=iTzAYDiN-BOT V6 BUILD AUDIT=
Release: 6.0.0-rebecca-3xui360
Date: 2026-08-16

Static validation
- PHP syntax: 217/217 PASS
- JavaScript syntax: 24/24 PASS
- JSON parse: 6/6 PASS
- install.sh bash syntax: PASS
- V6 feature assertions: 23/23 PASS
- stale 3x-ui 3.5.0 labels in non-vendor source: 0
- token/private-key secret-like matches in non-vendor source: 0

Rebecca coverage
- First-class panel type and connection test
- Personal API key (Bearer) + legacy JWT compatibility
- Service-driven user provisioning and sales lifecycle
- User lifecycle, usage, reset, revoke, next-plan, bulk actions
- Services, service users/actions, Nodes, node usage/settings, Hosts, Inbounds
- System and maintenance diagnostics
- Live OpenAPI discovery and guarded OpenAPI console for endpoints advertised by the connected Rebecca build
- Web + Telegram management entry points

3x-ui v3.6 coverage
- Modern token vs Legacy profile separation retained
- Telegram-ID lookup
- Custom monthly traffic-reset day
- Inbound sync/repair/auto selection with reset-policy snapshot
- Subscription live info, raw download, generic format probe and User-Agent auto-detection probe
- Authenticated OpenAPI tooling and dynamic API console
- No read-back dependency on node API tokens

Important
This audit is static/local validation. Live end-to-end calls against the user's own Rebecca and 3x-ui installations, credentials, database, Telegram bot and payment environment still need a staging test before production deployment.
