Extension principles

  • Use supported APIs, models, hooks, and route helpers instead of direct page scraping.
  • Preserve authorization, CSRF protection, tenancy, ownership, and audit logging.
  • Use canonical WBAMS routes and terminology.
  • Make retries idempotent and external calls timeout safely.
  • Keep secrets out of source, browser code, logs, and exception pages.

Database

The WBAMS 1.0.x schema uses descriptive unprefixed table names. Do not reintroduce the removed tbl prefix. Use schema inspection rather than historical application-version assumptions when detecting v1 capabilities.

Routes

Generate links through route helpers. Knowledgebase and Update article URLs use lowercase slugs without numeric IDs. The control application lives under /control, and retired compatibility redirects are intentionally absent.

CMS development

Keep page content in the CMS. New builder sections should define editable data, responsive output, sanitization, preview behavior, documentation, and Serepok styling. Page-specific CSS and JavaScript must remain scoped.

Release tests

At minimum, lint changed PHP, validate Composer metadata, install into an empty database, authenticate both control and customer contexts, traverse known routes, test CMS actions, scan for fatal markers, and verify that temporary data and diagnostics are removed.