ZAIAHTRIX2 AUTHENTICATION SECURITY UPGRADE
==========================================

Base: ZAIAHTRIX2_V8_FINAL_9_5_INFINITYFREE_TEST_FIXED_v3-4.zip

Changes in this package:
1. Added secure Remember Me (30 days) using random selector/validator tokens stored server-side under private_security/remember_tokens.
2. Remember-Me credentials are rotated after successful restoration and revoked on logout.
3. Added optional Google OAuth sign-in/sign-up flow:
   - auth/google.php
   - auth/google_callback.php
   - auth/google_complete.php
   It is OFF until GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET are supplied.
   Existing Google users are matched by verified email. New Google users complete phone + role before account creation.
4. Added Google OAuth configuration placeholders to config.php.
5. Removed the testing master-password/admin owner bypass from admin/login.php. Admin access is database-backed only.
6. Existing central authentication/session/role architecture is preserved.

IMPORTANT:
- Google Sign-In cannot become live until a Google OAuth Web Application is created and its credentials are configured.
- The existing fingerprint feature remains compatible with the project but is NOT claimed to be full server-side WebAuthn verification. A true WebAuthn/passkey implementation should be added later with a vetted PHP WebAuthn library rather than hand-rolled cryptographic verification.
- No payment provider code was changed.
- No money/wallet/commission architecture was changed.
- No AI functionality was added.

Validation:
- PHP syntax check: 807 PHP files checked, 0 syntax errors.
