rejection.
- Account profile updates and backend rejection of expired passport codes.
Test users and test records are NOT included in the SQL or packaged content.
Desktop/mobile browser checks passed: adoption WhatsApp button visibility,
photo rendering, no horizontal overflow at 390 px, admin form submission,
community reply interface and no JavaScript page errors.

PROVIDER SELF-REGISTRATION UPDATE
- All four provider types persist their profession-specific details.
- Pending/rejected accounts cannot access provider tools, publish a public
  profile, enable availability or receive bookings through forged requests.
- Admin approval, rejection reasons, and immediate enforcement for existing
  sessions passed; owner accounts remain immediately usable.
- Missing profession details and attempted admin-role registration rejected.
- Pending detail edits cannot bypass approval.
- Registration role cards and public/admin layouts checked at desktop,
  tablet and phone widths, with no horizontal page overflow or JS errors.
- Mobile native form submission and tablet admin approval controls passed;
  the approved applicant reached their provider dashboard without signing
  out. Provider profile/account layouts passed at 320, 390, 768 and 1024 px.

Organisation registration update validation:
- All PHP files pass PHP 8.3 syntax validation.
- MariaDB integration: self-registration, required group details, linked account,
  Pending publication/action restrictions, forged requests, admin edit protection,
  rejection reason, approval, public listing, pledges and existing-session revocation.
- Admin-created organisations publish directly as approved records.
- Existing four provider registration/approval and owner registration tests pass.
- Rendered form DOM: all six account roles switch correctly, unrelated fields are
  disabled, organisation fields required, website optional, admin review has CSRF.
- Browser visual preview could not run because this environment blocks Chrome's
  process socket. Responsive CSS uses 3 columns on desktop, 2 on mobile, and the
  existing responsive application/review layouts. No new visual screenshot check.
