TokGrab Installer Overview
Goal
Provide a browser-only installer that works on shared hosting without shell access.
Routes
/install/install/environment/install/database/install/migrate/install/admin/install/finalize/install/repair
Wizard Steps
- Environment checks — PHP version, required extensions, writable directories.
- Database setup — host/port/database/user/password with a live connection test.
- Migrations — creates all database tables from the browser.
- Admin account — name, email, password, and optional starter content.
- Finalize — generates the application key if missing and writes the install lock.
Automatic .env Bootstrap
A fresh package ships without .env (secrets are never packaged). On first load the app
creates a minimal .env from .env.example with a freshly generated APP_KEY, so the installer
can run without any manual file editing or shell access.
Install Lock
- On success, writes
storage/app/installed.lock. - All
/install/*routes redirect to the homepage when the lock exists.
Failure Recovery
- Each step keeps track of the last completed step.
- A
/install/repairpage helps retry a failed step safely.
Security Rules
- CSRF-protected forms on every step
- Server-side validation on every step
- No stack traces exposed in the installer UI
- No default admin credentials