=====================================================================
 ONLINE PARENT-TEACHER MEETING SYSTEM  --  PROTOTYPE PHASE
=====================================================================
 Project      : Online Parent-Teacher Meeting System
 Assignment   : No. 3 - Prototype Phase
 Semester     : Spring 2026 (CS619)
 Group ID     : S26PROJECT93B83
 Student ID   : BC230201693
 Supervisor   : Akmal Khan (akmalkhan@vu.edu.pk)
 Technology   : PHP 8.x, MySQL 8.x, HTML5, CSS3 (XAMPP Server)
=====================================================================

---------------------------------------------------------------------
1. HOW TO RUN THE APPLICATION
---------------------------------------------------------------------
Step 1 : Install and open XAMPP. Start the "Apache" and "MySQL"
         modules from the XAMPP Control Panel.

Step 2 : Copy the whole folder "OPTMS_Prototype" into:
             C:\xampp\htdocs\

Step 3 : Open your browser and go to:
             http://localhost/phpmyadmin

Step 4 : Click the "Import" tab, choose the file
             OPTMS_Prototype/database/optms_prototype.sql
         and click "Go".
         (The script creates the database "optms_prototype" and the
          three tables together with sample data.)

Step 5 : Open the application in your browser:
             http://localhost/OPTMS_Prototype/index.php

NOTE: If your MySQL root account has a password, open
      includes/db.php and set it in the DB_PASS constant.

---------------------------------------------------------------------
2. DEFAULT LOGIN CREDENTIALS
---------------------------------------------------------------------
 ADMIN   ->  Username : admin        Password : admin123
 PARENT  ->  User Name: Ali Khan     Password : parent123

 (A parent can also create a brand-new account from the
  Parent -> Registration page.)

---------------------------------------------------------------------
3. FOLDER STRUCTURE
---------------------------------------------------------------------
 OPTMS_Prototype/
 |-- index.php                     -> Task 4  : Main / Home interface
 |-- README.txt                    -> This file
 |
 |-- database/
 |    |-- optms_prototype.sql      -> Tasks 1,2,3 : Database + 3 tables
 |
 |-- includes/
 |    |-- db.php                   -> MySQL connection + helper functions
 |    |-- header.php               -> Shared page header + navigation
 |    |-- footer.php               -> Shared page footer
 |
 |-- assets/css/
 |    |-- style.css                -> Design system: "School Register"
 |
 |-- admin/
 |    |-- _nav.php                 -> Shared admin sidebar definition
 |    |-- login.php                -> Task 5  : Admin login + error message
 |    |-- dashboard.php            -> Task 6  : Admin dashboard
 |    |-- add_teacher.php          -> Task 7  : Add teacher + messages
 |    |-- update_teacher.php       -> Tasks 8,9 : Search + update teacher
 |    |-- delete_teacher.php       -> Task 10 : Search + delete teacher
 |    |-- logout.php               -> Task 11 : Admin logout
 |
 |-- parent/
 |    |-- _nav.php                 -> Shared parent sidebar definition
 |    |-- index.php                -> Task 12 : Parent main interface
 |    |-- register.php             -> Task 12 : Parent registration
 |    |-- login.php                -> Task 13 : Parent login + error message
 |    |-- dashboard.php            -> Task 14 : View all teachers
 |    |-- update_profile.php       -> Task 15 : Update parent profile
 |    |-- logout.php               -> Task 16 : Parent logout
 |
 |-- uploads/teachers/             -> Uploaded teacher pictures

---------------------------------------------------------------------
3A. INTERFACE DESIGN SYSTEM  ("School Register")
---------------------------------------------------------------------
 Colours : deep forest #143A2B (sidebar, headings), pale sage canvas
           #EEF2EC, marigold #F2A93B (record chips, active menu item),
           teal-green #1D7A5F (buttons and confirmations).
 Type    : serif headings, system sans body text, monospace for record
           numbers such as TCH-001 and USR-010.
 Shells  : a split screen (forest panel + form) for sign in and
           registration; a fixed sidebar shell for every signed-in page.
 Cards   : white record cards with a coloured left spine - teal for
           normal actions, marigold for look-ups, red for removal.
 Messages: plain sentences that name what happened and what to do next.

