Nokri Theme - Changelog

Version 1.6.8 – Security & Stability Update

🔒 Security Hardening
- Fixed a broken-access-control flaw in the email account-verification link that could let an account's role be changed via a crafted verification URL. The token is now strictly validated (exact, non-empty, constant-time match) and the user id is sanitised.
- Applied the same hardening to the phone/OTP verification and "resend code" flows; verification codes are now sent only to the number on record and can no longer be matched against an empty value or redirected to another device.
- Chat: reading, deleting and marking conversations, deleting attachments, and blocking users are now restricted to the rightful participants (blocking is admin-only), fixing private-message disclosure and data tampering.
- Chat: user search now requires login (prevents anonymous user/email enumeration) and all chat database queries use prepared statements (prevents SQL injection).
- No design or feature changes. Compatible with the latest WordPress and PHP 7.4–8.3.
- Recommended update for all users. Update the Nokri theme (1.6.8), Nokri Framework (1.6.8), Nokri Elementor Widgets (1.6.7) and SB Chat (2.0.5) together.

🐞 Bug Fixes
- Fixed the "Categories With Images" widget where the category image, title and openings count overlapped and the card layout collapsed. Category images are now constrained to 64×64 and the card reserves space correctly, matching the demo.

📁 Updated Files
- template-parts/verification-logic.php
- template-parts/registration/email-verification.php
- inc/theme-shortcodes/classes/authentication.php
- css/theme.css
- style.css (version bump)
- wp-content/plugins/nokri_framework/index.php (version bump)
- wp-content/plugins/nokri-elementor/nokri-elementor.php (version bump)
- wp-content/plugins/sb_chat/includes/utilities.php
- wp-content/plugins/sb_chat/models/conversations.php
- wp-content/plugins/sb_chat/models/users.php
- wp-content/plugins/sb_chat/sbchat.php (version bump)

Version 1.6.7 – Security & Stability Update

🔒 Security Hardening
- Strengthened access checks so private data (resumes, applicant details, portfolio images, account members) is only visible/editable by the correct users.
- Hardened file-upload endpoints to require authentication.
- Improved handling of job listings and profile fields to prevent malicious input from being stored or displayed.
- Additional database-query and token-generation hardening.
- No design or feature changes. Compatible with the latest WordPress and PHP 7.4–8.3.
- Recommended update for all users. Update both the Nokri theme and the Nokri Framework plugin to 1.6.7.

Version 1.6.6 – Update

🔥 New Additions
- Added 8 New Home Page Layouts
- Added 2 New Job Search Page Styles
- Added 2 New Job Detail Page Styles
- Added 2 New Candidate Search Page Styles
- Added 2 New Candidate Detail Page Styles
- Added 2 New Employer Search Page Styles
- Added 2 New Employer Detail Page Styles
- Added Video Section in candidate profiles
- Added Portfolio Gallery Section in candidate profiles
- Added Schedule / Working Hours Section for candidates
- Added Skills Section with improved <ul> structure
- Added Google Maps & Leaflet.js integration in employer profiles
- Added new shortcode: "Featured Candidates Grid" (`featured_candidate_grid`) – WPBakery wrapper around the existing `nokri_render_featured_candidates_grid()` renderer (heading, description, count, candidate type)
- Added "Section Background Color" field (White / Gray) to the "Premium Jobs New" shortcode – outputs `.rec-jobs-bg-gray` modifier class
- Added "Section Text Theme" field (Light Background / Dark Background) to "Featured Candidates 5" and "Trending Keywords Section" shortcodes – outputs a generic `.theme-text-light` modifier class so heading, description and link colors flip to white over dark backgrounds

