CERDIKKIDS — INSTALL ON cPANEL (full version with accounts + MySQL)
====================================================================

WHAT YOU GET
------------
- Parent accounts: sign up, log in, confirm email, forgot/reset password, delete account
- Children's progress saved in the cloud and shared across phones/tablets/computers
- 7-day free trial (length set by you), then plans that YOU design and price
- Payments with ToyyibPay, tied to the parent's account; receipts by email
- Admin panel: dashboard, customer list/search/CSV, grant plans or trial days, disable accounts,
  orders, plan/price/trial/mission/exam settings, one-click updates with backup + rollback, system check, activity log
- PDPA basics: consent at sign-up, privacy notice, "download my data", "delete my account"


FILES IN THIS PACKAGE
---------------------
public_html/cerdikkids/index.html        The app (30 topics, 3,000 checked questions)
public_html/cerdikkids/assets/           Adi, Lisa and the logo
public_html/cerdikkids/.htaccess         Security headers + optional HTTPS redirect
public_html/cerdikkids/api/install.php   One-time installer (delete it afterwards)
public_html/cerdikkids/api/auth.php      Accounts
public_html/cerdikkids/api/sync.php      Progress sync
public_html/cerdikkids/api/pay.php       ToyyibPay
public_html/cerdikkids/api/admin.php     Admin API
public_html/cerdikkids/api/update.php    One-click updates and rollback
public_html/cerdikkids/api/ai.php        Claude AI (only after a child finishes a topic's 100 questions)
public_html/cerdikkids/api/_lib.php      Shared code (blocked from the web)
cerdikkids-config.php                    Your passwords and keys (stays OUTSIDE public_html)


STEP 1 — UPLOAD
---------------
1. cPanel > File Manager. Stay in your HOME folder (/home/yourcpaneluser, the folder that CONTAINS public_html).
2. Upload cerdikkids-cpanel.zip there, right-click > Extract.
   (Updating an old version? First rename your existing cerdikkids-config.php, extract, then copy your keys in.)
3. Check PHP: cPanel > Select PHP Version: 7.4 or newer, with these ticked: pdo_mysql, mbstring, curl, openssl.


STEP 2 — CREATE THE DATABASE
----------------------------
1. cPanel > MySQL Databases.
2. Create a database (e.g. cerdikkids) — cPanel adds your prefix, e.g. myuser_cerdikkids.
3. Create a database user with a strong password.
4. "Add user to database" > tick ALL PRIVILEGES.
Write down the full names (with prefix) and the password.


STEP 3 — FILL IN cerdikkids-config.php
--------------------------------------
File Manager > right-click cerdikkids-config.php (home folder) > Edit. Set at least:
  site_url     https://yourdomain.my/cerdikkids/   (your real address, with the trailing slash)
  db_name, db_user, db_pass                         from Step 2
  install_key  any random text, 12+ characters (you use it once, in Step 4)
Fill the smtp_* lines too so emails work (Step 5). You can add ToyyibPay and AI keys now or later.


STEP 4 — RUN THE INSTALLER (once)
---------------------------------
1. Open https://yourdomain.my/cerdikkids/api/install.php
2. Every line should show a green tick. Fix any red line (the page tells you how).
3. Enter your install key, your name, admin email and a strong admin password. Press Install.
4. DELETE public_html/cerdikkids/api/install.php afterwards.
5. Open https://yourdomain.my/cerdikkids/ and log in with the admin account.
   Admin panel: Parent area (bottom-right "Ibu Bapa") > Children & settings > Admin panel.


STEP 5 — EMAIL (confirm email, forgot password, receipts)
---------------------------------------------------------
1. cPanel > Email Accounts > create no-reply@yourdomain.my and choose a password.
2. In cerdikkids-config.php:
     smtp_host 'mail.yourdomain.my'   smtp_port 587   smtp_secure 'tls'
     smtp_user 'no-reply@yourdomain.my'   smtp_pass '...'   mail_from 'no-reply@yourdomain.my'
   (Port 465 with smtp_secure 'ssl' also works.)
3. Admin panel > System > "Send test email". A green tick in the status list means it works.
Without email, people can still sign up and log in, but "forgot password" and receipts won't arrive.
(Admin panel > Customers > a customer > "Send password-reset link" also needs email.)


