Skip to main content

Pre-Launch Checklist

Complete this checklist before opening the project to players. Mark an item only after a real test.

Domain and HTTPS​

  • the domain opens without certificate warnings;
  • HTTP redirects to HTTPS;
  • alternate hostnames redirect to one canonical domain;
  • /src/, /internal_data/, and hidden files are not public;
  • Cloudflare uses Full (strict), when enabled.

Production settings​

  • debug and development mode are disabled;
  • cookies use Secure, HttpOnly, and an appropriate SameSite mode;
  • the cookie domain matches the website;
  • local admin access is restricted to trusted addresses;
  • the database uses a dedicated account without global privileges;
  • secrets are absent from templates, JavaScript, and public directories.

Users​

Test in a private browser window:

  1. registration;
  2. email confirmation;
  3. sign-in and sign-out;
  4. password recovery;
  5. sign-in with 2FA when enabled;
  6. linking and removing a social profile;
  7. language and theme switching.

Game operations​

  • game account creation or linking;
  • character loading;
  • balance in the correct server scope;
  • test purchase and delivery;
  • compensation after a delivery failure;
  • mandatory PIN for protected operations;
  • errors do not expose internal paths or stack traces.

Payments​

  1. Enable the gateway sandbox or test mode.
  2. Create an order for the minimum test amount.
  3. Verify gateway redirect and return URL.
  4. Verify webhook/IPN processing and final order status.
  5. Confirm that a repeated webhook does not credit funds twice.
  6. Test cancelled and expired orders.

Do not enable real payments until the full test flow passes.

Email and support​

  • the test message is delivered and DKIM-signed;
  • SPF and DMARC pass;
  • From and Reply-To addresses are correct;
  • confirmation and recovery links use the production domain;
  • tickets and replies work, while attachments remain limited to ticket participants.

Background jobs and operations​

  • cron runs job.php regularly;
  • the queue has no permanently failing jobs;
  • logs rotate and contain no passwords, codes, or tokens;
  • database and file backups exist;
  • a restore test has passed;
  • free space covers at least two upgrades and one backup.

Browsers and performance​

  • desktop Chrome, Firefox, and Edge;
  • a 390px mobile viewport and a real device;
  • light and dark themes;
  • Russian and English locales;
  • no horizontal scrolling or overlapping controls;
  • the Lighthouse audit passes.

Result​

Record the launch date, client version, responsible person, and backup location. Continue with the initial settings upload or updates.