# Work Log

Use this file as a chronological, commit-style record of project work. Add a dated entry whenever files are created, fixed, changed, or removed. Include checks performed and the next resume point.

## 2026-10-11 — Initial PHP foundation

**Added**
- `.env.example` and `.gitignore` for local configuration and generated files.
- `app/config.php`, `app/db.php`, `app/helpers.php`, and `app/bootstrap.php` for environment configuration, PDO, session setup, escaping, and CSRF helpers.
- `sql/install.sql` with initial tables for users, clicks, postback events, admins, settings, and login attempts.
- `public/index.php` landing page and `README.md` setup notes.

**Notes**
- Workspace initially contained only `plan.md`.
- Quotex tracking parameter and postback contract are not confirmed. Referral attribution and callback processing remain pending that information.
- Tests were not run.

## 2026-10-11 — Signup and account flow

**Added**
- `app/ratelimit.php` for database-backed signup and login throttling.
- `public/signup.php`, `public/login.php`, `public/logout.php`, and `public/dashboard.php`.
- Updated `app/helpers.php` with IP handling, redirects, and current-user helpers.
- Updated landing page links and README status.

**Behavior**
- Signup creates a user with a random 32-character click ID and starts a session.
- Signup and login forms validate CSRF tokens; passwords use `password_hash` and `password_verify`.
- Dashboard displays signup, registration, confirmation, and first-deposit progress.
- Quotex registration link remains unavailable until tracking details are confirmed.

**Checks**
- Tests were not run.
- The folder is not a Git repository, so these notes are a local work log rather than actual Git commits.

## Resume point

Next, confirm the Quotex affiliate tracking parameter and postback contract. Then implement the tracking redirect and callback handling against the verified provider details. Before public launch, also add admin setup, account deletion and retention behavior, rate-limit cleanup, and the legal/privacy pages listed in `plan.md`.

## 2026-10-11 — Tracking redirect

**Added**
- `public/go.php` requires an authenticated user, records the click and request metadata, then redirects to a configured HTTPS referral URL with that user's click ID.
- Added `REFERRAL_URL` and `CLICK_PARAM_NAME` settings to `app/config.php` and `.env.example`.
- Updated the dashboard to link to the tracking redirect and documented configuration in `README.md`.
- Updated the current-user query to include the click ID needed by the redirect.

**Behavior and checks**
- Redirect returns HTTP 503 until the URL and parameter are configured; rejects non-HTTPS URLs and invalid parameter names.
- The actual provider parameter is still unconfirmed and must be verified before setting these values.
- Tests were not run.

**Next**
- Confirm Quotex tracking and callback documentation, then implement callback processing and event deduplication based on the confirmed contract.

## 2026-10-11 — Allow local blank MySQL password

**Fixed**
- `app/config.php` now accepts an explicitly empty `DB_PASSWORD`, which supports Laragon's default local `root` account while still requiring the setting to exist.
- `README.md` clarifies that blank passwords are for local development and production should use a dedicated database account with a password.

**Checks**
- Tests were not run.

## 2026-10-11 — Fix links when served from a subfolder

**Fixed**
- Changed internal form actions, links, and post-login/logout redirects to relative paths so routes continue to work when the project is opened under a path such as `/public/`.

**Checks**
- Tests were not run; verify by reloading the landing page and opening the signup link.

## 2026-10-11 — Admin settings dashboard

**Added**
- `bin/create-admin.php` creates the first admin from the command line using `ADMIN_INITIAL_PASSWORD`; it refuses to create a second account.
- `public/admin/login.php`, `dashboard.php`, and `logout.php` provide a throttled, CSRF-protected admin session and settings interface.
- Admin settings cover referral URL, click parameter name, postback secret, allowed IPs, and required verification level. The tracking redirect now reads referral URL and parameter from saved settings, falling back to `.env` values.
- Added `admin_actions` audit table; settings changes are recorded without storing the secret in audit details.
- Added `sql/migrations/001_admin_actions.sql` for databases installed before this feature.
- Added setup instructions to `README.md`.

**Notes and checks**
- Provider-specific credentials are not assumed; callback handling is still pending confirmation of the provider's contract.
- Callback URL shown in the admin page is informational until the postback endpoint exists.
- Tests were not run.

## 2026-10-11 — Manual account-flow check

**Verified by user**
- Signup works.
- Login works.
- Logout works.

**Next check**
- Apply the admin-actions migration if needed, create the first admin account, and verify admin login and settings save.