🎨 Improvements
- Improved Bootstrap 5 Accordion UI in candidate profile templates
- Enhanced Grid/List layout switching logic for employer listings
- Improved layout structure and responsiveness across profile templates
- Optimized profile sections rendering based on backend settings
- Improved theme styling consistency across all pages
- Hardened `nokri_get_user_profile_pic()` against missing or deleted attachment IDs – the function now falls back to the configured default avatar when the saved attachment no longer exists instead of returning an empty image src
- Aligned `shortcode_atts` default values with their `vc_map` field defaults in multiple shortcodes (side-categories, blog-post-minimal-2, trending-keywords, premium-jobs) so legacy saved instances still render meaningful text
- Improved taxonomy term lookup in premium job shortcodes – saved values are now resolved by term_id, slug, OR name, so imported pages render correctly even when term IDs no longer match across installs
- Tab DOM ids in premium-job tab widgets now use the resolved `$term->term_id` instead of the raw saved value – fixes invalid HTML ids when the saved value contains spaces or special characters
- WPBakery `textarea_safe` content (#E-8_ base64 / backtick encoding) is now properly decoded before render in section taglines (side-categories, call_to_action_6, hero-section-6, featured-employers) so HTML inside tagline fields renders correctly
- Hero Section New 3 (hero-section-7.php) cleaned up – removed the embedded "Trending Keywords" and "Hot Categories" sub-sections, vc_map fields, and related render logic per design simplification

🛠 Fixes
- Fixed parse error caused by unclosed { in candidate profile template
- Fixed cover image not loading issue in employer profile templates
- Fixed incorrect column structure causing sidebar misalignment
- Fixed AJAX job apply issue caused by debug output (print_r)
- Fixed undefined variable warning ($read_more) in success stories widget
- Removed leftover debug code from employer profile templates
- Fixed layout rendering issue in employer grid/list styles
- Fixed multiple styling issues across the entire theme
- PHP 8 compatibility: fixed fatal `TypeError: count(): Argument #1 must be of type Countable|array, null given` across every shortcode that consumes `vc_param_group_parse_atts()` output (61 files bulk-hardened – the function's result is now cast to array at the source)
- PHP 8 compatibility: fixed warning `Trying to access array offset on false` raised when `wp_get_attachment_image_src()` returns false for a missing attachment (57 files bulk-hardened with an `?: array('')` fallback)
- PHP 8 compatibility: fixed fatal `Unsupported operand types: string + int` in Featured Candidates 5 (`$no_of_cands + 1` when the field was saved empty)
- Fixed heading/description fallback bug in Premium Jobs New and Blog Post Modern 2 – the null-coalescing operator (`??`) was used where the Elvis operator (`?:`) was needed, so the runtime fallback never triggered for empty-string saved values
- Fixed `Attempt to read property "name" on null` from `get_term()` returning null when a shortcode references a term that was deleted or never existed on this install (premium_jobs_with_tabs.php, premium_jobs_with_tabs2.php, hero_premium_section.php)
- Fixed jobs not rendering on imported pages in premium-jobs, premium_jobs_with_tabs, premium_jobs_with_tabs2, hero_premium_section, hero-section-6 – the saved `job_class` values were labels/slugs from the source install, not local term IDs, so the WP_Query failed silently; now resolved via flexible term lookup before being used in `tax_query`
- Fixed `Undefined variable $ad_image` in Call To Action Minimal when the optional ad image was not enabled
- Fixed `Undefined variable $button_link` (orphan dead code) in Call To Action shortcode
- Fixed `Undefined array key "client_link"` in Our Clients Slider repeater rows that were saved without a link
- Fixed imported shortcode content showing as quote + first word only (e.g. `"Remote` instead of `Remote work from home`) – added runtime filter `nokri_fix_imported_shortcode_quotes()` that decodes `&quot;`/`&#34;`/`&#x22;` and `&#39;`/`&apos;` inside non-WPBakery shortcode brackets before `do_shortcode` runs. WPBakery's own `[vc_*]` shortcodes are intentionally skipped so row design options (padding, margin, background, css= class) keep working
- Fixed empty `src=""` for the `<img>` in candidate listings on installs where `_cand_dp` user-meta references a no-longer-existent attachment (`nokri_get_user_profile_pic`)

