=== Circumflex Booking development changelog ===

== 1.5.19 ==

* State clearly on the final review screen that the request has not been sent and name the profile-specific submit action required to finish.
* Reflow the review summary from two columns to one based on the booking component's own width and prevent ordinary labels from breaking inside words.
* Split customer messages, notification delivery and email templates into skimmable settings cards, with templates collapsed until needed.
* Move service-specific buffers and deadlines into an advanced section whose collapsed summary shows the effective values, while opening the section before native validation focuses an invalid field.
* Keep Core's default profile behind a deliberate, confirmed return control after an add-on profile has been selected, without turning a temporary fallback into a permanent profile change.

== 1.5.18 ==

* Add an explicit customer-facing practitioner order with drag-and-drop and accessible move controls.
* Keep first-available grouping and automatic assignment in their existing fairness order.
* Include practitioner order in portable configuration and migrate existing sites without changing bookings or availability.
* Bundle the complete maintained Norwegian PHP and JavaScript runtime catalogs in the WordPress.org archive and fail release validation on untranslated or fuzzy Core messages.
* Translate plugin-list descriptions without mixed English and Airspace wording.

== 1.5.17 ==

* Let the secure customer portal use profile-specific wording while keeping the standard appointments profile unchanged.
* Keep Airspace email previews and linked Pro screens free of treatment-domain example wording.

== 1.5.16 ==

* Let administrators choose whether the standard appointments profile accepts one service or one or more services per booking, while add-on profiles such as Airspace retain their own rule.

== 1.5.15 ==

* Make the administrative day/week capacity layer independent of a selected service and remove the confusing service selector from the calendar.
* Add a prominent Calendar for filter that shows every practitioner or resource by default and narrows bookings, free capacity and controlled public availability together.
* Present unreserved schedule periods as available capacity while keeping service duration and buffers authoritative in the actual booking flow.

== 1.5.14 ==

* Replace the administrative calendar's chronological cards with an ordinary day/week time grid and one track per practitioner or resource.
* Keep bookings visually primary while showing continuous publicly bookable periods and Pro-controlled public-availability holds as distinct background layers.
* Add daily-overview and all-details presets, hide rejected and cancelled records by default, remember each user's day/week/month choice, and keep month view booking-only.

== 1.5.13 ==

* Keep bookings across all services together in the administrative calendar while using an automatically selected active service only to calculate bookable time.
* Replace repeated start cards with continuous publicly bookable time ranges that already respect duration, buffers, reservations, and Pro controlled public availability.

== 1.5.12 ==

* Combine bookings and selected-service availability in the administrative calendar, keep Pro-held starts visibly available only internally, and prefill manual booking from a real open slot.

== 1.5.11 ==

* Replace visible notification event identifiers in settings and queue history with localized, profile-aware labels while preserving the stable internal keys.

== 1.5.10 ==

* Add extension API 16 so validated booking profiles can apply one bounded terminology document to explicitly registered extension text domains.
* Validate and limit registered domains while always retaining Core's own translation boundary and safe fallback behavior.

== 1.5.9 ==

* Hide inactive services, practitioners and schedule rules by default, with a URL-preserved control to reveal and manage them.
* Count and search deleted-service booking snapshots without requiring a current catalog row, and flag detached history before rescheduling.
* Preserve inactive unassigned practitioners in configuration export, serialize related catalog writes, and expand integrity checks for every logical relationship.

== 1.5.8 ==

* Keep booking and resource administration readable when deleting an obsolete service leaves inactive practitioners or exercise areas without assignments.
* Block service deletion when an active practitioner would lose its final assignment, and reject reactivation until a replacement service is assigned.
* Revise affected practitioner rows during service deletion so stale administration forms cannot overwrite the detached assignment state.

== 1.5.7 ==

* Make the optional inclusive end date independent of whether a date rule applies to one practitioner or every practitioner.
* Preserve existing individual one-day rules during the additive schema-10 migration, and treat an individual period as upcoming until its final date has passed.

== 1.5.6 ==

* Let either a closed or extra-open date rule apply to every practitioner or exercise area for one inclusive date period.
* Preserve existing shared closures as closed rules during the additive schema-9 migration, and keep closed time authoritative when shared rules overlap.

