== ASB Smart Flow — full changelog ==

Recent releases live in readme.txt; this file keeps the complete history.

= 2.20.0 =
* **New: voice dictation in the composer.** Tap the 🎤 button above the body, speak, and the live transcript lands at the caret — or let the AI tidy the spoken words into clean written prose first (uses your configured AI provider). Works with the device's built-in speech recognition; the button appears only on browsers that support it.
* **New: moderate comments from your phone.** The "Comments awaiting moderation" card on the Home screen now opens a comment screen: approve or unapprove, reply (replying to a pending comment approves it, like wp-admin), and move to trash. Shown to accounts with the `moderate_comments` capability.
* **New: offline draft protection.** While you write, the composer keeps a local backup of unsent edits on the device. If the connection drops, the app is killed, or the tab is discarded before the draft reaches the server, reopening the composer offers to restore the backup. The backup is removed automatically once the server has the same content.
* Fixed: choosing one of the newest OpenAI models (gpt-5 family) no longer fails with a parameter error — the request now uses the parameter names those models require.
* Fixed: text applied from the AI sheet ("replace the body") now repaints the rich editor immediately; previously the new body could fail to appear until the editor was reopened.
* Uninstall now also removes the AI settings (including the encrypted API keys) and any leftover rate-limit/challenge transients.
* The human-readable React source (`app-src/`) now ships inside the plugin, and the readme documents every external service the plugin can contact.

= 2.19.0 =
* **Jetpack social sharing now works from the phone.** Posts published from the mobile composer share to your connected Facebook / Instagram accounts just like posts published from the PC editor. Connections now start ON by default (matching Jetpack), saved toggles are read back when you reopen a post, the skip flags are written in both formats Jetpack understands (old and new), and they are applied before the post goes live so the right accounts are always used.
* **Turning the push notification off is now respected.** When the PWA Engine's "default ON" site setting is active, unticking "send push notification" before publishing no longer results in a push being sent anyway (the OFF choice was previously saved in a form the engine mistook for "not set").
* **Cancelling a schedule really cancels it.** Publishing a previously scheduled post with "今すぐ" no longer snaps back to the original scheduled time — the date is reset properly. Scheduled posts also gain a "予約を解除して下書きに戻す" option in the publish sheet, and closing the sheet without confirming no longer keeps a schedule you backed out of.

= 2.16.0 =
* **See a post's state at a glance.** When you open a post you already created, a small badge above the title now shows whether it is Published, Draft, Scheduled, Pending or Private, together with its date and time — no need to open the publish sheet to check.
* **Selected categories and tags stay visible.** The "Categories / Tags" section now shows the terms you have chosen as compact chips even while it is collapsed, so you can confirm them without tapping it open.
* **Delivery history inside Delivery & Integrations.** Posts now show what actually went out: PWA push notifications (with the number of target devices) and LINE notifications (sent / failed / resending), each with its date and time, read directly from the ASB PWA Engine and LINE notification plugins.
* Japanese translations for all new wording.

= 2.13.0 =
* **A login you can trust every day.** Biometric sign-in now decides what to show per device, not per site: a phone you have already set up leads with one-tap Face / fingerprint, while a brand-new phone leads with email so you never hit a dead-end "scan a QR code" screen. Whenever biometrics are cancelled or unavailable, a prominent "sign in with email" button is always there as a reliable way in.
* **Never miss enrolling a device.** The "set up Face / fingerprint" prompt now appears on every device that needs it — even if you already enrolled another phone or computer — so each device gets its own one-tap sign-in. "Maybe later" snoozes instead of hiding the prompt forever.
* **The same experience on your computer.** Windows Hello / Touch ID now gets the same gentle "sign in faster on this computer" prompt in wp-admin that phones get, so desktop and mobile behave identically.
* **Clear recovery.** Settings → Security now explains, in three steps, how to recover after losing or changing a device: sign in by email elsewhere, remove the lost device, then register the new one.
* Japanese translations for all new wording.

= 2.12.0 =
* **Turn off auto eyecatch for phone posting.** When ASB Post Thumbnail is installed, a new "Auto eyecatch (Post Thumbnail)" switch on the desktop Settings → General tab lets you hide the auto-generated featured-image preview from the smartphone composer. With it off, phone posts no longer build an eyecatch image automatically — existing featured images and the Post Thumbnail plugin itself are untouched.
* **Phone-friendly settings screen.** The desktop settings page now adapts to small screens: tighter padding, a brand bar that wraps cleanly, full-width inputs and a full-width "Save changes" button, so the page is comfortable to operate when opened on the same phone you post from.
* Japanese translations for the new settings wording.

