<?php
declare(strict_types=1);
session_start();

/**
 * Project Manager (single page) — Light “store-like” UI
 * Files: phpmanager.php + projects.json
 */

const DATA_FILE = __DIR__ . '/projects.json';

function h(string $s): string { return htmlspecialchars($s, ENT_QUOTES, 'UTF-8'); }

function nowStamp(): string {
  // Optional NZ timezone:
  // date_default_timezone_set('Pacific/Auckland');
  return date('Y-m-d H:i:s');
}

function loadData(): array {
  if (!file_exists(DATA_FILE)) {
    $init = ["projects" => []];
    file_put_contents(DATA_FILE, json_encode($init, JSON_PRETTY_PRINT | JSON_UNESCAPED_SLASHES));
    return $init;
  }
  $raw = file_get_contents(DATA_FILE);
  $data = json_decode($raw ?: '', true);
  if (!is_array($data) || !isset($data["projects"]) || !is_array($data["projects"])) {
    return ["projects" => []];
  }

  // Normalize missing fields so old JSON keeps working
  foreach ($data["projects"] as &$p) {
    if (!is_array($p)) $p = [];
    $p["name"] = (string)($p["name"] ?? "");
    $p["image"] = (string)($p["image"] ?? "");
    $p["description"] = (string)($p["description"] ?? "");
    if (!isset($p["versions"]) || !is_array($p["versions"])) $p["versions"] = [];
    foreach ($p["versions"] as &$v) {
      if (!is_array($v)) $v = [];
      $v["version"] = (string)($v["version"] ?? "");
      $v["url"] = (string)($v["url"] ?? "");
      $v["notes"] = (string)($v["notes"] ?? "");
      $v["added"] = (string)($v["added"] ?? "");
    }
    unset($v);
  }
  unset($p);

  return $data;
}

function saveData(array $data): bool {
  $fp = fopen(DATA_FILE, 'c+');
  if (!$fp) return false;
  if (!flock($fp, LOCK_EX)) { fclose($fp); return false; }

  ftruncate($fp, 0);
  rewind($fp);
  $json = json_encode($data, JSON_PRETTY_PRINT | JSON_UNESCAPED_SLASHES);
  $ok = ($json !== false) && (fwrite($fp, $json) !== false);

  fflush($fp);
  flock($fp, LOCK_UN);
  fclose($fp);
  return $ok;
}

function normalizeName(string $name): string {
  $name = trim($name);
  $name = preg_replace('/\s+/', ' ', $name);
  return $name ?? '';
}

function isValidProjectLink(string $url): bool {
  $url = trim($url);
  if ($url === '') return false;
  if (!preg_match('/\.(html|php)(\?.*)?$/i', $url)) return false;

  // Allow relative or absolute http(s)
  if (preg_match('#^https?://#i', $url)) return true;
  if (preg_match('#^[a-zA-Z0-9_\-./]+(\?.*)?$#', $url)) return true;
  return false;
}

function isValidImageLink(string $url): bool {
  $url = trim($url);
  if ($url === '') return true; // optional
  // Allow relative or absolute; common image extensions
  if (!preg_match('/\.(png|jpg|jpeg|webp|gif|svg)(\?.*)?$/i', $url)) return false;

  if (preg_match('#^https?://#i', $url)) return true;
  if (preg_match('#^[a-zA-Z0-9_\-./]+(\?.*)?$#', $url)) return true;
  return false;
}

function findProjectIndex(array $projects, string $name): int {
  foreach ($projects as $i => $p) {
    if (isset($p['name']) && strcasecmp((string)$p['name'], $name) === 0) return $i;
  }
  return -1;
}

function sortProjectsAndVersions(array &$data): void {
  usort($data['projects'], fn($a, $b) => strcasecmp((string)($a['name'] ?? ''), (string)($b['name'] ?? '')));

  foreach ($data['projects'] as &$p) {
    if (!isset($p['versions']) || !is_array($p['versions'])) $p['versions'] = [];
    usort($p['versions'], function($x, $y){
      $vx = (string)($x['version'] ?? '');
      $vy = (string)($y['version'] ?? '');
      $looks = fn($v) => (bool)preg_match('/^\d+(\.\d+)*([a-zA-Z0-9\-\+\.]*)?$/', $v);
      if ($looks($vx) && $looks($vy)) return version_compare($vy, $vx);
      return strcasecmp($vy, $vx);
    });
  }
  unset($p);
}

if (!isset($_SESSION['csrf'])) $_SESSION['csrf'] = bin2hex(random_bytes(16));

