����JFIF��`�`�����Viewing File: /home/u820193700/domains/thereown.com/public_html/FOR-SRUJAN.md
# 📦 Deployment Instructions — For Srujan
**Project:** REOWN · Avahan Motors (Certified Pre-Owned Royal Enfield)
**From:** Chandan | **Target:** Hostinger shared hosting
**Time needed:** ~30 minutes | **Skill needed:** hPanel basics, phpMyAdmin

---

## What you're deploying
A single-page website (`reown-avahan.html`) + PHP/MySQL backend (`/api` folder).
The site currently works in demo mode; after your setup, the backend is live and
ready for the final frontend-API integration (Chandan will handle that separately).

## ✅ Step-by-step (do in this exact order)

**1. Hosting & SSL**
- Log in to Hostinger hPanel (Chandan will share access)
- Confirm plan is Premium or Business (needs PHP 8.1+ and MySQL)
- Websites → Add website → attach the domain
- Security → SSL → install free SSL → wait till Active
- Websites → PHP Configuration → select **PHP 8.1 or higher**

**2. Database**
- Databases → Management → Create new MySQL database
- Note down the 3 values it gives you (they carry a prefix like `u123456789_`):
  - DB name, DB username, DB password → **send these to Chandan on WhatsApp, not email**
- Open phpMyAdmin for that DB → Import tab → choose `schema.sql` from this zip → Go
- Verify: 5 tables appear (users, bikes, media, activity, leads)

**3. Files**
- File Manager → `public_html/`
- Upload ALL contents of this zip (keep folder structure: `/api`, `/uploads`, `.htaccess` files)
- Rename `reown-avahan.html` → `index.html`
- Check `/uploads` folder exists and contains its `.htaccess` (it blocks code execution — do not delete)

**4. Configure**
- Edit `api/config.php` → fill in the 3 DB values from step 2 → Save
- File permissions: `/uploads` folder = 755, all `.php` files = 644

**5. Initialize passwords (one time)**
- Visit: `https://DOMAIN/api/setup_passwords.php` → should say "Passwords set"
- 🚨 **IMMEDIATELY DELETE `api/setup_passwords.php` via File Manager.**
  Leaving it live lets anyone reset staff passwords. This is the single most
  important step — confirm to Chandan that it's deleted.

**6. Verify (2-minute smoke test)**
- `https://DOMAIN/` → site loads over HTTPS (padlock visible)
- `https://DOMAIN/api/index.php?action=bikes` → returns `[]`
- `https://DOMAIN/uploads/test.php` (if you create one) → must NOT execute → delete it after
- http:// version of the domain → must redirect to https://

**7. Backups**
- hPanel → Files → Backups → confirm weekly backups are ON
- phpMyAdmin → Export → download one `.sql` copy now, send to Chandan as day-zero backup

---

## ⛔ Do NOT
- Do not leave `setup_passwords.php` on the server after step 5
- Do not put DB passwords in any chat other than directly to Chandan
- Do not edit `uploads/.htaccess` or `.htaccess` — they are security rules
- Do not import schema.sql twice (it will error on existing tables — that's fine, don't force-drop)

## Handover checklist (send to Chandan when done)
- [ ] SSL active, http→https redirect working
- [ ] 5 DB tables imported
- [ ] config.php filled with real credentials
- [ ] setup_passwords.php DELETED (confirm explicitly)
- [ ] `action=bikes` returns []
- [ ] Day-zero DB export sent
- [ ] hPanel + DB credentials shared with Chandan only

**Questions:** WhatsApp Chandan — +91 90350 45535
Back to Directory �������}�!1AQa"q2���#B��R��$3br� %&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz�������������������������������������������������������������������������������� ������w�!1AQaq"2�B���� #3R�br� $4�%�&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz������������������������������������������������������������������������ ��?��_��+��?��(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(���(�����