=== Smart Admin Assistant Pro ===
Contributors: bdthemes
Tags: admin, dashboard, login, security, performance
Requires at least: 6.1
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 2.4.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Premium add-on for Smart Admin Assistant: SEO and Search Console, activity log, session monitor, 2FA, magic login, SMTP and server health.

== Description ==

Smart Admin Assistant Pro is the premium add-on for the Smart Admin Assistant plugin. It plugs into the free plugin's extension API and adds its own modules, settings sections, REST endpoints and admin pages. Since 2.0 the free plugin ships no locked or licence-gated features — everything premium lives in this add-on. From 2.4.0 that also covers the Custom Code snippet manager, which WordPress.org no longer allows the free plugin to include.

= Pro Features Include: =

* **Advanced Login Customization** - Customize login page with advanced styling, custom logos, backgrounds, and branding options
* **Media Replacement** - Replace media files without breaking links and references throughout your site
* **Custom Post Types Management** - Advanced custom post types management with enhanced features and capabilities
* **Advanced Content Ordering** - Advanced content ordering and sorting capabilities for better content management
* **External Permalinks** - Set external URLs for posts and pages to redirect to external websites
* **Role-Based Permissions** - Advanced role-based permissions and access control for better security
* **Admin Menu Customization** - Advanced admin menu customization and management for better user experience
* **List Table Enhancements** - Enhanced list tables with advanced features and better usability
* **Dashboard Customization** - Advanced dashboard customization and widgets for personalized admin experience
* **UI Enhancements** - Advanced UI enhancements and customizations for better visual experience
* **Advanced Code Snippets** - Advanced code snippet management with testing and validation capabilities
* **Code Import/Export** - Import and export code snippets and configurations for easy backup and migration
* **Code Testing & Validation** - Test and validate code snippets before execution to prevent errors
* **Advanced Insertion Points** - Advanced code insertion points and hooks management for precise code placement
* **Advanced User Tracking** - Advanced user activity tracking and analytics for better insights
* **Advanced Login Restrictions** - Advanced login restrictions and security features for enhanced protection
* **Custom Logout Redirects** - Custom logout redirects and user flow management for better user experience

= Requirements =

* WordPress 5.0 or higher
* PHP 7.4 or higher
* Smart Admin Assistant plugin (free version) **2.3.0 or newer** must be installed and activated. Pro 2.0 refuses to load on older free versions and shows an admin notice asking you to update; the free plugin 2.3 likewise deactivates Pro 1.x.

= Installation =

1. Upload the `smart-admin-assistant-pro` folder to the `/wp-content/plugins/` directory
2. Activate the plugin through the 'Plugins' menu in WordPress
3. Ensure the free Smart Admin Assistant plugin (2.3.0+) is also activated
4. Go to Smart Admin Assistant → License and activate your license key

= Frequently Asked Questions =

= Does this plugin work without the free version? =

No, Smart Admin Assistant Pro requires the free Smart Admin Assistant plugin to be installed and activated. The pro plugin extends the functionality of the free plugin.

= What happens if I deactivate the free plugin? =

If you deactivate the free Smart Admin Assistant plugin, the pro plugin will show a notice and may not function properly. Both plugins should remain active for optimal functionality.

= Do I need a license key? =

Yes. The License page (Smart Admin Assistant → License) is available as soon as the add-on is active; the premium modules load once a valid key has been activated against our license server.

= Can I use this plugin on multiple sites? =

The licensing terms depend on your purchase. Please refer to the license agreement that came with your purchase.

== External Services ==

This add-on connects to the following third-party services. None of them are contacted unless the related feature is enabled or the action is triggered by an administrator; no data is sent on the public front end except where stated.