$data = loadData();
sortProjectsAndVersions($data);

$notice = '';
$error  = '';
$action = $_POST['action'] ?? $_GET['action'] ?? '';

/* ---------- HANDLE POST ACTIONS ---------- */
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
  $csrf = (string)($_POST['csrf'] ?? '');
  if (!hash_equals($_SESSION['csrf'], $csrf)) {
    $error = "Security token mismatch. Refresh and try again.";
  } else {

    if ($action === 'add') {
      $selectedProject = normalizeName((string)($_POST['project'] ?? ''));
      $newProject      = normalizeName((string)($_POST['new_project'] ?? ''));
      $projectName     = $newProject !== '' ? $newProject : $selectedProject;

      $image       = trim((string)($_POST['image'] ?? ''));
      $description = trim((string)($_POST['description'] ?? ''));
      $version     = trim((string)($_POST['version'] ?? ''));
      $url         = trim((string)($_POST['url'] ?? ''));
      $notes       = trim((string)($_POST['notes'] ?? ''));

      if ($projectName === '') {
        $error = "Project name is required.";
      } elseif ($version === '') {
        $error = "Version is required.";
      } elseif (!isValidProjectLink($url)) {
        $error = "URL must be a relative path or http(s) link ending in .html or .php.";
      } elseif (!isValidImageLink($image)) {
        $error = "Image URL must be blank or end in .png/.jpg/.jpeg/.webp/.gif/.svg (relative or http(s)).";
      } else {

        $idx = findProjectIndex($data['projects'], $projectName);

        if ($idx === -1) {
          $data['projects'][] = [
            "name" => $projectName,
            "image" => $image,
            "description" => $description,
            "versions" => []
          ];
          $idx = count($data['projects']) - 1;
        } else {
          // If user provided image/description, update the project (optional)
          if ($image !== '') $data['projects'][$idx]['image'] = $image;
          if ($description !== '') $data['projects'][$idx]['description'] = $description;
        }

        if (!isset($data['projects'][$idx]['versions']) || !is_array($data['projects'][$idx]['versions'])) {
          $data['projects'][$idx]['versions'] = [];
        }

        // Prevent exact duplicate (same version + url)
        foreach ($data['projects'][$idx]['versions'] as $v) {
          if (($v['version'] ?? '') === $version && ($v['url'] ?? '') === $url) {
            $notice = "That exact version+URL already exists for this project.";
            // re-load & render
            $data = loadData();
            sortProjectsAndVersions($data);
            goto render;
          }
        }

        $data['projects'][$idx]['versions'][] = [
          "version" => $version,
          "url" => $url,
          "notes" => $notes,
          "added" => nowStamp()
        ];

        sortProjectsAndVersions($data);

        if (saveData($data)) {
          $notice = "Saved: {$projectName} v{$version}";
        } else {
          $error = "Failed to save projects.json (check permissions).";
        }

        $data = loadData();
        sortProjectsAndVersions($data);
      }
    }

    if ($action === 'delete_version') {
      $p = normalizeName((string)($_POST['p'] ?? ''));
      $v = (string)($_POST['v'] ?? '');
      $u = (string)($_POST['u'] ?? '');

