TELSPAY MEMBER APP v2026.5.0 — SECURE WORKFLOW RELEASE
======================================================

This full release includes the v2026.4.4 data-protection bind_param() hotfix.

REQUIRED DEPLOYMENT ORDER
1. Back up the application files and selected TELSPAY database.
   Preserve the existing uploads directory. Member photos, receipts and other
   user-uploaded documents are intentionally excluded from this release ZIP.
2. Install the private telspay_secure.php supplied to the SACCO administrator outside the public web root.
3. Upload and extract this release over the application directory.
4. If not already applied, run:
   database/member_app_operational_security_upgrade_2026_4_0.sql
5. Run the hotfix repair (safe to repeat):
   database/data_protection_consent_repair_2026_4_4.sql
6. Run:
   database/member_app_secure_workflow_upgrade_2026_5_0.sql
7. Run:
   database/member_app_secure_workflow_postcheck_2026_5_0.sql
   Every PASS/FAIL result must say PASS; both numeric anomaly checks must be 0.

PRIVATE CONFIGURATION REQUIRED
- TELSPAY_ADMIN_NOTIFY_EMAIL: valid administrator mailbox.
- TELSPAY_PAYMENT_HMAC_KEY: random secret of at least 32 characters.
- TELSPAY_TRANSFER_HMAC_KEY: separate random secret of at least 32 characters.
- TELSPAY_RECEIPT_HMAC_KEY: separate random secret of at least 32 characters.
- TELSPAY_BANK_RECEIPT_STORAGE_PATH: writable directory outside the public web root.
- Flutterwave secret/public keys and webhook hash.
- SMTP settings used by notifications/email_service.php.
- Tesseract OCR executable (default /usr/bin/tesseract) and PHP GD.

SECURITY NOTES
- Never include telspay_secure.php or production secrets in a downloadable/public ZIP.
- The slide confirmation flags are enforced again on the server.
- Transaction PINs remain one-way password hashes and are never emailed or logged.
- Feedback is emailed only to the configured administrator.
- Bank receipts are re-encoded and stored outside the public web directory.

ACCEPTANCE TESTS
1. First-login PIN: device check, current PIN when applicable, new PIN, confirm, review.
2. Mobile Money: entry, review, PIN popup, slide, banking loader, Flutterwave checkout.
3. Bank receipt: OCR extraction, review, PIN popup, slide, pending transaction email.
4. Loan: all four steps, consent checkbox, PIN popup, slide, pending status 1, two guarantor invitations.
5. Feedback: admin-only email and feedback audit record.
6. Internal transfer and successful Flutterwave deposit/loan repayment emails reach members and admin.
