# Mettle Build Checklist

## Phase 0 — Foundations ✅ COMPLETE
- [x] Create checklist.md
- [x] composer.json
- [x] .env.example
- [x] bootstrap.php
- [x] public/index.php
- [x] public/.htaccess
- [x] config/settings.php
- [x] config/routes.php
- [x] config/container.php
- [x] config/app.php
- [x] config/game.php
- [x] app/Middleware/MaintenanceMiddleware.php
- [x] app/Middleware/SecurityHeadersMiddleware.php
- [x] app/Middleware/SessionMiddleware.php
- [x] app/Middleware/CsrfMiddleware.php
- [x] app/Middleware/AuthMiddleware.php
- [x] app/Middleware/RateLimitMiddleware.php
- [x] resources/views/layouts/base.twig
- [x] resources/views/pages/home.twig
- [x] resources/views/pages/maintenance.twig
- [x] resources/views/pages/error.twig
- [x] resources/views/pages/admin/dashboard.twig
- [x] resources/css/app.css (Tailwind source)
- [x] public/assets/css/app.css (compiled placeholder)
- [x] public/assets/js/app.js
- [x] public/manifest.webmanifest
- [x] public/sw.js (stub)
- [x] bin/cron.php
- [x] bin/build.php
- [x] bin/package.php
- [x] phinx.php
- [x] database/migrations/20260101000000_create_foundation_tables.php
- [x] docs/DEPLOY.md
- [x] docs/DECISIONS.md
- [x] docs/LICENSES.md
- [x] CHANGELOG.md
- [x] app/Controllers/HomeController.php
- [x] app/Controllers/AdminController.php
- [x] app/Support/Clock.php
- [x] tailwind.config.js
- [x] phpunit.xml
- [x] tests/bootstrap.php
- [x] tests/Unit/FoundationTest.php
- [x] .gitignore
- [x] public/assets/img/logo.svg

### Phase 0 — Manual steps required before testing
- [ ] Run `composer install` locally
- [ ] Download Tailwind standalone CLI → project root as `./tailwindcss`, run `chmod +x tailwindcss`
- [ ] Run `./tailwindcss -i resources/css/app.css -o public/assets/css/app.css --minify`
- [ ] Download htmx.min.js → `public/assets/vendor/htmx.min.js`
- [ ] Download alpine.min.js → `public/assets/vendor/alpine.min.js`
- [ ] Copy `.env.example` to `.env` and fill in values
- [ ] Create MySQL database and user
- [ ] Run migrations: `vendor/bin/phinx migrate` (local) or via `/admin/maintenance/migrate`
- [ ] Replace SVG icon placeholders with real PNG icons (192×192, 512×512)

## Phase 1 — Accounts and Safety ✅ COMPLETE
- [x] AUTH-1: Registration (email, password ≥10 chars, common-password check, 18+ DOB, timezone)
- [x] AUTH-2: Email verification + password reset (tokens hashed, 24h/1h TTL)
- [x] AUTH-3: Login with rate limiting middleware, remember-me rotating cookie
- [x] AUTH-4: Onboarding wizard (welcome→safety→goals→lifestyle→diet→coach_tone→character→tests→done), resumable
- [x] AUTH-5: Account page (change password, export JSON, pause, delete with 7-day grace)
- [x] SAFE-1: Pre-exercise screening questionnaire (seed file, flagged for professional review)
- [x] SAFE-2: GP clearance lock/unlock
- [x] SAFE-3: Nutrition floor constants in config/game.php
- [x] SAFE-4: Risk flag schema + repository (nightly evaluation wired in cron stub)
- [x] SAFE-5: Diet-style warnings in ScreeningService::getDietWarning()
- [x] SAFE-6: Disclaimer in base layout and register page
- [x] NOTIF-3: Email queue table + EmailQueueRepository + EmailService + cron processor
- [x] Migration: 20260101000001_create_account_tables
- [x] Tests: AuthServiceTest (10 tests), ScreeningServiceTest (9 tests)

