TELSPAY MEMBER APP v2026.5.0 — REPAIR R1
============================================================

PURPOSE
This repair keeps the current v2026.5.0 application and resolves:
- registration data-protection bind/storage failures;
- missing internal-transfer and loan/consent signing configuration;
- loan application schema/submission failures;
- legacy Transaction PIN locks in bills and transfers;
- PIN-protected member Documents with QR-signed PDFs;
- browser autocomplete across first-party application forms.

SAFE DEPLOYMENT ORDER
1. Back up the current application files and database.
2. In phpMyAdmin, select the live SACCO database and import:
   database/telspay_v2026_5_0_repair_r1.sql
   Confirm that all five results at the bottom display PASS.
3. Import database/uganda_bill_payments_2026.sql if you want to pre-install
   the Uganda bill catalogue. The application can also install this file
   automatically when the bill-payment page first opens.
4. Upload the contents of public_html/invest.telspay.com over the current app.
5. Put secure_keys/telspay_secure.php at:
   /home/CPANEL_USER/secure_keys/telspay_secure.php
   It must remain outside public_html and use permission 0600 where available.
6. Confirm that HTTPS is active and PHP can write to the configured protected
   receipt/KYC paths.
7. Sign in with a test member, create or upgrade the 4-digit Transaction PIN,
   then test registration consent, internal transfer, bill payment, loan
   submission, guarantor response, and Profile > Documents.

TRANSACTION PIN REPAIR BEHAVIOUR
- A member with no PIN is marked SETUP_REQUIRED and can sign in to create one.
- A member with a legacy plaintext PIN is marked LEGACY_UPGRADE and must upgrade.
- A valid password-hashed PIN remains ACTIVE.
- Only accounts with three recorded failed attempts remain LOCKED.
- A stale legacy “Locked” flag with zero failed attempts no longer prevents
  first-time PIN enrolment.

SIGNING KEY BEHAVIOUR
Configured keys in telspay_secure.php always take priority. If an older host is
missing only an internal TELSPAY signing key, the app creates a stable random
key in telspay_system_secrets. Flutterwave, SMTP, SMS, Firebase and other
provider credentials are never generated or replaced by this fallback.

MEMBER DOCUMENTS
Profile > Documents requires the member's hashed Transaction PIN and a full
confirmation slide. Access lasts five minutes. Every view/download is audited.
Generated PDFs include a QR authenticity signature and a Uganda data-protection
notice. The public QR check exposes no member identity, balance or document body.

SUPPORT
Retain the support reference shown to a member and match it with the PHP error
log. Do not send database passwords, Flutterwave keys or telspay_secure.php by
email or chat.
