=== Bsaeed Family Tree Builder ===
Contributors: bigfamilyportal, bsaeed
Tags: family tree, genealogy, subscriptions, membership, paypal
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 6.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

All-in-one plugin: interactive family tree builder, PayPal subscriptions, user accounts, dashboard, i18n, and notifications.

== Description ==

Bsaeed Family Tree Builder is an all-in-one plugin for building and managing a family-tree/genealogy site with membership support:

* Interactive family tree canvas with photo albums and per-person social links
* PayPal-based subscription plans with a self-service "My Account" area
* Custom user registration, login, and password reset flows
* An admin dashboard with membership and subscription stats
* Multi-language support (i18n) with an admin translation editor
* In-app notifications for subscribers

Every feature listed above is fully available to all users; this plugin does not lock or limit its own built-in functionality behind a subscription tier.

= Shortcodes =

* `[bsaeed_family_tree_canvas tree_id="1"]` — render the family tree canvas
* `[bsaeed_subscribe plan="basic" price="$9/mo" description="..."]` — plan card with a Subscribe button
* `[bsaeed_my_account]` — subscriber dashboard (plan, status, next billing, cancel)
* `[bsaeed_register]` — registration form
* `[bsaeed_login]` — login form
* `[bsaeed_forgot]` — forgot-password form
* `[bsaeed_reset]` — password-reset form (linked from email)
* `[bsaeed_person_album person_id="5" tree_id="1"]` — photo album for a person
* `[bsaeed_notifications]` — bell icon with notification dropdown for logged-in users
* `[bsaeed_lang_switcher]` — language switcher

== External services ==

This plugin connects to PayPal to process subscription payments. It is only used if you configure PayPal billing under **Bsaeed Family Tree Builder → SAAS Plans**; the family tree and user-account features work without it.

What is sent and when:

* When you configure a plan, the plugin requests an OAuth access token from PayPal using the Client ID and Secret you provide.
* When a visitor subscribes, the plugin creates a PayPal billing subscription and sends the selected plan ID.
* PayPal sends subscription status updates (activated, renewed, cancelled, etc.) to this plugin's webhook endpoint, which the plugin verifies and stores against the relevant user account.
* No family tree data, member details, or photos are sent to PayPal — only subscription/billing information (plan ID, subscription ID, and billing status).

This service is provided by PayPal: [Terms of Service](https://www.paypal.com/us/legalhub/paypal/useragreement-full) and [Privacy Policy](https://www.paypal.com/us/legalhub/paypal/privacy-full).

== Installation ==

1. Upload the `bsaeed-family-tree-builder` folder to `/wp-content/plugins/`, or install the zip via **Plugins → Add New → Upload Plugin**.
2. Activate the plugin through the **Plugins** menu in WordPress.
3. Go to **Bsaeed Family Tree Builder** in the admin menu to configure PayPal settings and subscription plans (optional — only needed if you plan to charge for access).
4. Place the shortcodes above on the relevant pages (e.g. a page with slug `my-subscription` for `[bsaeed_my_account]`), or use **Bsaeed Family Tree Builder → Pages** to have these pages created for you automatically.

== Frequently Asked Questions ==

= Does this require PayPal? =

No. PayPal is only used if you choose to set up paid subscription billing. The family tree and user-account features work fully without it.

= Where do I configure subscription plans? =

Under **Bsaeed Family Tree Builder → SAAS Plans** in wp-admin.

= Does the free version limit how many family members, trees, or albums I can create? =

No. Every feature is fully available regardless of subscription status.

== Screenshots ==

1. Interactive family tree showing clearly organized generations, couples, and children
2. Add or edit a family member — name, photo, parents, and partners all in one screen
3. Find Connection — instantly see how any two family members are related
4. Admin dashboard with membership and subscription stats at a glance
5. Manage subscription plans and PayPal settings
6. Simple, clean login screen for your members
7. Customize your site's colour theme in a few clicks
8. Fully responsive — looks great on mobile devices too

== Changelog ==

= 6.0.1 =
* Security: closed a gap where a crafted link could display a fake "user approved/rejected" confirmation on the Users page; the flash message now requires a valid nonce tied to the real action.
* Security: sanitized the raw PayPal webhook payload before it is logged, even when signature verification fails.
* Security: hardened several password-type fields against being submitted as an array instead of a string.
* Security: fixed two DOM XSS issues where autocomplete results and notification content were inserted into the page without HTML-escaping.
* Security: removed a one-time legacy-data backfill query from two public, unauthenticated endpoints (it now runs once, correctly, at plugin activation instead) — this was reachable by anyone and could modify tree data site-wide.
* Audited every input-handling code path (AJAX handlers, form processors, admin pages) and every direct SQL query in the plugin for proper nonce/permission checks, sanitization, output escaping, and prepared statements.

= 6.0.0 =
* Renamed from "BFP Suite" to "Bsaeed Family Tree Builder" for a clearer, more distinctive plugin name.
* Fixed a subscription-hijacking risk: PayPal subscriptions are now bound to the initiating user via PayPal's custom_id field, and verified on return before being associated with any account.
* Fixed private/password-protected trees being searchable and readable via two endpoints that did not check tree visibility.
* Added nonce verification to the language-switcher parameter, which previously updated user preferences via GET with no CSRF protection.
* Removed all subscription-tier limits on members, trees, and albums, and removed plan-based ad suppression — every feature is now fully available to all users.
* Replaced direct authentication-cookie parsing with WordPress's session-token API for internal session handling.
* Sanitized the PayPal webhook payload before storage.
* Converted all inline `<style>`/`<script>` output to properly registered/enqueued assets.
* Updated bundled jsPDF (to 4.2.1) and GLightbox (to 3.3.1) libraries.
* Family Tree, PayPal Subscriptions, Users, Dashboard, i18n, SaaS & Notifications combined into a single suite.

== Upgrade Notice ==

= 6.0.0 =
This version renames the plugin from "BFP Suite" to "Bsaeed Family Tree Builder" and changes its internal code prefix. If upgrading from an earlier "BFP Suite" install, deactivate and delete the old plugin, then install this version fresh; your family tree data is stored in its own database tables and is preserved.
