516 lines
16 KiB
Text
516 lines
16 KiB
Text
== Changelog ==
|
|
|
|
= 1.4.3 =
|
|
|
|
_Release date: 2026-08-24_
|
|
|
|
**Added**
|
|
|
|
* Manager detection now uses the ecosystem presence constant `ROBOTSTXT_MANAGER_NOTICED` (ROBOTSTXT Manager 1.6.2+); a plugin-list scan remains as fallback for older Manager versions — same method name and return type, no caller changes
|
|
|
|
**Changed**
|
|
|
|
* Composer dependencies updated: `aws/aws-sdk-php` 3.392.3 → 3.393.4, `guzzlehttp/psr7` 3.0.0 → 3.0.1, `guzzlehttp/promises` 3.0.1 → 3.0.2, PHPStan 2.2.8 → 2.2.9, `johnbillion/wp-compat` 1.5.0 → 2.0.0 (now a PHPStan extension) (no known CVEs)
|
|
|
|
**Localization**
|
|
|
|
* POT regenerated for 1.4.3 (no string changes); Spanish (es_ES) and Catalan (ca) translations verified — 69/69 strings in both locales
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 5.3 - 7.1 (floor re-verified with wp-compat 2.0: `big_image_size_threshold` filter, WP 5.3; one false positive on `wp_enqueue_script()` positional `$in_footer` argument documented in docs/known-issues.md)
|
|
* PHP: 8.1 - 8.5 (full-range PHPCompatibility scan 5.6-8.5; floor set by `aws/aws-sdk-php` requiring >= 8.1)
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 3.13.6 (0 errors)
|
|
* WordPress Coding Standards: 3.4.1 (0 violations)
|
|
* PHPStan: Level 9, 0 errors
|
|
* PHPUnit: 83 tests, 130 assertions
|
|
* composer audit: no known CVEs
|
|
|
|
= 1.4.2 =
|
|
|
|
_Release date: 2026-08-17_
|
|
|
|
**Added**
|
|
|
|
* Dismissible admin notice on the Plugins page when the ROBOTSTXT Manager plugin is not installed or active, linking to https://www.robotstxt.software/plugins/robotstxt-manager/ — updates are delivered through ROBOTSTXT Manager
|
|
* Persistent (non-dismissible) notice on Settings → iDrivee2 under the same condition
|
|
|
|
**Changed**
|
|
|
|
* Removed the bundled Gitea auto-updater (`robotstxt-updater.php` and `update.json`); automatic updates are now handled by the ROBOTSTXT Manager plugin
|
|
* Plugin URI and new `Update URI` header point to https://www.robotstxt.software/plugins/idrivee2-media-upload/
|
|
* Author URI updated to https://www.robotstxt.software/
|
|
* Composer dependencies updated: `aws/aws-sdk-php` 3.383.2 → 3.392.3, `guzzlehttp/guzzle` 7.x → 8.0.2, WPCS 3.3.0 → 3.4.1, PHPStan 2.2.1 → 2.2.8 (no known CVEs)
|
|
|
|
**Localization**
|
|
|
|
* POT regenerated for 1.4.2 — includes the WP-CLI and data-cleanup strings that were missing since 1.4.0, and drops the removed updater strings
|
|
* Spanish (es_ES) and Catalan (ca) translations updated: 69/69 strings translated in both locales
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 5.3 - 7.1 (floor verified with wp-compat: `big_image_size_threshold` filter, WP 5.3)
|
|
* PHP: 8.1 - 8.5 (full-range PHPCompatibility scan 5.6-8.5; floor set by `aws/aws-sdk-php` requiring >= 8.1)
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 3.13.6 (0 errors)
|
|
* WordPress Coding Standards: 3.4.1 (0 violations)
|
|
* PHPStan: Level 9, 0 errors
|
|
* PHPUnit: 78 tests, 125 assertions
|
|
* composer audit: no known CVEs
|
|
|
|
= 1.4.1 =
|
|
|
|
_Release date: 2026-08-10_
|
|
|
|
**Highlights**
|
|
|
|
* Security hardening, data preservation option, and WP-CLI commands
|
|
* 66 tests (up from 38), 100% coverage of tested classes
|
|
|
|
**Added**
|
|
|
|
* Data preservation option — checkbox under Settings → iDrivee2 to opt in to data deletion on uninstall (default: preserve)
|
|
* WP-CLI commands: `wp idrivee2 test-connection`, `wp idrivee2 cleanup-local-files`, `wp idrivee2 stats --days=N`
