# Deployment Notes

## Recommended Layout

Keep the old project available until v2 is fully checked.

```text
/var/www/telegram_bot/
  old files...
  v2/
    .env
    bot_main.py
    bot/
    web/
```

Expose only this directory to the web:

```text
v2/web/public
```

Do not expose:

- `.env`
- `bot/`
- `web/src/`
- `docs/`
- `data/`
- `uploads/` unless intentionally served through controlled links

## PHP API

Set the web root or vhost to:

```text
/var/www/telegram_bot/v2/web/public
```

The bot should use:

```text
API_URL=https://your-domain.example/api.php
```

## ERP Web Login

The ERP panel (`web/public/index.php`) is protected by a session login. Add the
following to the production `.env` file:

```dotenv
ERP_LOGIN=admin
ERP_PASSWORD_SHA256=replace-with-a-64-character-lowercase-sha256-hash
ERP_SESSION_TTL=28800
```

Generate the password hash on Ubuntu without writing the plain password to the
application source:

```bash
read -rsp 'ERP parolu: ' ERP_PLAIN_PASSWORD
echo
printf '%s' "$ERP_PLAIN_PASSWORD" | sha256sum | awk '{print $1}'
unset ERP_PLAIN_PASSWORD
```

The API continues to use `API_TOKEN`; ERP web credentials do not authorize API
requests. Serve the ERP over HTTPS so the secure session cookie is protected in
transit.

### Google login (optional)

Create an OAuth 2.0 client of type **Web application** in Google Cloud and add
the exact production callback URL to its authorized redirect URIs. Then add:

```dotenv
GOOGLE_OAUTH_CLIENT_ID=your-client-id
GOOGLE_OAUTH_CLIENT_SECRET=your-client-secret
GOOGLE_OAUTH_REDIRECT_URI=https://your-domain.example/google-callback.php
GOOGLE_OAUTH_ALLOWED_EMAILS=user@example.com
GOOGLE_OAUTH_ALLOWED_DOMAIN=
```

Multiple allowed emails are comma-separated. Alternatively, set
`GOOGLE_OAUTH_ALLOWED_DOMAIN=example.com` to permit every verified Google
account in that email domain. At least one of these restrictions is required.
The callback uses PHP cURL; on Ubuntu verify it with `php -m | grep -i curl`.
If it is absent, install the `php-curl` package and restart the active web/PHP
service.

### File upload limits

Task and court-case uploads accept files up to 20 MB. For PHP-FPM/FastCGI,
deploy `web/public/.user.ini` with the application. The effective values must be:

```ini
upload_max_filesize = 20M
post_max_size = 25M
```

`post_max_size` is intentionally larger because it includes multipart form
overhead in addition to the file itself. PHP may cache `.user.ini` values for
up to five minutes; reload PHP-FPM after deployment when possible.

For Apache `mod_php`, put the same values in the active `php.ini` or virtual
host configuration and restart Apache. For PHP's built-in server, start it with:

```text
php -d upload_max_filesize=20M -d post_max_size=25M -S 127.0.0.1:8000 -t web/public
```

If Nginx is used, also set `client_max_body_size 25M;` and reload Nginx.

## Bot Service

Example systemd unit:

```ini
[Unit]
Description=Telegram Bot v2
After=network.target

[Service]
WorkingDirectory=/var/www/telegram_bot/v2
ExecStart=/var/www/telegram_bot/v2/venv/bin/python bot_main.py
Restart=always
RestartSec=5

[Install]
WantedBy=multi-user.target
```

## Migration Order

1. Configure v2 `.env`.
2. Deploy PHP API to a test URL.
3. Test API with read-only actions: `hamisi`, `aciq_tapshiriqlar`, `iclaslar_aralik`.
4. Start v2 bot with a test Telegram bot token.
5. Test Telegram read commands.
6. Test create/update commands on test records.
7. Migrate web panel pages.
8. Switch production bot token only after v2 behavior is verified.
