========================================================================
 SSSTIKTOK — YOUR REAL WEBSITE + FOOTER MANAGER PANEL (READY TO USE)
========================================================================

This is YOUR complete original website (navbar with hamburger + language
switcher, hero, all sections, all 19 languages, your real footer design)
with the secure Footer Manager admin panel added on top. Nothing of your
design was changed — only the managed footer link row + a manageable
copyright were added inside your existing footer.

------------------------------------------------------------------------
 RUN IT
------------------------------------------------------------------------
LOCAL:
    npm install
    npm start                (or:  npm run dev)
    Website:  http://localhost:3000/
    Panel:    http://localhost:3000/footer

    Different port:  PORT=4000 npm start

PRODUCTION:
    npm install
    pm2 restart all          (or cPanel "Restart", or npm start)

------------------------------------------------------------------------
 ADMIN PANEL  (English UI, always)
------------------------------------------------------------------------
URL:    https://YOUR-DOMAIN/footer
Login:  footerlink  /  8876
Change: config/footer_admin_config.js  (ADMIN_USERNAME / ADMIN_PASSWORD),
        then restart once.

Features:
  - Add / edit / delete / enable-disable / reorder footer links
  - Per-link COLOUR: 10 presets + custom picker, with a live colour preview
  - Per-link BOLD / ITALIC / FONT SIZE
  - Row ALIGNMENT (left / center / right), SPACE between links,
    MAX links per row (1–15; extra links wrap to the next row, centered)
  - Editable COPYRIGHT text (supports {year})
  - Live footer preview inside the panel

------------------------------------------------------------------------
 YOUR EXISTING LINKS ARE PRE-LOADED
------------------------------------------------------------------------
The panel starts with your current links:
    C168 | CM88 | 78win | GK88 | YG88 | hit club   (red)
so it is never empty.
  >> Their URLs are placeholders (e.g. https://c168.example). Open
     /footer, click Edit on each link, set the REAL URL, and Save. <<

------------------------------------------------------------------------
 HOW THE FOOTER WAS WIRED
------------------------------------------------------------------------
Inside your existing footer (in every language page), just below the
copyright line, this line was added:

    {% include 'partials/footer_links.html' %}

and the copyright line was made manageable (your original text is kept as
a fallback). Everything else in your pages is untouched.

Changes appear on the site INSTANTLY after you Save in the panel — no
restart needed for content. Restart only after changing credentials.

------------------------------------------------------------------------
 FILES ADDED
------------------------------------------------------------------------
    config/footer_admin_config.js          credentials + security
    footer/footer-manager.js               data layer (JSON + cache + seed)
    footer/footer-routes.js                admin routes, auth, CSRF
    templates/partials/footer_links.html   managed footer link row
    templates/admin/footer_login.html      login page
    templates/admin/footer_manager.html    dashboard
    static/admin/footer-admin.css / .js    admin UI (admin pages only)
    data/                                  stores footer.json (auto-created)

FILES MODIFIED
    app.js         mounts /footer routes, exposes footer data to pages,
                   skips ad injection on the admin panel.
    package.json   fixed "dev" script (was nodemon index.js -> node app.js).
    robots.txt     added "Disallow: /footer".
    templates/**/  every language page: added the include + managed
                   copyright inside your existing footer.

REMOVED (unused junk, not referenced by app.js):
    fix_*.js, translate_*.js, check_deepl_langs.js, zip_creator.js,
    test_app.html, test_demo.html, error logs.
    (node_modules removed too — restored by `npm install`.)

------------------------------------------------------------------------
 NOTES
------------------------------------------------------------------------
- COLOURS: the hex box in "Link appearance" is the field that gets saved
  (name="color"). Presets and the colour picker just write into it, so the
  chosen colour is applied even if JavaScript is blocked. An invalid or
  empty hex no longer resets a link to white — the previous colour is kept.
- The panel's own CSS/JS (/static/admin/*) are served with "no-cache" and
  a ?v= version stamp, so an updated panel is never hidden behind an old
  browser cache. The rest of /static keeps the 30-day immutable cache.
  (An old cached copy of these two files was why the colour picker
  appeared to do nothing and why the panel layout looked broken.)
- The npm "uuid moderate vulnerability" warning is safe to ignore (this
  app uses uuid v4 without the affected buffer path). Do NOT run
  "npm audit fix --force" (it makes a breaking uuid upgrade).
- No new npm dependencies were added by the Footer Manager.

SECURITY: server-side signed HttpOnly session cookie, CSRF on all writes,
login rate limiting + generic error, session timeout, optional IP allow
list, admin pages noindex + no-store + out of robots/sitemap, titles
auto-escaped (no XSS), colours hex-only (no CSS injection), font size
clamped, dangerous URL schemes rejected.
========================================================================
