# Mansi Diet Care — cPanel/PHP installation

This package retains all 33 public pages, 21 complete articles, the selected hero portrait, the existing admin interface, and the section backgrounds, responsive hero, compressed local fonts, lazy animations and all motion treatments. The frontend uses the same URLs and appearance. PHP handles page responses, enquiries, administration, content editing, image uploads, chat, and payments.

Requires Apache-compatible cPanel hosting with PHP 8.2 or newer, OpenSSL, JSON and the usual PHP image metadata functions. No database account is required; records are protected outside the public web directory. Enable `mod_rewrite` and `mod_headers` (normally present on cPanel).

## Quick upload — important folder placement

The ZIP belongs in the cPanel account home directory, one level above `public_html`. Extracting it inside `public_html` would create the wrong nested folders and expose the private setup. Follow the steps below, then run the one-time admin setup. No build command or Node.js is required on the hosting server.

## Install without exposing private data

1. Back up the existing document root and hosting account before replacing files. Keep backups outside `public_html`.
2. Upload/extract the package in the account's HOME directory, usually `/home/mansidie`. The two folders must be siblings: `/home/mansidie/public_html` and `/home/mansidie/mansi-private`. **Do not put `mansi-private` inside `public_html`.** For a custom document root, set `MDC_PRIVATE_DIR` securely or adjust the private directory location in `api.php`.
3. Select PHP 8.2 or newer. In cPanel Terminal, run `php ~/mansi-private/setup.php`. It prompts for the admin email and a new password without showing that password. It never overwrites an existing configuration. Configuration permissions should be `600`; private directory/data permissions `700`/`600`.
4. Confirm DNS is directed to this hosting account and enable AutoSSL for `mansidietcare.in` and `www.mansidietcare.in`. Test using HTTPS: login and chat use Secure, HttpOnly, SameSite cookies.
5. Open `/admin` and sign in. Check a booking and contact submission, status changes, article editing, image upload, password change, visitor/admin chat and denied unauthenticated access. Remove test enquiries and chats afterwards.

## Mail

Enquiries always persist in the protected admin inbox. Create/verify `consult@mansidietcare.in`, confirm the host permits PHP `mail()` and configure the domain's SPF/DKIM. Only then set `mail_enabled` to `true` in the **private** configuration and test an actual delivery. A record marked “queued to hosting mail server” confirms acceptance by the local mail server; it does not prove delivery to an inbox. This PHP edition does not require Resend credentials. Newsletter requests are saved; this is not a newsletter campaign sender.

## Payments

Payments stay unavailable until an activated Razorpay merchant account is supplied. Add `razorpay_key_id`, `razorpay_key_secret` and `razorpay_webhook_secret` in the private config. Register `https://mansidietcare.in/api/payments/webhook` with the `payment.captured` event. Test with Razorpay test-mode credentials first. The server validates checkout signatures, webhook signatures, amounts, currency and payment status; the client cannot set plan prices.

## Chat

Visitor/admin messages are stored privately. The live stream checks once per second and reconnects every 20 seconds to fit common shared-hosting execution limits. Apache/PHP must allow concurrent requests and unbuffered event-stream responses. Some hosts buffer SSE or restrict concurrent PHP workers: verify this on the actual account before claiming production realtime chat. The admin must enable availability and keep the admin panel open for the online indicator.

## Existing records and credentials

This is a fresh PHP data store. Previous preview-hosted enquiries, chats, article edits and settings are not migrated automatically. If they contain real data, export them securely and map them into the protected storage before switching the domain. Never put exports, configuration, credentials or raw enquiry data into `public_html`, a public repository or a public download.

## Security and operations

Requests that change data require the allowed Origin. Admin sessions use signed, expiring cookies and are invalidated when the password changes. Passwords are PBKDF2 hashed with individual random salts. Rate counters are locked; record replacement is atomic. Image uploads validate the declared type, actual dimensions and size. Private files are kept outside the web root; public files get a restrictive CSP and browser security headers. Keep PHP/cPanel patched, use a strong password and maintain encrypted offsite backups. No implementation can promise that a site is unhackable.

This final package has been tested locally. As requested, upload it through your own cPanel; production PHP version, permissions, SSL, outgoing mail and event-stream behavior must be checked on that account.
