Six fixes from a codebase review:
- Consolidate the ad hoc install.php + migrate_v2..v6.php chain into one
canonical schema.sql (structure reference) plus a simplified install.php
that creates all tables and seeds site_settings, the superadmin account,
and the standard prayer library. The six migrate_v*.php scripts are
deleted — their cumulative effect is now fully captured in schema.sql.
- Delete the two root-level setup.php/novena_group.php files that existed
only to redirect to their admin/ equivalents of the same name; confirmed
unreferenced by any link or .htaccess rule.
- Decouple includes/build_slides.php from data/prayers.php's implicit
`global $opening, $mysteries, ...` contract. data/prayers.php now
explicitly returns its arrays; build_slides.php loads them through a
small memoized get_prayer_data() and destructures them by key.
- Add CSRF protection (includes/csrf.php: csrf_token/csrf_field/csrf_verify)
across every POST-handling endpoint — 10 form pages and 7 API endpoints —
plus token wiring in the JS/inline scripts that call the FormData- and
JSON-body API endpoints (builder.js, setup.js, and the inline scripts in
admin/audio.php, admin/novena_group.php, and index.php).
- Stop round-tripping the SMTP password in plaintext through the settings
form: the field now renders blank with a "currently set" hint, and a
blank submission leaves the stored password unchanged instead of
clearing it.
- Add login rate-limiting: users.failed_login_attempts / locked_until
columns, is_locked_out()/record_login_failure()/record_login_success()
helpers in includes/auth.php, and lockout handling in login.php (5
failed attempts locks the account for 15 minutes). README documents the
one manual ALTER TABLE needed to add these columns to an existing
production database.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Each prayer in the library has an optional default_bead_type (small/large/
crucifix). Standard prayers get sensible defaults: Our Father=large,
Hail Mary=small, Sign of Cross=crucifix, Divine Mercy beads accordingly.
In the sequence, each step card shows a bead selector (—/○/●/✝) so users
can override the default per step. Adding a prayer pre-fills its default.
Bead library icon hints (○●✝) appear on prayer cards in the library.
Modal now includes a Bead selector for creating/editing prayers.
Remove the separate Bead Markers library section — beads live on prayers.
build_slides: prayer steps with bead_type now get a real bead_index so
the ring advances correctly during presentation.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Superuser+ can now build a custom prayer sequence from scratch:
- Two-panel builder UI: step sequence (left) + searchable prayer library (right)
- 16 standard prayers seeded globally; users can create private custom prayers
- Admin can promote private prayers to global and manage the library
- Four attribution modes per step: Leader/All, Leader only, All together, None
- Optional subject name/pronoun for variable substitution in prayers
- Custom sessions fully presented via the existing presenter (auto-split works)
- migrate_v4.php creates custom_prayers + builder_steps tables
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>