== Changelog == = 1.4.3 = _Release date: 2026-08-24_ **Added** * Manager detection now uses the ecosystem presence constant `ROBOTSTXT_MANAGER_NOTICED` (ROBOTSTXT Manager 1.6.2+); a plugin-list scan remains as fallback for older Manager versions — same method name and return type, no caller changes **Changed** * Composer dependencies updated: `aws/aws-sdk-php` 3.392.3 → 3.393.4, `guzzlehttp/psr7` 3.0.0 → 3.0.1, `guzzlehttp/promises` 3.0.1 → 3.0.2, PHPStan 2.2.8 → 2.2.9, `johnbillion/wp-compat` 1.5.0 → 2.0.0 (now a PHPStan extension) (no known CVEs) **Localization** * POT regenerated for 1.4.3 (no string changes); Spanish (es_ES) and Catalan (ca) translations verified — 69/69 strings in both locales **Compatibility** * WordPress: 5.3 - 7.1 (floor re-verified with wp-compat 2.0: `big_image_size_threshold` filter, WP 5.3; one false positive on `wp_enqueue_script()` positional `$in_footer` argument documented in docs/known-issues.md) * PHP: 8.1 - 8.5 (full-range PHPCompatibility scan 5.6-8.5; floor set by `aws/aws-sdk-php` requiring >= 8.1) **Tests** * PHP Coding Standards: 3.13.6 (0 errors) * WordPress Coding Standards: 3.4.1 (0 violations) * PHPStan: Level 9, 0 errors * PHPUnit: 83 tests, 130 assertions * composer audit: no known CVEs = 1.4.2 = _Release date: 2026-08-17_ **Added** * Dismissible admin notice on the Plugins page when the ROBOTSTXT Manager plugin is not installed or active, linking to https://www.robotstxt.software/plugins/robotstxt-manager/ — updates are delivered through ROBOTSTXT Manager * Persistent (non-dismissible) notice on Settings → iDrivee2 under the same condition **Changed** * Removed the bundled Gitea auto-updater (`robotstxt-updater.php` and `update.json`); automatic updates are now handled by the ROBOTSTXT Manager plugin * Plugin URI and new `Update URI` header point to https://www.robotstxt.software/plugins/idrivee2-media-upload/ * Author URI updated to https://www.robotstxt.software/ * Composer dependencies updated: `aws/aws-sdk-php` 3.383.2 → 3.392.3, `guzzlehttp/guzzle` 7.x → 8.0.2, WPCS 3.3.0 → 3.4.1, PHPStan 2.2.1 → 2.2.8 (no known CVEs) **Localization** * POT regenerated for 1.4.2 — includes the WP-CLI and data-cleanup strings that were missing since 1.4.0, and drops the removed updater strings * Spanish (es_ES) and Catalan (ca) translations updated: 69/69 strings translated in both locales **Compatibility** * WordPress: 5.3 - 7.1 (floor verified with wp-compat: `big_image_size_threshold` filter, WP 5.3) * PHP: 8.1 - 8.5 (full-range PHPCompatibility scan 5.6-8.5; floor set by `aws/aws-sdk-php` requiring >= 8.1) **Tests** * PHP Coding Standards: 3.13.6 (0 errors) * WordPress Coding Standards: 3.4.1 (0 violations) * PHPStan: Level 9, 0 errors * PHPUnit: 78 tests, 125 assertions * composer audit: no known CVEs = 1.4.1 = _Release date: 2026-08-10_ **Highlights** * Security hardening, data preservation option, and WP-CLI commands * 66 tests (up from 38), 100% coverage of tested classes **Added** * Data preservation option — checkbox under Settings → iDrivee2 to opt in to data deletion on uninstall (default: preserve) * WP-CLI commands: `wp idrivee2 test-connection`, `wp idrivee2 cleanup-local-files`, `wp idrivee2 stats --days=N` **Security** * Logger: validate IP with `filter_var( FILTER_VALIDATE_IP )` instead of `sanitize_text_field` * Admin page: `wp_unslash()` at read point for `$_POST['test_file']` * Cron cleanup: `wp_delete_file()` replaces `WP_Filesystem()` (cron-safe, no credentials needed) * Uninstall: data preservation is opt-in per AGENTS policy (default: preserve all data) **Changed** * WordPress minimum corrected 4.1 → 5.3 (wp-compat verified) * Uninstall: `delete_post_meta_by_key()` replaces raw SQL * `robotstxt-updater.php` documented as EXTERNAL DEPENDENCY **Compatibility** * WordPress: 5.3 - 7.1 * PHP: 8.1 - 8.5 **Tests** * PHP Coding Standards: 3.13.5 (0 errors) * WordPress Coding Standards: 3.3.0 (0 violations) * PHPStan: Level 9, 0 errors * PHPUnit: 66 tests, 109 assertions = 1.3.0 = _Release date: 2026-07-18_ **Highlights** * New image sub-sizes control: ship less data per upload, ideal