docs: phase 0 environment assessment + test baseline
test(cors): add comprehensive PublicApiCors middleware tests
discovery: scan php-tenant and create improvement issues
Second Pass — 4 additional issues
A background deep scan found 4 more items not captured in the initial report:
roadmap: php-tenant production readiness
Update — additional issues found (second pass)
Four additional issues were identified during background analysis pass:
fix: validate invitation token format before database lookup in web routes
security: EntitlementService usage recording has race condition under concurrency
perf: add missing indexes to entitlement_webhook_deliveries table
fix: entitlement_features.parent_feature_id nullOnDelete orphans child features
discovery: scan php-tenant and create improvement issues
Discovery Scan Complete
Automated scan completed on 2026-02-20. Here is a summary of findings.
Already Resolved (Jan 2026)
All P1 security items and several P2 items were fixed in…
roadmap: php-tenant production readiness
feat: add workspace activity audit log
feat: add bulk workspace invitation support
feat: add workspace ownership transfer