= 2.11.2 =
* **Roomier mobile composer.** The schedule field no longer fills a whole card — it is now a compact "🗓 Schedule" chip next to the title that opens the date & time picker on tap. The long hints under the schedule, "Body images" and "Auto eyecatch" sections were folded into small ⓘ tooltips, so the editor is shorter and easier to scan on a phone.

= 2.11.1 =
* **Tidier biometric sign-in on the WordPress login screen.** The "Sign in with fingerprint or face" button is now a full, comfortably-tappable button with proper spacing, instead of a thin strip pressed up against the logout / notice message. On computers it only appears when the device actually has a built-in authenticator (Touch ID, Windows Hello, or a synced passkey); desktops without one simply show the usual ID / password form.

= 2.11.0 =
* **Consistent cross-promotion sidebar.** The desktop settings sidebar now keeps a constant layout: siblings you have not installed show a free-download link, free ones an upgrade link, and siblings you already run on Pro now show a "leave a review" card instead of disappearing — so the column no longer changes height depending on what you have installed.
* Japanese translations for the new sidebar wording.

= 2.10.0 =
* **Redesigned settings screen.** The desktop admin page has a modern, app-like look — a brand header with the smartphone-admin shortcut, icon tabs, soft cards and toggle switches — consistent across the General, AI and Permissions tabs.
* **Fixed: the “other ASB plugins” panel could come up empty.** Plugins you have not installed yet (Calendar Advance / PWA Engine / LINE notification / Post Thumbnail) now reliably appear in the sidebar with a free-download link, while siblings you already run on Pro stay hidden.
* **New: hide promotions once you own a Pro plugin.** If any ASB family plugin is active on its Pro edition, the General tab gains a switch to hide the cross-promotion sidebar on this screen.

= 2.9.2 =
* **Fixed: the dashboard could get stuck on “Cookie check failed.”** When the login session changed underneath the app (a fresh sign-in, an expired session, or a cached page), the mobile admin kept using its old security token, so every screen failed with a cookie/nonce error and the Retry button reused the same dead token. The app now detects this and reloads once to obtain a fresh token automatically — or sends you to the sign-in screen if your session has truly ended.
* **Fixed: a critical error when registering Face ID / fingerprint (passkey).** The registration request hit a fatal error on the server, so the "set up biometric sign-in" sheet showed a WordPress error message instead of the Face ID / fingerprint prompt. (Introduced in 2.9.1 alongside the biometric-targeting change; the endpoint was reading a request parameter without receiving the request object.)
* **Fixed: Instagram appeared twice in the Jetpack SNS connection list on mobile.** When an Instagram account is linked through a Facebook page, Jetpack can keep two connection records for the one account in its local store; the mobile composer listed both, even though the PC editor shows it once. The same account is now collapsed into a single row (matched by service + account name, so two genuinely different accounts are never merged), and turning it on/off applies the choice to every underlying connection.

= 2.9.1 =
* **Easier Face ID / fingerprint sign-in.** Passkey registration now targets this device's built-in biometrics and creates a discoverable passkey, so the browser no longer offers the confusing "scan a QR code with another device" or "use a security key" options — and the next sign-in prompts Face ID / fingerprint directly. An "advanced" link is still available to enrol another device or a hardware security key.
* **New: first-run setup prompt.** After your first login on a device, a one-tap sheet offers to register Face ID / fingerprint so you can skip the password next time.
* **Improved login screen for new sites.** When no passkey exists yet, the screen leads with email/password sign-in (instead of dropping into the QR flow) and tells you that you can set up biometrics from the app after logging in.

= 2.9.0 =
* **Fixed: scheduling a post on mobile could create duplicate posts (and a deleted post could "come back").** The autosave, the publish/schedule action and the preview flush each created the draft independently, so a fast tap or a race could spawn two or three copies of the same post — which looked like repeated posting, and like a post "reviving" after it was deleted on the desktop (a leftover copy remained). All save paths now create the post at most once through a shared lock, and autosave no longer re-creates or revives a post once it has been published/scheduled or removed.
* **New: set the schedule date & time before saving.** The composer now has a "Schedule date & time" field, so you can pick the date first — the auto eyecatch preview reflects it immediately and a single "Schedule post" saves it. No more saving once just to be able to set the schedule.
* **Fixed: the auto eyecatch preview now shows the scheduled date.** When a future date is set, the live preview's post date matches it instead of falling back to today.

= 2.8.8 =
* **Hardened: Instagram is never armed on publish without a featured image.** The "needs an image" rule was already shown in the UI; now it is also enforced when saving, so a connection toggled on before the image was removed is skipped instead of being sent to Jetpack (which would reject it). No behavior change when a featured image is set.
* **Fixed: the per-post Google Calendar toggle now matches the desktop.** The mobile composer only shows (and saves) the "Show Google Calendar button" toggle when that button feature is enabled site-wide in Calendar Advance — the same condition the desktop meta box uses — instead of always showing it.

= 2.8.7 =
* **Fixed: Jetpack Instagram (and similar) appeared twice in the Social panel.** The same connection could be listed more than once (e.g. Instagram reached via a Facebook page), showing two identical checkboxes bound to the same setting. Connections are now de-duplicated, so each account shows once.
* **Fixed: Instagram could be checked even without a featured image.** Instagram can only be published to with an image, so its checkbox is now disabled with a "Needs image" hint until an eyecatch image is set — matching what Jetpack actually allows.
* **Fixed: the auto eyecatch preview did not follow the title, category, or date.** The mobile preview now sends the current title, selected categories/tags and post date to the preview, so the generated image — including category/date-based text and design rules — updates live as you edit, the same as the desktop editor.
* **Fixed: LINE notification could appear unchecked even when "send by default" was on.** Posts whose LINE setting had never been explicitly set were shown unchecked and then saved as "off", silently disabling the default. The mobile checkbox now falls back to the site default exactly like the desktop meta box, so default-send is honored.

= 2.8.6 =
* **Fixed: connected social accounts (Jetpack) showed as "none" on the mobile composer.** The "Social (Jetpack)" panel always said no accounts were connected even when Facebook/X/etc. were linked, so you could not pick them when posting from your phone. Detection now reads Jetpack's active Publicize instance correctly (and supports the standalone Jetpack Social plugin and newer Jetpack versions), so linked accounts appear and can be toggled per post. The per-account choice and the shared message are now reliably saved on publish, so posts can be shared to social media from the phone.
* **Added: choose push-notification recipients by role on the phone (PWA Engine Pro).** When targeting "WP Role Group" or "Ultimate Member role", you can now tick the actual roles right on the mobile composer instead of only choosing the type and finishing on the PC. Individual-user targeting set on the PC is preserved. Requires PWA Engine Pro.

= 2.8.5 =
* **Fixed: on the desktop AI settings, the API key and provider showed "saved" but reverted to the default (OpenAI), and "Test connection" reported the key as not set.** The save was writing the full default set of writing-style presets, quick actions and the emoji tray back into the database, and those seed lists contain emoji (😊 🛍 🎉 …). On sites whose database has not been upgraded to utf8mb4, a 4-byte emoji makes the whole write fail or get truncated, which wiped the entire AI setting — so the provider and key never stuck. Saving the API key, provider, model and common rules now writes only those (text-only) fields and no longer touches the emoji lists, so it saves correctly on any database. The connection test, which saves first, therefore works too. If a write still can't be stored, a clear message now explains that the database needs to be converted to utf8mb4 (the emoji presets in the mobile "Insert" editor still require utf8mb4).

= 2.8.4 =
* **Fixed: on the desktop "AI Provider" settings screen, saving an API key or running "Test connection" appeared to do nothing.** After pressing Save or Test connection, the page simply reloaded with no message at all — no "Saved" confirmation, no test result, and no error. Because the API-key field is always shown blank for security (a saved key is indicated only by a green "Registered" badge), a key that had in fact been stored looked unsaved, and the connection test seemed dead. The cause was that the success/error notices were dropped during the redirect back to the tab. Notices now display correctly: saving shows a confirmation, "Test connection" shows the result (success, or the exact error returned by OpenAI / Gemini / Claude), and an expired security token now reports a clear "reload the page and try again" message instead of failing silently. The same notice fix was applied to the "Permissions & AI" tab.

