# HRMS Project

Two folders:

- `frontend/` — your existing React (Vite) app, Paxes admin template UI
- `backend/`  — new Express.js + Node.js API that provides the login flow

The frontend already expected these exact API calls (this was in your code
already, in `src/api/axios.js` and `src/context/AuthContext.jsx`) — the
backend below was built to match them exactly, so nothing in your frontend
API-calling code had to change:

- `POST /api/auth/login` → `{ token, user }`
- `GET  /api/auth/me` → `{ user }`
- `POST /api/auth/logout`
- `POST /api/auth/change-password`

What I changed in `frontend/`: wired `AuthProvider` in `main.jsx`, added the
`/login` route and wrapped the dashboard routes with `ProtectedRoute` in
`App.jsx` (it existed but wasn't used), made the API URL configurable via
`.env`, and connected the topbar's user name / Log Out link to real auth
instead of hardcoded "David Dev".

## 1. Backend setup (do this first)

```
cd backend
cp .env.example .env
npm install
```

Edit `backend/.env`: set `DB_HOST`, `DB_USER`, `DB_PASSWORD`, `DB_NAME` to
match your MySQL server (defaults assume `hrms_db` on `127.0.0.1`), and
change `JWT_SECRET` to any long random string.

Then:
```
npm start
```

You should see:
```
Using MySQL table "users" for users — no seeding needed.
HRMS backend running on http://localhost:5000
```

Log in with a row that already exists in your `users` table — the
`password` column must be a bcrypt hash (starts with `$2a$`, `$2b$`, or
`$2y$`), not plain text.

## 2. Frontend setup

```
cd frontend
cp .env.example .env
npm install --legacy-peer-deps
npm run dev
```

`--legacy-peer-deps` is needed once because `react-pdf` in this template
still lists React 18 as a peer while the project uses React 19 — that
conflict already existed in your template before I touched anything, it's
not related to the backend.

Open the URL Vite prints (usually `http://localhost:5173`). You'll land on
`/login` first since routes are now protected — log in with the seeded
admin account above.

## 3. Putting it on your Ubuntu server

- Backend: run `npm install && npm start` inside `backend/` (use `pm2` or a
  systemd service to keep it running instead of a plain terminal).
- Frontend: run `npm run build` inside `frontend/` — this outputs a `dist/`
  folder of static files. Serve that with nginx, same as any static site.
- In `frontend/.env`, set `VITE_API_URL` to your backend's real address
  (e.g. `http://your-server-ip:5000/api`) **before** running `npm run
  build` — Vite bakes this value in at build time.
- In `backend/.env`, set `CORS_ORIGIN` to your frontend's real address
  (e.g. `https://your-domain`). To allow more than one frontend, list the
  origins separated by commas, such as
  `http://localhost:5173,https://your-domain`.
- The local backend uses `backend/.env`. For the production server, copy
  `backend/.env.production.example` to `backend/.env.production`, set a
  secure database password and JWT secret, then start it with
  `NODE_ENV=production`. The production file overrides the local settings.
  `127.0.0.1` means MySQL is running on the same machine as that backend;
  it points to your local MySQL when developing and the server's MySQL when
  deployed.

## Notes

- User login now reads/writes MySQL (`hrms_db.users` — `id, name, email,
  password, created_at`), not a JSON file. Set `DB_HOST`, `DB_USER`,
  `DB_PASSWORD`, `DB_NAME` in `backend/.env` to match your server before
  running `npm start`. If your table/column names differ, edit the `TABLE`
  and `COL_*` constants at the top of `backend/src/data/userStore.js`.
- Passwords are bcrypt hashes in the `password` column — `bcryptjs`
  understands `$2a$`/`$2b$`/`$2y$` prefixes natively, so hashes generated
  by PHP/Laravel or Node both work without conversion.
- Login sessions are JWTs valid for 7 days (`JWT_EXPIRES_IN` in
  `backend/.env`).
- There's no user-creation endpoint yet — insert rows directly (e.g. via
  phpMyAdmin) with a bcrypt-hashed password. Ask if you want a signup or
  admin "create user" endpoint added.