|
|
|
|
**Security**
|
|
|
|
* Logger: validate IP with `filter_var( FILTER_VALIDATE_IP )` instead of `sanitize_text_field`
|
|
* Admin page: `wp_unslash()` at read point for `$_POST['test_file']`
|
|
* Cron cleanup: `wp_delete_file()` replaces `WP_Filesystem()` (cron-safe, no credentials needed)
|
|
* Uninstall: data preservation is opt-in per AGENTS policy (default: preserve all data)
|
|
|
|
**Changed**
|
|
|
|
* WordPress minimum corrected 4.1 → 5.3 (wp-compat verified)
|
|
* Uninstall: `delete_post_meta_by_key()` replaces raw SQL
|
|
* `robotstxt-updater.php` documented as EXTERNAL DEPENDENCY
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 5.3 - 7.1
|
|
* PHP: 8.1 - 8.5
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 3.13.5 (0 errors)
|
|
* WordPress Coding Standards: 3.3.0 (0 violations)
|
|
* PHPStan: Level 9, 0 errors
|
|
* PHPUnit: 66 tests, 109 assertions
|
|
|
|
= 1.3.0 =
|
|
|
|
_Release date: 2026-07-18_
|
|
|
|
**Highlights**
|
|
|
|
* New image sub-sizes control: ship less data per upload, ideal for large camera files. Reduces work in both the WP 7.1 client-side path (browser) and the server-side path.
|
|
|
|
**Added**
|
|
|
|
* Settings field **Image Sub-sizes** under Settings → iDrivee2 with three modes: `all` (default), `thumbnail` (only the default thumbnail), `none` (no sub-sizes).
|
|
* `IDRIVEE2_MEDIA_SUBSIZES_MODE` wp-config.php constant — same priority pattern as the S3 credentials; the field becomes read-only when set.
|
|
* In `thumbnail` and `none` modes the `big_image_size_threshold` filter is also disabled, so WordPress no longer creates a `-scaled` derivative for images larger than 2560px.
|
|
|
|
**Security**
|
|
|
|
* `composer audit` CVEs resolved: `guzzlehttp/guzzle` 7.11 → 7.15, `guzzlehttp/psr7` 2.11 → 2.13, `mtdowling/jmespath.php` 2.8 → 2.9 (CVE-2026-55767 / 55568 / 55766 / 54133).
|
|
|
|
**Tooling**
|
|
|
|
* `bin/preflight.sh` added — automated pre-deploy verification per AGENTS-testing-build-deployment.md (PHPCS, PHPStan, PHPCompatibility, PHPUnit + coverage, composer audit, candidate ZIP inspection).
|
|
* `.claude/settings.json` added — mechanical deny rules for `deploy.sh`, `git push/tag/merge` per AGENTS.md.
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 4.1 - 7.1
|
|
* PHP: 8.1 - 8.5
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 3.13.5 (0 errors)
|
|
* WordPress Coding Standards: 3.3.0 (0 violations)
|
|
* PHPStan: Level 9, 0 errors
|
|
* PHPUnit: 38 tests, 60 assertions
|
|
|
|
= 1.2.1 =
|
|
|
|
_Release date: 2026-06-05_
|
|
|
|
**Fixed**
|
|
|
|
* **Infinite recursion on image upload** — `wp_update_post()` (called to update the attachment GUID after S3 upload) was firing the `edit_attachment` WordPress action, which re-triggered the upload method, which called `wp_update_post()` again, creating infinite recursion. Xdebug killed the process at 512 stack frames, WordPress reported "The server cannot process the image". Fixed by: (1) removing the `edit_attachment` hook — `wp_update_attachment_metadata` covers all new-upload scenarios; (2) adding a static re-entry guard (`$in_progress` per attachment ID) as a safety net.
|
|
|
|
* **Fatal error: fclose() on already-closed stream** — The AWS SDK (via Guzzle) closes file streams automatically after reading them for upload. The `finally` block was attempting to `fclose()` streams that were already closed, throwing `TypeError: fclose(): Argument #1 ($stream) must be an open stream resource`. Fixed by checking `is_resource($fh)` before calling `fclose()`.