      $pIdx = findProjectIndex($data['projects'], $p);
      if ($pIdx === -1) {
        $error = "Project not found.";
      } else {
        $versions = $data['projects'][$pIdx]['versions'] ?? [];
        $new = [];
        $removed = 0;

        foreach ($versions as $item) {
          $vv = (string)($item['version'] ?? '');
          $uu = (string)($item['url'] ?? '');
          if ($vv === $v && $uu === $u && $removed === 0) {
            $removed++;
            continue;
          }
          $new[] = $item;
        }

        $data['projects'][$pIdx]['versions'] = $new;

        // Remove project if empty
        if (count($new) === 0) {
          array_splice($data['projects'], $pIdx, 1);
        }

        sortProjectsAndVersions($data);

        if (saveData($data)) {
          $notice = "Deleted entry.";
        } else {
          $error = "Failed to save projects.json (check permissions).";
        }

        $data = loadData();
        sortProjectsAndVersions($data);
      }
    }
  }
}

render:

// Dropdown list
$projectNames = array_map(fn($p) => (string)($p['name'] ?? ''), $data['projects'] ?? []);
?>
<!doctype html>
<html lang="en">
<head>
  <meta charset="utf-8">
  <meta name="viewport" content="width=device-width, initial-scale=1">
  <title>Project Store Manager</title>
  <style>
    :root{
      --bg: #f4f7fb;
      --card: #ffffff;
      --text: #0f172a;
      --muted: #64748b;
      --line: #e2e8f0;
      --brand: #2563eb;
      --brand2:#38bdf8;
      --danger:#ef4444;
      --shadow: 0 10px 30px rgba(15, 23, 42, 0.08);
      --shadow2: 0 6px 18px rgba(15, 23, 42, 0.08);
      --radius: 18px;
    }

    *{ box-sizing:border-box; }
    body{
      margin:0;
      font-family: ui-sans-serif, system-ui, -apple-system, Segoe UI, Roboto, Helvetica, Arial;
      background:
        radial-gradient(1200px 600px at 20% -10%, rgba(56,189,248,0.22), transparent 55%),
        radial-gradient(900px 500px at 85% 0%, rgba(37,99,235,0.18), transparent 55%),
        var(--bg);
      color: var(--text);
    }

    .wrap{ max-width: 1180px; margin: 0 auto; padding: 22px; }
    header{
      display:flex;
      align-items:flex-end;
      justify-content:space-between;
      gap:16px;
      margin-bottom: 16px;
    }
    h1{ margin:0; font-size: 26px; letter-spacing: -0.3px; }
    .sub{ margin:6px 0 0; color: var(--muted); font-size: 14px; }
    .pill{
      display:inline-flex; align-items:center; gap:8px;
      padding: 8px 12px;
      border: 1px solid var(--line);
      background: rgba(255,255,255,0.85);
      border-radius: 999px;
      box-shadow: var(--shadow2);
      color: var(--muted);
      font-size: 12px;
      white-space:nowrap;
    }

    .grid{
      display:grid;
      grid-template-columns: 1fr;
      gap: 16px;
      align-items:start;
    }
    @media(min-width: 980px){
      .grid{ grid-template-columns: 400px 1fr; }
    }

    .card{
      background: var(--card);
      border: 1px solid var(--line);
      border-radius: var(--radius);
      box-shadow: var(--shadow);
      overflow:hidden;
    }

    .card-head{
      padding: 16px 16px 12px;
      border-bottom: 1px solid var(--line);
      display:flex;
      align-items:center;
      justify-content:space-between;
      gap: 10px;
    }
    .card-title{
      margin:0;
      font-size: 16px;
      letter-spacing:-0.2px;
    }
    .card-body{ padding: 16px; }

    label{
      display:block;
      margin: 12px 0 6px;
      font-size: 12px;
      color: var(--muted);
    }

    input, select, textarea{
      width:100%;
      padding: 11px 12px;
      border-radius: 14px;
      border: 1px solid var(--line);
      background: #ffffff;
      color: var(--text);
      outline: none;
      box-shadow: 0 1px 0 rgba(15,23,42,0.02);
    }
    textarea{ min-height: 90px; resize: vertical; }
    input:focus, select:focus, textarea:focus{
      border-color: rgba(37,99,235,0.55);
      box-shadow: 0 0 0 4px rgba(37,99,235,0.14);
    }

