# GroupChat

A private, invite-only, anonymous group chat app — like a stripped-down WhatsApp group,
built as a single Node.js app (`server.js` contains the backend, database schema, and the
entire frontend).

## Features

- Only **one admin account** exists, ever. Only the admin can create or delete groups.
- Admin adds allowed **phone numbers** to a group (paste numbers, or use the browser's
  Contact Picker on supported Android/Chrome devices).
- Joining a group works via a generated **invite link/code**.
- **No private/direct chat** — only the group chat exists.
- Members chat under a chosen **alias**, and never see the list of who's in the group
  (only the admin can see that).
- Members can send **text, images, videos, and files**.
- Admin can **open and participate in any group's chat** (as "Admin"), and **switch
  between groups** from a dropdown right inside the chat view.
- Admin can **remove a member (or an un-joined invited number)** from a group at any
  time — this instantly disconnects them if they're currently chatting, and they can't
  rejoin unless re-added.

## 1. Install Node.js

Install Node.js 18+ from https://nodejs.org if you don't have it. Check with:

```bash
node --version
```

## 2. Install dependencies

From this folder:

```bash
npm install
```

This downloads `express`, `express-session`, `better-sqlite3`, `multer`, and `socket.io`.

## 3. Run the app

```bash
npm start
```

You should see:

```
GroupChat server running at http://localhost:3000
```

A `db.sqlite` file and an `uploads/` folder are created automatically next to `server.js`.

## 4. Set up the admin account

Open **http://localhost:3000/admin** in your browser. The first visit asks you to create
the one and only admin account (username + password, 6+ characters). This can only be
done once — after that, it's a normal login screen.

## 5. Create a group (as admin)

- Click **Create Group**, give it a name.
- Paste phone numbers (one per line or comma-separated) into the box and click
  **Add Numbers**. These are the *only* numbers allowed to join.
  - "Import from Phone Contacts" uses the browser's native Contact Picker API, which
    currently only works in **Chrome on Android, over HTTPS**. On desktop or iOS,
    paste the numbers manually (e.g. export them from your phone as a CSV/text list).
- Click **Copy Link** and send that invite link to your members (via SMS, WhatsApp,
  email — whatever you like).

## 5b. Manage a group (as admin)

- **Open Chat**: click this on any group card to view and send messages in that group,
  under the alias "Admin". Inside the chat, use the dropdown in the top-right to jump
  straight to another group's chat.
- **View / Manage Members**: shows every invited number, whether they've joined and
  under what alias, and a **Remove** button next to each one. Removing a number kicks
  them out immediately (if they're online) and revokes their access — they can't rejoin
  unless the admin adds their number again.

## 6. Join a group (as a member)

- Open the invite link.
- Enter the **same phone number** the admin added, and choose a display **alias**.
- You'll land in the group chat. You can send text messages, images, and files.
- You will only ever see aliases next to messages — never phone numbers, and never a
  member list.

## Notes on deploying for real-world use

- Right now this runs on `localhost` only. To let people outside your machine join,
  deploy it to a host with a public URL and HTTPS (e.g. a small VPS, Render, Railway,
  Fly.io, etc.), then set `cookie.secure = true` in the session config inside
  `server.js`.
- The SQLite database (`db.sqlite`) is a single file — back it up if you care about the
  data.
- Uploaded files are stored under `uploads/<group_id>/`; deleting a group removes its
  folder and all its messages.
- Session storage uses Express's default in-memory store, which is fine for a small
  self-hosted deployment but will reset admin login on server restart — that's expected
  and does not affect group data.
