Knowledgebase

Existing Applications: Everything That Matters, Briefly Print

  • phplaravel, migration, billing, php, backup, security, troubleshooting, redirects
  • 0

The summary.

WHEN INHERITING AN APPLICATION

Back up, change every credential you control, and put it under version control exactly as found.

You do not know who holds the existing credentials.

CHECK THREE THINGS IMMEDIATELY

Whether configuration files are publicly reachable, whether backups sit in the public directory, and whether debug output is visible.

All three are common and immediately exploitable.

FIX SECURITY FIRST, THEN THE PHP VERSION

Everything else can wait.

MIGRATE INCREMENTALLY, NEVER IN ONE STEP

Route specific paths to the new application and move areas across progressively.

Migrate something self-contained first and anything handling money last.

Establish what is genuinely still used — frequently substantial parts are not.

ALWAYS SET A TIMEOUT ON EXTERNAL CALLS

And put each service in its own class, so it can be substituted in tests.

VERIFY EVERY WEBHOOK SIGNATURE

Otherwise anyone can send a request claiming a payment succeeded. Respond quickly and process in a queue.

NEVER TRUST THE REDIRECT BACK FROM A PAYMENT GATEWAY

Verify with the gateway directly, and check amount, currency, reference, and that it has not already been processed.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot