== Changelog ==

= 1.4.1 =

_Release date: 2026-08-10_

**Highlights**

* Security hardening, data preservation option, and WP-CLI commands
* 66 tests (up from 38), 100% coverage of tested classes

**Added**

* Data preservation option — checkbox under Settings → iDrivee2 to opt in to data deletion on uninstall (default: preserve)
* WP-CLI commands: `wp idrivee2 test-connection`, `wp idrivee2 cleanup-local-files`, `wp idrivee2 stats --days=N`

**Security**

* Logger: validate IP with `filter_var( FILTER_VALIDATE_IP )` instead of `sanitize_text_field`
* Admin page: `wp_unslash()` at read point for `$_POST['test_file']`
* Cron cleanup: `wp_delete_file()` replaces `WP_Filesystem()` (cron-safe, no credentials needed)
* Uninstall: data preservation is opt-in per AGENTS policy (default: preserve all data)

**Changed**

* WordPress minimum corrected 4.1 → 5.3 (wp-compat verified)
* Uninstall: `delete_post_meta_by_key()` replaces raw SQL
* `robotstxt-updater.php` documented as EXTERNAL DEPENDENCY

**Compatibility**

* WordPress: 5.3 - 7.1
* PHP: 8.1 - 8.5

**Tests**

* PHP Coding Standards: 3.13.5 (0 errors)
* WordPress Coding Standards: 3.3.0 (0 violations)
* PHPStan: Level 9, 0 errors
* PHPUnit: 66 tests, 109 assertions

= 1.3.0 =

_Release date: 2026-07-18_

**Highlights**

* New image sub-sizes control: ship less data per upload, ideal for large camera files. Reduces work in both the WP 7.1 client-side path (browser) and the server-side path.

**Added**

* Settings field **Image Sub-sizes** under Settings → iDrivee2 with three modes: `all` (default), `thumbnail` (only the default thumbnail), `none` (no sub-sizes).
* `IDRIVEE2_MEDIA_SUBSIZES_MODE` wp-config.php constant — same priority pattern as the S3 credentials; the field becomes read-only when set.
* In `thumbnail` and `none` modes the `big_image_size_threshold` filter is also disabled, so WordPress no longer creates a `-scaled` derivative for images larger than 2560px.

**Security**

* `composer audit` CVEs resolved: `guzzlehttp/guzzle` 7.11 → 7.15, `guzzlehttp/psr7` 2.11 → 2.13, `mtdowling/jmespath.php` 2.8 → 2.9 (CVE-2026-55767 / 55568 / 55766 / 54133).

**Tooling**

* `bin/preflight.sh` added — automated pre-deploy verification per AGENTS-testing-build-deployment.md (PHPCS, PHPStan, PHPCompatibility, PHPUnit + coverage, composer audit, candidate ZIP inspection).
* `.claude/settings.json` added — mechanical deny rules for `deploy.sh`, `git push/tag/merge` per AGENTS.md.

**Compatibility**

* WordPress: 4.1 - 7.1
* PHP: 8.1 - 8.5

**Tests**

* PHP Coding Standards: 3.13.5 (0 errors)
* WordPress Coding Standards: 3.3.0 (0 violations)
* PHPStan: Level 9, 0 errors
* PHPUnit: 38 tests, 60 assertions

= 1.2.1 =

_Release date: 2026-06-05_

**Fixed**

* **Infinite recursion on image upload** — `wp_update_post()` (called to update the attachment GUID after S3 upload) was firing the `edit_attachment` WordPress action, which re-triggered the upload method, which called `wp_update_post()` again, creating infinite recursion. Xdebug killed the process at 512 stack frames, WordPress reported "The server cannot process the image". Fixed by: (1) removing the `edit_attachment` hook — `wp_update_attachment_metadata` covers all new-upload scenarios; (2) adding a static re-entry guard (`$in_progress` per attachment ID) as a safety net.

* **Fatal error: fclose() on already-closed stream** — The AWS SDK (via Guzzle) closes file streams automatically after reading them for upload. The `finally` block was attempting to `fclose()` streams that were already closed, throwing `TypeError: fclose(): Argument #1 ($stream) must be an open stream resource`. Fixed by checking `is_resource($fh)` before calling `fclose()`.

**Compatibility**

* WordPress: 4.1 - 7.1
* PHP: 8.1 - 8.5

**Tests**

* PHP Coding Standards: 3.13.5 (0 errors)
* WordPress Coding Standards: 3.3.0 (0 violations)
* PHPStan: Level 9, 0 errors
* PHPUnit: 22 tests, 54 assertions

= 1.2.0 =

_Release date: 2026-06-02_

**Highlights**

* Media uploads dramatically faster: concurrent S3 uploads + streaming from disk

**Performance**

* Concurrent uploads via AWS CommandPool (default 5, configurable via IDRIVEE2_UPLOAD_CONCURRENCY)
* Files now stream directly from disk (fopen + resource) instead of loading fully into memory
* Removed per-file headObject pre-check (eliminates N extra HTTP round-trips per image)
* Single DB write for upload stats per attachment (replaces one write per file)
* Hook priority lowered from 999 to 10