STEP 6 — PAYMENTS WITH TOYYIBPAY
--------------------------------
1. Test first with a sandbox account at https://dev.toyyibpay.com
   Create a Category and copy its Category Code; copy your User Secret Key.
2. In cerdikkids-config.php:
     toyyibpay_secret, toyyibpay_category, toyyibpay_sandbox => true
3. Log in as a normal parent (not admin), Parents > Subscription > Subscribe. Pay in the sandbox.
   You return to the app and the plan is active on every device. A receipt email is sent.
4. When all is well, use your real toyyibpay.com keys and set toyyibpay_sandbox => false.
Prices always come from your Admin settings on the server. A payment is only accepted after the
server confirms it with ToyyibPay (amount must match). Orders appear in Admin > Orders; if ToyyibPay's
dashboard shows a payment that didn't arrive, use "Mark paid" there.


STEP 7 — HTTPS (needed for payments and safe logins)
----------------------------------------------------
1. cPanel > SSL/TLS Status > Run AutoSSL.
2. When the site opens without a warning, edit public_html/cerdikkids/.htaccess and remove the "#" from the last 3 lines.


STEP 8 — AI (optional)
----------------------
Get a key at https://console.anthropic.com, set a monthly spend limit there, paste it into anthropic_api_key.
Check: Admin > System shows a green tick for AI. AI only writes new questions after a child has
answered all 100 in a topic, and powers the optional "AI progress report". It needs a logged-in parent.


HOW IT WORKS (for your own reference)
-------------------------------------
- Trial: starts when the parent signs up (length from Admin settings; you can change a single customer's trial).
- Plans: decided by the server only. Nothing in the browser can switch a plan on.
- If two devices save at the same time, the app merges them and keeps the child profile with more progress.
- Each parent's data is saved as one record plus a summary table (children, sessions, last active) used by the admin reports.
- Logins last 60 days; logging out, resetting the password or disabling an account ends them.
- Wrong-password tries, sign-ups, payments and AI calls are rate limited.


BACKUPS (please set this up)
----------------------------
cPanel > Backup > "Download a MySQL Database Backup" (or turn on cPanel's scheduled backups).
Your customers' accounts and progress live in that database.


ONE-CLICK UPDATES (admin panel)
-------------------------------
When there is a new version you receive a file like cerdikkids-update-2.1.0.zip. To install it:
1. Log in as admin > Parent area > Children & settings > Admin panel > "Updates" tab.
2. Choose the zip. You see the new version number, the release notes and which files will change.
3. Press "Install update". The app first makes an automatic backup, installs the files, upgrades the
   database if needed, then reloads. That's it.
Safety built in:
- Only an admin can do this. The zip is checked: it must be a CerdikKids update, every file is checked
  against its fingerprint, and anything outside the app's own files is refused.
- Your cerdikkids-config.php, your .htaccess and all customer data are never touched.
- If anything fails halfway, the previous version is put back automatically.
- Same tab > "Backups & rollback": restore any earlier version with one click (the current version is saved
  first, so a rollback can be undone). The last 8 backups are kept.
- If you ever upload the files by hand instead, the database upgrades itself on the next visit.
Needs: the PHP "zip" extension (Select PHP Version > zip) and a PHP upload limit of at least 4M
(cPanel > Select PHP Version > Options > upload_max_filesize). The Updates tab shows both checks.
If the tab says the folder is not writable, in File Manager make sure the app folder and its files
belong to your cPanel account (normal on cPanel) and are not set to read-only.
Only install updates you received from your own developer, the same as any software.


TROUBLESHOOTING
---------------
App shows "Almost there!"               The installer hasn't been run yet (Step 4).
Installer: "Database connection" red    Check db_name/db_user/db_pass (they include your cPanel prefix) and the user's privileges.
Sign-up works but no email              Step 5; check Admin > System > recent emails for the error message.
"ToyyibPay did not accept the bill"     Wrong secret key / category code, or sandbox keys with sandbox => false.
Paid but plan not active                Admin > Orders > Mark paid (after checking ToyyibPay); check that api/pay.php?callback=1 isn't blocked.
Everything else                         cPanel > Metrics > Errors shows the exact PHP error.


GOOD TO KNOW
------------
- Mock exams are practice exams inside CerdikKids, not official MOE exams.
- The privacy notice text is in the app code (PRIVACY in account.js); have it reviewed for your business.
- Not built yet: parent-to-parent sharing of children between two accounts, social login (Google/Apple), push notifications,
  a native mobile app.
