# ZTG Teltonika Kill Switch Portal (PHP 8.1 + MySQL)

A multi-user portal to toggle a Teltonika RutOS firewall rule (e.g. rule ID **20**) ON/OFF per device, with:
- User login + roles (admin/operator/viewer)
- Device inventory (IP/DNS, port, HTTPS, API user/pass, rule ID)
- Block (60 min) + Unblock + Auto-revert cron worker
- Daily bandwidth capture + reporting
- Audit log per device

## Requirements
- PHP 8.1+
- MySQL/MariaDB
- Web server (Apache/Nginx)
- PHP extensions: `pdo_mysql`, `curl`, `openssl`

## Install
1. Create a database and user.
2. Import `sql/schema.sql`
3. Copy `config/config.php.example` to `config/config.php` and edit:
   - DB credentials
   - `APP_KEY` (32+ chars). A generated example is included below.
4. Point your web root to the `/public` directory.

## Default admin login
After importing the schema, a default admin is created:
- Email: `admin@example.com`
- Password: `ChangeMe123!`

Change this immediately after first login.

## Cron
Auto-revert worker, run every minute:

```bash
* * * * * /usr/bin/php /path/to/project/cron/revert.php >/dev/null 2>&1
```

Daily bandwidth collector, run at server midnight:

```bash
0 0 * * * /usr/bin/php /path/to/project/cron/bandwidth_daily.php >/dev/null 2>&1
```

## Teltonika calls used
- `POST /api/login` -> token
- `PUT /api/firewall/traffic_rules/config/{rule_id}` with `{"data":{"enabled":"1"}}` or `"0"`
- `GET /api/firewall/traffic_rules/config` to read current enabled state (refresh)
- `GET /api/interfaces/status` to read bandwidth interface counters

## Existing installs
For an existing database, apply `sql/bandwidth_migration.sql` after backing up the database.

## Generated APP_KEY suggestion
`RLq80kV62sI90Lxbk4v3gxxAQz5M6sz2`
