This commit is contained in:
Javier Casares 2026-08-12 13:18:40 +00:00
commit bc1cb5e00a
32 changed files with 4254 additions and 0 deletions

100
readme.txt Normal file
View file

@ -0,0 +1,100 @@
=== Manager (by ROBOTSTXT) ===
Contributors: javiercasares, robotstxt
Tags: dashboard, catalog, updates, subscriptions, management
Requires at least: 7.0
Tested up to: 7.1
Stable tag: 0.1.0
Requires PHP: 8.4
Version: 0.1.0
License: GPL-3.0-or-later
License URI: https://www.gnu.org/licenses/gpl-3.0.txt
Client-side dashboard for the ROBOTSTXT plugin ecosystem. Browse the catalog, see what's installed, and spot subscription issues — all from your own wp-admin.
== Description ==
Manager (by ROBOTSTXT) is a WordPress plugin that customers install on **their own** site. It connects to a remote Plugins Core installation (via REST API + account-level API key) and provides a single dashboard for the ROBOTSTXT plugin ecosystem:
* Lists the full plugin catalog with name, type (free/premium), price, and current version.
* For each catalog entry, shows the **local install state**: not installed, installed (inactive), up to date, or update available.
* One-click actions (Phase 2+): Install free plugins, Buy paid plugins (redirects to checkout on the store site), trigger native WordPress updates.
* Subscription health dashboard (Phase 4+): license expiring soon, payment failed, expired — surfaced as admin notices so issues are visible before updates silently stop.
This plugin does **not** re-implement the per-plugin update mechanism. Every ROBOTSTXT plugin bundles its own copy of the `Robotstxt_Core_Plugin_Updater` SDK, so updates keep working even if Manager is deactivated. Manager's value is visibility and one place to click.
**Phase 1 (current):** Read-only catalog view with local install-state resolution. Settings screen with API key (encrypted at rest), store URL, cache TTL, and connection test. Install/Update/Buy buttons are present but disabled pending Phase 2+.
== Using the plugin ==
= Settings =
Configure at **ROBOTSTXT → Settings**:
* **Store URL** — Base URL of the remote Plugins Core installation (defaults to `https://plugins.robotstxt.es`).
* **API Key** — Account-level API key issued by the ROBOTSTXT store. Encrypted before storage; masked in the UI (last 4 characters shown). Use the "Test connection" button to verify connectivity.
* **Catalog Cache (minutes)** — How long the catalog response is cached in a transient. Default: 60 minutes.
* **Data on Uninstall** — Opt-in checkbox. When enabled, all Manager options and transients are deleted on uninstall. Default: off.
= Main screen =
**ROBOTSTXT → Plugins** shows the catalog table:
| Column | Description |
|---|---|
| Plugin | Name and current version from the store. |
| Type | Free or Premium. |
| Price | Annual price in EUR, or — for free plugins. |
| Local state | Not installed / Installed (inactive) / Up to date / Update available (vX → vY). |
| Action | Install / Buy / Update (Phase 2+; disabled in Phase 1). |
Click "Refresh catalog" to force a fresh fetch from Core.
== Installation ==
Extract the ZIP to `/wp-content/plugins/robotstxt-manager/`. Activate from the Plugins screen. Go to **ROBOTSTXT → Settings** to configure the Store URL and API key.
== Frequently Asked Questions ==
= Is this plugin compatible with WordPress Multisite? =
No. This plugin is intentionally not compatible with WordPress Multisite, matching the architecture of the rest of the ecosystem.
= What PHP version is required? =
PHP 8.4 or higher.
= Do I need Plugins Core installed on my site? =
No. Plugins Core runs on the ROBOTSTXT store site. This plugin talks to it remotely via REST API. You do not need Core, Mollie, or Sync installed locally.
= How is the API key stored? =
Encrypted at rest using AES-256-CBC with a key derived from your site's WordPress `AUTH_KEY` and `AUTH_SALT` constants. Never stored in plaintext, never logged, never exposed in any response.
== Compatibility ==
* WordPress: 7.0 - 7.1
* PHP: 8.4 - 8.5
== Changelog ==
= 0.1.0 =
_Release date: 2026-08-12_
* Phase 1 scaffold: plugin header, autoloader, lifecycle hooks, constants.
* Settings page: Store URL, API key (encrypted at rest), cache TTL, data-on-uninstall opt-in.
* Connection test AJAX endpoint with nonce and capability check.
* Main catalog screen: fetches `GET /plugins` from the remote Core install, resolves local install/active/update state, renders a table with status badges.
* "Refresh catalog" admin-post action.
* Per-project tooling: Composer, PHPCS + WPCS + PHPCompatibility, PHPStan level 9 + wp-compat, PHPUnit. `bin/preflight.sh` and `bin/deploy.sh`.
== Compliance ==
This plugin adheres to the following security measures and review protocols for each version:
* [WordPress Plugin Handbook](https://developer.wordpress.org/plugins/)
* [WordPress Plugin Security](https://developer.wordpress.org/plugins/wordpress-org/plugin-security/)
* [WordPress APIs Security](https://developer.wordpress.org/apis/security/)
* [WordPress Coding Standards](https://github.com/WordPress/WordPress-Coding-Standards)
* [Plugin Check (PCP)](https://wordpress.org/plugins/plugin-check/)