SECURITY HARDENING APPLIED
- Removed hard-coded DB password, Firebase private key, Fast2SMS key and payment token from source.
- Added protected config/config.php with placeholders/environment-variable support.
- Removed old API/old admin copies, embedded ZIP backups and logs from public tree.
- Added HTTPS redirect, directory-listing prevention, sensitive-file blocking and security headers.
- Added central request limits/rate limiting/auth helpers and secure admin session cookies.
- Disabled unauthenticated api/add_money.php wallet-credit endpoint.
- Hardened user/admin login and migrates legacy MD5 passwords after successful login; plaintext fallback removed.
- Hardened password/MPIN OTP reset: 6-digit cryptographic OTP, 10-minute expiry, one-time deletion, rate limiting, prepared statements.
- Hardened MPIN update and payment order creation with token authentication and validation.
- Webhook secret moved to protected config.
- Hardened admin session queries and same-origin POST CSRF check.
- Reworked status_insert dynamic SQL with allowlists/prepared statements.
- Protected cron/result ingestion endpoints with X-Cron-Secret.
- Removed known third-party admin JS/CSS references and embedded Firebase credential cron.

MANDATORY MANUAL STEPS
1) ROTATE all credentials that were present in the old ZIP. Do not reuse old values.
2) Put new values in config/config.php or environment variables.
3) Create a NEW Firebase service-account key outside public_html and update notification code to read it from a protected path/env. account.json was intentionally removed.
4) Test app/admin flows on staging before replacing production.
5) Enable Cloudflare/WAF/rate limiting and hosting-level backups/2FA. Code alone cannot guarantee DDoS prevention or 100% security.


USER-PRESERVED FUNCTIONALITY (2026-08-26):
- api/resgiter.php keeps the original OTP/register branching. OTP was NOT enabled or redesigned.
- Auto-result cron/result endpoint behavior was preserved; no new shared-secret header requirement was added to cron_declare.php, cron_declare2.php, receive_result_api.php.
- cronss.php keeps auto-result logic but hard-coded DB/Firebase credentials were removed. Put a NEW rotated Firebase service-account JSON at config/firebase-service-account.json and DB credentials in config/config.php or environment variables.
