BGI HRMS Payroll & Attendance - Phase 11
Mobile PWA + Staff App API + QR Attendance + Offline Sync + Device Binding

PHASE 11 ADDED MODULES
1. Staff Mobile PWA shell
2. PWA manifest and service worker
3. Staff mobile dashboard
4. Device binding request and admin approval
5. Mobile API token system
6. Mobile login API
7. Staff profile API
8. Attendance summary API
9. QR attendance session generation
10. QR punch request and approval-ready scan log
11. Offline punch draft queue
12. Offline punch sync API
13. Mobile push subscription storage
14. Staff mobile notification inbox
15. Mobile audit log
16. API rate log base
17. QR session expiry cron
18. Offline queue reprocess cron
19. Sample offline punch CSV
20. Phase 11 responsive mobile UI CSS

INSTALLATION
1. Phase 1 to Phase 10 should already be installed.
2. Take a full database and files backup.
3. Import phase11_schema.sql in the same ERP database.
4. Upload all folders from this ZIP to the project root.
5. Open: /admin/hrms/phase11_dashboard.php
6. Configure Mobile App Settings.
7. Approve staff devices from Staff Devices page.
8. Generate QR attendance session from QR Attendance Sessions page.
9. Staff opens: /staff/hrms/mobile_app.php

OPTIONAL CRON
php cron/hrms_phase11_expire_qr_sessions.php
php cron/hrms_phase11_offline_queue_reprocess.php

MAIN ADMIN FILES
admin/hrms/phase11_dashboard.php
admin/hrms/mobile_app_settings.php
admin/hrms/staff_devices.php
admin/hrms/qr_attendance_sessions.php
admin/hrms/offline_sync_queue.php
admin/hrms/mobile_api_tokens.php
admin/hrms/pwa_install_guide.php
admin/hrms/mobile_audit.php

STAFF MOBILE FILES
staff/hrms/mobile_app.php
staff/hrms/device_bind.php
staff/hrms/qr_scan.php
staff/hrms/offline_punch.php
staff/hrms/mobile_notifications.php
staff/hrms/manifest.json
staff/hrms/service_worker.js

API FILES
api/hrms/mobile_login.php
api/hrms/mobile_profile.php
api/hrms/mobile_attendance_summary.php
api/hrms/mobile_device_bind.php
api/hrms/mobile_qr_punch.php
api/hrms/mobile_offline_sync.php
api/hrms/mobile_push_subscribe.php
api/hrms/mobile_token_refresh.php
api/hrms/mobile_logout.php

IMPORTANT FLOW
Staff mobile login -> Device binding -> Admin approval -> QR / offline punch -> queue validation -> daily attendance recalculation.

SECURITY NOTES
- Mobile tokens are stored as hashes in DB.
- Device binding can be enforced from Mobile App Settings.
- QR sessions expire automatically.
- Offline punch is queued first and should be reviewed/reprocessed.
- This patch does not delete existing HRMS data.
- PHP code is written in English and kept PHP 5.6 compatible.