 All colours and sizes are defined once as CSS custom properties at the
 top of assets/css/style.css, so the same design can be extended to the
 remaining modules in the final deliverable.

---------------------------------------------------------------------
4. DATABASE TABLES
---------------------------------------------------------------------
 TABLE: admin
   Id [PK] INT | Name VARCHAR(50) | Password VARCHAR(255)
   Emailid VARCHAR(100) | Contact VARCHAR(100)

 TABLE: user
   User_id [PK] INT | UserName VARCHAR(50) | Password VARCHAR(255)
   Email VARCHAR(100) | Contact VARCHAR(100)

 TABLE: teacher
   teacherid [PK] INT | teacherName VARCHAR(100)
   teacherPicture VARCHAR(255)   (stores the uploaded image file name)

 NOTE: The Password columns use VARCHAR(255) instead of VARCHAR(50)
 because new passwords are stored using PHP password_hash() with the
 bcrypt algorithm, which produces a 60-character string. This directly
 satisfies non-functional requirement NFR-SEC-02 of the SRS document.

---------------------------------------------------------------------
5. TASK-WISE IMPLEMENTATION SUMMARY
---------------------------------------------------------------------
 Task 1  : "admin" table created with a seeded administrator account.
           Login checks the id/password and shows an error if wrong.
 Task 2  : "user" table created for parent (client) accounts.
 Task 3  : "teacher" table created with picture support.
 Task 4  : Home page with Home | Admin | Parent navigation links.
 Task 5  : Admin login form; invalid credentials show
           "Invalid Username or Password. Please try again."
 Task 6  : Admin dashboard with Add / Update / Delete / Logout menu
           and a live list of all teacher records.
 Task 7  : Add Teacher form. Success -> "Teacher record inserted
           successfully!" Empty form -> "Please fill all the required
           fields..." Duplicate ID -> "Teacher ID already exists".
 Task 8  : Update Teacher search. Missing record -> "Record Not Found".
 Task 9  : Existing record is loaded into an editable form; clicking
           Update saves the change and shows a success message.
 Task 10 : Delete Teacher search. Missing record -> "Teacher Not Found".
           Existing record is shown with a Delete button (with a
           JavaScript confirmation prompt).
 Task 11 : Admin Logout destroys the session and returns to the login
           page showing "You have successfully logged out."
 Task 12 : Parent main interface with Registration and Login. Duplicate
           signup -> "The user is already registered."
 Task 13 : Parent login; invalid credentials show
           "Invalid User Name or Password. Please try again."
 Task 14 : Parent dashboard listing every teacher (ID, name, picture).
 Task 15 : Update Profile page for the logged-in parent.
 Task 16 : Parent Logout with a confirmation message.

---------------------------------------------------------------------
6. SECURITY MEASURES APPLIED (mapped to the SRS)
---------------------------------------------------------------------
 * NFR-SEC-01 : All database queries use MySQLi prepared statements
                with bound parameters, preventing SQL Injection.
 * NFR-SEC-02 : Passwords are hashed with password_hash() / bcrypt and
                verified with password_verify().
 * NFR-SEC-03 : Every value printed to the browser is escaped through
                the helper function e() (htmlspecialchars), preventing
                Cross-Site Scripting (XSS).
 * Session guards (require_admin / require_parent) block direct URL
   access to protected pages, and session_regenerate_id() is called on
   every successful login to prevent session fixation.
 * File uploads are restricted to JPG / JPEG / PNG / GIF and to a
   maximum size of 2 MB, and are renamed before being saved.

---------------------------------------------------------------------
7. IMPORTANT NOTE
---------------------------------------------------------------------
 This submission covers the PROTOTYPE PHASE only. It implements the
 admin teacher-management module and the parent registration/login/
 profile module. The remaining modules described in the SRS (PTM slot
 booking, fee payment gate, DMC and grade management, virtual meeting
 room and the feedback system) will be delivered in the FINAL
 DELIVERABLE of the project.
=====================================================================
