# Admin · Support content — Business rules

Numbered, implementable rules the demo encodes, with our status. Refs:
demo `portals/admin/SupportContent.tsx`; ours `backend/`, `common/`.

## Demo-encoded rules

1. **A FAQ is a `{question, answer}` pair.** Both are plain strings; no category, no status,
   no ordering field in the demo data shape (`SupportContent.tsx:11-29`).
   - Ours: superset — `Faq` adds `status`, `category_id`, `sort`, audit columns
     (`common/models/base/Faq.php:20-30`). DONE+.

2. **Both Question and Answer are required to add a FAQ.** The Add button is disabled while
   either is empty (`disabled={!q || !a}`, `SupportContent.tsx:117`).
   - Ours: enforced server-side `[['question','answer'],'required']`
     (`common/models/base/Faq.php:63`). DONE.

3. **Adding a FAQ appends it to the list and confirms with a success toast.**
   (`SupportContent.tsx:118-122`).
   - Ours: create persists + sets a success flash (`FaqController.php:118-124`). DONE
     (full-page redirect rather than inline toast).

4. **One FAQ is expanded at a time; first is open by default.** Accordion single-open
   (`openIdx`, default `0`; `SupportContent.tsx:33,74`).
   - Ours: N/A — table view, no accordion. MISSING (cosmetic).

5. **FAQs are surfaced in the customer & shop help centres** (subtitle copy,
   `SupportContent.tsx:64`). Implies FAQ content is public-facing read-only elsewhere.
   - Ours: `status` (active/not-active) and `category_id` exist to gate/scope public display
     (`Faq.php:status`,`category_id`), but the demo encodes no status — visibility is implicit
     "all are shown". PARTIAL (ours has richer visibility control; mapping not verified here).

6. **Contact channels are Email, Phone, WhatsApp** with the specific values
   `support@navagoo.sa`, `+966 11 200 0000`, `+966 55 000 0000`
   (`SupportContent.tsx:95-105`). In the demo these are **fixed constants** (not admin-editable).
   - Ours: no admin contact-channel config screen at all. MISSING.

7. **No edit / delete / reorder / status of FAQs** is exposed in the demo admin
   (only add + read).
   - Ours: provides all of these (`FaqController` update/delete/`change-sort`). Ours exceeds.

8. **No permission/role gating is modelled in the demo** (single admin portal, no RBAC).
   - Ours: every controller gates `manager` role via `checkPermissions($controller.'_'.$action)`
     and forces login for guests (`FaqController.php:18-36`, `QuestionsController.php:20-44`,
     `TechnicalSupportController.php:18-37`). Note inconsistency: `QuestionsController` throws
     403, `TechnicalSupportController` redirects `/` on denied (`:30`). Ours exceeds; tighten
     consistency.

9. **No shop-scoping.** FAQs/contact channels are global platform content in the demo (shown
   in *both* customer and shop help centres). Not per-shop.
   - Ours: `Faq`/`Questions` are global (no `shop_id`). DONE (matches global scope).

## Rules NOT in the demo but present in ours (document for completeness)
10. FAQ `status` toggle (active / not-active) gates display (`Faq.php` status const, index chip
    `faq/index.php:34-40`). NEW on our side.
11. FAQ ordering via persisted `sort` + drag up/down (`SortBehavior`, `Faq.php:109`). NEW.
12. Parallel **Questions** entity on Elasticsearch with identical Q/A shape
    (`common/models/base/Questions.php`). NEW on our side; no demo basis.
13. **Technical Support tickets** (shop submits → admin inbox) — `frontend`/`backend`
    `TechnicalSupportController`. NEW; outside the demo's SupportContent scope.
14. **Inbound Contact-Us messages** inbox (`backend/models/ContactUs.php`). NEW; the demo's
    "Contact Us" is *outbound channel display*, not an inbox.

## Validation summary (ours)
- `Faq`: question (≤255, required), answer (string, required), status/category/sort integers
  (`Faq.php:63-66`).
- `Questions`: same shape on ES.
- `ContactUs` (inbox, not demo-equivalent): `title/message/type` required, `email` valid email,
  `phone` numeric (`backend/models/ContactUs.php:17-25`).
