=== UseFlowy Push - Real-Time Chat Widget ===
Contributors: useflowy
Tags: chat, widget, websocket, real-time, pusher, useflowy, gutenberg
Requires at least: 5.8
Tested up to: 6.7
Requires PHP: 7.4
Stable tag: 2.7.0
License: MIT
License URI: https://opensource.org/licenses/MIT

Add a real-time chat widget powered by UseFlowy Push Service. Connect your WordPress site with WebSocket channels for live chat, notifications, and more.

== Description ==

UseFlowy Push brings real-time WebSocket channels to your WordPress site — similar to Pusher, but built into the UseFlowy BotBuilder platform.

**Features:**

* Real-time chat widget with Flow Design aesthetics
* Public, private, and presence WebSocket channels
* Server-side publish API from PHP
* Customizable theme (light/dark/auto), colors, and position
* Auto dark mode detection via `prefers-color-scheme`
* Shortcode support: `[useflowy_chat]` and `[useflowy_push]`
* Gutenberg block: "UseFlowy Chat" block in the editor
* Custom CSS override field in admin
* Global on/off toggle for the widget
* Connection test button in admin settings
* Admin notices when App Key is not configured
* Multisite support with network-wide defaults
* Clean uninstall (all options removed on deletion)
* Mobile-responsive (fullscreen on small screens)
* Automatic reconnection with exponential backoff
* i18n ready with `.pot` template file

== Installation ==

1. Upload `useflowy-push` folder to `/wp-content/plugins/`
2. Activate the plugin
3. Go to **UseFlowy Push** in the admin sidebar
4. Enter your **App Key** from UseFlowy Dashboard → Settings → API → Push Channels
5. Optionally add your **App Secret** for server-side publishing and private channel auth

== Frequently Asked Questions ==

= Where do I find my App Key? =

In your UseFlowy Dashboard, go to Settings → API → Push Channels tab. Create a Push App and copy the `appKey`.

= How do I send messages from PHP? =

Use the helper:
`UseFlowy_Push_API::send_message('channel-name', 'event-name', ['text' => 'Hello']);`

= Can I use private channels? =

Yes. Set an Auth Endpoint URL in Settings. The plugin provides a REST endpoint at `/wp-json/useflowy/v1/auth` that signs channel subscriptions using HMAC-SHA256.

= How do I add the widget with Gutenberg? =

Search for "UseFlowy Chat" in the block inserter. You can configure channel, theme, colors, and greeting directly in the block sidebar.

= Does the plugin work with multisite? =

Yes. On multisite installs, options can be set at the network level as site options. New blogs automatically get default settings on creation.

= How do I customize the widget styles? =

Use the "Custom CSS" field in Settings → Appearance. You can override any `.useflowy-chat-*` class. The CSS is sanitized and injected after the default stylesheet.

== Changelog ==

= 2.7.0 =
* New connector: **WooCommerce** — your chat assistant now sells. Live catalog with real prices and stock (visual product cards), order placement natively in WooCommerce (status Pending — no online payment; the assistant relays YOUR payment instructions from the new "Order Settings" panel in Settings → Connectors), order lookup by customer email, and cancellation. Variable products get their store link (the exact variant must be picked in the store).
* Guard rails: the assistant never places orders under your business's own email, re-validates stock live before creating an order, and explains payment exactly as you configured it.

= 2.6.0 =
* Connector settings panels: connectors can now declare their own admin settings (`get_settings_fields()`) — each ACTIVE connector shows a collapsible gear inside its own card in Settings → Connectors, so every configuration visibly lives with the connector it affects. Deactivating the connector hides the gear and preserves the stored values. First consumer: the Booking Policy below.
* Booking policy (IziBooking): send tight-deadline reservations to your WhatsApp instead of letting the bot book them — same-day, or a minimum notice you configure in HOURS (wall-clock, for around-the-clock businesses) or DAYS (calendar dates, for daytime businesses — the hour the customer writes at never matters). The bot explains the reason you configure and shows a WhatsApp button with the service/date/time pre-filled; tomorrow and beyond keep booking normally.
* Fix: the bot can no longer reuse your business's own contact email as the booking contact — if the customer hasn't given theirs, it asks (booking notifications go to the customer's email).
* Widget: quick-reply chips can now open links safely (https only) — used by the WhatsApp handoff button.

= 2.5.2 =
* Booking UX: the bot now always asks which duration/price tier the customer prefers when a service has several (it used to silently assume 60 min) — and never quotes one tier while booking another.

= 2.5.1 =
* Fix: "Reset conversation" not taking effect on sites with page/CDN caching (e.g. LiteSpeed Cache on Hostinger) — all plugin REST responses now send `Cache-Control: no-store`, and the chat-history / quick-replies requests carry a cache-buster. Optionally add `/wp-json/useflowy` to your cache plugin's "Do Not Cache" exclusions for belt and suspenders.

