ToroNet Support - PHP/MySQL WhatsApp Cloud API starter
====================================================

IMPORTANT
- This starter is for Meta's TEST phone number only.
- Do NOT enter the existing production ToroNet number or disconnect Zoho Desk.
- Test first with the Meta test recipient number you have added/verified.
- Requires PHP 8.1+, PDO MySQL, cURL, JSON, HTTPS.
- This is a starter foundation, not yet a complete production replacement for Zoho Desk.

DEPLOYMENT
1. In cPanel, create a MySQL database and a database user. Grant ALL PRIVILEGES on this database.
2. Upload the `public` folder contents into a new subdomain/document root, e.g. support-test.toronet.mx.
3. Upload `private/config.example.php` OUTSIDE public_html, rename it `config.php`, and fill it in.
   Example: /home/CPANELUSER/private/toronet-support/config.php
4. Edit `public/bootstrap.php` and update CONFIG_PATH to the real path above.
5. Import `private/schema.sql` in phpMyAdmin.
6. Create an admin password hash locally using PHP:
   php -r "echo password_hash('YOUR-STRONG-PASSWORD', PASSWORD_DEFAULT), PHP_EOL;"
   Insert the hash into the users table (see schema notes below).
7. Configure Meta app webhook callback:
   https://support-test.YOURDOMAIN.TLD/webhook.php
   Verify token must exactly match `webhook_verify_token` in config.php.
   Subscribe to the WhatsApp `messages` webhook field and subscribe the app to your WABA.
8. In Meta, use your TEST phone number ID and temporary test access token. Never paste tokens into chat.
9. In config.php, set `app_secret`, `access_token`, `phone_number_id`, `graph_api_version`, `waba_id`.
10. Open /login.php, sign in with your seeded admin.
11. Test receiving a WhatsApp message from a verified test recipient, then reply from the inbox.
12. After testing, create a long-lived/system-user token with least privilege and plan production migration separately.

CONFIG PATH
The application expects the private config file at the path set in `public/bootstrap.php`.
Never place config.php, access tokens, or app secrets under public_html.

CREATE ADMIN
After importing schema.sql, run this SQL after replacing values:
INSERT INTO users (name,email,password_hash,role,is_active)
VALUES ('ToroNet Admin','admin@YOURDOMAIN.TLD','PASTE_PASSWORD_HASH','admin',1);

META WEBHOOK
GET validates the verification token and returns hub.challenge.
POST validates X-Hub-Signature-256 using the Meta App Secret, deduplicates inbound message IDs, stores messages and updates delivery statuses.
Do not disable signature validation in production.

LIMITATIONS IN THIS STARTER
- Text messages only in the send UI; incoming message payloads are persisted as JSON and text is shown when available.
- Media download/preview, templates UI, canned responses, SLA rules, email channel, and reports need further implementation.
- Customer history starts when this webhook receives events; Zoho's historic chats do not automatically transfer.
- Test number credentials and recipient restrictions apply until production assets are configured.
