JANTA555 SUPPORT BACKEND PATCH

- /api/user/messages.php added for Android chat/list/presence/image/voice-note actions.
- /api/user/calls.php compatibility path added.
- /api/web/call-room.php and /api/call/{signal,ice-config}.php compatibility paths added.
- Support token now portable HMAC-signed token: same support secret on all four servers = same token accepted.
- Existing DB support sessions remain accepted for backward compatibility.
- Voice calls only. Server rejects/removes video path.
- Global admin busy check: only one ringing/accepted support call per app on a server.
- Call history synthesized into messages[] with message_type=call.
- Voice notes: only M4A/MP4 ftyp, <=7 MB, random filename.
- Images: base64 decoded, dimensions checked, decoded and re-encoded as fresh JPEG before storage. Original metadata/trailing data is not stored.
- Upload directory blocks executable/script extensions and sets nosniff.
- Text input rejects obvious script/PHP/shell payload markers; SQL uses prepared statements.
- Message rate limiting enabled.

IMPORTANT FOR 4 HOSTINGS:
Copy the SAME config/support-secrets.php app secret to all four support servers. Keep database row-sync worker active for support_messages, support_presence, app_users and social_support_calls so chat/call state is consistent across failover hosts.