## Phase 2 — Check-ins and Character ✅ COMPLETE
- [x] CHK-1: Full check-in every 28 days, resumable, XP reward
- [x] CHK-2: 8 check-in questions (goals, time, sleep, energy, stress, problem areas, motivation, barriers)
- [x] CHK-3: 6 guided self-tests with timers (Alpine.js stopwatch/countdown), skip option, locked by screening
- [x] CHK-4: Optional weight and waist entry
- [x] CHK-5: Stat recalculation, weak spot identification, radar chart comparison
- [x] CHK-6: Daily micro check-in (sleep/energy/soreness/mood 1–5, pain flag) via htmx fragment
- [x] GAME-1: Character creation (name, class, default avatar) wired into onboarding
- [x] Stat calculation (7.3): all 6 tests → stats, age bands, sex norms, knees variant, skipped carry-forward
- [x] config/norms.php: score bands for all 6 tests × 6 age groups × 2 sexes
- [x] LevelTable: XP threshold formula, levelFromXp, progress()
- [x] XpEngine: award() with duplicate prevention via unique key, daily limits, level-up detection
- [x] StatCalculator: getBand(), interpolate(), weakSpot(), unspecified sex averaging
- [x] Migration: 20260101000002_create_checkin_and_character_tables
- [x] Tests: StatCalculatorTest (15), LevelTableTest (10), CheckInServiceTest (7) — 55 total, 0 warnings

## Phase 3 — Training and Intervals ✅ COMPLETE
- [x] TRN-1: Exercise library (exercises table, seed file, wger importer)
- [x] TRN-2: Weekly plan generator (sessions_per_week from availability, muscle group rotation)
- [x] TRN-3: Session lifecycle (create, start, log sets, complete, skip)
- [x] TRN-4: Readiness-adjusted plan (7.5): full/reduced/mobility tiers
- [x] TRN-5: Deload week (week 4 of every second block, 60% volume)
- [x] TRN-6: XP awards (base + per-minute, HIIT/HIIW bonus)
- [x] TRN-7: Progression tracking (best weight/reps, suggest next-session increment)
- [x] INT-1: HIIT unlock (≥6 sessions over ≥3 weeks)
- [x] INT-2: Weekly HIIT cap (max 3 per week)
- [x] INT-3: HIIT → HIIW downgrade on reduced readiness
- [x] INT-4: HIIT → mobility swap on low readiness
- [x] INT-5: HIIT locked → hiiw fallback
- [x] INT-6: Protocol selection (tabata/amrap/emom by readiness, low_impact for hiiw)
- [x] INT-7: Interval session metadata (protocol, work/rest/rounds, avg/peak effort)
- [x] INT-8: Consecutive-easy tracking → level-up suggestion
- [x] Readiness (7.5): R score from daily check-in drives session type and volume
- [x] Plan generator (7.4): weak-stat bias, availability-based session count
- [x] Exercise seed import (bin/import-wger.php)
- [x] Migration: 20260101000003_create_training_tables
- [x] Tests: TrainingServiceTest (9), IntervalServiceTest (17) — 81 total, 0 warnings

## Phase 4 — Nutrition ✅ COMPLETE
- [x] NUT-1: TDEE (Mifflin-St Jeor), macro targets from diet profile, kcal floor enforcement (SAFE-3)
- [x] NUT-2: Meal logging (recipe or custom entry, servings, htmx fragment update)
- [x] NUT-3: Risk floor check (7-day rolling average below kcal floor)
- [x] NUT-4: Meal-plan generator (7.6) — 7-day plan, diet-tag filtered, closest-kcal recipe selection
- [x] NUT-5: XP for meal logging (5 XP, limit 4/day)
- [x] NUT-6: Delete meal log entry (htmx)
- [x] config/diets.php: 10 diet profiles with macro ratios, tags, warnings, fasting flags
- [x] Recipe seed: 150 recipes across breakfast/lunch/dinner/snack × all diet tags (4 sub-files)
- [x] NutritionRepository: recipes, meal logs, meal plans, plan items
- [x] NutritionService: TDEE, kcalTarget, macroTargets, logMeal, getDayLogs, getDayTotals, isBelowFloor, getOrGeneratePlan
- [x] NutritionController: /eat (daily log), /eat/plan (weekly plan), POST /eat/log, POST /eat/log/{id}/delete
- [x] Migration: 20260101000004_create_nutrition_tables (recipes, meal_logs, meal_plans, meal_plan_items)
- [x] Templates: eat/index.twig (daily log + macro summary + log form), eat/plan.twig (7-day plan), partials/meal_log_row.twig
- [x] Tests: NutritionServiceTest (20 tests) — 101 total, 0 warnings