## 2026-10-11 — Initial postback processing phase

**Added**
- `public/postback.php` validates the secret stored by the admin settings page, optionally checks an IP allowlist, accepts GET/form POST/JSON POST, logs callback deliveries, matches users by click ID, and applies monotonic `reg`, `conf`, `ftd`, and `dep` milestones.
- Duplicate matched callbacks are detected by `event_id`; every delivery attempt is recorded in `postback_events`.
- `withdrawal` is logged without downgrading user status. Deposit amounts are logged but not totaled until their provider semantics are confirmed.
- Added an Apache rewrite in `public/.htaccess`, a `processed_postback_events` table, and migration `sql/migrations/002_postback_processing.sql`.
- Migration `002` also hashes and removes any plaintext `postback_secret` saved by the earlier admin settings version.
- Admin settings now hash the postback secret before storing it.
- Updated README with the provisional callback contract and deployment notes.

**Checks and limitations**
- Tests were not run.
- Field names/status meanings and `sumdep` semantics remain provisional until verified against Quotex documentation or a real provider test callback.
- Apache `mod_rewrite` must be enabled for the `/postback/{secret}` path.

## 2026-10-11 — Applied postback database migration

**Applied**
- Ran `sql/migrations/002_postback_processing.sql` against the local `family_site` database using Laragon's MySQL client.

**Verified**
- `processed_postback_events` exists.
- No legacy plaintext `postback_secret` or `postback_secret_hash` setting was present after migration.

## 2026-10-11 — Admin user and postback management

**Added**
- `public/admin/users.php` supports searching/filtering/pagination and manual approve/reject actions with optional notes and audit records.
- `public/admin/postbacks.php` provides paginated and filtered postback log inspection with escaped raw payloads.
- `public/admin/export.php` exports filtered user data to CSV with spreadsheet formula-injection protection.
- Added moderation fields to new installs and migration `sql/migrations/003_manual_user_review.sql` for existing databases.
- Added admin navigation and documented migration/admin features in `README.md`.

**Checks**
- Tests were not run. Apply migration `003` before opening user management on the existing database.

**Database update**
- Applied `sql/migrations/003_manual_user_review.sql` to the local `family_site` database; it completed successfully.

## 2026-10-11 — Application hardening

**Added**
- `app/bootstrap.php` now logs uncaught exceptions, returns a generic production-facing 500 response, and sets browser security headers.
- `public/.htaccess` redirects non-local Apache hosts to HTTPS while allowing localhost HTTP development.
- Added `bin/cleanup.php` to delete login-attempt records older than 30 days.
- Updated README with Apache, HTTPS, cleanup, and retention guidance.

**Checks**
- Tests were not run.

## 2026-10-11 — Family access control

**Added**
- Added a configurable plain-text Family page managed from admin settings.
- Added server-side access checks: admin approval grants access, rejection blocks it, and otherwise the configured Quotex status threshold controls access.
- Dashboard now shows review status and links to the Family page only when access is granted; the page independently enforces the same rule.

**Checks**
- Tests were not run.

## 2026-10-11 — Responsive site UI

**Added**
- Added `public/assets/app.css` with a shared responsive visual system for forms, cards, progress steps, admin tables, filters, and navigation.
- Refreshed the landing page, signup/login forms, member dashboard, Family page, and admin screens with consistent branding and mobile layouts.
- Removed the UTF-8 BOM from `public/index.php` so PHP can send headers before output.

**Checks**
- Tests and browser visual review were not run.

## 2026-10-11 — Restore PHP opening tag

**Fixed**
- Restored the missing `<` at the beginning of `public/index.php`, which caused the PHP bootstrap line to display as text.

**Checks**
- Confirmed the file now begins with `<?php`.

## 2026-10-11 — Apply Quotex postback field mapping from user screenshot

**Updated**
- `public/postback.php` now accepts Quotex aliases `eid`, `cid`, `sid`, and `uid`, and recognizes dynamic event flags such as `reg=true` when needed.
- It preserves site/link IDs, country, user agent, deposit amount, and withdrawal amount in the sanitized log payload.
- Admin settings now show a copyable callback template using the fields shown in the user's Quotex Affiliate Center screenshot.
- Updated README with the observed field mapping. Deposit totals remain unchanged until their accounting semantics are confirmed.

**Checks**
- No test callback has been sent yet.