    .row{ display:flex; gap: 12px; }
    .row > div{ flex:1; }

    .btn{
      border: none;
      cursor: pointer;
      border-radius: 14px;
      padding: 11px 14px;
      font-weight: 750;
      color: #fff;
      background: linear-gradient(135deg, var(--brand), var(--brand2));
      box-shadow: 0 10px 18px rgba(37,99,235,0.18);
    }
    .btn:active{ transform: translateY(1px); }

    .btn-ghost{
      border: 1px solid var(--line);
      background: #fff;
      color: var(--muted);
      border-radius: 12px;
      padding: 8px 10px;
      cursor:pointer;
    }

    .btn-danger{
      border: 1px solid rgba(239,68,68,0.35);
      background: rgba(239,68,68,0.06);
      color: var(--danger);
      border-radius: 12px;
      padding: 8px 10px;
      cursor:pointer;
    }

    .notice, .error{
      border-radius: 16px;
      padding: 12px 14px;
      margin: 12px 0 16px;
      border: 1px solid var(--line);
      background: rgba(255,255,255,0.8);
      box-shadow: var(--shadow2);
    }
    .notice{ border-left: 5px solid rgba(34,197,94,0.9); }
    .error{ border-left: 5px solid rgba(239,68,68,0.9); }

    /* Store-like project cards */
    .store{
      padding: 16px;
      display:grid;
      grid-template-columns: repeat(auto-fit, minmax(260px, 1fr));
      gap: 16px;
    }

    .proj-card{
      border: 1px solid var(--line);
      background: #fff;
      border-radius: 18px;
      overflow:hidden;
      box-shadow: var(--shadow2);
      display:flex;
      flex-direction:column;
      min-height: 240px;
    }

    .cover{
      position:relative;
      height: 150px;
      background: linear-gradient(135deg, rgba(37,99,235,0.18), rgba(56,189,248,0.18));
    }
    .cover img{
      width:100%;
      height:100%;
      object-fit: cover;     /* ✅ “crop” to same size */
      object-position: center;
      display:block;
    }
    .cover .fallback{
      position:absolute; inset:0;
      display:flex; align-items:center; justify-content:center;
      color: rgba(15,23,42,0.55);
      font-weight: 700;
      letter-spacing: -0.2px;
    }

    .proj-body{ padding: 14px; display:flex; flex-direction:column; gap:10px; }
    .proj-title{
      display:flex; align-items:center; justify-content:space-between; gap:10px;
    }
    .proj-title h3{ margin:0; font-size: 16px; letter-spacing:-0.2px; }
    .badge{
      display:inline-flex; align-items:center;
      padding: 4px 10px;
      border-radius: 999px;
      background: rgba(37,99,235,0.08);
      color: rgba(37,99,235,0.95);
      border: 1px solid rgba(37,99,235,0.22);
      font-size: 12px;
      font-weight: 700;
      white-space:nowrap;
    }

    .desc{
      color: var(--muted);
      font-size: 13px;
      line-height: 1.35;
      min-height: 34px;
    }

    details{
      border-top: 1px solid var(--line);
      margin-top: 6px;
      padding-top: 10px;
    }
    summary{
      cursor:pointer;
      color: var(--brand);
      font-weight: 750;
      font-size: 13px;
      list-style:none;
    }
    summary::-webkit-details-marker{ display:none; }

    .version{
      display:flex;
      justify-content:space-between;
      gap: 10px;
      padding: 10px 0;
      border-bottom: 1px dashed rgba(226,232,240,0.9);
    }
    .version:last-child{ border-bottom:none; }