= BdThemes license server (licenses.bdthemes.co) =
* **What it is used for:** validating and deactivating your license key, and checking for plugin updates.
* **What is sent:** the license key and the license email you enter, this site's domain, the add-on version and product id; update checks send the license key and add-on version.
* **When:** when you activate or deactivate a key on the License page, on the periodic license re-check, and when WordPress checks for plugin updates.
* Terms of use: https://bdthemes.com/terms-of-use/ — Privacy policy: https://bdthemes.com/privacy-policy/

= BdThemes Search Console connector (callback.bdthemes.com) =
* **What it is used for:** the SEO → Search Console feature. The connector is a middleware run by BdThemes that holds the Google OAuth grant and proxies Google Search Console API requests, so this plugin never stores your Google credentials.
* **What is sent:** when you click "Connect Search Console" your site's home URL and a one-time state token are sent and you are redirected to the connector (which then sends you to Google); after connecting, the connector's API key for your site is stored in your database and sent with every request (site URL, selected property, date range and query parameters).
* **When:** only when an administrator clicks Connect, and afterwards when the SEO dashboard is opened or its data cache expires (automatic refresh only once connected; disconnecting stops all requests).
* Terms of use: https://bdthemes.com/terms-of-use/ — Privacy policy: https://bdthemes.com/privacy-policy/
* Search Console data itself is subject to Google's terms: https://policies.google.com/terms — https://policies.google.com/privacy

= Google reCAPTCHA (www.google.com/recaptcha) =
* **What it is used for:** the Security → CAPTCHA Protection feature when the reCAPTCHA type is selected (the math and image CAPTCHA types run entirely on your server).
* **What is sent:** the reCAPTCHA `api.js` script is loaded on the login and comment forms (and the WooCommerce login form) in the visitor's browser (Google receives the visitor's IP address, browser data and cookies per its policy); on submit, the response token and the visitor's IP address are sent from your server to `https://www.google.com/recaptcha/api/siteverify` together with your secret key.
* **When:** only while reCAPTCHA is enabled in the plugin settings and a site key/secret are configured; also when an administrator clicks "Test CAPTCHA".
* Terms of service: https://policies.google.com/terms — Privacy policy: https://policies.google.com/privacy

= ip-api.com (IP geolocation) =
* **What it is used for:** the Session Monitor shows the approximate country/city and ISP of logged-in sessions.
* **What is sent:** the public IP address of a logged-in user's session (private/reserved addresses are never sent). Results are cached for 24 hours; lookups are limited per request.
* **When:** only when the Session Monitor module is enabled and an administrator opens the Session Monitor page.
* Terms of service and privacy: https://ip-api.com/docs/legal

= Requests to your own site (no third party) =
* The SEO checklist and Server Health monitor fetch your own home page, robots.txt and sitemap over HTTP to measure response time and check on-page basics; the Broken Link Checker requests the URLs found in your content to test them. These are ordinary HTTP requests to the linked sites and carry no personal data.

= Optional, off by default =
* Two-factor authentication can render the enrollment QR code through `api.qrserver.com` **only** if a developer explicitly opts in via the `bdtsaa_2fa_allow_external_qr` filter; by default the QR code is generated locally and nothing is sent.

== Changelog ==

### 2.4.1 [September 20, 2026]
* Fixed: Adding a redirect in URL Redirect Manager no longer removes the empty row a moment later — a rule is kept in the editor until both From and To are filled in
* Fixed: A source path typed as a full URL is no longer saved as "/", which turned the rule into a redirect of the whole homepage
* Fixed: A redirect whose From points at another domain is now refused with an explanation instead of being stored as a homepage redirect, and it can no longer overwrite the rule that was already saved
* Changed: URL Redirect Manager now saves with an explicit Save Changes button instead of saving while you type
* Changed: The From field shows the path that will actually be stored as soon as you leave the field, and warns when it matches the site homepage