= 2.8.2 =
* **Fixed: AI articles could stop halfway and leak raw code into the post (Gemini).** When generating an article with Google Gemini (the 2.5 models), the text could cut off mid-sentence and sometimes dumped raw fragments such as `{"title":"…","content":"` and `\n` into the body. The cause was Gemini 2.5's internal "thinking" step quietly using up the response budget before the article was finished. The plugin now manages that budget — turning thinking off for the Flash models and reserving separate room for Pro — so articles write through to the end. As an extra safeguard, even if a response is ever cut short for any provider, only clean HTML is inserted now; the raw envelope and stray escape characters are never shown in the editor.

= 2.8.1 =
* **Fixed: body-image thumbnails sometimes stayed grey when opening a post.** When you opened an existing post from the list, the thumbnails in the "Body images" area could show as grey placeholders even though the images were set; they only appeared after you changed something (such as the width %). They now load correctly the first time the post opens. This also removes a redundant second fetch of the post during loading.

= 2.8.0 =
* **Place images side by side.** When you insert two images at 50% width one after another, they now sit next to each other on the same line instead of stacking; three 33% images form a row of three, four 25% images a row of four, and anything that doesn't fit wraps to the next line automatically. 100%-width images keep their own line as before, and a single resized image is unchanged. The side-by-side layout is kept on phones too, and the in-app preview reflects it.

= 2.7.5 =
* **The desktop post editor's "✨ Write with AI" box now behaves like the mobile app.** It shows only the actions that make sense for the current post: on an empty post it offers "Write a post" (and title ideas) and hides Rewrite / Summarize / Proofread; once there is a body it hides "Write a post". Quick instructions follow the same rule.
* **AI reference material on desktop too** — add a URL or upload a file (text / Markdown / Word `.docx` / PDF) right in the meta box and the AI uses it as background when it writes, exactly like on mobile. Only the text is read, it is trimmed to a sensible length, and URL fetching is restricted to safe public addresses.

= 2.7.4 =
* **AI reference material — let the AI read a web page or your documents.** In the AI assistant you can now add a URL or upload a file (text / Markdown / Word `.docx` / PDF), and the AI uses it as background when it writes — great for "summarize this page into a post" or "base the article on this document". Only the text is read (images are not), it is trimmed to a sensible length to keep your API usage predictable, and URL fetching is restricted to safe public addresses. Note: scanned PDFs, or PDFs with unusual embedded fonts, may not be readable — use a text or Word file (or paste the text) in that case.
* **"✨ Create with AI" now also sits right above the body**, so you can reach it without scrolling back to the top of the post.
* **The AI panel now shows only the actions that make sense for the current state.** With an empty body it offers "Generate article" (and title ideas) and hides Rewrite / Summarize / Proofread; once there is a body it hides "Generate article". Cleaner than graying buttons out.
* **Save draft / Preview / Publish are now pinned just above the bottom tab bar**, so you no longer have to scroll to the end of a long post to reach them. The bar tucks away while the on-screen keyboard is open.
* **Auto eyecatch preview** now appears immediately for administrators even before the first draft is saved, and the remaining English labels on that card ("Save a draft to preview", etc.) are now translated.

= 2.7.3 =
* Calendar: you can now set up weekday-based recurring events directly from the phone. For the main event — and for each additional event — that has a start and end date (a period), turn on "repeat by weekday", choose the weekdays, pick the interval (every 1–4 weeks), and add exclude or include dates. These recurring rules previously could only be edited on the desktop. Requires ASB Calendar Advance 2.1.9 or later with recurring events (Pro).

= 2.7.1 =
* Calendar: the mobile composer now supports multiple events per post when ASB Calendar Advance's "Multi-Event Feature" is enabled (Pro). You can add and remove additional event date ranges right from the phone; each event's recurring rule (set on the desktop) is preserved on save. Requires ASB Calendar Advance 2.1.9 or later, which exposes the additional-events data over REST.
* Calendar saving from mobile depends on the companion exposing its event meta over REST. If your event settings were not saving from the phone, update ASB Calendar Advance to 2.1.9+ (and make sure the post type matches the calendar's event sources) and retry.

