# Copy this file to .env (same directory as config.php) and fill in real
# values. .env must NEVER be committed or placed inside public_html.

# --- Database (see database/schema.sql) ------------------------------------
DB_HOST=127.0.0.1
DB_PORT=3306
DB_NAME=zc_safeguarding
DB_USER=root
DB_PASS=

# --- Encryption -------------------------------------------------------------
# 32-byte key, base64-encoded. Generate with:
#   php -r "echo base64_encode(random_bytes(32)) . PHP_EOL;"
# Rotating this key makes every existing *_ciphertext column unreadable —
# treat it like a database credential and back it up securely.
ENCRYPTION_KEY_BASE64=CONFIGURATION REQUIRED — GENERATE AND STORE SECURELY

# Pepper mixed into every case-reference / follow-up-code / IP hash before
# it's stored. Independent of ENCRYPTION_KEY_BASE64 on purpose. Generate with:
#   php -r "echo bin2hex(random_bytes(32)) . PHP_EOL;"
HASH_PEPPER=CONFIGURATION REQUIRED — GENERATE AND STORE SECURELY

# --- Email (staff notifications) ---------------------------------------------
# Leave SMTP_HOST blank to use PHP's built-in mail() (the cPanel-standard
# local MTA). Set it to use a real SMTP relay instead (recommended — plain
# mail() is easily flagged as spam and many hosts throttle or disable it).
SMTP_HOST=
SMTP_PORT=587
SMTP_SECURE=tls
SMTP_USER=
SMTP_PASS=
MAIL_FROM_ADDRESS=safeguarding@example.org
MAIL_FROM_NAME=Zimbabwe Cricket Safeguarding

# --- WhatsApp ----------------------------------------------------------------
# Switch providers by changing ONLY this line + the credentials below it —
# nothing in app/ needs to change. Use ultramsg for testing/initial launch,
# then set this to cloud_api (and fill in the Cloud API block) for official
# launch. See README "WhatsApp bot > Switching providers".
WHATSAPP_PROVIDER=ultramsg

# Long random string, used for BOTH providers as an extra layer on top of
# whatever provider-specific check applies. The webhook URL you configure
# with the provider must be:
#   https://<your-domain>/api/whatsapp/webhook.php?s=<this value>
# Generate with: php -r "echo bin2hex(random_bytes(24)) . PHP_EOL;"
WHATSAPP_WEBHOOK_SECRET=

# UltraMsg (unofficial, QR-linked — fine for testing, NOT recommended for
# the live safeguarding line; see README).
ULTRAMSG_INSTANCE_ID=
ULTRAMSG_TOKEN=

# Official WhatsApp Business Platform (Meta Cloud API) — for the real
# launch. From Meta Business Manager / developers.facebook.com:
#   WHATSAPP_CLOUD_PHONE_NUMBER_ID — the Phone Number ID (not the phone number itself)
#   WHATSAPP_CLOUD_ACCESS_TOKEN    — a permanent token from a System User, not the 24h test token
#   WHATSAPP_CLOUD_APP_SECRET      — the app's secret; used to verify X-Hub-Signature-256 on every webhook
#   WHATSAPP_CLOUD_VERIFY_TOKEN    — a string YOU make up; enter the same value in the Meta webhook config
WHATSAPP_CLOUD_PHONE_NUMBER_ID=
WHATSAPP_CLOUD_ACCESS_TOKEN=
WHATSAPP_CLOUD_APP_SECRET=
WHATSAPP_CLOUD_VERIFY_TOKEN=

# --- App environment ---------------------------------------------------------
APP_ENV=production

# Absolute site URL (no trailing slash) — used in links inside email/WhatsApp
# staff notifications. e.g. https://safeguarding.zimcricket.org
APP_URL=