= 2.5.0 =
* Performance: manifest-driven connector cache — availability (60s) and customer bookings (300s) are now cached on the platform side per the connector manifest; a successful booking write invalidates them immediately.
* Performance: WP-side transient for the services CPT enrichment (30 min), matching the manifest TTL.
* Booking UX: single contact (name + email) covers the whole party — the bot never asks for every member's details.
* Booking UX: focused availability — when the visitor already picked a time, the chat shows that slot only instead of the whole-day carousel (new optional `startTime` param).
* Booking flow: availability is verified on the turn where the visitor proposes a date; creation proceeds directly once contact details arrive (no re-checks, no extra confirmation).
* Fix: corrected the create-booking tool description to match the connector's automatic group split (visitors total, one call).
= 2.4.0 =

* Connector Contract v0.3 Fase 5a: widget-side presentation for `sub_bot` / `return_to_caller` turns. New pure module `sub-bot-presentation.js` (transparent default, optional badge chip, return_to_caller renders nothing). Base visual connector's `render.sub_bot` spec now declares `avatar { visible, badge }` (§7.4.1c). Additive `subBot` turn meta on the chat payload is consumed when present — bots today resolve to the transparent default, no visual change. Prerequisite for Fase 5 (SubBotNodeHandler).


= 2.3.0 =

* Fix: welcome prompt cards now send the natural-language quick-reply VALUE (e.g. "Show me your services") instead of the display label — truncated labels with "…" are never sent to the bot anymore.
* Fix: "Talk to human" / "Hablar con humano" welcome cards are hidden again — the hide rule now matches the emoji-stripped label and the chip value (the "👤 " prefix used to defeat the regex).
* Fix: builder canvas annotation (e.g. "👋 Greets + 4 options") no longer leaks as the visitor-facing welcome subtitle.
* Welcome-context transient cache key now includes the plugin version, so every update invalidates stale caches automatically.


= 2.2.0 =
* Refactor: alineación del plugin a PROJECT_RULES — splits por responsabilidad (admin traits, theme adapters, REST controller, frontend class), eliminación de dead code y debug logs, consolidación de duplicados (get_page_slug, izibooking_tables_exist, color math).
* Tooling: phpcs.xml.dist (WordPress-Core + Docs), .editorconfig, composer.json con WPCS.
* Internal: versiones sincronizadas (readme, header, USEFLOWY_PUSH_VERSION) a 2.2.0.

= 1.3.1 =
* Security: Removed `appSecret` from all frontend JavaScript output — appSecret is now only used server-side
* Security: Added server-side chat proxy endpoint (`/wp-json/useflowy/v1/chat`) — widget calls local proxy instead of UseFlowy API directly
* Security: Added channel-level authorization — `is_channel_allowed()` restricts private channel auth to configured channels
* Security: Added origin verification on chat proxy requests
* Security: Added per-visitor rate limiting (20 messages/minute) on chat proxy
* Security: Removed `appSecret` from admin inline script block data
* Added: Rate limiting on backend `/chat/:botId` endpoint (20 req/min per visitor) and `/push/apps/:appKey/bots` (30 req/min)
* Added: Rate limiting uses `visitorId` + `appKey` as key for per-visitor isolation

= 1.3.0 =
* Added: Custom top-level admin menu with gradient SVG icon
* Added: Flow Design admin panel with hero header, glassmorphism cards, tab navigation
* Added: Custom toggle switch for Enable Widget
* Added: Radio group selectors for Theme and Widget Position
* Added: Color picker with hex value display
* Added: Code blocks with syntax-style formatting
* Added: Status badge (Active/Disabled/Not Configured) with pulse animation
* Added: Shortcodes & Block submenu page
* Added: Branded footer with animated heart
* Changed: Admin page moved from Settings submenu to top-level menu (position 80)
* Changed: Admin CSS completely rewritten with Flow Design system
* Changed: Admin notice URLs updated to new menu page
* Fixed: Admin scripts now load on all UseFlowy Push admin pages

= 1.1.0 =
* Added: Global on/off toggle (`useflowy_push_enabled`) respected in `enqueue_scripts()`
* Added: Admin notices when App Key is empty or widget is disabled
* Added: Connection test button in settings page
* Added: Custom CSS field with CSS sanitization
* Added: Auto dark mode via `prefers-color-scheme` media query
* Added: Gutenberg block "UseFlowy Chat" with sidebar controls
* Added: Multisite support with network-wide defaults
* Added: `uninstall.php` for clean option removal on plugin deletion
* Added: `languages/useflowy-push.pot` template for i18n
* Added: Plugin row meta links (Documentation, Support)
* Added: Version display in settings page header
* Fixed: Missing `assets/js/widget-init.js` causing 404 on every page load
* Fixed: i18n — all strings now use `__()` with `useflowy-push` text domain

= 1.0.0 =
* Initial release
* Chat widget with Flow Design
* Shortcode support
* Server-side publish API
* Private/presence channel auth
* Dark/light/auto themes
