Source layout
| Path | Responsibility |
|---|---|
| index.php | Existing front controller, route handlers, permission gates and page rendering. |
| app/bootstrap.php | Configuration, autoloading, database/session setup, headers and URL helpers. |
| app/Core/ | Authentication, database access, security, uploads, mail, workflow and transfer services. |
| app/SubmissionWizard.php | Multi-step author submission workflow. |
| app/manuals.php | Allowlisted manual routes and files. |
| assets/ | Existing styles, scripts and local editor assets. |
| database/schema.sql | Fresh-install schema, not a live cleanup script. |
| storage/ | Private runtime files and uploads; preserve on upgrade. |
| docs/ | Offline role manuals and reference screenshots. |
| cron/reminders.php | Scheduled reminders and configured retention cleanup. |
Version 2.4 preserves the established code structure to reduce regression risk. New security and documentation code includes explanatory comments. This release does not perform a wholesale framework migration or split unrelated routes.
Backups and database housekeeping
The supplied package contains schema, not a populated production database. No table, user or manuscript deletion is required by 2.4. The scheduled task handles expired reset records, old sign-in attempts and configured draft retention. Review those policies before scheduling it.
Links
Use the documentation centre for every role guide. For publisher-managed external links, test the actual saved website, author guide, payment, support and legal URLs. They are database content and cannot be certified from this source package alone.
Troubleshooting
- Manual page not found: confirm
app/manuals.php, the named HTML file and Apache rewrites are uploaded. - Styles or images missing: verify document root, subdirectory setup, assets and branded-domain HTTPS.
- HTTP 500: note the incident reference and inspect the private server log. Do not enable public error output on a production site.
- Email not delivered: check journal/platform SMTP settings, sender DNS and mail logs.
- Failed authenticator codes: check device/server clocks and wait for the throttle interval if repeated attempts were made.