SPARTAN FITNESS / WHITE-LABEL COMMERCIAL INSTALLER
=================================================

QUICK START (client hosting)
----------------------------
1. Upload the ZIP to the client's domain/subdomain and extract it into the
   document root (index.php and .htaccess must end up at the top level, not
   inside a sub-folder).
2. Normally nothing to do here - cPanel's File Manager and most FTP clients
   extract folders as 755 and files as 644. Only if CSS/JS/images come back
   403, fix the permissions:
     - SSH:    php fix_permissions.php        (CLI only - see the note below)
     - cPanel: select the storage/, logs/ and public/uploads/ folders,
               chmod 755, then apply to all sub-folders and files.
   NOTE: fix_permissions.php deliberately refuses to run over HTTP (it
   returns 403 by design, and .htaccess blocks it too), so do not try to
   open it in a browser - it rewrites permissions recursively and must only
   ever run from a shell.
3. Open the domain. If the system is not installed yet, every page redirects
   to /install/ automatically - just follow the wizard.
4. Step 1: gym/system name, administrator details, theme colour, sidebar
   colour and database credentials.
5. Step 2: SMTP details (optional - can be left blank and set later from
   .env / Settings).
6. Finish Installation:
   - imports DB/install.sql (full schema)
   - creates the administrator with a secure random password
   - generates the client logo and writes .env
   - creates storage/installed.lock
   - rewrites memberapp/main.dart.js and index.html for the installed domain
     (the member app also resolves its API host from the page URL at runtime,
     so one build works on any domain or sub-folder - no rebuild needed)
   - removes install/index.php so the wizard cannot run again
7. Login with the displayed temporary credentials and change the password
   on first login (it is enforced).

OPENING /INSTALL/ ON AN ALREADY-RUNNING SYSTEM
----------------------------------------------
You will see a friendly "already set up" page with Login / Dashboard
buttons. Nothing to do - the system detects a live installation and will
not run the wizard. A stale lock file pointing at a broken/empty database
is detected automatically and removed so a real install can proceed.

SERVER REQUIREMENTS
-------------------
- PHP 8.0+ with pdo/mysqli, curl, openssl, mbstring, json
- Apache with mod_rewrite (or LiteSpeed). The included .htaccess handles
  security and pretty URLs automatically.
- MariaDB/MySQL 5.7+
- storage/ and logs/ must be writable by PHP (sessions and uploads live
  under storage/)
- node/npm and a compiler are NOT required - the Flutter web build is
  shipped pre-built in memberapp/

AFTER INSTALL (PUSH NOTIFICATIONS)
----------------------------------
Push notifications are controlled by .env:
- FCM_CREDENTIALS  = path to storage/firebase-service-account.json
- FCM_PROJECT_ID   = Firebase project id (e.g. spartan-fitness-8e5e3)
- FCM_SERVER_KEY   = legacy server key (optional, newer setups only need
                     the service account)
Copy the service-account JSON into storage/ and set the values, then use
the Test Notification button in Settings to verify.

WHITE-LABEL BRANDING
--------------------
- System name is used throughout the application.
- A client-specific initials logo is generated automatically.
- The client can upload a real logo from Settings.
- Primary, hover and sidebar colours can be changed from Settings.
- Dynamic theme CSS applies the selected colours to the admin UI and login.
- SMTP settings are generated into .env during installation.

SECURITY (already handled)
--------------------------
The .htaccess blocks direct web access to .env, storage/, logs/, includes/,
DB/, app/, install/ sources and any Flutter source folder; it also disables
directory listing and adds basic security headers. Expected status codes:
403 for all protected paths, 404 only for unknown routes.

WHAT IS NOT IN THIS PACKAGE
---------------------------
- The Flutter/Dart source tree - only the compiled bundle in memberapp/ is
  shipped. Rebuild with: flutter build web --release --base-href /memberapp/
- .env - written by the installer from the credentials you enter. Never ship
  one.
- storage/firebase-service-account.json - drop your own Firebase
  service-account file into storage/ and set FCM_* in .env after installing.
- storage/installed.lock, storage/sessions/*, logs/* - runtime state; start
  empty so the installer runs.
- The local database - DB/install.sql is a clean schema (30 tables) and the
  wizard imports it. Import an existing dump yourself only if you are
  migrating a live system.

MEMBER APP DOMAIN
-----------------
memberapp/ is a single pre-built bundle. It works out its API root from the
page URL (https://your-domain/ -> https://your-domain/api), so it needs no
per-domain rebuild.

ANDROID APK NOTE
----------------
No APK is bundled. Build/re-sign the Android app for each production backend
or update it to use a configurable API endpoint.