### 2.4.1 [September 20, 2026]
* Fixed: Adding a redirect in URL Redirect Manager no longer removes the empty row a moment later — a rule is kept in the editor until both From and To are filled in
* Fixed: A source path typed as a full URL is no longer saved as "/", which turned the rule into a redirect of the whole homepage
* Fixed: A redirect whose From points at another domain is now refused with an explanation instead of being stored as a homepage redirect, and it can no longer overwrite the rule that was already saved
* Changed: URL Redirect Manager now saves with an explicit Save Changes button instead of saving while you type
* Changed: The From field shows the path that will actually be stored as soon as you leave the field, and warns when it matches the site homepage

### 2.4.0 [September 14, 2026]
* Added: The Custom Code snippet manager now ships in this add-on. Snippet storage, insertion points, the editor screen and CSS/JavaScript/HTML rendering moved here from the free plugin, which can no longer include them — WordPress.org does not permit a directory-hosted plugin to save and run arbitrary code. PHP snippets, display conditions, scheduling, minification and import/export are unchanged
* Changed: Existing snippets are picked up automatically. They stay in the same database table, which this plugin now creates and removes
* Changed: The licence card no longer shows the "Modules in use" meter — the same figure is still available in the licence details dialog
* Changed: Requires Smart Admin Assistant 2.4.0 or newer — update the free plugin first

### 1.7.0 [August 19, 2026]
* Changed: Requires Smart Admin Assistant 2.3.0 or newer — update the free plugin first
* Added: All premium features now ship in this add-on instead of being unlocked inside the free plugin — SEO, SMTP, redirects, code snippets, admin menu design, login page builder, 2FA, CAPTCHA, magic login, activity log, session monitor, cron manager, developer tools and server health
* Added: Pro React admin bundle that plugs its tabs and pages into the free dashboard
* Changed: License page moved to Smart Admin Assistant → License, and is reachable before a key is activated
* Changed: Pro options, CAPTCHA fields and script handles renamed to a `bdtsaapro_` prefix (existing values migrate automatically)
* Fixed: Deactivation now clears every scheduled event this plugin owns
* Fixed: The media replacement screen no longer requests a stylesheet that does not exist
* Changed: Uninstall now removes everything this add-on owns — its tables, options, post meta, crons and licence data

### 1.6.4 [August 11, 2026]
* Fixed: All pro modules could be silently disabled on sites where the stored active-modules list was empty, despite a valid license and with no way to recover; an empty list is now repaired and all modules load again

### 1.6.3 [August 11, 2026]
* Fixed: Admin menu items hidden with Menu Design stayed visible on every screen outside the plugin's own pages

### 1.6.2 [August 4, 2026]
* Added: REST API for the new WP-Cron Manager tab (requires free version 2.2.0)
* Fixed: Magic Login links showed the login page instead of signing the user in while the Custom Login URL feature was enabled
* Fixed: Magic Login emails could go out with an empty subject or body when the saved template fields were blank; the defaults are now used instead
* Fixed: Magic Login email templates support HTML such as links and line breaks (requires free version 2.2.0)

### 1.6.1 [July 29, 2026]
* Security: Hardened Magic Login form handling
* Fixed: Scripts and styles now load only on the screens where they are used
* Fixed: Renamed several AJAX actions to avoid conflicts with other plugins (requires free version 2.1.1)
* Fixed: Disabling all pro modules re-enabled them, and the dependency notice would not stay dismissed
* Fixed: Failed database operations (broken links, IP blocklist, optimizer) now report accurate errors
* Improved: Lighter server metrics, batched activity-log cleanup, and less frequent cron checks
* Improved: REST endpoints now validate their query parameters

### 1.6.0 [July 27, 2026]
* Added: Server Monitor module — live CPU, RAM, swap, and disk metrics with WordPress health insights, powering the new Server Health dashboard
* Added: REST API endpoint for server metrics, with built-in caching to keep dashboard polling lightweight
* Fixed: Server CPU readings could blend together on Linux hosts; each reading is now smoothed independently

