OpenWitness listing 52 - pre-registered expected verdict Fixture: https://ow52.nexomedico.med.br/door Declared request: GET /door Edge product: Cloudflare WAF custom ruleset, phase http_request_firewall_custom. Edge rule: host ow52.nexomedico.med.br AND path /door AND User-Agent contains curl/ OR Python-urllib/ OR node-fetch => block before Worker origin. Expected verdicts under Coppice readiness-l0 v0.1 / tester source 0.1.2, written without running the reference tester: L0-1: PASS - hostname resolves and Cloudflare serves a publicly trusted, hostname-valid TLS certificate. L0-2: FAIL - browser User-Agent receives origin 200 while selected standard non-browser profiles (curl and Python-urllib) are blocked at Cloudflare edge with 403. L0-3: FAIL - for Accept: application/json, the Cloudflare edge refusal is HTTP 403 with Content-Type text/html. L0-4: PASS - GET is declared; browser-profile POST receives 405 Method Not Allowed with Allow: GET, while an edge-blocked probe profile receives the same 403 it receives on declared GET. L0-5: PASS - /robots.txt is outside the WAF block rule, returns 200 to all profiles, and contains User-agent: * / Allow: /, so /door is allowed. Expected-verdict SHA-256: 30585df8b77f2644c3b7e188b3b91407bbff9c4eb21899484c14cd01e1d94e9a This is the expected verdict commitment. The Coppice reference tester has not been run before this text and hash were created.