Diagnostic order

  1. Reproduce precisely.Record URL, role, inputs, expected result, actual result, and time.
  2. Inspect the response.Status, final URL, redirect chain, content type, and visible error markers.
  3. Check logs.Web server, PHP, WBAMS activity, module, scheduler, gateway, and email.
  4. Check state.Permissions, session, CSRF token, database row, feature setting, and storage object.
  5. Test the smallest fix.Change the owning layer and repeat the exact reproduction plus neighboring routes.

Common problems

Access Denied
Confirm authentication, role permissions, feature authorization, ownership, and any stale session.
Blank or critical page
Check PHP/web logs, missing view paths, database tables, file permissions, and OPcache.
Redirect to an index
Verify the query parameter is allowlisted and preserved through route normalization.
Broken image
Inspect the final URL, case-sensitive path, storage configuration, permission, and generated markup.
Media library fails
Test the authenticated endpoint, JSON response, CSRF token, writable media path, and browser console.
Automation did not run
Compare web and CLI PHP, scheduler frequency, lock state, permissions, and the last completed task.

Smoke-test rule

A route returning 200 is not enough. Confirm the final URL, authenticated context, absence of fatal markers, expected page identity, and meaningful data. Include first-run states such as EULA acceptance and empty datasets.

Never debug by exposing secrets

Redact passwords, session IDs, API keys, database credentials, encryption hashes, payment tokens, and customer data from output and screenshots.