### 1.5.0 [July 26, 2026]
* Security: Fixed a two-factor authentication bypass. The 2FA setup flow could be used to complete login without verifying a second factor — either by posting directly to the final "complete" step, or by re-running setup against an already-enrolled account. Setup completion now requires a second factor to be verified within the same pending-login session, and already-enrolled users are routed to verification instead of setup.
* Security: The Developer Tools "manage WP debug log" feature no longer writes a plaintext `wp-config.php.bdtsaa-bak` backup next to wp-config.php (web-accessible on most installs, exposing database credentials and secret keys). The config is now updated via an atomic replace with no on-disk backup, and any backup left by a previous version is removed automatically.
* Security: The 2FA verification screen now enforces the account lockout at entry, so the "maximum attempts" limit can no longer be bypassed to brute-force verification codes.
* Security: Magic Login email codes are now generated with a cryptographically secure random source instead of str_shuffle().
* Security: Magic Login token authentication is now throttled per account after repeated invalid attempts.
* Security: Magic Login now derives the client IP from REMOTE_ADDR only, ignoring spoofable forwarding headers unless the site opts in via the `bdtsaa_trust_proxy_headers` filter.
* Security: The Performance module no longer leaves predictable, web-accessible ".htaccess" backup copies (".htaccess.bdtsaa-backup-*") in the site root when toggling browser-caching rules. Writes now use a random temporary file with an in-memory restore, and any backups left by earlier versions are removed automatically.
* Security: Two-factor recovery codes are now compared in constant time (hash_equals) to remove a theoretical timing side channel.
* Security: The Magic Login form no longer reveals whether an account exists for a submitted username or email; it always shows the same "check your inbox" response, preventing username/email enumeration.
* Security: The dependency admin notice can no longer be dismissed via a forged GET request; dismissal now always requires a valid nonce and capability.
* Fixed: The stored license state is now loaded on plugins_loaded, before any plugin's init hooks run — previously the free plugin could query the license before it was bootstrapped and treat the whole request as unlicensed, making premium features intermittently appear locked.
* Fixed: The debug-log REST endpoint always returned an empty log (it called a method that did not exist); it now returns the actual log lines for the React dashboard.
* Fixed: Clearing the debug log via REST reported success even when the file was missing or not writable; it now reports an accurate result and surfaces a clear error when the file cannot be written. Both endpoints now resolve the log path through the viewer's containment-checked helper.
* Fixed: Clearing the activity log (REST and AJAX) and clearing all IP blocks now report an accurate error when the underlying database operation fails, instead of always reporting success.
* Fixed: The spam-comment cleanup now reports an error when the deletion query fails rather than reporting success with a count of zero.
* Fixed: Removed a stray "1" that was rendered above the license activation form.
* Fixed: Plugin activations were logged in the Activity Log even when "Log plugin changes" was disabled; activation logging now respects the toggle, matching deactivation and update logging.
* Improved: Aligned the Singleton trait with the free plugin (added the direct-access guard) and centralized license-key display masking. No functional change.
* Added: Compatibility with WordPress 7.0.1
* Added: REST API endpoints for Activity Log and Debug Log (React dashboard integration)
* Added: Pro React admin integration with license data for the new dashboard UI
* Improved: Activity log with individual entry deletion, cleaner option tracking, and improved CSV export
* Improved: Login page customization compatibility with the React admin dashboard
* Improved: License activation and deactivation flow with clearer error feedback
* Added: Performance module support for removing .htaccess browser caching rules when disabled
* Fixed: Login template builder event handling and template switching in React admin context

### 1.4.0 [June 11, 2026]
* Added: Debug Log Viewer with live refresh, clear, and download capabilities (Developer Tools)
* Added: Auto Update Delay option to defer plugin and theme auto-updates by 5–7 days (Developer Tools)
* Added: URL Redirect Manager and Smart 404 Redirect runtime support (Utilities)
* Added: Login page template builder with layout templates and advanced style settings (Pro)

### 1.3.1 [May 11, 2026]
* Fixed: Resolved CAPTCHA validation issue preventing successful authentication on login forms

### 1.3.0 [May 7, 2026]
* Added: Compatibility with WordPress 7.0
* Added: 2FA (Two-Factor Authentication) support to the Security module
* Improved: Updated codebase for the latest WordPress core APIs and standards

### 1.2.2 [March 30, 2026]
* Added: Disable Emojis option in Performance Module to reduce unnecessary script loading and improve page load times
* Improved: Code quality and overall plugin stability
* Fixed: Various minor bugs and edge case issues

### 1.2.1 [February 22, 2026]
* Improved: General performance optimizations and code improvements
* Improved: Enhanced compatibility with Smart Admin Assistant free version
* Fixed: Minor bug fixes and stability improvements

### 1.2.0 [January 21, 2026]
* Added: Comprehensive activity logging system to monitor user activities, system modifications, and security events
* Fixed: Resolved SMTP configuration and settings persistence issues

### 1.1.7 [January 1, 2026]
* Fixed: WordPress 6.9 compatibility issue.
* Improved: Enhanced asset loading performance through minified CSS and JavaScript files

### 1.1.6 [November 30, 2025]
* Fixed: Magic Login not working when Custom Login URL was enabled. (thanks to Guozhen Chen)
* Fixed: Missing resource (404) caused by incorrect file path; file relocated from Pro plugin directory. (thanks to Guozhen Chen)

### 1.1.5 [November 26, 2025]
* Improved: Fixed recaptcha login issues specific to WooCommerce login page. (thanks to Guozhen Chen)

### 1.1.4 [November 18, 2025]
* Improved: system requirements and compatibility.

### 1.1.3 [October 30, 2025]
* Fixed: pro plugin activation issue.

### 1.1.2 [October 16, 2025]
* Fixed login page button color issue.

### 1.1.1 [October 1, 2025]
* Introduced Magic Login feature in Login and User Module, enabling seamless login experience. (Pro)
* Enhanced image size management functionality and user experience.

### 1.1.0 [September 28, 2025]
* SMTP setup feature added in Additional Module. (Pro)
* Added: Custom avatar feature added in Additional Module. (Pro)
* Added: Image size management feature added in Additional Module. (Pro)

### 1.0.1 [September 28, 2025]
* Added support for Custom Logout Redirects

### 1.0.0 [September 28, 2025]
* Initial release
* Unlocks all premium features from Smart Admin Assistant
* Advanced login customization
* Media replacement functionality
* Custom post types management
* Advanced content ordering
* External permalinks
* Role-based permissions
* Admin menu customization
* List table enhancements
* Dashboard customization
* UI enhancements
* Advanced code snippets
* Code import/export
* Code testing & validation
* Advanced insertion points
* Advanced user tracking
* Advanced login restrictions

== Upgrade Notice ==

= 1.5.0 =
Important security update: fixes 2FA bypass, Magic Login hardening, wp-config and .htaccess backup removal, and multiple bug fixes. Also includes React dashboard integration and REST API support. Recommended for all users.

= 1.4.0 =
Major update with Debug Log Viewer, Developer Tools, URL redirect runtime support, and a redesigned login page template builder. Recommended for all users.

= 1.0.0 =
Initial release of Smart Admin Assistant Pro. Unlocks all premium features from the free Smart Admin Assistant plugin.
