=================================================================
   ZChat 2.0 - Web Forms Edition (modern rewrite)
=================================================================

This readme ships inside zchat-webforms-modern.zip. The download published
as zchat-webforms.zip is the Enterprise Web Forms edition, a precompiled
ASP.NET 4.8 application built from zchat_install_webform.


This is the complete ASP.NET Web Forms 4.8 edition of ZChat. It is the
full application source (Web.config, Global.asax, all pages, App_Code,
handlers, and the visitor widget), plus the SQL install scripts and a
local runner. It is small because ASP.NET Web Forms runs on the .NET
Framework already installed on Windows and is compiled by IIS at runtime,
so it does not ship compiled DLLs the way the ASP.NET Core package does.

Contents
--------
  WebForms\        - The application. Deploy this folder to IIS.
  install-source\  - SQL scripts (schema, seed accounts, feature tables).
  run-webforms.cmd - One-command local demo (Windows + IIS Express).
  run-webforms.ps1 - PowerShell runner with overridable DB and port options.

Not in this edition (ASP.NET Core edition only)
-----------------------------------------------
  The Web Forms edition covers the full day-to-day product below, but the
  following newer capabilities are currently in the ASP.NET Core edition only.
  Choose the Core edition if any of these matter to you:

  - Inbound email channel (support mail arriving as conversations)
  - Two-factor sign-in (TOTP) for agents
  - Proactive triggers targeted by referrer, browser language, or
    returning-visitor count (URL and dwell-time targeting ARE included here)

Features
--------
  - Live operator console: waiting queue, accept, real-time (polling) chat,
    canned replies with /shortcut expansion, two-way typing indicators,
    transfer to another agent or department, presence (online/away/busy),
    new-chat sound + desktop alerts, and keyboard shortcuts.
  - Visitor widget: pre-chat + offline forms with department routing, emoji
    picker, file uploads (both directions), read receipts, agent-typing and
    reconnect indicators, proactive greeting from chat triggers, conversation
    resume, background-tab new-message alert, and full accessibility
    (dialog semantics, ARIA live region, Escape, focus management,
    reduced-motion) - about 16 KB.
  - Admin: dashboard (live auto-refresh), agents & roles (with presence and
    active-chat counts), departments (with live load counts), widget builder,
    reports (date range + CSV), session history (search/date/CSV), missed
    chats (reply by email + CSV), audit log (search/date/CSV), IP blocks
    (CIDR + expiry + CSV), knowledge base (create/edit/delete), AI chatbot
    settings, durable signed webhooks with retry, GDPR export/erase, and
    email transcripts.
  - Security & ops: per-request license enforcement, per-IP failed-login
    lockout, per-IP widget/upload rate limiting, friendly 404/500 pages,
    unhandled-exception logging, and liveness/readiness health probes.

  See WebForms\README.txt for the full, detailed feature list.

=================================================================
   Quick demo (one command)
=================================================================

Requirements: .NET Framework 4.8 (built into Windows), IIS Express (ships
with Visual Studio or as a standalone download), and SQL Server Express
with the sqlcmd command-line tools.

  run-webforms.cmd

On first run this creates the demo database (Server=.\SQLEXPRESS,
Database=ZChat), installs the schema, seed accounts, and Web Forms feature
tables, serves the app with IIS Express on http://localhost:8088/, and
opens the sign-in page. Re-running is safe - an already-set-up database is
detected and left untouched.

  Admin: admin / admin123
  Agent: agent1 / agent123
  (Please change these passwords after first login.)

  Options (run-webforms.ps1):
      -Port 8090            use a different port
      -Server ".\SQL2019"  target a different SQL instance
      -Database "zchatwf"  use a different database name
      -SkipDatabaseSetup   never touch the database

=================================================================
   Production install on IIS
=================================================================

See WebForms\README.txt for step-by-step IIS deployment: create the
database, run the three SQL scripts, copy the WebForms folder to an IIS
application on .NET Framework 4.8, set the ZChat connection string in
Web.config, and place your zchat.lic in WebForms\App_Data.

The Web Forms edition uses the same ZChat SQL Server schema as the ASP.NET
Core edition, so both can run against the same database.

=================================================================
   Licensing
=================================================================

ZChat validates zchat.lic on every request and will not run without a valid
license (bin\ZChat.Licensing.dll performs the check). Place your zchat.lic in
WebForms\App_Data. The included trial license is valid on localhost only; a
Domain, IP, or Enterprise license is required for a public host. Health.aspx
reports the current license state and edition.

=================================================================
   Upgrading - read this first
=================================================================

  - Everyone signs in again once. Sessions are now tied to the account's
    password, so a password change, an administrator reset, or deleting
    the account ends every other session for that account within seconds.
    Tickets issued by earlier builds carry no such binding and are refused.

  - Behind a reverse proxy? ZChat no longer trusts X-Forwarded-For by
    default (a visitor could forge it to evade the IP block list and the
    sign-in throttle). List your proxy in web.config or every visitor is
    recorded as the proxy's address:
        <add key="ZChat:TrustedProxies" value="10.0.0.5" />

  - Webhooks may only target public addresses; localhost, private and
    link-local ranges are refused when saved and before every send, and
    redirects are not followed. For a receiver on your private network:
        <add key="ZChat:WebhooksAllowPrivateTargets" value="true" />

  - Chat attachments can now be expired. Default keeps them for ever:
        <add key="ZChat:UploadRetentionDays" value="90" />

  - Database setup repairs itself: launching against a half-built
    database creates whatever is missing; a complete one is left alone.