### 2.4.0 [September 14, 2026]
* Added: The Custom Code snippet manager now ships in this add-on. Snippet storage, insertion points, the editor screen and CSS/JavaScript/HTML rendering moved here from the free plugin, which can no longer include them — WordPress.org does not permit a directory-hosted plugin to save and run arbitrary code. PHP snippets, display conditions, scheduling, minification and import/export are unchanged
* Changed: Existing snippets are picked up automatically. They stay in the same database table, which this plugin now creates and removes
* Changed: The licence card no longer shows the "Modules in use" meter — the same figure is still available in the licence details dialog
* Changed: Requires Smart Admin Assistant 2.4.0 or newer — update the free plugin first

### 1.7.0 [August 19, 2026]
* Added: Site health email reports — scheduled weekly or daily delivery, "email after each scan", and the manual send from Settings and the scan report modal. Moved here from the free plugin; settings saved there are picked up automatically
* Changed: A failed report now says why (the mailer's own reason, e.g. a refused SMTP login) instead of only "check your mail configuration"
* Changed: Requires Smart Admin Assistant 2.3.0 or newer — update the free plugin first
* Added: All premium features now ship in this add-on instead of being unlocked inside the free plugin — SEO, SMTP, redirects, code snippets, admin menu design, login page builder, 2FA, CAPTCHA, magic login, activity log, session monitor, cron manager, developer tools and server health
* Added: Pro React admin bundle that plugs its tabs and pages into the free dashboard
* Changed: License page moved to Smart Admin Assistant → License, and is reachable before a key is activated
* Changed: Pro options, CAPTCHA fields and script handles renamed to a `bdtsaapro_` prefix (existing values migrate automatically)
* Fixed: Deactivation now clears every scheduled event this plugin owns
* Fixed: The media replacement screen no longer requests a stylesheet that does not exist
* Changed: Uninstall now removes everything this add-on owns — its tables, options, post meta, crons and licence data

### 1.6.4 [August 11, 2026]
* Fixed: All pro modules could be silently disabled on sites where the stored active-modules list was empty, despite a valid license and with no way to recover; an empty list is now repaired and all modules load again

### 1.6.3 [August 11, 2026]
* Fixed: Admin menu items hidden with Menu Design stayed visible on every screen outside the plugin's own pages

### 1.6.2 [August 4, 2026]
* Added: REST API for the new WP-Cron Manager tab (requires free version 2.2.0)
* Fixed: Magic Login links showed the login page instead of signing the user in while the Custom Login URL feature was enabled
* Fixed: Magic Login emails could go out with an empty subject or body when the saved template fields were blank; the defaults are now used instead
* Fixed: Magic Login email templates support HTML such as links and line breaks (requires free version 2.2.0)

### 1.6.1 [July 29, 2026]
* Security: Hardened Magic Login form handling
* Fixed: Scripts and styles now load only on the screens where they are used
* Fixed: Renamed several AJAX actions to avoid conflicts with other plugins (requires free version 2.1.1)
* Fixed: Disabling all pro modules re-enabled them, and the dependency notice would not stay dismissed
* Fixed: Failed database operations (broken links, IP blocklist, optimizer) now report accurate errors
* Improved: Lighter server metrics, batched activity-log cleanup, and less frequent cron checks
* Improved: REST endpoints now validate their query parameters

### 1.6.0 [July 27, 2026]
* Added: Server Monitor module — live CPU, RAM, swap, and disk metrics with WordPress health insights, powering the new Server Health dashboard
* Added: REST API endpoint for server metrics, with built-in caching to keep dashboard polling lightweight
* Fixed: Server CPU readings could blend together on Linux hosts; each reading is now smoothed independently

