# Half-Mind administration guide

Updated 9 September 2026. Start at `/siteadmin/`. This guide covers the PHP Half-Mind site; On On Podcast and Running in the 70s have separate WordPress administration.

## Everyday tasks

| Task | Where to go | Completion check |
| --- | --- | --- |
| Review maintenance tools | `/siteadmin/` | Correct dashboard and current admin menu appear |
| Make backups | `/siteadmin/backup.php` | Download and restore-test the appropriate backup |
| Check a release | `/siteadmin/verify.php` | Review changed files and rerun database checks |
| Read these guides | `/siteadmin/docs.php` | Choose a guide; download its editable source if needed |
| Audit encoding | `/siteadmin/encoding.php` | Run the three separate checks and retain reports |
| Review directory quality | `/regionalwebsite/directory_health.php` | Investigate findings before changing records |
| Review kennel rankings | `/where/awhere_kennel_leaderboard.php` | Four ranking views load correctly |

Some newer installations also have `/siteadmin/health.php` and an add-club tool. Their current code was not supplied for this documentation release; use the installed dashboard links and do not assume a filename or shared password behavior.

## Change the Site Administration password

With the password-kit bootstrap installed:

1. Extract `half-mind-siteadmin-password-kit.zip` on your computer.
2. Open `Set-Admin-Password.html` in Chrome or Edge with the accompanying JavaScript files present.
3. Enter a unique password of at least 16 characters twice. Save it in your password manager.
4. Create and download `siteadmin_password.php`.
5. Back up the existing `/siteadmin/admin_bootstrap.php` and any existing password override file privately.
6. On first installation, upload the kit's `admin_bootstrap.php` and generated `siteadmin_password.php` into `/siteadmin/`. On later resets, replace only the generated password file.
7. Keep the filename exact; remove a browser-added `(1)` or `(2)` suffix. Test a new login and confirm the old password is rejected.

The local tool creates a salted hash without transmitting the readable password. Leave `siteadmin_config.php` and backup settings intact. Existing sessions must log in again on their next request after the password changes; a request already running is not cancelled.

The password-kit bootstrap uses this priority: `SITEADMIN_PASSWORD_OVERRIDE_HASH` from `siteadmin_password.php`, then `SITEADMIN_PASSWORD_HASH` from `siteadmin_config.php`, then the Directory Health hash if no siteadmin hash is defined. An installed bootstrap from another release may differ. Deleting the override re-enables the older configured password. Directory Health's own password is not changed by this reset.

Do not reinstall an older bootstrap merely to follow these instructions if your server now has a newer version with additional functions. Have the password changes merged into that current version.

## Regular maintenance

- Before changing code or data: download the affected current files and database backups; note the change and rollback plan.
- Weekly: back up both configured database targets, even if they currently point to one shared database. Check the actual target names privately.
- Monthly: back up files and separately protect excluded assets/configuration. Perform a restore test periodically.
- After each release: test the changed feature, its related pages and authentication; review PHP logs; then record verification and accept a baseline if appropriate.
- Quarterly: review stored backup retention, broken links and outdated pages. Keep at least two dated recoverable generations.

## Use update verification correctly

The supplied verifier compares a fixed list of files to a saved SHA-256 baseline. Missing or changed files are findings, not automatically errors: an intentional update changes a checksum. Database checks are started separately; previously saved results may be stale. Run them again after connection/schema changes.

The fixed list in the supplied verifier does not include every newer addition, including the lightbox JavaScript, kennel leaderboard, encoding audit or all documentation assets. Test these explicitly. A passing checksum comparison is not PHP linting, a security audit or a successful functional test.

Review changes, test the site, record the result and only then choose **Accept files as baseline**. Accepting a broken release merely makes the broken files the new reference. Keep the private baseline and verification history with operational backups.

## Directory maintenance

Use the installed directory edit form for corrections. Record the club's exact name, country/state, website, contact and any relevant history. Before adding a club, search for alternate names and abbreviations to avoid duplicates. Use the installed add-club tool if present; otherwise follow the established contact process. Do not guess SQL column names or IDs.

The broken-link monitor was requested, but its current code, cron schedule and installation status were not supplied here. Do not assume checks are running. Confirm the installed tool's last-run time and configuration before documenting it as operational.

## Handle private information

Use HTTPS and keep credentials, SQL files and rollback copies outside the public website. A hidden-profile flag must remain respected by public aggregations. Do not include passwords, authentication hashes, member emails or full private records in support screenshots. Administrative page authentication does not automatically protect every static file beside it.

## Country Continents administration

Open `/siteadmin/country_continents.php` using your existing Site Administration
login. If login returns you to the dashboard, open the editor address again.
The editor keeps old areas intact and edits only `wherecountry_continent_real`.

1. Select **Only show entries needing assignment**.
2. Review a country/territory and choose one of the seven continents.
3. Use that row's **Save** button. Each row saves separately.
4. Repeat until the pending list is clear; use search to find a specific entry.
5. Test a known profile on My Milestones, the world map and Export.

The migration's initial proposals followed existing areas for 216 entries.
Thirteen were left for review: Egypt, Georgia, Armenia, Azerbaijan, Cyprus,
Kazahkstan, Russia, Turkey, Indonesia, Saipan, East Timor, UK-South Georgia and
UK-Falkland Islands. This includes boundary/transcontinental cases and unusual
old groupings; not all 13 span continents. Decide a consistent site convention.
Each country earns one continent. Australia is included in Oceania.

Review existing proposals too: they are based on old areas, not an independent
geographic audit. Changes affect every user who selected that country on their
next page load. New countries need a classification here. Clearing an assignment
makes affected users' continent totals pending; it does not clear their selections.

The editor checks the prior value before saving. If another edit occurred,
review the current value and try again instead of overwriting it blindly.

## Certificate and leaderboard checks

The new certificate requires `/where/awhere_export.php` and both TTF files in
`/where/certificate-fonts/`. Keep the accompanying font license. Test Preview,
Download PDF and CSV while logged in. The existing logo must be readable at
`/halfmindlogo_200w.gif` or `/images/halfmindlogo_200w.gif`; PHP GD supports its
conversion. Missing logo support does not stop the rest of the certificate.

Inspect the actual PDF, not only the export landing page. Confirm name, kennel,
continent ribbon, all five totals, detail pages and special characters. CSV
also includes continent fields. It is a private account export, not a public
leaderboard download.

The personalized kennel link uses exact-name search and retains global rank.
Check a kennel below the normal top 50 and switch ranking tabs. Do not interpret
members' summed travel as unique countries visited by the club.