📁 Updated Files
- template-parts/profiles/candidate-resume4.php
- template-parts/profiles/employer-profile4.php
- template-parts/profiles/employer-profile5.php
- template-parts/profiles/employer-profile6.php
- template-parts/profiles/employer-profile7.php
- inc/utilities-custom.php (profile-picture guard; imported-shortcode-quote filter)
- inc/theme-shortcodes/classes/candidate.php
- inc/theme-shortcodes/shortcodes.php (registered the new Featured Candidates Grid shortcode)
- inc/theme-shortcodes/shortcodes/featured-candidate-grid.php (new file)
- inc/theme-shortcodes/shortcodes/premium-jobs.php
- inc/theme-shortcodes/shortcodes/premium_jobs.php
- inc/theme-shortcodes/shortcodes/premium_jobs_grid.php
- inc/theme-shortcodes/shortcodes/premium_jobs_grid_new.php
- inc/theme-shortcodes/shortcodes/premium_jobs_with_tabs.php
- inc/theme-shortcodes/shortcodes/premium_jobs_with_tabs2.php
- inc/theme-shortcodes/shortcodes/hero_premium_section.php
- inc/theme-shortcodes/shortcodes/hero_section.php
- inc/theme-shortcodes/shortcodes/hero_section1.php
- inc/theme-shortcodes/shortcodes/hero_section2.php
- inc/theme-shortcodes/shortcodes/hero_section3.php
- inc/theme-shortcodes/shortcodes/hero_section4.php
- inc/theme-shortcodes/shortcodes/hero_section_new.php
- inc/theme-shortcodes/shortcodes/hero-section-6.php
- inc/theme-shortcodes/shortcodes/hero-section-7.php
- inc/theme-shortcodes/shortcodes/hero-section-8.php
- inc/theme-shortcodes/shortcodes/hero-section-9.php
- inc/theme-shortcodes/shortcodes/side-categories.php
- inc/theme-shortcodes/shortcodes/call_to_action.php
- inc/theme-shortcodes/shortcodes/call_to_action_6.php
- inc/theme-shortcodes/shortcodes/call_to_action_minimal.php
- inc/theme-shortcodes/shortcodes/call_action2.php
- inc/theme-shortcodes/shortcodes/call_action4.php
- inc/theme-shortcodes/shortcodes/call_action_latest.php
- inc/theme-shortcodes/shortcodes/featured_candidate5.php
- inc/theme-shortcodes/shortcodes/featured-employers.php
- inc/theme-shortcodes/shortcodes/trending-keywords.php
- inc/theme-shortcodes/shortcodes/blog-post-minimal.php
- inc/theme-shortcodes/shortcodes/blog-post-minimal-2.php
- inc/theme-shortcodes/shortcodes/blog-post-modern3.php
- inc/theme-shortcodes/shortcodes/appsection-modern.php
- inc/theme-shortcodes/shortcodes/appsection-modern_latest.php
- inc/theme-shortcodes/shortcodes/app_section_2.php
- inc/theme-shortcodes/shortcodes/appsection.php
- inc/theme-shortcodes/shortcodes/our-clients-slider.php
- inc/theme-shortcodes/shortcodes/about_us.php
- inc/theme-shortcodes/shortcodes/about_us_minimal.php
- inc/theme-shortcodes/shortcodes/cand_emp_sec.php
- inc/theme-shortcodes/shortcodes/cand_emp_sec1.php
- inc/theme-shortcodes/shortcodes/cand_emp_sec2.php
- inc/theme-shortcodes/shortcodes/categories-with-bg-minimal.php
- inc/theme-shortcodes/shortcodes/categories-with-images-minimal.php
- inc/theme-shortcodes/shortcodes/categories_slider.php
- inc/theme-shortcodes/shortcodes/categories_with_icons.php
- inc/theme-shortcodes/shortcodes/categories_with_images.php
- inc/theme-shortcodes/shortcodes/categories_with_images2.php
- inc/theme-shortcodes/shortcodes/categories_with_images3.php
- inc/theme-shortcodes/shortcodes/categories_with_images_new.php