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 4.1 - 7.1
|
|
* PHP: 8.1 - 8.5
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 3.13.5 (0 errors)
|
|
* WordPress Coding Standards: 3.3.0 (0 violations)
|
|
* PHPStan: Level 9, 0 errors
|
|
* PHPUnit: 22 tests, 54 assertions
|
|
|
|
= 1.2.0 =
|
|
|
|
_Release date: 2026-06-02_
|
|
|
|
**Highlights**
|
|
|
|
* Media uploads dramatically faster: concurrent S3 uploads + streaming from disk
|
|
|
|
**Performance**
|
|
|
|
* Concurrent uploads via AWS CommandPool (default 5, configurable via IDRIVEE2_UPLOAD_CONCURRENCY)
|
|
* Files now stream directly from disk (fopen + resource) instead of loading fully into memory
|
|
* Removed per-file headObject pre-check (eliminates N extra HTTP round-trips per image)
|
|
* Single DB write for upload stats per attachment (replaces one write per file)
|
|
* Hook priority lowered from 999 to 10
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 4.1 - 7.1
|
|
* PHP: 8.1 - 8.5
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 3.13.5 (0 errors)
|
|
* WordPress Coding Standards: 3.3.0 (0 violations)
|
|
* PHPStan: Level 9, 0 errors
|
|
* PHPUnit: 22 tests, 54 assertions
|
|
|
|
= 1.1.4 =
|
|
|
|
_Release date: 2026-06-02_
|
|
|
|
**Highlights**
|
|
|
|
* Full dev tooling setup (PHPCS, PHPStan level 9, PHPUnit) and first test suite
|
|
* WordPress 7.1 and PHP 8.5 compatibility declared
|
|
|
|
**Added**
|
|
|
|
* Composer dev tooling: PHPCS/WPCS, PHPStan (level 9), PHPUnit, PHPCompatibility
|
|
* phpstan.neon, phpcs.xml, phpunit.xml configuration
|
|
* PHPUnit test suite (22 tests, 54 assertions): plugin headers, Config, Rate_Limiter
|
|
* bin/deploy.sh: automated ZIP generation with production vendor only
|
|
* docs/: db-migrations.md, known-issues.md
|
|
|
|
**Changed**
|
|
|
|
* Tested up to WordPress 7.1; PHP compatibility extended to 8.5
|
|
* PHPStan level upgraded from 8 to 9
|
|
* `IDRIVEE2_MEDIA_VERSION` constant defined in plugin main file; replaces `get_file_data()` call in enqueue
|
|
* Admin page: proper `sanitize_key()` for `$_GET['page']`, type-check for `$_POST['test_file']`
|
|
* deploy.sh: switched from `composer update` to `composer install` for reproducible builds from lock file
|
|
* Logger stats: switched to `time() - ($n * DAY_IN_SECONDS)` arithmetic for consistent UTC dates
|
|
* uninstall.php: variable renamed to satisfy WP prefix naming rules
|
|
|
|
**Fixed**
|
|
|
|
* WP_Filesystem null guard before file operations in Media_Uploader
|
|
* Type-safety on all `get_option()`/`get_transient()` results (guards against mixed types)
|
|
* Rate_Limiter arithmetic: transient value narrowed to int before subtraction
|
|
* robotstxt-updater.php: short ternary operators replaced, `serialize()` annotated
|
|
* Media_Uploader deletion queue: malformed `timestamp=0` entries now requeued instead of deleted immediately
|
|
* Logger: UTC-consistent date arithmetic in both `track_s3_operation()` and `get_s3_stats()`
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.8 - 7.1
|
|
* PHP: 8.2 - 8.5
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 3.13.5 (0 errors)
|
|
* WordPress Coding Standards: 3.3.0 (0 violations)
|
|
* PHPStan: Level 9, 0 errors
|
|
* PHPCompatibility scan: 8.2-8.5
|
|
|
|
= 1.1.3 =
|
|
|
|
_Release date: 2026-02-04_
|
|
|
|
**Highlights**
|
|
|
|
* Critical bug fix for namespace issue causing fatal error
|
|
|
|
**Fixed**
|
|
|
|
* Critical namespace issue with Robotstxt_Updater class causing fatal error
|
|
* Fatal error "Class 'iDrivee2Media\Robotstxt_Updater' not found" resolved
|
|
* Added global namespace prefix (`\`) to `Robotstxt_Updater::init()` call in main plugin file
|
|
* Plugin now loads correctly without PHP fatal errors
|
|
|
|
**Technical Details**
|
|
|
|
* Issue: `Robotstxt_Updater` class is defined in global namespace but was called from within `iDrivee2Media` namespace
