Church Cashbook Maintenance Manual
Quarterly RBAC and endpoint verification.
Quarterly security review
A brief security health check should be performed every quarter. This does not require specialist security knowledge — it is a structured review of access controls, configuration, and the security indicators already built into the system.
RBAC and user access review
- ☐ Review the list of SUPERADMIN users — confirm each is a known, active individual with a legitimate reason for that role
- ☐ Review TREASURER role assignments across all churches — confirm no unexpected assignments
- ☐ Identify any user accounts marked inactive that still have role assignments — remove the assignments
- ☐ Confirm that no test or temporary accounts created during setup remain active
System configuration checks
- ☐ Confirm
cookie_secure = truein the liveconfig.php - ☐ Confirm HTTPS is active and the certificate is valid (check expiry date — Rochen typically auto-renews, but verify)
- ☐ Confirm
display_errorsisOffin the live PHP configuration — visible via System Info → PHP information - ☐ Confirm the
.htaccessfile is present and intact — visible via System Info → Filesystem checks
Endpoint verification
- ☐ Confirm
/public/admin/returns 403 or redirects to login when accessed without a session - ☐ Confirm
/app/,/church_records/, and/vendor/are not web-accessible (should return 403 or 404) - ☐ Confirm the config file path is outside the web root — visible via System Info → Filesystem checks
Pentest suite
The automated pentest suite (tests/pentest.php) covers OWASP Top 10 attack scenarios. Run it against the production server (with appropriate authorisation) at least annually, and after any significant code deployment. All 93 assertions should pass.