SHOPV3 - TU DONG NHAN DOMAIN
============================

Ban nay KHONG can sua APP_URL moi khi copy source sang domain/shop khac.

Mac dinh trong .env:
  APP_URL=https://localhost       # fallback cho CLI truoc request dau tien
  AUTO_APP_URL=true
  ALLOWED_HOSTS=AUTO
  AUTO_CORS_ORIGIN=true

Cach hoat dong:
1. TrustHosts xac minh hostname request dua tren virtual host SERVER_NAME.
2. Request hop le se tu dat app.url = https://domain-hien-tai.
3. CORS, /storage URL va WebAuthn relying-party ID duoc dong bo theo domain.
4. Domain da xac minh duoc luu tai storage/framework/cache/trusted-app-domain.json
   de Artisan/queue/cron CLI co the tao URL dung sau request HTTP dau tien.

Voi cPanel/shared hosting binh thuong: chi can upload va cau hinh DB, khong can sua APP_URL.

Neu hosting/proxy dac biet tra SERVER_NAME sai va website bao Invalid Host/403:
  ALLOWED_HOSTS=domaincuaban.com,www.domaincuaban.com
sau do chay:
  php artisan optimize:clear

KHONG nen dung ALLOWED_HOSTS=*.

OAuth Google/Facebook/GitHub van phai khai bao redirect/callback domain moi trong
console cua tung provider neu ban su dung dang nhap mang xa hoi.

APP_KEY TU DONG RIENG TUNG SHOP:
- File .env trong ZIP de APP_KEY= rong.
- Lan boot dau tien, bootstrap/app.php tu sinh base64 key 32-byte bang random_bytes().
- APP_KEY da co gia tri se KHONG bao gio bi tu dong thay doi.
- Neu .env khong writable, cap quyen ghi tam thoi cho owner cua PHP roi load lai site.


HTTP 500 COMPATIBILITY FIX
--------------------------
APP_KEY is no longer written back into .env. When APP_KEY= is blank, each
installation creates its own key at storage/app/private/.shopv3-app-key.
Make sure storage/ and bootstrap/cache/ are writable by the PHP/cPanel user.
Typical shared-hosting permissions are directories 755/775 and files 644;
the generated key itself is restricted to 600 where supported.