|
|
* Solution: Changed `Robotstxt_Updater::init()` to `\Robotstxt_Updater::init()` to explicitly reference global namespace
|
|
* Location: idrivee2-media-upload.php line 67
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.8 - 6.9
|
|
* PHP: 8.2 - 8.4
|
|
* MariaDB: 10.6+
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 0 errors
|
|
* WordPress Coding Standards (WPCS): 3.3
|
|
* PHPStan: Level 8 (0 errors)
|
|
* PHPCompatibility: 8.2-8.4
|
|
|
|
= 1.1.2 =
|
|
|
|
_Release date: 2026-02-04_
|
|
|
|
**Highlights**
|
|
|
|
* Build system improvements for consistent PHP 8.2+ deployments
|
|
|
|
**Changed**
|
|
|
|
* Deployment script updated to use PHP 8.2 as platform base for production builds
|
|
* Now uses `composer update --no-dev` instead of `composer install --no-dev`
|
|
* Temporarily configures `platform.php 8.2` during build for consistent dependency resolution
|
|
* Platform configuration cleaned up after build completes
|
|
* Deploy script updated to bin/deploy.sh version 1.1.0
|
|
|
|
**Improved**
|
|
|
|
* Production packages now guarantee PHP 8.2+ compatibility regardless of development environment PHP version
|
|
* Build consistency ensures reliable deployments across different server environments with varying PHP versions
|
|
* Using `composer update` ensures latest compatible versions for target PHP version
|
|
* Dependency resolution is consistent and predictable
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.8 - 6.9
|
|
* PHP: 8.2 - 8.4
|
|
* MariaDB: 10.6+
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 0 errors
|
|
* WordPress Coding Standards (WPCS): 3.3
|
|
* PHPStan: Level 8 (0 errors)
|
|
* PHPCompatibility: 8.2-8.4
|
|
|
|
= 1.1.1 =
|
|
|
|
_Release date: 2026-02-04_
|
|
|
|
**Highlights**
|
|
|
|
* Deployment script improvements to ensure production packages are complete
|
|
|
|
**Fixed**
|
|
|
|
* Deployment script now includes essential files in production packages
|
|
* update.json (auto-update system) now included in deploy
|
|
* robotstxt-updater.php (auto-update handler) now included in deploy
|
|
* readme.txt (WordPress.org documentation) now included in deploy
|
|
* changelog.txt (full changelog) now included in deploy
|
|
* Updated script documentation and output messages
|
|
|
|
**Improved**
|
|
|
|
* Production packages now contain all files required for automatic updates from Gitea
|
|
* Deploy script version updated to 1.1.0
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.8 - 6.9
|
|
* PHP: 8.2 - 8.4
|
|
* MariaDB: 10.6+
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 0 errors
|
|
* WordPress Coding Standards (WPCS): 3.3
|
|
* PHPStan: Level 8 (0 errors)
|
|
* PHPCompatibility: 8.2-8.4
|
|
|
|
= 1.1.0 =
|
|
|
|
_Release date: 2026-02-04_
|
|
|
|
**Highlights**
|
|
|
|
* Configuration and consistency improvements for PHP 8.2+ compatibility
|
|
* Updated plugin repository URLs to Gitea
|
|
* Fixed text domain consistency across all files
|
|
|
|
**Changed**
|
|
|
|
* Added explicit PHP version requirement (>=8.2) to composer.json
|
|
* Updated update.json with correct plugin information
|
|
* Fixed Text Domain in robotstxt-updater.php to match plugin slug (idrivee2-media-upload)
|
|
* Migrated repository from GitHub to Gitea (git.robotstxt.es)
|
|
* Added Gitea Plugin URI and Primary Branch headers
|
|
|
|
**Fixed**
|
|
|
|
* Composer now validates PHP version during dependency installation
|
|
* Plugin update system correctly identifies the plugin
|
|
* Translations properly loaded for updater error messages
|
|
|
|
**Improved**
|
|
|
|
* All text domains now consistently use 'idrivee2-media-upload'
|
|
* Update metadata accurately reflects plugin information
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.8 - 6.9
|
|
* PHP: 8.2 - 8.4
|
|
* MariaDB: 10.6+
