=== Aplose Newsletter ===
Contributors: oandrade
Tags: newsletter, mautic, double-opt-in, email, gdpr
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.2.1
License: GPLv3 or later
License URI: https://www.gnu.org/licenses/gpl-3.0.html

Newsletter signup with double opt-in confirmation email and Mautic segment sync.

== Description ==

**Aplose Newsletter** collects newsletter subscriptions on your WordPress site with a GDPR-friendly double opt-in flow, then syncs confirmed contacts to **your** Mautic instance.

**Mautic** is open-source marketing automation (segments, email campaigns, lead scoring, workflows). This plugin is the WordPress signup front door; after confirmation, contacts land in the Mautic segment you choose so you can nurture and email them without a SaaS per-contact fee.

* Visitors submit first name (optional), last name (optional) and email (required), plus consent.
* WordPress stores a pending subscription and sends a confirmation email via `wp_mail`.
* The confirmation link opens a page with a confirm button (a simple GET never confirms).
* After confirmation, the contact is created or found in Mautic and added to the selected segment.
* Display modes: shortcode `[aplose_newsletter]` and optional site-wide exit-intent popup.
* Mautic connection via **OAuth2** (authorization code). Client secret and tokens stay server-side and are never sent to the browser.
* Optional admin notification email when someone confirms.
* In-plugin documentation under Aplose Newsletter → Documentation.

**Languages:** English (default) and French (`fr_FR`) are included. The site language in Settings → General controls which translation is used.

**Try it:** subscribe to the Aplose newsletter on https://www.aplose.fr/ (powered by this plugin). Welcome bonus: a 6-step method to create and run your business, with concrete examples.

**MGC Premium:** WordPress and Mautic are provided on the Ma Gestion Cloud MGC Premium plan (dedicated managed hosting, no extra software licence).

**Caching note:** if full-page caching is enabled, exclude pages that display the newsletter form so the REST nonce stays valid.

== Installation ==

1. Upload the plugin folder to `/wp-content/plugins/` or install through the WordPress Plugins screen.
2. Activate the plugin.
3. Go to **Aplose Newsletter → Settings**.
4. Create an OAuth2 API credential in Mautic using the Redirect URI shown in settings.
5. Enter your Mautic URL, Client ID and Client Secret, then click **Connect to Mautic**.
6. Select the target segment and save.
7. Enable the shortcode and/or exit popup as needed.
8. Place `[aplose_newsletter]` on any page, post or widget.

== Frequently Asked Questions ==

= Where does the plugin send data? =

Confirmation emails are sent by WordPress (`wp_mail`). After the visitor confirms, WordPress calls the **Mautic REST API** at the base URL you configured, using OAuth2 tokens stored on the server. Catalog/marketing traffic goes only to that Mautic instance — not to the plugin author's servers.

= Who sends the confirmation email? =

WordPress, using `wp_mail`. The Mautic contact is created only after the visitor confirms.

= What redirect URI should I use in Mautic? =

Copy the Redirect URI from Aplose Newsletter → Settings. It looks like:
`https://your-site.example/wp-admin/admin.php?page=aplose-newsletter&aplose_newsletter_oauth=1`

= Are OAuth secrets exposed to visitors? =

No. The client secret and access/refresh tokens stay in WordPress options on the server. Front-end JavaScript only receives the REST URL and a WordPress REST nonce.

= Can I close a browser tab and show the popup? =

No. Browsers do not allow custom UI on tab close. The exit popup uses mouse leave at the top of the viewport instead.

= Why do scripts load on many pages when the exit popup is enabled? =

When the exit-intent popup is enabled, CSS/JS load site-wide so the popup can appear from any page. If you only use the shortcode, disable the popup and assets load only when the shortcode is rendered.

== External services ==

This plugin connects to external services to send confirmation emails (via your WordPress mail setup) and to sync confirmed subscribers.

1) **Your Mautic instance** (required for sync after confirmation)
- **Service purpose:** create or find the contact and add it to the segment chosen in settings.
- **What is sent / when:** after a visitor confirms their email, WordPress sends the subscriber email and optional first/last name to the Mautic API at the URL configured by the site administrator, authenticated with OAuth2 tokens stored on the server.
- **Service provider:** chosen and configured by the site owner (your own Mautic host or managed provider).
- **Terms / privacy:** depend on your Mautic provider and hosting contract.

2) **Ma Gestion Cloud signup page** (optional link in admin settings / documentation)
- **Service purpose:** optional account creation link for users who want hosted WordPress and Mautic (Ma Gestion Cloud / MGC Premium).
- **What is sent / when:** no background data transfer by the plugin. Data is only sent if an administrator voluntarily clicks the signup link and submits the external form.
- **Terms of service:** https://www.ma-gestion-cloud.fr/conditions-generales-dutilisation-des-services/
- **Privacy policy:** https://www.ma-gestion-cloud.fr/politique-de-confidentialite/

== Changelog ==

= 1.2.1 =
* Keep “Tested up to” only in readme.txt (WordPress.org plugin header rule).

= 1.2.0 =
* Complete French translation pack (en/fr), refreshed POT, and robust textdomain loading for WordPress.org language packs.

= 1.1.10 =
* Documentation: live demo CTA (Aplose newsletter + welcome bonus), stronger Mautic positioning, MGC Premium includes Mautic and WordPress.

= 1.1.9 =
* Align readme with WordPress.org review model (External services, data-flow FAQ); no Angular front-end in this plugin.

= 1.1.8 =
* Plugin Check compliance: i18n translators comment, Tested up to, sanitization, prefixed uninstall vars, DB phpcs notes.

= 1.1.7 =
* Optional admin notification email when a visitor confirms their newsletter subscription.

= 1.1.6 =
* Admin screen to list pending and confirmed subscriptions, with row and bulk delete.

= 1.1.5 =
* When an already confirmed email is submitted again, send a status email while keeping the same on-screen success message.

= 1.1.4 =
* Refresh confirmation screens after clicking the email link (icons, card layout, styled buttons).

= 1.1.3 =
* Clickable privacy policy link opens a configurable popup from settings.

= 1.1.2 =
* Refresh public form visuals: mail icon, styled subscribe button, clearer layout.

= 1.1.1 =
* Fix OAuth authorize URL encoding so redirect_uri with query args matches Mautic.

= 1.1.0 =
* Switch Mautic authentication to OAuth2 (authorization code). Redirect URI shown in settings.

= 1.0.1 =
* Added admin documentation (how it works + Aplose Ma Gestion Cloud / MGC Premium).

= 1.0.0 =
* Initial release: double opt-in, Mautic sync, shortcode and exit-intent popup.

== Upgrade Notice ==

= 1.2.1 =
Header compliance for WordPress.org automated checks.

= 1.2.0 =
Full French / English i18n for publication.

= 1.1.9 =
Readme alignment for WordPress.org review (external services disclosure).

= 1.1.8 =
Plugin Check compliance fixes.