**Compatibility**

* WordPress: 4.1 - 7.1
* PHP: 8.1 - 8.5

**Tests**

* PHP Coding Standards: 3.13.5 (0 errors)
* WordPress Coding Standards: 3.3.0 (0 violations)
* PHPStan: Level 9, 0 errors
* PHPUnit: 22 tests, 54 assertions

= 1.1.4 =

_Release date: 2026-06-02_

**Highlights**

* Full dev tooling setup (PHPCS, PHPStan level 9, PHPUnit) and first test suite
* WordPress 7.1 and PHP 8.5 compatibility declared

**Added**

* Composer dev tooling: PHPCS/WPCS, PHPStan (level 9), PHPUnit, PHPCompatibility
* phpstan.neon, phpcs.xml, phpunit.xml configuration
* PHPUnit test suite (22 tests, 54 assertions): plugin headers, Config, Rate_Limiter
* bin/deploy.sh: automated ZIP generation with production vendor only
* docs/: db-migrations.md, known-issues.md

**Changed**

* Tested up to WordPress 7.1; PHP compatibility extended to 8.5
* PHPStan level upgraded from 8 to 9
* `IDRIVEE2_MEDIA_VERSION` constant defined in plugin main file; replaces `get_file_data()` call in enqueue
* Admin page: proper `sanitize_key()` for `$_GET['page']`, type-check for `$_POST['test_file']`
* deploy.sh: switched from `composer update` to `composer install` for reproducible builds from lock file
* Logger stats: switched to `time() - ($n * DAY_IN_SECONDS)` arithmetic for consistent UTC dates
* uninstall.php: variable renamed to satisfy WP prefix naming rules

**Fixed**

* WP_Filesystem null guard before file operations in Media_Uploader
* Type-safety on all `get_option()`/`get_transient()` results (guards against mixed types)
* Rate_Limiter arithmetic: transient value narrowed to int before subtraction
* robotstxt-updater.php: short ternary operators replaced, `serialize()` annotated
* Media_Uploader deletion queue: malformed `timestamp=0` entries now requeued instead of deleted immediately
* Logger: UTC-consistent date arithmetic in both `track_s3_operation()` and `get_s3_stats()`

**Compatibility**

* WordPress: 6.8 - 7.1
* PHP: 8.2 - 8.5

**Tests**

* PHP Coding Standards: 3.13.5 (0 errors)
* WordPress Coding Standards: 3.3.0 (0 violations)
* PHPStan: Level 9, 0 errors
* PHPCompatibility scan: 8.2-8.5

= 1.1.3 =

_Release date: 2026-02-04_

**Highlights**

* Critical bug fix for namespace issue causing fatal error

**Fixed**

* Critical namespace issue with Robotstxt_Updater class causing fatal error
* Fatal error "Class 'iDrivee2Media\Robotstxt_Updater' not found" resolved
* Added global namespace prefix (`\`) to `Robotstxt_Updater::init()` call in main plugin file
* Plugin now loads correctly without PHP fatal errors

**Technical Details**

* Issue: `Robotstxt_Updater` class is defined in global namespace but was called from within `iDrivee2Media` namespace
* Solution: Changed `Robotstxt_Updater::init()` to `\Robotstxt_Updater::init()` to explicitly reference global namespace
* Location: idrivee2-media-upload.php line 67

**Compatibility**

* WordPress: 6.8 - 6.9
* PHP: 8.2 - 8.4
* MariaDB: 10.6+

**Tests**

* PHP Coding Standards: 0 errors
* WordPress Coding Standards (WPCS): 3.3
* PHPStan: Level 8 (0 errors)
* PHPCompatibility: 8.2-8.4

= 1.1.2 =

_Release date: 2026-02-04_

**Highlights**

* Build system improvements for consistent PHP 8.2+ deployments

**Changed**

* Deployment script updated to use PHP 8.2 as platform base for production builds
* Now uses `composer update --no-dev` instead of `composer install --no-dev`
* Temporarily configures `platform.php 8.2` during build for consistent dependency resolution
* Platform configuration cleaned up after build completes
* Deploy script updated to bin/deploy.sh version 1.1.0

**Improved**

* Production packages now guarantee PHP 8.2+ compatibility regardless of development environment PHP version
* Build consistency ensures reliable deployments across different server environments with varying PHP versions
* Using `composer update` ensures latest compatible versions for target PHP version
* Dependency resolution is consistent and predictable

**Compatibility**

* WordPress: 6.8 - 6.9
* PHP: 8.2 - 8.4
* MariaDB: 10.6+

**Tests**

* PHP Coding Standards: 0 errors
* WordPress Coding Standards (WPCS): 3.3
* PHPStan: Level 8 (0 errors)
* PHPCompatibility: 8.2-8.4

= 1.1.1 =

_Release date: 2026-02-04_

**Highlights**

* Deployment script improvements to ensure production packages are complete

**Fixed**

* Deployment script now includes essential files in production packages
* update.json (auto-update system) now included in deploy
* robotstxt-updater.php (auto-update handler) now included in deploy
* readme.txt (WordPress.org documentation) now included in deploy
* changelog.txt (full changelog) now included in deploy
* Updated script documentation and output messages

