=== Codlino – COD Order Forms for WooCommerce ===
Contributors: tahabelmezrar
Tags: woocommerce, cash on delivery, forms, elementor
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 7.4
Requires Plugins: woocommerce
Stable tag: 0.6.1
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Customizable Arabic cash-on-delivery forms for WooCommerce with optional Sheets integration.

== Description ==
Arabic dashboard, multiple independently configured forms, Elementor shortcode
[codlino_form id="123"], RTL layout and responsive styling. Each form orders a published simple or variable WooCommerce product, with an
optional quantity selector. Orders use WooCommerce CRUD APIs,
COD, on-hold status, stock handling and the standard receipt page; HPOS declared.

Start a new form with no fixed fields and create up to 30 fields: text, textarea,
email, phone, number or select. Use a small required checkbox under each field. Choose optional
price display and colors for the box, fields, field borders, button and button text.
Fields are visible in WooCommerce order details. Optional role mapping populates
customer name, city, phone, address and email. Legacy fixed fields migrate to
editable/deletable fields without changing existing form IDs.

Three ready-made styles (Classic, Express, Premium) apply their palette and layout
without replacing fields. Select Arabic/Latin fonts, button text size, vertical
padding, width, gap above the button and optional gentle shake animation.
Remote selected fonts load from Google Fonts; Janna must be loaded by your site.
Reduced-motion preferences disable animation. Optional Moroccan mobile format
validation accepts 06/07 and 212/+212/00212 international formats on the server.

Optional phone/IP duplicate blocking lasts 24 hours after an accepted order,
with editable messages. Optional HTTPS JSON webhooks run asynchronously with
up to three attempts. Webhook failure never cancels an accepted WooCommerce order.
Powered by Taha Belmezrar.

== Installation ==
1. Activate WooCommerce 8.2+ and enable Cash on delivery.
2. Upload codlino-cod-order-forms-0.6.1.zip. When upgrading from CODFlow,
   deactivate CODFlow first, then install and activate Codlino.
3. Create a published simple or variable product. Include delivery in its price; for physical
   products leave COD shipping-method restrictions empty.
4. Open Codlino, create/edit a form, choose its product and save as published.
5. Embed its shortcode in Elementor or a WordPress Shortcode block.
6. Verify orders and enabled integrations on staging before live traffic.

== Operational details ==
* One product per form; optional quantity (1–100 maximum, subject to stock).
* Variable products support up to 200 variations. Configure attributes, prices,
  stock and variation images in WooCommerce. Choose buttons, colors, images or
  select lists per attribute in Codlino. Prices displayed are per unit.
* No coupons, shipping-zone pricing or upsells.
* Assign a field role to map it to customer details; unmapped fields are metadata.
  Email role populates billing email; WooCommerce handles notifications. One field
  per role is allowed. Publishing requires at least one field. The builder uses JavaScript.
* Store country is used. No state/postcode mapping; verify tax rules for this model.
* Delivery line costs zero. On-hold orders are unpaid.
* Site font is the default. Janna is local; Cairo, Tajawal, Noto Sans Arabic, Inter,
  Poppins and Open Sans use Google Fonts only when selected (internet required).
* Duplicate protection counts accepted Codlino submissions where protection was
  enabled, across protected forms on this site. Historical orders and orders from
  other checkout flows are not scanned. Cancellation does not remove the 24h block.
* Phone protection makes phone required. It normalizes common country-code formats;
  Moroccan validation is a separate optional switch; it checks syntax, not ownership
  or whether a number is allocated/active. A mapped phone is required for either switch.
* IP means public network address: several customers may share one IP. REMOTE_ADDR
  is used; trusted proxies require the codlino_client_ip filter configured by an admin.
* Generic webhooks require direct HTTPS JSON endpoints returning 2xx without redirects.
  Google Sheets mode includes an Arabic setup guide, generated Apps Script receiver,
  copy button and admin-only test. It follows only Google content redirects via GET
  and verifies a matching JSON write acknowledgment. Each form uses a private token.
  Tests add a dummy Sheet row, never a WooCommerce order. WP-Cron runs real delivery/retries.
* A guard table is created on upgrade. Expired blocks stop blocking by timestamp,
  even before daily cleanup. WP-Cron also retires temporary request records.
* Request retry protection lasts 48 hours. AJAX refreshes nonce/request IDs for
  cached pages. Without JavaScript, exclude form pages from full-page caching.
* Deactivation/removal preserves forms, orders and configuration.

== External services and privacy ==
Codlino does not phone home to its author and has no analytics or licensing
connection. A merchant can use the form and create orders with all external
integrations disabled. The default font uses the site's own styles.

= Google Fonts (optional) =
Selecting Cairo, Tajawal, Noto Sans Arabic, Inter, Poppins or Open Sans loads a
stylesheet from fonts.googleapis.com and font files from fonts.gstatic.com.
Requests happen in the admin preview and visitors' browsers where that font is
used. Google receives the browser IP address and normal HTTP request information.
Choose the site font or locally supplied Janna to avoid these Google requests.
Service: https://fonts.google.com/
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

= Google Apps Script and Google Sheets (optional) =
The merchant configures and deploys the bundled receiver using their own Google
account and spreadsheet. Enabling the integration sends accepted order data
from the WordPress server to the configured script.google.com/macros/s/.../exec
endpoint. Data includes order/form/event identifiers, customer name, phone,
city, country, products, selected attributes, quantity, totals, currency, status
and configured form fields. A private per-form receiver token authenticates the
POST. Google may serve its response at script.googleusercontent.com/macros/echo;
Codlino reads it by GET without forwarding the POST body or token. Google also
receives the server IP address and normal HTTP request information. Clicking
Test sends synthetic sample data and creates a test row, with no WooCommerce
order. Real delivery and retries run through WP-Cron.
Service: https://developers.google.com/apps-script
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

= Merchant-configured generic webhooks (optional) =
Enabling a webhook sends the same order payload, without the Sheets token, to
the merchant's own HTTPS endpoint. Clicking Test sends synthetic sample data.
The endpoint provider's terms/privacy policy apply; merchants must review them
and disclose relevant processing to shoppers before enabling their integration.

