EDITORIALFLOW · VERSION 2.4 PRODUCTION

Security & Access

Security controls, operational responsibilities and review boundaries.

Application controls reviewed

Production configuration

Use HTTPS everywhere, keep debug false, enable two-factor authentication for administrators, and protect database, SMTP and cPanel credentials. Preserve the application encryption secret during upgrades; replacing it can make stored encrypted credentials unreadable. Restrict installer access before first setup and remove installation/migration entry points afterwards.

Uploads and retention

File type checks do not provide antivirus scanning. If required by institutional policy, add scanning at the hosting/service layer. Back up files and database together. Do not remove audit history, memberships, manuscripts or schema objects as routine cleanup.

Security review limits

This release includes a focused source review and targeted hardening, not an independent penetration test or a guarantee against every attack. Live hosting configuration, external integrations, delivery, data-dependent permissions and business workflows require staging verification. Read the bundled VALIDATION.md for checks actually performed and remaining limits.

Reference guidance