    .v-left{ display:flex; flex-direction:column; gap: 4px; min-width: 0; }
    .v-top{ display:flex; gap: 10px; align-items:center; flex-wrap:wrap; }
    .vtag{
      font-size: 12px;
      font-weight: 800;
      color: #0b2a6f;
      background: rgba(56,189,248,0.18);
      border: 1px solid rgba(56,189,248,0.35);
      padding: 3px 10px;
      border-radius: 999px;
      white-space:nowrap;
    }
    .link{
      color: var(--brand);
      text-decoration:none;
      font-weight: 800;
      font-size: 13px;
    }
    .link:hover{ text-decoration: underline; }
    .meta{ color: var(--muted); font-size: 12px; overflow:hidden; text-overflow:ellipsis; white-space:nowrap; max-width: 100%; }
    .notes{ color: var(--text); font-size: 12.5px; line-height: 1.35; }
    code{ background: rgba(15,23,42,0.05); padding: 2px 6px; border-radius: 8px; }
    .foot{ padding: 0 16px 16px; color: var(--muted); font-size: 12px; }
  </style>
</head>
<body>
  <div class="wrap">
    <header>
      <div>
        <h1>🎮 Project Store Manager</h1>
        <p class="sub">A clean “game store” view for your projects — with versions, notes, and links.</p>
      </div>
      <div class="pill">📁 Data: <code>projects.json</code></div>
    </header>

    <?php if ($notice): ?>
      <div class="notice"><?= h($notice) ?></div>
    <?php endif; ?>
    <?php if ($error): ?>
      <div class="error"><?= h($error) ?></div>
    <?php endif; ?>

    <div class="grid">
      <!-- Left: Add form -->
      <div class="card">
        <div class="card-head">
          <h2 class="card-title">Add / Update</h2>
          <span style="color:var(--muted); font-size:12px;">Projects + Versions</span>
        </div>
        <div class="card-body">
          <form method="post" action="">
            <input type="hidden" name="csrf" value="<?= h($_SESSION['csrf']) ?>">
            <input type="hidden" name="action" value="add">

            <label>Project (choose existing)</label>
            <select name="project">
              <option value="">— Select —</option>
              <?php foreach ($projectNames as $pn): ?>
                <option value="<?= h($pn) ?>"><?= h($pn) ?></option>
              <?php endforeach; ?>
            </select>

            <label>…or create a new project</label>
            <input type="text" name="new_project" placeholder="e.g. Nelson Airport Dashboard">

            <label>Project image URL (optional)</label>
            <input type="text" name="image" placeholder="e.g. https://site.com/img/banner.jpg or images/banner.jpg">

            <label>Project description (optional)</label>
            <textarea name="description" placeholder="What is this project? What does it do?"></textarea>

            <div class="row">
              <div>
                <label>Version</label>
                <input type="text" name="version" placeholder="e.g. 1.2.0" required>
              </div>
            </div>

            <label>URL to this version (must end in .html or .php)</label>
            <input type="text" name="url" placeholder="e.g. apps/tool/v3/index.html" required>

            <label>Version notes (optional)</label>
            <textarea name="notes" placeholder="What changed? Bug fixes? New feature?"></textarea>

            <div style="margin-top:14px;">
              <button class="btn" type="submit">Save entry</button>
            </div>

            <p style="margin:10px 0 0; color:var(--muted); font-size:12px;">
              If you add an image/description while selecting an existing project, it will update that project’s card.
            </p>
          </form>
        </div>
        <div class="foot">Tip: Images are displayed as a consistent cropped banner automatically.</div>
      </div>

      <!-- Right: Store cards -->
      <div class="card">
        <div class="card-head">
          <h2 class="card-title">Your Projects</h2>
          <span style="color:var(--muted); font-size:12px;"><?= count($data['projects'] ?? []) ?> total</span>
        </div>

        <?php if (empty($data['projects'])): ?>
          <div class="card-body">
            <p style="color:var(--muted); margin:0;">No projects yet — add your first one on the left 😄</p>
          </div>
        <?php else: ?>
          <div class="store">
            <?php foreach ($data['projects'] as $proj): ?>
              <?php
                $pName = (string)($proj['name'] ?? '');
                $pImg  = trim((string)($proj['image'] ?? ''));
                $pDesc = trim((string)($proj['description'] ?? ''));
                $versions = $proj['versions'] ?? [];
                if (!is_array($versions)) $versions = [];
                $count = count($versions);

