Church Cashbook Maintenance Manual
Gates to clear before the first live deployment and before each subsequent release to production.
⚠ Complete this checklist before going live
This checklist must be completed in full before any deployment to the Rochen production server. Each item should be signed off by the person responsible and retained as a governance record.
1. Test suite
- ☐ All run.php functional tests passing (447 assertions, 0 failures, 0 errors)
- ☐ All stress.php tests passing (65 assertions)
- ☐ All pentest.php security tests passing (93 assertions)
- ☐ All PHPUnit unit tests passing (162 tests, 0 failures)
- ☐ Tests run against PHP 8.4 — confirm
php --versionmatches the production PHP version
2. Dev-only files removed
The following must be absent from the production server. Verify via cPanel file manager or SFTP after deployment:
- ☐
tests/directory is not present - ☐
vendor/directory is not present - ☐
composer.jsonis not present - ☐
composer.lockis not present - ☐
phpunit.xmlis not present - ☐
.phpunit.result.cacheis not present - ☐ Any
.DS_Store,*.swp, or other editor/OS artefacts are not present
3. Configuration
- ☐
config.phpis in place outside the web root (church_records/config/config.php) - ☐
cookie_secure = truein productionconfig.php - ☐
APP_ENVis not set totestordev - ☐ Database credentials in
config.phppoint to the production MariaDB instance - ☐ Gift Aid encryption key is set, is 64 hex characters, and has been backed up securely offline
- ☐ Error alert email address is set to the correct operations inbox
4. Server and hosting
- ☐ HTTPS is active and the SSL certificate is valid
- ☐ HTTP requests redirect to HTTPS
- ☐ PHP version confirmed as 8.4.x in cPanel
- ☐ MariaDB version confirmed as 11.4.x in phpMyAdmin
- ☐
.htaccessis in place at the web root — confirmed via System Info page - ☐
display_errorsisOffin the live PHP configuration — confirmed via System Info → PHP information - ☐ Storage directory (
church_records/) is outside the web root and not web-accessible - ☐ Storage directory is writable — confirmed via System Info → Filesystem health
5. Database
- ☐ Schema has been imported from
church_accounts.sql(usingutf8mb4_unicode_cicollation throughout) - ☐ Database created with character set
utf8mb4and collationutf8mb4_unicode_ci - ☐ All pending schema migration scripts have been run and verified
- ☐ A post-import backup has been taken
6. Application smoke test
After deployment, perform a brief manual smoke test before notifying any users:
- ☐ Login page loads correctly over HTTPS
- ☐ Superadmin login succeeds
- ☐ System Info page loads and shows all green indicators
- ☐ A test parish is visible and transactions page loads
- ☐ Password reset email is sent and received (trigger a reset for the admin account)
- ☐ A test transaction can be entered and voided
- ☐ An export CSV can be downloaded
7. Backup
- ☐ Akeeba Backup is configured and a first manual backup has been taken and verified
- ☐ Off-server backup destination is configured and the first backup has transferred successfully
Sign-off
Completed by: ____________________________
Date: ____________________________
Notes: ____________________________________________________________________
____________________________________________________________________