== 1.5.5 ==

* Move shared closures into the date-exception editor below the weekly schedule, where administrators can apply one closed rule to the selected practitioner or every practitioner.
* Retain the optional inclusive end date for all-practitioner closures and keep individual extra-opening rules unchanged.

== 1.5.4 ==

* Prefer the maintained bundled Norwegian catalog in manual installations, including network-activated multisite plugins and sites with an older global language pack.

== 1.5.3 ==

* Let administrators close one inclusive date period across every practitioner or exercise area with one shared rule, either for whole days or for the same time range on every date.
* Preserve existing one-day shared closures during the additive schema-8 migration, and list a period as upcoming until its final date has passed.

== 1.5.2 ==

* Add extension API 15 with an opt-in, profile-owned uppercase-code input policy, including browser constraints, normalization and matching server validation.
* Preserve the existing public payload and participant behavior for the appointments profile and every field that does not explicitly enable a policy.
* Add a separate self-contained ZIP for manual clean-site installations, with the maintained Norwegian PHP and JavaScript runtime catalogs bundled while the WordPress.org archive remains language-pack based.
* Let administrators close a whole day or time range across every practitioner or exercise area with one shared rule, while retaining existing bookings for explicit review.

== 1.5.1 ==

* Add extension API 14 presentation controls so a vertical add-on can disable resource recommendations and next-start prompts, opt into a neutral exact-availability strip and replace time guidance with one direct question.
* Preserve the API 13 resource-overview presentation as the backward-compatible default for other add-ons.

== 1.5.0 ==

* Add extension API 13 with a bounded date–service–resource–time public workflow for vertical add-ons while Core retains authoritative availability, conflict checks and submission.
* Accept a same-origin, aggregate-only resource overview for recommendation context and fail safely back to exact available times when that optional aggregate cannot be loaded.

== 1.4.3 ==

* Let administrators drag weekly schedule periods into a clear display order, with accessible move buttons as a keyboard and no-JavaScript alternative.
* Add complete, reversible profile-recommended email templates for review before settings are saved, and omit empty optional detail rows from plain-text and HTML messages.
* Add extension API 12 so separately installed vertical profiles can provide bounded administration terminology without forking Core.
* Include protected WordPress email verification in Core Free while keeping SMS delivery and automatic confirmation in compatible external/Pro add-ons.
* Let administrators permanently delete inactive services and unused practitioners/resources while retaining immutable booking history and preventing deletion when resource history still depends on the record.
* Let administrators permanently remove inactive weekly periods and date exceptions after an explicit confirmation.
* Make it configurable whether the complete buffered interval must fit opening hours; when disabled, the session must fit while its full same-date buffer continues to block conflicts.

== 1.4.2 ==

* Adapt the public date picker to the configured booking window: show times directly for today-only booking, compact date cards for two to seven days, and the full calendar for longer windows.
* Allow a zero-day booking horizon when a site should offer appointments only on the current date.

== 1.4.1 ==

* Make dashboard links for all-time booking totals open the all-bookings view while keeping operational shortcuts focused on their intended time ranges.

== 1.4.0 ==

* Add extension API 10 with a site-wide catalog and explicit selector for validated booking profiles, including safe fallback when a selected add-on is unavailable.
* Add an optional participant identifier across booking storage, administration, search, CSV, notification context and WordPress privacy handling.
* Add a provider-neutral, protected contact-verification proof lifecycle for compatible add-ons; Circumflex Booking Free includes no SMS transport, settings or provider.
* Keep profile changes separate from services, resources, opening hours and existing bookings, and expose effective profile state in local diagnostics.
* Hide ended bookings by default in the administration, with upcoming, past and all views based on each booking's end time.

== 1.3.5 ==

* Hide past date exceptions by default while retaining them in dedicated past and all views.
* Sort date exceptions chronologically, with the newest past exception shown first and an optional date-order toggle.

== 1.3.4 ==

* Improve plain-language guidance across booking, customer self-service, administration, notifications, privacy, and diagnostics in English and Norwegian.
* Clarify that a month with no bookable appointments has no available times.

== 1.3.3 ==

* Shorten the start-time guidance in public booking and customer changes to plain language.

== 1.3.2 ==

* Present sliding booking choices as start times instead of calendar blocks, while keeping the complete appointment interval and availability state in each accessible name.
* Explain that an unavailable start may overlap an earlier reservation and is not itself evidence of a reservation covering the displayed appointment range.