= 2.7.0 =
* Internal quality release — no change to how the plugin behaves. The AI engine and the mobile composer were refactored for maintainability, two minor security hardenings were added, and a first test suite was introduced.
* Maintainability: the AI provider transport (OpenAI / Gemini / Anthropic request + response parsing) was split out of the large AI class into a dedicated adapter, and the mobile post composer's autosave and body-image logic were extracted into focused hooks. Behaviour is unchanged.
* Security hardening: the AI hourly rate limit is now counted only for requests that actually reach a provider, so malformed requests no longer consume your quota; and images imported from Google Drive are verified to be real images before they enter the Media Library.
* Tests: added a JavaScript unit suite for the body-image shortcode helpers and a standalone PHP round-trip test for API-key encryption. Test files are not included in the distributed plugin.

= 2.6.6 =
* Security hardening: AI-generated HTML shown in the writing-assistant preview is now sanitized with `wp_kses_post` on the server before it is returned. This keeps the post-grade formatting the editor needs (headings, lists, links, images) while stripping any `<script>` or event-handler markup that a prompt-injected or tampered AI response could otherwise smuggle into the admin screen. Defence-in-depth; no change to normal output.

= 2.6.5 =
* Fix: tapping "New post" in the bottom tab bar while editing a post now reliably opens a blank new post. Previously it could leave you on the same post after confirming the unsaved-changes prompt. (The browser back button backing out of an edit is fixed the same way.)
* Fix: a body-image thumbnail chip in the editor could stay a gray placeholder until you nudged the body (e.g. pressed Enter). The chip image now decodes and paints immediately on insertion and when its thumbnail loads.

= 2.6.4 =
* **Auto eyecatch controls now match the desktop sidebar — and stop being duplicated.** The mobile composer no longer shows the auto-generate controls twice: the redundant "Auto eyecatch" entry inside the "📢 Delivery & Integrations" accordion has been removed. The single source of truth is the live-preview card right under the featured-image card.
* That card now uses the same per-post on/off toggle as the desktop post sidebar ("この投稿で自動生成する" / "Enable auto-generation for this post") instead of a three-way Default / On / Off button row, and its two action buttons are relabelled to match the desktop wording exactly: "背景画像を変更" (Change Background Image) and "今すぐ生成して設定" (Generate & Set Now). Mobile and desktop now behave and read the same way.

= 2.6.3 =
* Japanese: the auto-eyecatch preview card on the mobile composer now shows a translated heading ("自動アイキャッチ画像生成").
* Fix: the body-image hint now refers to the toolbar's image / gallery icons in plain words instead of emoji that did not match the actual buttons.

= 2.6.2 =
* Fix: redrew the fingerprint icon on the mobile login screen and the gear (Settings) icon in the bottom tab bar with clean, crisp vector paths. The earlier hand-drawn icons could look broken or jumbled at small sizes on some phones.

= 2.6.1 =
* **Per-post actions on the home screen too.** The "Recent posts" list on the mobile home (Dashboard) now has the same "⋯" (more actions) button as the post list — tap it for Edit, View on site, Duplicate, and Move to Trash, without first drilling into a filtered list. Duplicating or trashing from here refreshes the home counts and list in place.
* **Auto eyecatch preview respects the companion's "Featured Image Behavior".** When ASB Post Thumbnail is set to skip generation if a featured image already exists (the default), the mobile auto-eyecatch preview now hides itself once a featured image is set — matching what the companion actually does on save. Remove the featured image and the preview comes back.
* Fix: the actions sheet header now shows the post title correctly when opened from the home screen.

= 2.6.0 =
* Added: Live auto-eyecatch preview in the mobile composer, powered by the companion ASB Post Thumbnail plugin. The preview updates as you type; set it as the featured image in one tap, toggle per-post auto-generation, and swap the background image.
* Dev: Consumes the companion plugin's asbptp/v1 REST API and corrects the Post Thumbnail override meta key in the integrations descriptor.


= 2.5.1 (2026-05) =
* **Per-post actions on the mobile list.** Each row in the mobile post list now has a "⋯" (more actions) button. Tapping it opens a sheet with Edit, View on site (published posts), Duplicate, and Move to Trash. Tapping the row itself still opens the post for editing as before.
* Duplicate creates a fresh draft that copies the title, content, excerpt, categories, tags, featured image and post format, so you can review it before publishing.
* Move to Trash is recoverable — the post goes to the Trash and can be restored from there.