**Improved**

* Production packages now contain all files required for automatic updates from Gitea
* Deploy script version updated to 1.1.0

**Compatibility**

* WordPress: 6.8 - 6.9
* PHP: 8.2 - 8.4
* MariaDB: 10.6+

**Tests**

* PHP Coding Standards: 0 errors
* WordPress Coding Standards (WPCS): 3.3
* PHPStan: Level 8 (0 errors)
* PHPCompatibility: 8.2-8.4

= 1.1.0 =

_Release date: 2026-02-04_

**Highlights**

* Configuration and consistency improvements for PHP 8.2+ compatibility
* Updated plugin repository URLs to Gitea
* Fixed text domain consistency across all files

**Changed**

* Added explicit PHP version requirement (>=8.2) to composer.json
* Updated update.json with correct plugin information
* Fixed Text Domain in robotstxt-updater.php to match plugin slug (idrivee2-media-upload)
* Migrated repository from GitHub to Gitea (git.robotstxt.es)
* Added Gitea Plugin URI and Primary Branch headers

**Fixed**

* Composer now validates PHP version during dependency installation
* Plugin update system correctly identifies the plugin
* Translations properly loaded for updater error messages

**Improved**

* All text domains now consistently use 'idrivee2-media-upload'
* Update metadata accurately reflects plugin information

**Compatibility**

* WordPress: 6.8 - 6.9
* PHP: 8.2 - 8.4
* MariaDB: 10.6+

**Tests**

* PHP Coding Standards: 0 errors
* WordPress Coding Standards (WPCS): 3.3
* PHPStan: Level 8 (0 errors)
* PHPCompatibility: 8.2-8.4

= 1.0.0 =

_Release date: 2026-02-03_

**Highlights**

* First stable production-ready release
* Enterprise-grade security with comprehensive logging
* OWASP Top 10 (2021) compliance
* PHPStan level 8 compliance with zero errors
* Security rating: A+ (Excellent)

**Added**

* Security logging system with comprehensive audit trail
* Rate limiting protection (60s users, 30s admins)
* S3 operation statistics tracking (30-day retention)
* Logger class for security and operations logging
* Rate_Limiter class for abuse prevention
* Comprehensive security audit documentation (7,500+ lines)
* Code quality report with metrics (3,200+ lines)

**Changed**

* Capability checks switched from role checks to manage_options
* Type safety with strict type hints throughout
* Error messages now user-friendly with translations
* Admin interface shows rate limit feedback

**Fixed**

* All 17 PHPStan level 8 type safety issues resolved
* Array type specifications added to all methods
* Null handling for AWS error messages
* Return type declarations match actual returns
* All capability checks use manage_options

**Security**

* OWASP Top 10 (2021) 100% compliance
* Enhanced nonce validation
* Comprehensive input sanitization and output escaping
* Security logging for all critical operations
* Rate limiting to prevent brute force attacks

**Compatibility**

* WordPress: 6.8 - 6.9
* PHP: 8.2 - 8.4
* MariaDB: 10.6+

**Tests**

* PHP Coding Standards: 0 errors
* WordPress Coding Standards (WPCS): 3.3
* PHPStan: Level 8 (0 errors)
* PHPCompatibility: 8.2-8.4

= 0.3.0 =

_Release date: 2025-02-03_

**Highlights**

* Complete refactoring to class-based architecture
* Modular file structure with dependency injection
* Added PHPUnit test framework
* Moved from Media to Settings menu

**Added**

* Settings page in WordPress Admin (Settings → iDrivee2)
* Timestamped test files (test-YYYYMMDDHHMMSS.txt)
* Persistent test files with delete capability
* Database-stored configuration option
* Hybrid configuration (wp-config.php + database)
* Class-based architecture with 6 classes
* PHPUnit test structure
* PHPStan static analysis
* Deployment script (bin/deploy.sh)
* Uninstall script
* Composer scripts (test, phpcs, phpstan, lint)

**Changed**

* Menu location from Media → iDrivee2 to Settings → iDrivee2
* Architecture from functional to object-oriented
* JavaScript version from hardcoded to dynamic

**Fixed**

* Code duplication eliminated (7 instances)
* WordPress Coding Standards violations
* PHP compatibility issues
* Type safety with strict declarations

**Compatibility**

* WordPress: 6.7 - 6.9
* PHP: 8.2 - 8.4
* MariaDB: 10.6+

**Tests**

* PHP Coding Standards: 0 errors
* WordPress Coding Standards (WPCS): 3.3
* PHPStan: Basic structure added
* PHPCompatibility: 8.2+

= 0.1.13 =

_Release date: 2024-XX-XX_

**Highlights**

* Initial public release
* Basic S3-compatible storage integration

**Added**

* Automatic media upload to S3
* Local file deletion after upload
* CDN URL rewriting
* WordPress admin testing interface
* Configuration via wp-config.php constants
* Multisite support

**Compatibility**

* WordPress: 6.5+
* PHP: 7.4+
* MariaDB: 10.6+
