Handles `GET /v1/control/verification-sessions/{session_id}/evidence`.
Errors
Returns 401 without a session, 403 for an API key or a role without
VERIFICATIONS_READ, 404 for a session this tenant does not have, and
503 when a store cannot be reached.
Authorizations
A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.
Path Parameters
The session id
Response
What was submitted and how it was read. No image bytes, no evidence identifiers.
One kind of evidence and how far it got, as a customer sees it.
Which check.
How far it got: PRESENT, PENDING, STALE, UNSUPPORTED or
UNAVAILABLE.
Whether this check may contribute to clearing the transaction.
Sent explicitly rather than left for the caller to derive from state.
A customer's integration that had to maintain its own list of which
states count would silently start treating a new state as passing.
Operator-facing detail, such as a correlation or an error.
RFC 3339 time it was gathered, when it was.