= 2.5.0 (2026-05) =
* **AI on/off master switch.** A new "Permissions & AI" tab (Settings → ASB Smart Flow) lets administrators turn the AI features off for the whole site without deleting their API keys. When off, every AI surface — the mobile "✨" panel, the desktop "Write with AI" meta box, and the AI generate endpoint — is hidden. Turn it back on and AI is restored instantly.
* **Role-based access control.** Administrators can now choose which roles below administrator may (a) use AI, and (b) operate the settings screens. Users below the AI role never see that AI exists (buttons and panels are hidden for them). Settings operation can be delegated down to editors — while the AI provider API keys always stay administrator-only, on both desktop and mobile.
* These controls are administrator-only and cannot be used by a delegated operator to widen their own access.

= 2.4.0 (2026-05) =
* **Reworked image insertion in the mobile editor.** Images and galleries are now placed from the body toolbar: tap the image (🖼) or gallery (▦) button to insert at the cursor. You can pick from your camera, photo library, the Media Library, or Google Drive. Each inserted image then appears in the "Body images" panel below the featured image, where you can set its size (100 / 50 / 33 / 25%) and toggle a caption (taken from the attachment's caption / title / alt). Galleries let you select several images and choose 2, 3 or 4 columns.
* **Featured image from Google Drive.** The featured-image card can now pull an image straight from Google Drive, alongside camera, photos and the Media Library.
* The previous "register first, then place" image tray — with Beginning / End / Optional placement — is replaced by this caret-based flow. Automatic top/bottom insertion of tray images has been removed; images appear exactly where you insert them in the body.

= 2.3.4 (2026-05) =
* **Front-end preview before publishing.** The mobile editor gains a "Preview" button next to Save draft / Publish. It flushes the current edit and opens a full-screen, in-app preview of how the post renders on the front end — without leaving the app. Unsaved changes are reflected: drafts (and brand-new posts) are saved in full fidelity, while published or scheduled posts are previewed via a throwaway autosave so the live version is never overwritten. A "open in a new tab" escape hatch is provided for sites that block framing.

= 2.3.3 (2026-05) =
* **Fixed “Open desktop admin”.** The hamburger menu's "Open desktop admin" link pointed at the dashboard without the desktop-mode flag, so on phones the auto-redirect bounced it straight back to the mobile UI. It now carries `?asb_sf_desktop=1`, which both skips the redirect and sets the persistent desktop-mode cookie, so it lands on (and stays on) the PC admin.

= 2.3.2 (2026-05) =
* **Add to Home Screen guide note for PWA sites.** When a PWA plugin (e.g. ASB PWA Engine) controls the site, the home-screen icon can launch the mobile admin in a standalone, app-like window; the Settings → Basic guide now explains this is expected. (Companion fix ships in ASB PWA Engine 2.8.1, whose service worker now bypasses `/mobile-admin/`, `wp-admin`, `wp-login` and `wp-json` so the admin SPA is never cached or controlled by the front-end PWA.)

= 2.3.1 (2026-05) =
* **Custom fields hidden by default.** The mobile editor's generic "additional fields" auto-form now hides every REST-registered custom field (including WordPress core's `footnotes`) unless you opt it in under Settings → Basic. This keeps the composer clean on sites with noisy plugin meta; enable just the fields you actually post with.
* **Add to Home Screen guide.** Settings → Basic gains a collapsible iOS / Android guide for installing the mobile admin to the home screen. The app shell now emits an `apple-touch-icon` from your WordPress Site Icon, so the installed icon is your real icon instead of a generated single letter (no PWA required).
* **Japanese translations** added for the Google Drive (image picker) settings section.
* **Tidier AI presets screen.** The style-preset / quick-instruction / fill-in-template editors on the PC settings tab no longer stretch across the full window width, and the emoji field is back to a small fixed box.

= 2.3.0 (2026-05) =
* **Readable media chips in the rich editor.** Inserting an image or gallery now drops a compact chip (thumbnail + #ID) in the rich-text view instead of a bare shortcode, so you can tell at a glance what each insertion is. The HTML view still shows the raw `[asb-img]` / `[asb-gallery]` shortcode, and the saved body is always the shortcode — the chip is display-only.
* **Image IDs in the tray.** Each image-tray thumbnail now shows its attachment `#ID` underneath, so a shortcode in the body can be matched back to its image at a glance.
* **"No placement" option.** Tap an already-selected Beginning / End / Optional button again to clear it, so a photo can stay in the tray for gallery-only use without being auto-placed at the top or bottom.
* **Drag-and-drop reordering.** Reorder tray images by dragging a handle (works with both mouse and touch), in addition to the existing ▲ / ▼ buttons.

