DafexBank database conversion
==============================

Files
-----
1. transfer.php
   Your transfer page converted to database-backed data.
2. db.php
   MySQL connection.
3. transfer_api.php
   Secure server-side API for loading accounts/recipients/transactions and saving transfers.
4. dafexbank.sql
   Creates the database/tables and seeds the data visible in your supplied page.

Installation
------------
1. Create a MySQL database in phpMyAdmin or MySQL.
2. Import dafexbank.sql.
3. Edit db.php with your MySQL username/password.
4. Put transfer.php, db.php and transfer_api.php in the same PHP website directory.
5. Make sure your login code sets:
       $_SESSION['username']
   to the same username stored in the users table.
6. Open transfer.php.

Important
---------
The original page stored transfers in browser localStorage and changed the balance only in JavaScript.
The converted page does not use localStorage for banking data. Accounts, recipients and transactions are read from MySQL.
Transfers are inserted into transactions by transfer_api.php.

The supplied page currently displays "Transfer on hold". The API therefore records new transfers with status=held and does NOT deduct the account balance.
If your intended business rule is to deduct funds immediately, change the server-side status/business rule deliberately; do not rely on JavaScript for balances.

For a real banking application, also:
- store passwords only as password_hash() hashes;
- never store passwords in cookies;
- use HTTPS;
- add CSRF protection;
- use proper authorization for every account/transaction;
- add an audit log and transaction idempotency;
- use decimal money fields (the schema does);
- perform balance changes only inside server-side database transactions.
