# Phase 10 — Security, Performance, Testing & Production Deployment

## Security hardening
- [x] Strict CSP retained and all inline JavaScript/event handlers removed
- [x] HSTS emitted only for verified HTTPS requests
- [x] Trusted proxy list required before honoring forwarded client/protocol headers
- [x] Dynamic responses default to `Cache-Control: no-store`
- [x] Request IDs generated/propagated and included in server error logs
- [x] JSON request-body size limit
- [x] Session idle timeout, absolute timeout and periodic ID regeneration
- [x] Secure/HttpOnly/SameSite session cookies
- [x] Strong upload directory execution restrictions
- [x] Dot/config file denial in public `.htaccess`
- [x] Production security audit command
- [x] Card PAN/CVV remains outside application storage

## Performance
- [x] PDO native prepared statements and DB connect timeout
- [x] Static asset expiry/compression rules for Apache/cPanel
- [x] Short local cache for public restaurant discovery
- [x] Idempotent database index optimizer using `INFORMATION_SCHEMA`
- [x] Existing pagination/range limits retained
- [x] Cron overlap prevented with MySQL advisory lock
- [x] Runtime job history/cleanup

## Operations
- [x] `/healthz` liveness endpoint
- [x] `/readyz` readiness endpoint with DB/key check and no secrets
- [x] `bin/security-audit.php`
- [x] `bin/optimize.php`
- [x] `bin/backup-db.php`
- [x] `bin/test.php`
- [x] Runtime job logging migration
- [x] Production runbook and cPanel upgrade sequence

## Automated verification
- [x] Full PHP lint
- [x] Phase 1–9 regression smoke tests
- [x] Phase 10 proxy/request-ID/cache/session-config smoke tests
- [x] Migration structure/FK sanity
- [x] Route duplicate detection
- [x] HTTP front-controller boot
- [x] Inline-script/handler scan
- [x] Secret/private-key scan
- [x] Release manifest and ZIP integrity

## Must still be verified on the target cPanel/MySQL 8 host
- [ ] Run all migrations against the real MySQL 8 instance
- [ ] Run `bin/optimize.php` and inspect EXPLAIN plans for local data volumes
- [ ] Confirm HTTPS redirect/HSTS behind the actual cPanel proxy topology
- [ ] Confirm cron path and advisory lock behavior
- [ ] Perform restore test from a real `mysqldump` backup
- [ ] Run two-device ordering/reservation/payment concurrency acceptance tests
- [ ] Install the genuine Crowne Plaza SVG logo
- [ ] Replace mock integrations with vendor adapters only after vendor UAT