= Local storage =
Orders and customer details are stored in WooCommerce. Form settings, webhook
endpoints and receiver tokens are stored in the WordPress database. Order
metadata keeps submitted form fields, selected attributes and delivery state;
enabled Sheets delivery stores its endpoint and token with the order for retries.
Duplicate phone/IP guards use salted HMAC identifiers with 24-hour expiry;
request records expire after 48 hours. Orders retain the WooCommerce customer
IP and submitted details subject to the merchant's WooCommerce retention policy.
Deactivation/removal preserves settings, forms and orders. Merchants manage
WooCommerce customer-data retention and any external spreadsheet/webhook copies.

== Extension points ==
codlino_validate_submission($error, $fields, $form_id)
codlino_order_created($order, $form_id)
codlino_client_ip($ip)
Order metadata retains _codflow_form_id, _codflow_full_name, _codflow_request_id,
_codflow_fields and optional webhook delivery metadata for upgrade compatibility.

== Frequently Asked Questions ==
= Do I need a license key or an account? =
No. All features included in this plugin work without a paid license key or an
author account. Google integrations require the merchant's own Google account.

= Is Elementor required? =
No. Use [codlino_form id="123"] in a WordPress Shortcode block or an Elementor
Shortcode widget. WooCommerce is required; Elementor is optional.

= Does disabling the webhook stop WooCommerce orders? =
No. Orders are saved directly in WooCommerce. External delivery is optional.

= Does installing this plugin send data to the author? =
No. Optional Google Fonts and merchant-configured integrations are described
under External services and privacy.

== Screenshots ==
1. Codlino admin workspace with organized form settings and navigation.
2. Classic, Express and Premium cash-on-delivery form designs.

== Upgrade Notice ==
= 0.6.1 =
Refined dashboard and order-form styling, coordinated color presets and improved
mobile spacing. Existing saved colors are preserved. Apply a preset under
Appearance to use the new palette on an existing form.

== Changelog ==
= 0.6.1 =
Refined admin and storefront styling with consistent emerald, ivory and ink
palettes, responsive spacing, clear focus states and coordinated presets.
Existing merchant color settings remain preserved.

= 0.6.0 =
Rename to Codlino – COD Order Forms for WooCommerce with text domain
codlino-cod-order-forms. Add allowlisted, typed request sanitizers and explicit
permission/nonce checks at admin save endpoints. Replace manual core admin
header/footer loading with redirects and per-user admin validation notices.
Retain persisted identifiers and legacy shortcode/cron compatibility.

= 0.5.6 =
Constrain the admin menu icon to 20px on every WordPress admin screen.

= 0.5.5 =
Selected Codlino icon in the admin menu, dashboard header and information section.
Soft section backgrounds and clearer navigation colors.

= 0.5.4 =
Admin dashboard refresh: emerald brand header, distinct section accents, clearer
inputs, cards, focus states and responsive navigation. Frontend styling unchanged.

= 0.5.3 =
Set the enqueued Google font resource version and place the documented Apps Script
response-host analyzer exception at the validated host literal. No delivery or
security behavior changes.

= 0.5.2 =
Plugin Check fixes: translator comments, prefixed template variables, safe field
attributes, WordPress font enqueue/late printing, sanitized server input and
prepared SQL identifiers. Document narrowly scoped analyzer exceptions for
nonce-verified delegation, read-only navigation and atomic uncached guard queries.
Google Sheets acknowledgment handling is unchanged and documented as service
communication. Tested up to reflects the merchant-reported WordPress 7.1 site.

= 0.5.1 =
Publication preparation: document optional external services and local storage,
clarify account requirements, and correct the 0.4.1 changelog version.

= 0.5.0 =
Save in place and advance through setup sections. Empty forms save as drafts with
an Arabic popup. WooCommerce variations with colors/images/sizes and optional
quantity. Server-authoritative variation prices, eligibility and stock.
Selected attributes and quantity are included in webhook/Sheets data.
= 0.4.1 =
Light dashboard refresh: white surfaces, quiet green accent, numbered sections,
clearer text and controls, mobile navigation and refined frontend presentation.
= 0.4.0 =
Built-in Google Sheets setup guide and Apps Script generator, private per-form
receiver token, verified Google response handling and admin webhook test.
= 0.3.0 =
Fields from scratch, per-field required checkbox and customer role mapping.
Three templates, font selection, button size/gap/motion and Moroccan phone validation.
= 0.2.0 =
Arabic dashboard and branding, custom field builder, configurable colors,
optional HTTPS webhook, optional 24-hour phone/IP duplicate blocking.
= 0.1.1 =
RTL layout, hidden required markers, optional fields and price visibility.
= 0.1.0 =
Initial MVP.