### 1.5.0 [July 26, 2026]
* Security: Fixed a two-factor authentication bypass. The 2FA setup flow could be used to complete login without verifying a second factor — either by posting directly to the final "complete" step, or by re-running setup against an already-enrolled account. Setup completion now requires a second factor to be verified within the same pending-login session, and already-enrolled users are routed to verification instead of setup.
* Security: The Developer Tools "manage WP debug log" feature no longer writes a plaintext `wp-config.php.bdtsaa-bak` backup next to wp-config.php (web-accessible on most installs, exposing database credentials and secret keys). The config is now updated via an atomic replace with no on-disk backup, and any backup left by a previous version is removed automatically.
* Security: The 2FA verification screen now enforces the account lockout at entry, so the "maximum attempts" limit can no longer be bypassed to brute-force verification codes.
* Security: Magic Login email codes are now generated with a cryptographically secure random source instead of str_shuffle().
* Security: Magic Login token authentication is now throttled per account after repeated invalid attempts.
* Security: Magic Login now derives the client IP from REMOTE_ADDR only, ignoring spoofable forwarding headers unless the site opts in via the `bdtsaa_trust_proxy_headers` filter.
* Security: The Performance module no longer leaves predictable, web-accessible ".htaccess" backup copies (".htaccess.bdtsaa-backup-*") in the site root when toggling browser-caching rules. Writes now use a random temporary file with an in-memory restore, and any backups left by earlier versions are removed automatically.
* Security: Two-factor recovery codes are now compared in constant time (hash_equals) to remove a theoretical timing side channel.
* Security: The Magic Login form no longer reveals whether an account exists for a submitted username or email; it always shows the same "check your inbox" response, preventing username/email enumeration.
* Security: The dependency admin notice can no longer be dismissed via a forged GET request; dismissal now always requires a valid nonce and capability.
* Fixed: The stored license state is now loaded on plugins_loaded, before any plugin's init hooks run — previously the free plugin could query the license before it was bootstrapped and treat the whole request as unlicensed, making premium features intermittently appear locked.
* Fixed: The debug-log REST endpoint always returned an empty log (it called a method that did not exist); it now returns the actual log lines for the React dashboard.
* Fixed: Clearing the debug log via REST reported success even when the file was missing or not writable; it now reports an accurate result and surfaces a clear error when the file cannot be written. Both endpoints now resolve the log path through the viewer's containment-checked helper.
* Fixed: Clearing the activity log (REST and AJAX) and clearing all IP blocks now report an accurate error when the underlying database operation fails, instead of always reporting success.
* Fixed: The spam-comment cleanup now reports an error when the deletion query fails rather than reporting success with a count of zero.
* Fixed: Removed a stray "1" that was rendered above the license activation form.
* Fixed: Plugin activations were logged in the Activity Log even when "Log plugin changes" was disabled; activation logging now respects the toggle, matching deactivation and update logging.
* Improved: Aligned the Singleton trait with the free plugin (added the direct-access guard) and centralized license-key display masking. No functional change.
* Added: Compatibility with WordPress 7.0.1
* Added: REST API endpoints for Activity Log and Debug Log (React dashboard integration)
* Added: Pro React admin integration with license data for the new dashboard UI
* Improved: Activity log with individual entry deletion, cleaner option tracking, and improved CSV export
* Improved: Login page customization compatibility with the React admin dashboard
* Improved: License activation and deactivation flow with clearer error feedback
* Added: Performance module support for removing .htaccess browser caching rules when disabled
* Fixed: Login template builder event handling and template switching in React admin context

### 1.4.0 [June 11, 2026]
* Added: Debug Log Viewer with live refresh, clear, and download capabilities (Developer Tools)
* Added: Auto Update Delay option to defer plugin and theme auto-updates by 5–7 days (Developer Tools)
* Added: URL Redirect Manager and Smart 404 Redirect runtime support (Utilities)
* Added: Login page template builder with layout templates and advanced style settings (Pro)

### 1.3.1 [May 11, 2026]
* Fixed: Resolved CAPTCHA validation issue preventing successful authentication on login forms

### 1.3.0 [May 7, 2026]
* Added: Compatibility with WordPress 7.0
* Added: 2FA (Two-Factor Authentication) support to the Security module
* Improved: Updated codebase for the latest WordPress core APIs and standards