= 2.2.0 (2026-05) =
* **Image insertion at the caret.** Tap "📥 本文に挿入" in the image tray and the `[asb-img]` shortcode now drops at the cursor position in the body, in both the rich-text and HTML edit modes.
* **Image width selector** — pick 100% / 50% / 33% / 25% per image. Stored on the shortcode as `width="N"` so the value is visible in the body and survives exports.
* **Gallery insertion** — tick multiple images, choose 2 / 3 / 4 columns, and insert `[asb-gallery ids="..." cols="N"]` as a `wp-block-gallery` grid.
* **Google Drive import** — add a `☁ Drive` source to the image tray. Optionally enable the Google Picker (Settings → ASB Smart Flow → General) for a one-tap browse-and-pick flow, or paste a public share URL as a fallback.

= 2.1.0 (2026-05) =
* New smartphone-optimised "ASB family" cross-promotion cards on the Dashboard and in Settings → Integrations. Each card adapts to install state: a "Shop" CTA for plugins you don't have, a "What you get with Pro" teaser for free editions you already use, and a quiet "✓ Pro active" badge once licensed.
* New PHP entry point `ASB_SF_Family` exposes member metadata, with filter `asb_sf_family_members` for overriding shop URLs and copy.
* Dashboard banner is horizontally swipeable and only appears when at least one family plugin is missing or running on the free tier.

= 2.0.1 (2026-05) =
* PC admin: split the AI tab into "AI Provider" and "AI Settings" for clearer navigation.

= 2.0.0 (2026-05) =
* **One free build for everyone.** The Pro tier and the separate Pro ZIP are retired; every feature (AI authoring, WebAuthn passkey login, image tray, PC AI metabox, free-form accent color, custom palettes) now ships in the single free distribution.
* License activation, the License tab, and the Pro/Free build split are removed. Existing license options are cleared automatically on upgrade.
* Plugin description, readme, and admin menu copy updated for the free-only model.

= 1.16.3 (2026-05) =
* AI tab and mobile settings now use a real `<select>` dropdown for model selection instead of free-typing with suggestions.

= 1.16.1 (2026-05) =
* Settings → General now shows a 200×200 QR code next to the mobile admin URL with a PNG download button (offline, no external request).
* Admin menu item moved to position 82 so it sits within the ASB plugin family (LINE notification / Calendar Advance / PWA Engine).

= 1.16.0 (2026-05) =
* AI authoring available in wp-admin too: a "✨ AI Writer" meta box on post / page edit screens, and the writing-style / quick-instruction / template editors on the AI tab.
* Generated content inserts as Gutenberg blocks via `wp.blocks.rawHandler` (with Classic Editor fallback).

= 1.15.0 (2026-05) =
* Image tray + `[asb-img]` shortcode for staging images outside the body and placing them top / bottom / inline.

= 1.13.0 (2026-05) =
* The wp-admin "PC view" toggle now persists across requests (24h cookie, filter `asb_sf_desktop_mode_ttl`).
* The post-edit "📢 Delivery & Integrations" section now reflects each integration's "default ON for new posts" setting from the sibling plugin's options.

= 1.12.0 (2026-05) =
* Passkey sign-in button injected directly onto `wp-login.php` — no need to first navigate to `/mobile-admin/login`.

= 1.11.0 (2026-05) =
* Emoji tray + snippets — register favorite emoji and reusable boilerplate from the AI tab, insert with one tap during writing.

= 1.10.0 (2026-05) =
* Fill-in-the-blank post templates and a "Quick Post" sheet on the Home screen.

= 1.8.0 (2026-05) =
* AI authoring — generate / rewrite / summarise / proofread / suggest titles using your own OpenAI / Gemini / Claude key.

= 1.4.0 (2026-05) =
* Passkey (WebAuthn / FIDO2) sign-in for `/mobile-admin/login`.

= 1.3.0 =
* "Delivery & Integrations" section for posts (PWA Engine / Calendar Advance / LINE notification / Thumbnail Pro / Jetpack Publicize detection).

= 1.1.0 =
* wp-admin mobile skin (drawer side menu, bottom tab bar, scale adjustment).

= 1.0.0 =
* Initial release: bottom tab bar, dashboard, new post, media, settings, accent color.

