<?php

/**
 * Go-Live Security Checklist — KiyoHR
 */

return [
    'must_pass' => [
        ['item' => 'Zero open Critical findings', 'status' => 'pass'],
        ['item' => 'Zero open High findings', 'status' => 'pass'],
        ['item' => 'Security headers middleware enabled', 'status' => 'pass'],
        ['item' => 'Private storage for PII uploads', 'status' => 'pass'],
        ['item' => 'API permission fail-closed for named routes', 'status' => 'pass'],
        ['item' => 'Security feature tests green', 'status' => 'pass_static_suite'],
        ['item' => 'DB-backed security suite (group database)', 'status' => 'requires_mysql_cli'],
        ['item' => 'Score >= 80', 'status' => 'pass'],
    ],
    'notes' => [
        'SecurityStaticChecksTest: 5/5 passing (auth face gate, headers, CORS, mass-assignment, $hidden)',
        'ProductionSecurityHardeningTest: run with mysql client on PATH for schema dump',
    ],
    'production_env' => [
        'APP_DEBUG=false',
        'APP_ENV=production',
        'SESSION_SECURE_COOKIE=true',
        'SESSION_ENCRYPT=true',
        'CORS_ALLOWED_ORIGINS set to real origins',
        'RAZORPAY keys configured; webhook URL registered',
        'HTTPS terminated; force HTTPS at proxy',
    ],
    'ops' => [
        'Backups verified',
        'Log rotation configured',
        'Queue workers supervised',
        'Scheduler cron installed',
        'Firewall rules applied',
    ],
    'go_no_go' => 'GO (conditional on CI security tests + production env verification)',
];
