# Post-install checklist

Tick each line in order. Anything that fails: see `TROUBLESHOOTING.md`.

## Platform
- [ ] `php scripts/check-requirements.php` shows no FAIL
- [ ] `https://admin.<your-domain>/login` opens with a padlock (HTTPS)
- [ ] Super Admin sign-in works, and two-factor setup was completed
- [ ] `php artisan schedule:list` lists the Kaabe jobs; cPanel → Cron Jobs shows the two lines
- [ ] Dashboard → *System alerts* shows no errors after 15 minutes
- [ ] `platform/storage/logs/laravel-<date>.log` has no errors
- [ ] `APP_DEBUG=false` (a wrong URL shows a plain 404 page, not a stack trace)

## First business
- [ ] *New business (automatic)* reaches **Ready → Active**; the provisioning log shows every step
- [ ] `https://<business>.<your-domain>` opens the POS sign-in with a padlock
- [ ] Owner temporary password works; the owner must choose a new password at first sign-in
- [ ] Owner lands on the **Business dashboard**
- [ ] Create a product with stock → make a sale → stock goes down → the sale appears in Reports → Sales summary
- [ ] Add a second branch in the Super Admin (Professional allows 3). On Basic the second branch is refused.
- [ ] Add a Cashier user; the cashier sees only Sales and Customers

## Subscriptions and plans
- [ ] Business → Subscription: *Record payment* (amount, date, reference, notes) appears in History and Payments
- [ ] *Extend* moves the end date; *Change plan* Professional → Basic removes Appointments, Work Orders, Deliveries, Messages and Price Rules from the POS menu, and typing their address shows *No access*
- [ ] *Suspend* → the POS shows the "account suspended" page; *Resume* → the POS works again
- [ ] A subscription ending within 7 days shows the *subscription.expiring* alert

## Monitoring and sync
- [ ] Within 5 minutes of a sale, **Sales & monitoring** shows it (today's total and transactions)
- [ ] Sync health shows **Sync OK**; a business with no sales shows *No recent activity* (not *failed*)
- [ ] *Sync now* repeated twice does not change the totals
- [ ] Branch drill-down → *Transactions* lists that day's sales, and matches the central total

## Security
- [ ] `https://<business>.<your-domain>/kaabe/.env` → 403 or 404, never the file
- [ ] `https://<business>.<your-domain>/database/database.sql` → 403
- [ ] `https://unknown-name.<your-domain>` → "Business not found" (if you use the wildcard)
- [ ] A POS form submitted without the page's token is refused (CSRF): open the POS, wait for the session to expire, submit → refused
- [ ] Staff roles: sign in as an Auditor → changes are refused (403)

## Backups
- [ ] After the first night, `~/kaabe-backups/<date>/` contains the central and every business `.sql.gz`, plus `SHA256SUMS`
- [ ] One backup downloaded off the server
- [ ] Restore test on a scratch database done once (`BACKUP-RESTORE.md` §3)

## InMotion-only checks (could not be executed in the test environment)
- [ ] `php -v` (web and CLI) shows 8.3; required extensions enabled; `proc_open` allowed.
- [ ] `mysql --version` ≥ MariaDB 10.6; database quota allows 1 + number of businesses.
- [ ] Every-minute cron accepted; `~/kaabe/platform/storage/logs` shows the scheduler running.
- [ ] cPanel API token: provision one test business; database, user and (if enabled) sub-domain appear in cPanel.
- [ ] AutoSSL certificate for `admin.<domain>` and business sub-domains (or wildcard).
- [ ] Force HTTPS Redirect on; `http://admin.<domain>` → 301 to https.
- [ ] Upload limits: import a CSV of a few hundred products; upload a product image.
- [ ] Nightly backup folder created; download one backup off the server; JetBackup includes all `<prefix>_*` databases.

