<?php

declare(strict_types=1);

/**
 * Generate production-only secret values for .env.
 *
 * The command never writes to disk. Copy the output into the target server's
 * secret manager or .env file outside Git.
 */

$args = array_slice($argv ?? [], 1);
$json = in_array('--json', $args, true);
$help = in_array('--help', $args, true) || in_array('-h', $args, true);

if ($help) {
    echo <<<TXT
Zavvion Events production secret generator

Usage:
  php bin/generate-production-secrets
  php bin/generate-production-secrets --json

Notes:
  - This command prints values only; it does not edit .env.
  - Store the output in the target server secret store or .env file.
  - Never commit generated values to Git.

TXT;
    exit(0);
}

/**
 * @return non-empty-string
 */
function zv_secret(int $bytes = 48): string
{
    return rtrim(strtr(base64_encode(random_bytes($bytes)), '+/', '-_'), '=');
}

$secrets = [
    'COOKIE_SECRET' => zv_secret(),
    'QR_SIGNING_SECRET' => zv_secret(),
    'MFA_OTP_SECRET' => zv_secret(),
    'SMS_OTP_SIGNING_SECRET' => zv_secret(),
];

if ($json) {
    echo json_encode([
        'status' => 'ok',
        'generated_at' => date('c'),
        'secrets' => $secrets,
        'warning' => 'Store these values outside Git. Do not paste them into committed files.',
    ], JSON_PRETTY_PRINT) . PHP_EOL;
    exit(0);
}

echo "# Generated at " . date('c') . PHP_EOL;
echo "# Store outside Git. Do not commit these values." . PHP_EOL;
foreach ($secrets as $key => $value) {
    echo $key . '=' . $value . PHP_EOL;
}
