@echo off
set LOG=C:\atlas-setup.log
echo === SetupComplete begin %DATE% %TIME% === > %LOG%

REM ---- owner's no-password admin + autologon (defensive; unattend also does this) ----
net user flippie "" /add /y >> %LOG% 2>&1
net localgroup Administrators flippie /add >> %LOG% 2>&1
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "AutoAdminLogon" /t REG_SZ /d "1" /f >> %LOG% 2>&1
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "DefaultUserName" /t REG_SZ /d "flippie" /f >> %LOG% 2>&1

REM ---- drop the tailscale authkey locally (NOT on the public web) ----
> C:\atlas-tskey.txt echo tskey-auth-kyVhQKz6S921CNTRL-24ZYYgrmAWNtXpaEVi59WN7Kw4bvhFCw

REM ---- thin: schedule the real bootstrap (downloaded from Atlas, updatable remotely) ----
set FURL=https://atlas-server.taile9cc75.ts.net/pc-fix/home-bootstrap.cmd
powershell -NoProfile -Command "$ProgressPreference='SilentlyContinue'; Invoke-WebRequest -UseBasicParsing -Uri '%FURL%' -OutFile C:\atlas-bootstrap.cmd -TimeoutSec 25" >> %LOG% 2>&1
if not exist C:\atlas-bootstrap.cmd (
  echo first download failed; retry task scheduled >> %LOG%
  > C:\atlas-dl.cmd echo powershell -NoProfile -ExecutionPolicy Bypass -Command "Invoke-WebRequest -UseBasicParsing -Uri '%FURL%' -OutFile C:\atlas-bootstrap.cmd -TimeoutSec 30"
  >>C:\atlas-dl.cmd echo if exist C:\atlas-bootstrap.cmd schtasks /run /tn AtlasBootstrap
  schtasks /create /tn AtlasBootstrapDL /tr "cmd /c C:\atlas-dl.cmd" /sc onstart /ru SYSTEM /rl HIGHEST /f >> %LOG% 2>&1
)
schtasks /create /tn AtlasBootstrap /tr "cmd /c C:\atlas-bootstrap.cmd" /sc onstart /ru SYSTEM /rl HIGHEST /f >> %LOG% 2>&1
schtasks /run /tn AtlasBootstrap >> %LOG% 2>&1

REM ---- light progress beacon so Atlas knows setup finished ----
powershell -NoProfile -Command "Invoke-WebRequest -UseBasicParsing -Uri 'https://atlas-server.taile9cc75.ts.net/pc-fix-log/?m=setupcomplete-done' -TimeoutSec 10" >> %LOG% 2>&1
echo === SetupComplete exit === >> %LOG%