### 1.2.2 [March 30, 2026]
* Added: Disable Emojis option in Performance Module to reduce unnecessary script loading and improve page load times
* Improved: Code quality and overall plugin stability
* Fixed: Various minor bugs and edge case issues

### 1.2.1 [February 22, 2026]
* Improved: General performance optimizations and code improvements
* Improved: Enhanced compatibility with Smart Admin Assistant free version
* Fixed: Minor bug fixes and stability improvements

### 1.2.0 [January 21, 2026]
* Added: Comprehensive activity logging system to monitor user activities, system modifications, and security events
* Fixed: Resolved SMTP configuration and settings persistence issues

### 1.1.7 [January 1, 2026]
* Fixed: WordPress 6.9 compatibility issue.
* Improved: Enhanced asset loading performance through minified CSS and JavaScript files

### 1.1.6 [November 30, 2025]
* Fixed: Magic Login not working when Custom Login URL was enabled. (thanks to Guozhen Chen)
* Fixed: Missing resource (404) caused by incorrect file path; file relocated from Pro plugin directory. (thanks to Guozhen Chen)

### 1.1.5 [November 26, 2025]
* Improved: Fixed recaptcha login issues specific to WooCommerce login page. (thanks to Guozhen Chen)

### 1.1.4 [November 18, 2025]
* Improved: system requirements and compatibility.

### 1.1.3 [October 30, 2025]
* Fixed: pro plugin activation issue.

### 1.1.2 [October 16, 2025]
* Fixed login page button color issue.

### 1.1.1 [October 1, 2025]
* Introduced Magic Login feature in Login and User Module, enabling seamless login experience. (Pro)
* Enhanced image size management functionality and user experience.

### 1.1.0 [September 28, 2025]
* SMTP setup feature added in Additional Module. (Pro)
* Added: Custom avatar feature added in Additional Module. (Pro)
* Added: Image size management feature added in Additional Module. (Pro)

= 1.0.1 =
* Added support for Custom Logout Redirects

= 1.0.0 =
* Initial release
* Unlocks all premium features from Smart Admin Assistant
* Advanced login customization
* Media replacement functionality
* Custom post types management
* Advanced content ordering
* External permalinks
* Role-based permissions
* Admin menu customization
* List table enhancements
* Dashboard customization
* UI enhancements
* Advanced code snippets
* Code import/export
* Code testing & validation
* Advanced insertion points
* Advanced user tracking
* Advanced login restrictions

== Development ==

For local development from source:

1. Run `composer install` to generate the PSR-4 autoloader.
2. Run `npm install` to install front-end build dependencies.
3. Run `npm run dev` for a watch build with sourcemaps, or `npm run build` for a production build.
4. Compiled CSS and JS are output to `dist/` and loaded by WordPress at runtime.

Release builds compile assets automatically via GitHub Actions before creating the distribution zip.

== Upgrade Notice ==

= 2.4.1 =
Fixes URL Redirect Manager: new rules no longer disappear while you add them, and a source typed as a full URL is no longer stored as "/", which redirected the whole homepage. Check any redirect whose From shows "/".

= 2.4.0 =
Requires Smart Admin Assistant 2.4.0 or newer — update the free plugin first. The Custom Code snippet manager now lives in this add-on; existing snippets carry over untouched.

= 1.7.0 =
Requires Smart Admin Assistant 2.3.0 or newer — update the free plugin first. All premium features now ship in this add-on; the free plugin no longer contains locked features.

= 1.5.0 =
Important security update: fixes 2FA bypass, Magic Login hardening, wp-config and .htaccess backup removal, and multiple bug fixes. Also includes React dashboard integration and REST API support. Recommended for all users.

= 1.4.0 =
Major update with Debug Log Viewer, Developer Tools, URL redirect runtime support, and a redesigned login page template builder. Recommended for all users.

= 1.0.0 =
Initial release of Smart Admin Assistant Pro. Unlocks all premium features from the free Smart Admin Assistant plugin.