                // Determine "latest" (first after sort)
                $latest = $count ? $versions[0] : null;
                $latestVersion = $latest ? (string)($latest['version'] ?? '') : '';
                $latestUrl     = $latest ? (string)($latest['url'] ?? '') : '';
              ?>

              <div class="proj-card">
                <div class="cover">
                  <?php if ($pImg !== ''): ?>
                    <img src="<?= h($pImg) ?>" alt="<?= h($pName) ?> cover" loading="lazy" onerror="this.style.display='none'; this.parentNode.querySelector('.fallback').style.display='flex';">
                    <div class="fallback" style="display:none;">No image</div>
                  <?php else: ?>
                    <div class="fallback">No image</div>
                  <?php endif; ?>
                </div>

                <div class="proj-body">
                  <div class="proj-title">
                    <h3><?= h($pName) ?></h3>
                    <span class="badge"><?= $count ?> version<?= $count===1?'':'s' ?></span>
                  </div>

                  <div class="desc">
                    <?= $pDesc !== '' ? h($pDesc) : 'No description yet. Add one from the form.' ?>
                  </div>

                  <?php if ($latest): ?>
                    <div style="display:flex; align-items:center; justify-content:space-between; gap:10px;">
                      <div style="display:flex; align-items:center; gap:10px; min-width:0;">
                        <span class="vtag">v<?= h($latestVersion) ?></span>
                        <a class="link" href="<?= h($latestUrl) ?>" target="_blank" rel="noopener">Open latest</a>
                      </div>
                      <span class="meta" title="<?= h($latestUrl) ?>"><?= h($latestUrl) ?></span>
                    </div>
                  <?php else: ?>
                    <div class="meta">No versions yet.</div>
                  <?php endif; ?>

                  <?php if ($count): ?>
                    <details>
                      <summary>View all versions</summary>

                      <?php foreach ($versions as $ver): ?>
                        <?php
                          $v = (string)($ver['version'] ?? '');
                          $u = (string)($ver['url'] ?? '');
                          $n = trim((string)($ver['notes'] ?? ''));
                          $a = (string)($ver['added'] ?? '');
                        ?>
                        <div class="version">
                          <div class="v-left">
                            <div class="v-top">
                              <span class="vtag">v<?= h($v) ?></span>
                              <a class="link" href="<?= h($u) ?>" target="_blank" rel="noopener">Open</a>
                              <span class="meta" title="<?= h($u) ?>"><?= h($u) ?></span>
                            </div>

                            <?php if ($n !== ''): ?>
                              <div class="notes"><?= h($n) ?></div>
                            <?php endif; ?>

                            <?php if ($a !== ''): ?>
                              <div class="meta">Added: <?= h($a) ?></div>
                            <?php endif; ?>
                          </div>

                          <form method="post" action="" onsubmit="return confirm('Delete this version entry?');" style="margin:0;">
                            <input type="hidden" name="csrf" value="<?= h($_SESSION['csrf']) ?>">
                            <input type="hidden" name="action" value="delete_version">
                            <input type="hidden" name="p" value="<?= h($pName) ?>">
                            <input type="hidden" name="v" value="<?= h($v) ?>">
                            <input type="hidden" name="u" value="<?= h($u) ?>">
                            <button class="btn-danger" type="submit">Delete</button>
                          </form>
                        </div>
                      <?php endforeach; ?>
                    </details>
                  <?php endif; ?>
                </div>
              </div>
            <?php endforeach; ?>
          </div>
        <?php endif; ?>

        <div class="foot">
          Only links to <b>.html</b> / <b>.php</b> are accepted for version URLs.
        </div>
      </div>
    </div>
  </div>
</body>
</html>