== 1.3.1 ==

* Treat every add-on-held start as a complete reservation interval and make all overlapping public choices unavailable under the same rules as a real booking.
* Expose bounded treatment and buffer dimensions through extension API 8 so compatible add-ons can preserve their target and minimum after overlaps.

== 1.3.0 ==

* Add a versioned, customer-data-free public availability policy for compatible add-ons.
* Restrict add-on output to a validated subset of starts that Core calculated as available, and fail open if an extension fails or returns invalid data.
* Apply held public starts to both availability responses and the locked booking submission path without creating bookings or reservation rows.
* Keep administration and customer change flows on the actual calendar.

== 1.2.10 ==

* Keep advanced privacy, retention, and public-booking protection settings compact while showing their saved values.
* Preserve native browser validation by opening every containing settings or email-template panel before focus moves to an invalid field.

== 1.2.9 ==

* Keep the customer receipt visible while publishing a customer-data-free `booking-received=1` virtual receipt URL after successful public submissions.
* Emit one PII-free `circumflex_booking_received` data-layer event per accepted submission for exact GA4/GTM measurement without loading an analytics service.
* Restore the receipt without repeating the conversion event, remove direct or stale success markers, and let the customer start another booking with fresh configuration.

== 1.2.8 ==

* Add bounded practitioner-editor hooks for compatible add-ons.
* Expose only internal and opaque practitioner identifiers, and isolate extension failures from ordinary practitioner management.
* Add a committed public-booking event that exposes only the initial status and technical practitioner identifiers.

== 1.2.7 ==

* Add a bounded booking-overview status hook for compatible add-ons.
* Expose only the booking ID, status, and row version, and isolate extension failures from the ordinary booking list.

== 1.2.6 ==

* Add a bounded booking-detail action hook for compatible add-ons.
* Expose only the booking ID, status, practitioner ID, and row version; add-ons must re-authorize submitted actions and load current state themselves.
* Isolate extension rendering failures so the ordinary booking actions remain available.

== 1.2.5 ==

* Let compatible add-ons add settings to the service editor without changing the free plugin's manual-approval default.
* Let a fail-closed add-on policy choose a pending or confirmed initial status from the complete locked service selection.
* Persist automatic confirmation, reservations, audit history, customer and staff confirmations, and reminders in the original booking transaction.
* Show customers a status-specific receipt instead of review wording after an automatically confirmed booking.

== 1.2.4 ==

* Send explicit browser, proxy, and LiteSpeed no-cache signals for public availability responses while retaining the bounded 60-second WordPress transient.
* Keep every Circumflex Booking REST route, including separately installed add-on routes in the shared namespace, out of LiteSpeed's page cache.

== 1.2.3 ==

* Retain the release-aware booking asset URL when LiteSpeed's query-string removal is enabled.
* Apply the no-optimization marker to the external booking bundle rather than its inline translation data.

== 1.2.2 ==

* Omit hidden service durations from the public catalog, availability summaries, and booking receipts while preserving server-side scheduling calculations.
* Exclude the public booking bundle from LiteSpeed rewriting and combine the plugin release with the build hash in public asset versions.
* Default to hiding minutes in the browser unless the current server response explicitly makes a valid duration public.

== 1.2.1 ==

* Preserve visible treatment minutes for existing services across the schema upgrade on every supported database.

== 1.2.0 ==

* Add a bounded, customer-data-free milestone API for optional booking-flow statistics in separately installed add-ons.
* Keep extension configuration small, isolate extension failures, and load add-on assets only where the public booking form is rendered.
* Return reliably to the top of each booking step in mobile Chrome while retaining accessible focus behavior.
* Let administrators show or hide each service's treatment minutes without changing availability calculations.

== 1.1.2 ==

* Keep the public privacy-policy link visible and underlined when host themes define conflicting normal, visited, hover, active, or focus link colors.
* Add a hostile-theme browser regression for the contact step on desktop and mobile.
* Let compatible add-ons show and enforce their phone-number guidance before the public review step.

== 1.1.1 ==

* Add a stable, PII-free notification extension API for separately installed channel add-ons.
* Add progressive administration hooks for per-action notification channel choices.

