# LUCOS Backend - Setup Guide

## Quick Start

### 1. Database Setup
The backend is now running on **MySQL** (no ORM, lightweight).

**Create the database and table:**

```sql
-- Connect to MySQL
mysql -u root -p

-- Create database
CREATE DATABASE lucos;
USE lucos;

-- Run the migration (from migrations/001_create_users.sql)
-- Or paste the SQL:
CREATE TABLE users (
  id INT UNSIGNED NOT NULL AUTO_INCREMENT,
  name VARCHAR(100),
  email VARCHAR(255) NOT NULL UNIQUE,
  password VARCHAR(255) NOT NULL,
  role VARCHAR(10) DEFAULT 'USER',
  `createdAt` TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
  `updatedAt` TIMESTAMP DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
  PRIMARY KEY (id)
);

CREATE INDEX idx_email ON users(email);
```

### 2. Environment Setup

Copy `.env.example` to `.env` and update:

```env
DATABASE_HOST=localhost
DATABASE_PORT=3306
DATABASE_USER=root
DATABASE_PASSWORD=your_password
DATABASE_NAME=lucos
JWT_SECRET=your-secret-key-here
CORS_ORIGIN=http://localhost:3000
# Optional: allow multiple frontend origins
# CORS_ORIGIN=http://localhost:3000,https://staging.lucos.com
```

### 3. Run the Backend

```bash
npm run dev
```

Server will start on `http://localhost:5000`

## API Endpoints

- `POST /api/v1/auth/register` - Register new user
- `POST /api/v1/auth/login` - Login user
- `GET /api/v1/auth/me` - Get profile (requires auth)
- `POST /api/v1/auth/logout` - Logout
- `GET /api/v1/health` - Health check

## Architecture

- **Express.js** - Web framework
- **mysql2** - MySQL driver
- **JWT** - Authentication
- **bcrypt** - Password hashing
- **Zod** - Input validation
- **Raw SQL** - No ORM (lightweight & efficient)

## Auth Flow

1. User registers with email/password
2. Password is hashed with bcrypt
3. JWT token is issued and stored in httpOnly cookie
4. Token verified on protected routes via middleware
5. Token can also be sent via Authorization header (Bearer scheme)
