Validation performed for this secure-login package:
- Node --check passed for public_html/app.js and public_html/backup.js.
- JavaScript no longer sends or trusts the former x-demo-role header.
- PHP request paths were reviewed for session authentication, role authorization, CSRF checks, and parameterized SQL.
- New-install schema and existing-database migration both include app_users, session_version, and auth_attempts.
- Backup download validation accepts both the existing schema_version 1 backup and new schema_version 2 backups.
- Setup is HTTPS-only, gated by a private setup_key, serialized with a database advisory lock, and disabled after the first account exists.
- Existing customer/activity ownership columns are widened without dropping existing records.
Not performed:
- PHP syntax lint or PHP/MySQL runtime tests: a PHP interpreter and MySQL/MariaDB server are not available in this environment.
- Live cPanel deployment or browser end-to-end testing.
Before real use, install on the host, test administrator and visitor access, test disabled accounts and password reset, confirm visitors cannot call manager APIs, and verify backup download.
