I have no experience with these as well but I have made a jtag in the past for routers and xbox.
I only twisted 30awg wire to the radio shield above cpu and touched a bunch of stuff nearby. No dice. At first I used the battery ground pin. I think I found some emmc pins. I read you may end up with brom if its clk is grounded but it just delayed the preloader device from showing up.
I am tempted to buy another and remove the eMMC and CPU to find jtag/debug pins. At the very least I should end up with a full rom dump.
But next step I am trying to see if the USB port also works as TTL serial. I tried to tie to a raspberry pi clone board I had handy but I had wrong OS and the serial port was not available. I have old Nokia cables somewhere in the attic I will dig out next.