for large camera files. Reduces work in both the WP 7.1 client-side path (browser) and the server-side path. **Added** * Settings field **Image Sub-sizes** under Settings → iDrivee2 with three modes: `all` (default), `thumbnail` (only the default thumbnail), `none` (no sub-sizes). * `IDRIVEE2_MEDIA_SUBSIZES_MODE` wp-config.php constant — same priority pattern as the S3 credentials; the field becomes read-only when set. * In `thumbnail` and `none` modes the `big_image_size_threshold` filter is also disabled, so WordPress no longer creates a `-scaled` derivative for images larger than 2560px. **Security** * `composer audit` CVEs resolved: `guzzlehttp/guzzle` 7.11 → 7.15, `guzzlehttp/psr7` 2.11 → 2.13, `mtdowling/jmespath.php` 2.8 → 2.9 (CVE-2026-55767 / 55568 / 55766 / 54133). **Tooling** * `bin/preflight.sh` added — automated pre-deploy verification per AGENTS-testing-build-deployment.md (PHPCS, PHPStan, PHPCompatibility, PHPUnit + coverage, composer audit, candidate ZIP inspection). * `.claude/settings.json` added — mechanical deny rules for `deploy.sh`, `git push/tag/merge` per AGENTS.md. **Compatibility** * WordPress: 4.1 - 7.1 * PHP: 8.1 - 8.5 **Tests** * PHP Coding Standards: 3.13.5 (0 errors) * WordPress Coding Standards: 3.3.0 (0 violations) * PHPStan: Level 9, 0 errors * PHPUnit: 38 tests, 60 assertions = 1.2.1 = _Release date: 2026-06-05_ **Fixed** * **Infinite recursion on image upload** — `wp_update_post()` (called to update the attachment GUID after S3 upload) was firing the `edit_attachment` WordPress action, which re-triggered the upload method, which called `wp_update_post()` again, creating infinite recursion. Xdebug killed the process at 512 stack frames, WordPress reported "The server cannot process the image". Fixed by: (1) removing the `edit_attachment` hook — `wp_update_attachment_metadata` covers all new-upload scenarios; (2) adding a static re-entry guard (`$in_progress` per attachment ID) as a safety net. * **Fatal error: fclose() on already-closed stream** — The AWS SDK (via Guzzle) closes file streams automatically after reading them for upload. The `finally` block was attempting to `fclose()` streams that were already closed, throwing `TypeError: fclose(): Argument #1 ($stream) must be an open stream resource`. Fixed by checking `is_resource($fh)` before calling `fclose()`. **Compatibility** * WordPress: 4.1 - 7.1 * PHP: 8.1 - 8.5 **Tests** * PHP Coding Standards: 3.13.5 (0 errors) * WordPress Coding Standards: 3.3.0 (0 violations) * PHPStan: Level 9, 0 errors * PHPUnit: 22 tests, 54 assertions = 1.2.0 = _Release date: 2026-06-02_ **Highlights** * Media uploads dramatically faster: concurrent S3 uploads + streaming from disk **Performance** * Concurrent uploads via AWS CommandPool (default 5, configurable via IDRIVEE2_UPLOAD_CONCURRENCY) * Files now stream directly from disk (fopen + resource) instead of loading fully into memory * Removed per-file headObject pre-check (eliminates N extra HTTP round-trips per image) * Single DB write for upload stats per attachment (replaces one write per file) * Hook priority lowered from 999 to 10 **Compatibility** * WordPress: 4.1 - 7.1 * PHP: 8.1 - 8.5 **Tests** * PHP Coding Standards: 3.13.5 (0 errors) * WordPress Coding Standards: 3.3.0 (0 violations) * PHPStan: Level 9, 0 errors * PHPUnit: 22 tests, 54 assertions = 1.1.4 = _Release date: 2026-06-02_ **Highlights** * Full dev tooling setup (PHPCS, PHPStan level 9, PHPUnit) and first test suite * WordPress 7.1 and PHP 8.5 compatibility declared **Added** * Composer dev tooling: PHPCS/WPCS, PHPStan (level 9), PHPUnit, PHPCompatibility * phpstan.neon, phpcs.xml, phpunit.xml configuration * PHPUnit test suite (22 tests, 54 assertions): plugin headers, Config, Rate_Limiter * bin/deploy.sh: automated ZIP generation with production vendor only * docs/: db-migrations.md, known-issues.md **Changed** * Tested up to WordPress 7.1; PHP compatibility extended to 8.5 * PHPStan level upgraded from 8 to 9 * `IDRIVEE2_MEDIA_VERSION` constant defined in plugin main file; replaces `get_file_data()` call in enqueue * Admin page: proper `sanitize_key()` for `$_GET['page']`, type-check for `$_POST['test_file']` * deploy.sh: switched from `composer update` to `composer install` for reproducible builds from lock file * Logger stats: switched to `time() - ($n * DAY_IN_SECONDS)` arithmetic for consistent UTC dates * uninstall.php: variable renamed to satisfy WP prefix naming rules **Fixed** * WP_Filesystem null guard before file operations in Media_Uploader * Type-safety on all `get_option()`/`get_transient()` results (guards against mixed types) * Rate_Limiter arithmetic: transient value narrowed to int before subtraction * robotstxt-updater.php: short ternary operators replaced, `serialize()` annotated * Media_Uploader deletion queue: malformed `timestamp=0` entries now requeued instead of deleted immediately * Logger: UTC-consistent date arithmetic in both `track_s3_operation()` and `get_s3_stats()` **Compatibility** * WordPress: 6.8 - 7.1 * PHP: 8.2 - 8.5 **Tests** * PHP Coding Standards: 3.13.5 (0 errors) * WordPress Coding Standards: 3.3.0 (0 violations) * PHPStan: Level 9, 0 errors * PHPCompatibility scan: 8.2-8.5 = 1.1.3 = _Release date: 2026-02-04_ **Highlights** * Critical bug fix for namespace issue causing fatal error **Fixed** * Critical namespace issue with Robotstxt_Updater class causing fatal error * Fatal error "Class 'iDrivee2Media\Robotstxt_Updater' not found" resolved * Added global namespace prefix (`\`) to `Robotstxt_Updater::init()` call in main plugin file * Plugin now loads correctly without PHP fatal errors **Technical Details** * Issue: `Robotstxt_Updater` class is defined in global namespace but was called from within `iDrivee2Media` namespace * Solution: Changed `Robotstxt_Updater::init()` to `\Robotstxt_Updater::init()` to explicitly reference global namespace * Location: idrivee2-media-upload.php line 67 **Compatibility** * WordPress: 6.8 - 6.9 * PHP: 8.2 - 8.4 * MariaDB: 10.6+ **Tests** * PHP Coding Standards: 0 errors * WordPress Coding Standards (WPCS): 3.3 * PHPStan: Level 8 (0 errors) * PHPCompatibility: 8.2-8.4 = 1.1.2 = _Release date: 2026-02-04_ **Highlights** * Build system improvements for consistent PHP 8.2+ deployments **Changed** * Deployment script updated to use PHP 8.2 as platform base for production builds * Now uses `composer update --no-dev` instead of `composer install --no-dev` * Temporarily configures `platform.php 8.2` during build for consistent dependency resolution * Platform configuration cleaned up after build completes * Deploy script updated to bin/deploy.sh version 1.1.0 **Improved** * Production packages now guarantee PHP 8.2+ compatibility regardless of development environment PHP version * Build consistency ensures reliable deployments across different server environments with varying PHP versions * Using `composer update` ensures latest compatible versions for target PHP version * Dependency resolution is consistent and predictable **Compatibility** * WordPress: 6.8 - 6.9 * PHP: 8.2 - 8.4 * MariaDB: 10.6+ **Tests** * PHP Coding Standards: 0 errors * WordPress Coding Standards (WPCS): 3.3 * PHPStan: Level 8 (0 errors) * PHPCompatibility: 8.2-8.4 = 1.1.1 = _Release date: 2026-02-04_ **Highlights** * Deployment script improvements to ensure production packages are complete **Fixed** * Deployment script now includes essential files in production packages * update.json (auto-update system) now included in deploy * robotstxt-updater.php (auto-update handler) now included in deploy * readme.txt (WordPress.org documentation) now included in deploy * changelog.txt (full changelog) now included in deploy * Updated script documentation and output messages **Improved** * Production packages now contain all files required for automatic updates from Gitea * Deploy script version updated to 1.1.0 **Compatibility** * WordPress: 6.8 - 6.9 * PHP: 8.2 - 8.4 * MariaDB: 10.6+ **Tests** * PHP Coding Standards: 0 errors * WordPress Coding Standards (WPCS): 3.3 * PHPStan: Level 8 (0 errors) * PHPCompatibility: 8.2-8.4 = 1.1.0 = _Release date: 2026-02-04_ **Highlights** * Configuration and consistency improvements for PHP 8.2+ compatibility * Updated plugin repository URLs to Gitea * Fixed text domain consistency across all files **Changed** * Added explicit PHP version requirement (>=8.2) to composer.json * Updated update.json with correct plugin information * Fixed Text Domain in robotstxt-updater.php to match plugin slug (idrivee2-media-upload) * Migrated repository from GitHub to Gitea (git.robotstxt.es) * Added Gitea Plugin URI and Primary Branch headers **Fixed** * Composer now validates PHP version during dependency installation * Plugin update system correctly identifies the plugin * Translations properly loaded for updater error messages **Improved** * All text domains now consistently use 'idrivee2-media-upload' * Update metadata accurately reflects plugin information **Compatibility** * WordPress: 6.8 - 6.9 * PHP: 8.2 - 8.4 * MariaDB: 10.6+ **Tests** * PHP Coding Standards: 0 errors * WordPress Coding Standards (WPCS): 3.3 * PHPStan: Level 8 (0 errors) * PHPCompatibility: 8.2-8.4 = 1.0.0 = _Release date: 2026-02-03_ **Highlights** * First stable production-ready release * Enterprise-grade security with comprehensive logging * OWASP Top 10 (2021) compliance * PHPStan level 8 compliance with zero errors * Security rating: A+ (Excellent) **Added** * Security logging system with comprehensive audit trail * Rate limiting protection (60s users, 30s admins) * S3 operation statistics tracking (30-day retention) * Logger class for security and operations logging * Rate_Limiter class for abuse prevention * Comprehensive security audit documentation (7,500+ lines) * Code quality report with metrics (3,200+ lines) **Changed** * Capability checks switched from role checks to manage_options * Type safety with strict type hints throughout * Error messages now user-friendly with translations * Admin interface shows rate limit feedback **Fixed** * All 17 PHPStan level 8 type safety issues resolved * Array type specifications added to all methods * Null handling for AWS error messages * Return type declarations match actual returns * All capability checks use manage_options **Security** * OWASP Top 10 (2021) 100% compliance * Enhanced nonce validation * Comprehensive input sanitization and output escaping * Security logging for all critical operations * Rate limiting to prevent brute force attacks **Compatibility** * WordPress: 6.8 - 6.9 * PHP: 8.2 - 8.4 * MariaDB: 10.6+ **Tests** * PHP Coding Standards: 0 errors * WordPress Coding Standards (WPCS): 3.3 * PHPStan: Level 8 (0 errors) * PHPCompatibility: 8.2-8.4 = 0.3.0 = _Release date: 2025-02-03_ **Highlights** * Complete refactoring to class-based architecture * Modular file structure with dependency injection * Added PHPUnit test framework * Moved from Media to Settings menu **Added** * Settings page in WordPress Admin (Settings → iDrivee2) * Timestamped test files (test-YYYYMMDDHHMMSS.txt) * Persistent test files with delete capability * Database-stored configuration option * Hybrid configuration (wp-config.php + database) * Class-based architecture with 6 classes * PHPUnit test structure * PHPStan static analysis * Deployment script (bin/deploy.sh) * Uninstall script * Composer scripts (test, phpcs, phpstan, lint) **Changed** * Menu location from Media → iDrivee2 to Settings → iDrivee2 * Architecture from functional to object-oriented * JavaScript version from hardcoded to dynamic **Fixed** * Code duplication eliminated (7 instances) * WordPress Coding Standards violations * PHP compatibility issues * Type safety with strict declarations **Compatibility** * WordPress: 6.7 - 6.9 * PHP: 8.2 - 8.4 * MariaDB: 10.6+ **Tests** * PHP Coding Standards: 0 errors * WordPress Coding Standards (WPCS): 3.3 * PHPStan: Basic structure added * PHPCompatibility: 8.2+ = 0.1.13 = _Release date: 2024-XX-XX_ **Highlights** * Initial public release * Basic S3-compatible storage integration **Added** * Automatic media upload to S3 * Local file deletion after upload * CDN URL rewriting * WordPress admin testing interface * Configuration via wp-config.php constants * Multisite support **Compatibility** * WordPress: 6.5+ * PHP: 7.4+ * MariaDB: 10.6+