## Phase 5 — Game Layer ✅ COMPLETE
- [x] GAME-2: Streak tracking — daily increment, missed-day reset, longest streak
- [x] GAME-3: Quest system — 3–5 daily + 2 weekly quests, progress tracking, XP awards, all-daily bonus
- [x] GAME-4: Comeback mode — detected after 7-day gap, bonus XP award, coach message
- [x] COACH-1: Coach tone personalisation (motivational/calm/direct/humorous) stored in user_settings
- [x] COACH-2: Contextual tips — comeback > low_readiness > streak_milestone > weak_spot > default
- [x] COACH-3: Comeback detection and messaging in CoachService
- [x] NOTIF-1: Push subscription save/delete (VAPID, minishlink/web-push)
- [x] NOTIF-2: Push send to user + bulk reminder send via cron
- [x] PWA: Full service worker (cache-first assets, network-first pages, offline fallback, push handler)
- [x] Streaks: rest tokens (earn 1 per 7-day streak, max 3, covers 1 missed day), sick mode (freeze up to 7 days)
- [x] Cron: quest generation, weekly close, push reminders, nightly risk flag evaluation all wired
- [x] Migration: 20260101000005_create_game_layer_tables (streaks, quests, push_subscriptions)
- [x] GameRepository: streaks CRUD, quests CRUD + progress, push subscriptions
- [x] StreakService, QuestService, CoachService, PushService, GameController
- [x] Routes: /quests, /push/subscribe, /push/unsubscribe, /streak/sick, /offline
- [x] Templates: game/quests.twig (streak card + daily/weekly quest progress bars + sick mode form), pages/offline.twig
- [x] Tests: StreakServiceTest (13), QuestCoachTest (14) — 128 total, 0 warnings

## Phase 6 — Social ✅ COMPLETE
- [x] SOC-1: Party system — create (with invite code), join by code, leave (owner transfer), max size enforcement
- [x] SOC-2: Cheers — send cheer to party member, XP reward (daily limit), blocked-user guard
- [x] SOC-3: Leaderboard — party members ranked by total XP from xp_ledger
- [x] SOC-4: Challenges — create party challenge (metric: workouts/kcal/streak/cheers), progress tracking, expiry
- [x] SOC-5: Social feed — activity events (workout, streak, quest, cheer, challenge, joined_party), party-scoped
- [x] SOC-6: Privacy controls — per-user feed visibility (party/private)
- [x] SOC-7: Moderation — report user (spam/harassment/inappropriate/other), block/unblock
- [x] Migration: 20260101000006_create_social_tables (parties, party_members, cheers, challenges, challenge_progress, feed_events, reports, blocks)
- [x] SocialRepository: party CRUD, cheers, leaderboard, challenges + progress, feed events, block/report
- [x] SocialService: all SOC-1–7 business logic, XP awards, challenge progress wiring
- [x] SocialController: feed, party, leaderboard, cheer (htmx), challenge create, privacy, report, block/unblock
- [x] Routes: /social, /social/party, /social/leaderboard, /social/cheer, /social/challenge/create, /social/privacy, /social/report, /social/block, /social/unblock
- [x] Templates: social/feed.twig, social/party.twig, social/leaderboard.twig
- [x] Tests: SocialServiceTest (26 tests) — 154 total, 0 warnings

## Phase 7 — Polish and Should Items
- [ ] GAME-5–7, HAB-1–4, NUT-7–9, CHK-7, WEAR-1–2, COACH-4, ADM-1–4
- [ ] Lighthouse audit
