# Nuvisions Quote-to-Provision (PHP/MySQL)

Lightweight PHP 8.x + MySQL 8 implementation for Telecom Quote-to-Provision lifecycle.

## Included Deliverables

- MySQL schema with foreign keys and telecom-specific tables in `database/schema.sql`
- Secure PDO data access and RBAC/CSRF/password hashing in `app/Core`
- `ContractManager` and `ProvisioningService` classes in `app/Services`
- PHPMailer SMTP integration via `app/Services/MailerService.php`
- Dompdf PDF generation in `app/Services/PdfService.php`
- API endpoints for:
  - `POST /api/quotes/convert-to-contract`
  - `GET /api/contracts/expiring`
  - `POST /api/provisioning/complete`
- Server-rendered pages for login, quote builder, provisioning queue, and signer flow
- Cron scripts:
  - `scripts/cron_expiration_notifications.php`
  - `scripts/send_service_handover.php`

## Setup

1. Copy `.env.example` into real environment variables (Apache/Nginx/FPM).
   - For subdirectory deployments (example: `https://mayo2.nuvisions.net/contract_manager`), set:
     - `APP_URL=https://mayo2.nuvisions.net/contract_manager`
     - `APP_BASE_PATH=/contract_manager`
2. Install dependencies:
   - `composer require phpmailer/phpmailer dompdf/dompdf`
3. Create database and run:
   - `mysql -u <user> -p <db_name> < database/schema.sql`
4. Point web root to `public/`.
5. Ensure writable storage:
   - `chmod -R 775 storage/pdfs`
6. Create initial admin user password hash:
   - `php -r "echo password_hash('StrongPassword!', PASSWORD_BCRYPT).PHP_EOL;"`
7. Ensure your web server blocks direct PDF access:
   - Apache: `public/.htaccess`
   - Nginx: `deploy/nginx.conf`

## Server-rendered Pages

- `GET /login`
- `GET /dashboard/quote-builder` (Admin, Sales)
- `GET /dashboard/provisioning-queue` (Admin, Provisioning, Sales)
- `GET /sign/{quote_uuid}` signer page

## SMTP Variables

- `SMTP_HOST`
- `SMTP_PORT`
- `SMTP_USER`
- `SMTP_PASS`
- `SMTP_SECURE` (`tls` or `ssl`)

## Subdirectory Deployment

If app is hosted under `/contract_manager` instead of web root:

- Set `APP_BASE_PATH=/contract_manager`.
- Keep web root pointed to `public/`.
- Access app using `https://mayo2.nuvisions.net/contract_manager`.

## Cron Jobs

Run daily at 06:00 server time:

`0 6 * * * /usr/bin/php /var/www/nuvisions/scripts/cron_expiration_notifications.php >> /var/log/nuvisions-expiry.log 2>&1`

## API Notes

- Retrieve CSRF token: `GET /api/security/csrf`
- Send token in `X-CSRF-Token` for POST routes (except login API).
- Login sets `$_SESSION['user']` and enforces role checks.

## Production Security Checklist

- Force HTTPS + HSTS.
- Use secure session cookie flags (`Secure`, `HttpOnly`, `SameSite=Strict`).
- Rotate SMTP credentials and restrict relay by IP where possible.
- Restrict `storage/pdfs` from direct public listing.