== 1.1.0 ==

* Add configurable, object-scoped approval and rejection of assigned booking and time-change requests for linked practitioners.
* Add four editable practitioner decision email templates, manager-decision notifications, and self-notification suppression.
* Add practitioner readiness guidance, a versioned least-privilege capability, configuration format 3, and security regression coverage.
* Explain every non-obvious booking setting and link the public consent step to the privacy policy page selected in WordPress.
* Make every dashboard setup step reflect active booking readiness and show the exact next action when incomplete.
* De-emphasize completed configuration, show Turnstile success only when fully configured and active, and explain how to publish the booking form on a normal WordPress page.
* Label the distinct top-level administration menu "CF Booking" while retaining the full product name elsewhere.

== 1.0.2 ==

* Sanitize administrative request values when they are acquired and protect the pattern with a regression test.
* Confirm that every shipped feature is available without a license key or payment.
* Prepare WordPress.org language-pack delivery by excluding generated locale files from the release ZIP while retaining the translation template.
* Label the distinct top-level administration menu "CF Booking" while retaining the full product name elsewhere.

== 1.0.1 ==

* Clarify that MySQL 8.0 and MariaDB 10.11 are the tested and supported production baseline, not a database-version activation check.
* Report older database versions as a warning while keeping the plugin active.

== 1.0.0 ==

* First stable release of the customer booking, availability, manual approval, administration, and secure self-service workflows.
* Include responsive email notifications, configurable site identity, reminders, privacy tools, anti-spam controls, and Norwegian translation.
* Support shortcode, dynamic Gutenberg block, and optional Elementor embedding on WordPress 6.8+ with PHP 8.3+.

== 1.0.0-rc.9 ==

* Add a configurable email-header identity with safe WordPress site-title and hostname fallbacks instead of the plugin product name.
* Separate business cancellation from customer self-cancellation so each customer email has accurate terminology and its own editable template.
* Export the new setting in configuration format 2 while retaining backward-compatible format 1 imports.

== 1.0.0-rc.8 ==

* Clarify booking and cancellation deadline labels and contextual help without changing minute-based storage or configuration contracts.
* Prepare the public source, unique plugin URL, WordPress.org metadata, privacy disclosures, screenshots, and reproducible build instructions.
* Preserve the bundled Norwegian translation while keeping all source strings ready for WordPress language packs.

== 1.0.0-rc.7 ==

* Show minimum booking notice and cancellation deadline in decimal hours while preserving the existing minute-based storage and configuration contracts.
* Replace the editable service sort number with a complete drag-and-drop service order and accessible move-button fallback.
* Append new services predictably and protect complete reordering with capability, nonce, row locking, optimistic concurrency, audit, and cache invalidation.

== 1.0.0-rc.6 ==

* Give all twelve customer and internal notifications one responsive, accessible HTML design using the site identity and configured booking color.
* Preserve safe editable text templates and include their exact rendered content as PHPMailer's plain-text alternative.
* Add a sandboxed visual preview, plain-text preview, multipart test send, and complete all twelve event choices in administration.

== 1.0.0-rc.5 ==

* Dispatch the bounded notification worker through a signed, non-blocking same-site endpoint so email does not wait behind unrelated WP-Cron work.
* Keep the request-unique cron event and five-minute worker as durable fallbacks, clearing only the matching event after a successful direct start.
* Record the worker source in the PII-free heartbeat and test that the direct loopback completes while WordPress' shared cron lock is held.

== 1.0.0-rc.4 ==

* Refresh WordPress' request-local cron option caches at shutdown before deciding whether a consumed immediate event must be re-armed.
* Schedule the request event even when loopback cron is disabled, retaining server cron and the five-minute recovery worker.
* Extend the isolated regression with a stale autoloaded cron-cache reproduction.

== 1.0.0-rc.3 ==

* Give each enqueue request a non-sensitive unique cron argument so a notification cannot coalesce with another request's in-flight single event.
* Re-arm the request-owned event at shutdown if another loopback consumed it before the newly committed row became visible.
* Add a process-isolated regression for cross-request event ownership and shutdown re-arming.

== 1.0.0-rc.2 ==

* Trigger immediately due notification work through a non-blocking WordPress cron loopback while retaining the five-minute recovery worker.
* Preserve customer-receipt and internal-submission notices when a booking is reviewed before the first queue run, with stable event ordering.
* Clarify the internal notification template as a historical received event.