- inc/theme-shortcodes/shortcodes/client_with_bg.php
- inc/theme-shortcodes/shortcodes/client_with_bg_new.php
- inc/theme-shortcodes/shortcodes/contact_us.php
- inc/theme-shortcodes/shortcodes/counters.php
- inc/theme-shortcodes/shortcodes/employer_slider.php
- inc/theme-shortcodes/shortcodes/emp_list.php
- inc/theme-shortcodes/shortcodes/expert-talent.php
- inc/theme-shortcodes/shortcodes/how_works.php
- inc/theme-shortcodes/shortcodes/jobs_cand_cat_section.php
- inc/theme-shortcodes/shortcodes/job_location_images.php
- inc/theme-shortcodes/shortcodes/locations.php
- inc/theme-shortcodes/shortcodes/main_section_paralex.php
- inc/theme-shortcodes/shortcodes/pricing.php
- inc/theme-shortcodes/shortcodes/pricing-cand.php
- inc/theme-shortcodes/shortcodes/pricing-emp.php
- inc/theme-shortcodes/shortcodes/pricing-modren.php
- inc/theme-shortcodes/shortcodes/recent_jobs.php
- inc/theme-shortcodes/shortcodes/recent_jobs_list.php
- inc/theme-shortcodes/shortcodes/regular-jobs.php
- inc/theme-shortcodes/shortcodes/regular-jobs-2.php
- inc/theme-shortcodes/shortcodes/search_paralex_2.php
- inc/theme-shortcodes/shortcodes/search_paralex_2_new.php
- inc/theme-shortcodes/shortcodes/search_paralex_sidebar.php
- inc/theme-shortcodes/shortcodes/success_stories.php
- inc/theme-shortcodes/shortcodes/success_stories1.php
- inc/theme-shortcodes/shortcodes/success_stories_1.php
- inc/theme-shortcodes/shortcodes/success_stories_slider.php
- inc/theme-shortcodes/shortcodes/success_stories_slider_new.php
- inc/theme-shortcodes/shortcodes/top-clients.php
- inc/theme-shortcodes/shortcodes/top_hirings.php
- inc/theme-shortcodes/shortcodes/top_hirings_slider.php
- inc/theme-shortcodes/shortcodes/why-choos-us.php
- inc/theme-shortcodes/shortcodes/why-choose-us2.php
- wp-content/plugins/nokri-elementor/widgets/success_stories.php

⚡ Notes
- Improved overall theme stability and performance
- Ensured compatibility with latest WordPress standards
- Cleaned up debug code and optimized frontend behavior
- The theme is now PHP 8.0+ compatible. Previously several shortcodes raised fatal `TypeError` and warnings on PHP 8 because of nullable return values from `vc_param_group_parse_atts()` and `wp_get_attachment_image_src()`, and stricter type juggling on string+int arithmetic. All of those are guarded now.
- The runtime `the_content` filter `nokri_fix_imported_shortcode_quotes` (added in `inc/utilities-custom.php`, priority 9) is a workaround for migrated/imported `post_content` whose shortcode attribute values were saved with HTML-encoded quotes (`&quot;`). It can be removed safely once the database `post_content` has been cleaned of those encodings (or after every affected page has been re-saved in WPBakery). It is intentionally written to leave `[vc_*]` shortcodes untouched, so it does NOT interfere with WPBakery row design options (padding, margin, background color, custom css class).
- Tab DOM ids inside the premium job tab shortcodes were previously generated from raw saved values – on imported data, these could be non-numeric labels (e.g. "Featured") and produce invalid HTML id attributes. They are now generated from the resolved term_id integer.