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 0 errors
|
|
* WordPress Coding Standards (WPCS): 3.3
|
|
* PHPStan: Level 8 (0 errors)
|
|
* PHPCompatibility: 8.2-8.4
|
|
|
|
= 1.0.0 =
|
|
|
|
_Release date: 2026-02-03_
|
|
|
|
**Highlights**
|
|
|
|
* First stable production-ready release
|
|
* Enterprise-grade security with comprehensive logging
|
|
* OWASP Top 10 (2021) compliance
|
|
* PHPStan level 8 compliance with zero errors
|
|
* Security rating: A+ (Excellent)
|
|
|
|
**Added**
|
|
|
|
* Security logging system with comprehensive audit trail
|
|
* Rate limiting protection (60s users, 30s admins)
|
|
* S3 operation statistics tracking (30-day retention)
|
|
* Logger class for security and operations logging
|
|
* Rate_Limiter class for abuse prevention
|
|
* Comprehensive security audit documentation (7,500+ lines)
|
|
* Code quality report with metrics (3,200+ lines)
|
|
|
|
**Changed**
|
|
|
|
* Capability checks switched from role checks to manage_options
|
|
* Type safety with strict type hints throughout
|
|
* Error messages now user-friendly with translations
|
|
* Admin interface shows rate limit feedback
|
|
|
|
**Fixed**
|
|
|
|
* All 17 PHPStan level 8 type safety issues resolved
|
|
* Array type specifications added to all methods
|
|
* Null handling for AWS error messages
|
|
* Return type declarations match actual returns
|
|
* All capability checks use manage_options
|
|
|
|
**Security**
|
|
|
|
* OWASP Top 10 (2021) 100% compliance
|
|
* Enhanced nonce validation
|
|
* Comprehensive input sanitization and output escaping
|
|
* Security logging for all critical operations
|
|
* Rate limiting to prevent brute force attacks
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.8 - 6.9
|
|
* PHP: 8.2 - 8.4
|
|
* MariaDB: 10.6+
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 0 errors
|
|
* WordPress Coding Standards (WPCS): 3.3
|
|
* PHPStan: Level 8 (0 errors)
|
|
* PHPCompatibility: 8.2-8.4
|
|
|
|
= 0.3.0 =
|
|
|
|
_Release date: 2025-02-03_
|
|
|
|
**Highlights**
|
|
|
|
* Complete refactoring to class-based architecture
|
|
* Modular file structure with dependency injection
|
|
* Added PHPUnit test framework
|
|
* Moved from Media to Settings menu
|
|
|
|
**Added**
|
|
|
|
* Settings page in WordPress Admin (Settings → iDrivee2)
|
|
* Timestamped test files (test-YYYYMMDDHHMMSS.txt)
|
|
* Persistent test files with delete capability
|
|
* Database-stored configuration option
|
|
* Hybrid configuration (wp-config.php + database)
|
|
* Class-based architecture with 6 classes
|
|
* PHPUnit test structure
|
|
* PHPStan static analysis
|
|
* Deployment script (bin/deploy.sh)
|
|
* Uninstall script
|
|
* Composer scripts (test, phpcs, phpstan, lint)
|
|
|
|
**Changed**
|
|
|
|
* Menu location from Media → iDrivee2 to Settings → iDrivee2
|
|
* Architecture from functional to object-oriented
|
|
* JavaScript version from hardcoded to dynamic
|
|
|
|
**Fixed**
|
|
|
|
* Code duplication eliminated (7 instances)
|
|
* WordPress Coding Standards violations
|
|
* PHP compatibility issues
|
|
* Type safety with strict declarations
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.7 - 6.9
|
|
* PHP: 8.2 - 8.4
|
|
* MariaDB: 10.6+
|
|
|
|
**Tests**
|
|
|
|
* PHP Coding Standards: 0 errors
|
|
* WordPress Coding Standards (WPCS): 3.3
|
|
* PHPStan: Basic structure added
|
|
* PHPCompatibility: 8.2+
|
|
|
|
= 0.1.13 =
|
|
|
|
_Release date: 2024-XX-XX_
|
|
|
|
**Highlights**
|
|
|
|
* Initial public release
|
|
* Basic S3-compatible storage integration
|
|
|
|
**Added**
|
|
|
|
* Automatic media upload to S3
|
|
* Local file deletion after upload
|
|
* CDN URL rewriting
|
|
* WordPress admin testing interface
|
|
* Configuration via wp-config.php constants
|
|
* Multisite support
|
|
|
|
**Compatibility**
|
|
|
|
* WordPress: 6.5+
|
|
* PHP: 7.4+
|
|
* MariaDB: 10.6+
|