== 1.0.0-rc.1 ==

* Add a six-case WordPress/PHP/MySQL/MariaDB compatibility gate, deterministic release packaging, checksums, and a dependency/license/source trace.
* Add upgrade, backup/restore, concurrency, DST, realistic-volume performance, and full current-platform regression gates.
* Extend browser accessibility through contact, review, and optional Turnstile submission, and isolate pressed-state colors from theme overrides.

== 0.11.0-beta.1 ==

* Add WordPress privacy export/erasure, bounded automatic anonymization, retention controls, and privacy Site Health monitoring.
* Add optional fail-closed Cloudflare Turnstile, filtered CSV with spreadsheet-formula protection, and versioned configuration preview/import/export.
* Add scoped dashboard distributions, local diagnostics without personal data, queue pause, global customer-token revocation, and explicit permanent-uninstall cleanup.

== 0.10.0-beta.1 ==

* Add one shared renderer behind the shortcode, a dynamic Block API v3 Gutenberg block, and a conditionally registered Elementor widget.
* Add accessible adaptive color pairs, keyboard focus management, non-color states, and calendar/list date views.
* Improve theme isolation, responsive layouts, reduced-motion and forced-color behavior, plus handle-specific JavaScript translations.

== 0.9.0-alpha.1 ==

* Add private purpose-bound customer links for side-effect-free booking viewing, self-service cancellation, and one pending time-change proposal.
* Add customer change availability that keeps the original reservation while a proposed slot is held for manual approval.
* Add administration approval/rejection, customer and internal notifications, same-origin mutation protection, token rotation, and isolated end-to-end coverage.

== 0.8.0-alpha.1 ==

* Add editable plain-text notification templates, strict placeholders, synthetic previews, and test email delivery.
* Add a bounded idempotent email queue with five-minute cron processing, explicit retry policy, unknown-delivery protection, administration, and Site Health diagnostics.
* Add configurable version-bound reminders that are cancelled and rescheduled when relevant booking state changes.

== 0.7.0-alpha.1 ==

* Add bounded day, week, and month administration calendars plus server-side booking filters and stable pagination.
* Add explicit desktop drag-and-drop confirmation with mobile/keyboard fallback, object scope, optimistic concurrency, and fresh conflict checks.
* Add scoped operational dashboard counters, upcoming bookings, and quick links for blocks and extra availability.

== 0.6.0-alpha.1 ==

* Add an object-scoped booking list and detail view with explicit approval, rejection, cancellation, completion, and no-show actions.
* Add confirmed manual bookings, safe schedule changes, service/practitioner changes, and five-minute duration overrides with mandatory conflict checks.
* Add separately authorized internal notes, explicit audited terminal-status correction, optimistic concurrency, and transactional customer events.

== 0.5.0-alpha.1 ==

* Add a responsive, translatable `[circumflex_booking]` customer flow with conditional practitioner choice.
* Add gray unavailable times, strict public REST contracts, atomic pending bookings, service snapshots, and reservations.
* Add protected anti-spam counters, pending limits, honeypot and form-timing controls, readable references, and transactional outbox events.

== 0.4.0-alpha.1 ==

* Add weekly schedules, closures, extra-open dates, manual blocks, and a generated-time debugger.
* Add DST-aware slot generation, multi-service buffers, booking windows, and cached public availability.
* Add deterministic first-available allocation with stable transactional locking and schema version 3.

== 0.3.0-alpha.1 ==

* Add native, responsive administration for services, practitioners, and global booking settings.
* Add least-privilege Booking Manager and Practitioner roles with versioned capabilities.
* Add inherited service defaults, optimistic edit protection, transactional audit events, and schema version 2.

== 0.2.0-alpha.1 ==

* Add versioned InnoDB schema, integrity inspection, guarded reset, and data-preserving lifecycle behavior.
* Add transaction, resource-lock, reservation, status, time, service aggregation, and secure token primitives.
* Add database and domain test coverage, including real concurrent reservation verification.

== 0.1.0-alpha.1 ==

* Add the plugin bootstrap, requirement checks, Norwegian language pack, and admin status page.
* Add local build, test, and quality tooling.
