Backend progress log

- Django skeleton created under `backend/` with `manage.py`, `config/`, and ASGI/WSGI entrypoints.
- Settings split into `config/settings_base.py`, `config/settings_dev.py`, and `config/settings_prod.py`, with `DJANGO_ENV` switching via `config/settings.py` and the `config/settings/` wrappers; dev uses SQLite with open CORS, prod targets MySQL using env vars (`MYSQL_*`, `DJANGO_ALLOWED_HOSTS`, `CORS_ALLOWED_ORIGINS`, `DJANGO_SECRET_KEY`).
- Dependencies captured in `backend/requirements.txt` (Django 5.2, DRF, SimpleJWT, cors-headers, django-extensions, python-telegram-bot, mysqlclient, python-decouple); packages installed locally.
- Added `apps/users` with a custom Telegram-only `User` model (custom manager, referral code generation, `referral_code`/`referred_by` fields) and set `AUTH_USER_MODEL` in settings.
- Added Telegram initData validation helper (`utils/telegram.py`) and `/api/users/auth/telegram/` endpoint that issues JWTs, syncs profile fields, and links referrals via `start_param`.
- Added DRF serializers/viewsets for investments, rewards, transactions, and referral commissions; routes exposed under `/api/investments`, `/api/rewards`, `/api/transactions`, and `/api/commissions` with investment creation auto-calculating tier/rate/duration.
- Added `calculate_rewards` management command to generate daily rewards and multi-level commissions (L1 50%, L2 30%, L3 20%), credit user balances, log transactions, and update investment status (active/completed). Added unit tests covering reward generation, commission distribution, transaction logging, and idempotency.
- Added Telegram webhook endpoint to handle `/start` deep links, guarded by secret header, replying with a WebApp button that carries the referral code. Fixed Telegram auth view to persist profile updates and referral assignment before issuing JWTs.
- Admin registrations added for users, investments/rewards, commissions, and transactions for quick console management.
- Added tests for Telegram auth/webhook (user creation, referral binding, profile refresh, webhook secret + WebApp button URL). Run with `DJANGO_ENV=development python backend/manage.py test apps.users.tests`.
- Added API tests for investments and rewards to verify tier/schedule derivation, user scoping, auth requirements, and reward filtering. Run with `DJANGO_ENV=development python backend/manage.py test apps.investments.tests.test_views`.
- Added API tests for transactions and referral commissions covering user scoping, authentication, and filtering. Run with `DJANGO_ENV=development python backend/manage.py test apps.transactions.tests apps.referrals.tests`.
- Added edge-case coverage for `calculate_rewards` (pre-start skip, end-date completion) in `apps.investments.tests.test_calculate_rewards`.
- Fixed commission hierarchy ordering so level 1 credits the top-most upline; rerun `DJANGO_ENV=development python backend/manage.py test apps.investments.tests.test_calculate_rewards`.
- Added payment gateway contracts (`PaymentAddress`, `Deposit`, `WithdrawalRequest`, `GatewayCallbackLog`) and admin registrations to view/manage deposits, withdrawals, addresses, and callbacks. Apply migrations when ready.
- Added payments model unit tests covering defaults, uniqueness constraints, optional links to wallet transactions, and callback log payload/header persistence. Run with `DJANGO_ENV=development python backend/manage.py test apps.payments.tests`.
- Added Telegram auth/webhook edge cases (missing/invalid init data, invalid referral codes, referral non-overwrite, missing secret, non-start messages, callback data, missing chat). Run with `DJANGO_ENV=development python backend/manage.py test apps.users.tests`.
- Added investment/reward edge cases: validation (min/non-numeric), tier 6, ordering, detail scoping, reward auth/filtering. Run with `DJANGO_ENV=development python backend/manage.py test apps.investments.tests.test_views`.
- Added transaction edge cases: unknown type filter, descending ordering, metadata fields, and cross-user detail protection. Run with `DJANGO_ENV=development python backend/manage.py test apps.transactions.tests.test_views`.
- Added referral commission edge cases: unknown status filter, ordering (asc/desc), and cross-upline detail protection. Run with `DJANGO_ENV=development python backend/manage.py test apps.referrals.tests.test_views`.
- Added reward pipeline edge cases: completed investments skipped, single-upline and no-upline flows, and precision quantization for reward amounts. Run with `DJANGO_ENV=development python backend/manage.py test apps.investments.tests.test_calculate_rewards`.
- Added Telegram utils unit tests for initData validation hashing/expiry and sendMessage success/failure paths. Run with `DJANGO_ENV=development python backend/manage.py test apps.users.tests.test_telegram_utils`.

Carry-over next steps

- Apply migrations for the payments contracts: `DJANGO_ENV=development python backend/manage.py migrate`.
- Schedule the reward/commission command via cron; add tests around financial calculations.
- Document environment variables and runtime notes once services are added.
