# Telegram Bot Project v2

This is the clean rebuild of the existing project. The old files are intentionally left untouched while v2 is built and tested.

## What Is Included

- Clean PHP JSON API in `web/public/api.php`
- PHP repositories/controllers under `web/src`
- Python Telegram bot under `bot`
- Bot entry point: `bot_main.py`
- Database documentation in `docs/database-map.md`
- Environment-based configuration via `.env`

## Current Migration Status

Implemented in v2:

- Court case API endpoints used by the bot
- Task API endpoints used by the bot
- Hearing listing/creation endpoint
- Comment list/create endpoints
- Enforcement case listing endpoint
- Telegram commands:
  - `/start`
  - `/help`
  - `/is <id>`
  - `/case<ID>`
  - `/isler`
  - `/status <id> <status>`
  - `/tasks`
  - `/task<ID>`
  - `/iclaslar`
- AI replies with initial action parsing for reminders, case creation, and task creation
- JSON reminder storage

Still to migrate from old project:

- Full web panel UI
- Create/edit/delete flows for all web tabs
- File upload pages
- Google Calendar create/update/delete sync
- Email/SMS send flows
- Voice transcription
- Daily Telegram digest details
- Document generation helpers
- Metrics dashboard

## Setup

1. Copy `.env.example` to `.env`.
2. Fill `TELEGRAM_TOKEN`, `ANTHROPIC_API_KEY`, database settings, `API_TOKEN`,
   `ERP_LOGIN`, and `ERP_PASSWORD_SHA256`.
3. Point your web server document root to `v2/web/public`, or expose that folder as a separate vhost.
4. Install Python dependencies:

```bash
pip install -r requirements.txt
```

On Windows you can create a virtual environment with:

```powershell
.\setup_venv.ps1
```

5. Start the bot:

```bash
python bot_main.py
```

Or on Windows:

```powershell
.\start_bot.ps1
```

## Important

The v2 API supports an optional `API_TOKEN`. If set, bot requests must send the same token through the `X-API-Token` header. The v2 bot does this automatically when `API_TOKEN` is present in `.env`.

The ERP web panel requires a login and a SHA-256 password hash. Generate the
hash without a trailing newline, then place only the resulting 64-character
lowercase value in `ERP_PASSWORD_SHA256`:

```bash
read -rsp 'ERP parolu: ' ERP_PLAIN_PASSWORD
echo
printf '%s' "$ERP_PLAIN_PASSWORD" | sha256sum | awk '{print $1}'
unset ERP_PLAIN_PASSWORD
```

The web session expires after `ERP_SESSION_TTL` seconds of inactivity. The
default is 28800 seconds (8 hours). The web login does not replace `API_TOKEN`;
the bot API remains protected separately.

After `20260802_add_erp_user_profile.sql` is applied, the Settings pages can
store profile data and change the local SHA-256 password in the database. A
stored login or valid hash overrides the matching `.env` value; empty database
credential fields continue to use `.env` as a safe fallback.

Google login can be enabled alongside the local login by creating a Google
OAuth 2.0 Web application client and adding these values to `.env`:

```dotenv
GOOGLE_OAUTH_CLIENT_ID=your-client-id
GOOGLE_OAUTH_CLIENT_SECRET=your-client-secret
GOOGLE_OAUTH_REDIRECT_URI=https://your-domain.example/google-callback.php
GOOGLE_OAUTH_ALLOWED_EMAILS=user@example.com,second-user@example.com
GOOGLE_OAUTH_ALLOWED_DOMAIN=
```

The redirect URI must exactly match the authorized redirect URI in Google
Cloud. For safety, the Google button is enabled only when at least one allowed
email or an allowed domain is configured. Leave `GOOGLE_OAUTH_ALLOWED_DOMAIN`
empty when access should be limited to individual accounts.

Rotate the old database/server/API credentials after migration, because the legacy project stored secrets directly in source files.
