=== Clockdo – Publish Date Proof & Content Timestamp ===
Contributors: ray5051
Tags: timestamp, copyright, content protection, blockchain, verification
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.1.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Create verifiable OpenTimestamps records for WordPress posts, with durable proof history and independently checkable evidence.

== Description ==

Clockdo helps WordPress site owners protect their publish date by generating a verifiable content timestamp.

Clockdo creates a deterministic fingerprint (SHA-256) and requests an OpenTimestamps proof. Public posts use the public proof flow. Draft and private versions use a private, hash-only protocol and never send the title, author, URL, WordPress post ID, or post body. When full-text archive mode is enabled, every meaningful save in draft, pending, scheduled, private, or published state is first stored as an immutable local snapshot.

== Features ==
* Generate per-post timestamp records
* Request OpenTimestamps proof
* Export .ots and manifest files
* Automatic draft, publish, update, and opt-in private-post workflows
* Separate article coverage and immutable proof-history views
* Immutable full-text snapshots for every meaningful save when full-text archive mode is enabled
* Snapshot validation, idempotent requests, and recoverable asynchronous retries
* Optional public meta tags and post footer with verification link
* Independent verification using standard tools


== Use Cases ==

* Prove when an article was first published
* Add a visible publication record to your posts
* Protect against plagiarism disputes
* Maintain an independent timestamp history
* Provide verification material for disputes or takedown cases

English (Summary)
* Generate per-post records and proof history in the dashboard.
* Save proof artifacts to your WordPress uploads folder.
* Optionally inject public meta tags and/or a "Verify" footer link.
* Proofs are designed to be independently verifiable with standard OpenTimestamps tools.


== Installation ==

1. Upload the plugin folder to `/wp-content/plugins/` or upload the ZIP via Plugins -> Add New -> Upload Plugin.
2. Activate the plugin.
3. Go to the plugin Settings page and set your API Base URL and fetch/save your Site ID.
4. Ask your Clockdo operator to provision the Site Secret if you plan to enable draft or private-post proofs. Merely entering a domain never issues this credential, and the Settings page reports only whether it is configured.
5. Review the archive/submission settings. In legacy mode, public publish/update automation is enabled by default and draft/private automation is opt-in. Enabling export + full content + local storage activates full-text archive mode, in which every meaningful eligible save is retained and queued for its matching public/private proof.
6. Publish or save a post, then inspect article coverage and proof history on the dashboard.

== Frequently Asked Questions ==

= Is this a copyright registration? =
No. This plugin creates a verifiable timestamp record. It does not register copyright or determine legal ownership.

= Can this help in disputes? =
It provides independent timestamp evidence that may support your documentation process. Legal outcomes depend on jurisdiction and additional evidence.

= Does this prove ownership/copyright? =
No. It proves that a specific fingerprint existed by a certain time (via an OTS proof). Ownership depends on broader evidence and jurisdiction.

= What data is timestamped? =
A SHA-256 fingerprint of a canonical representation of content and/or a manifest that references it.

= What happens with drafts and private posts? =
Draft submissions and opted-in private-post submissions use a private protocol. The remote service receives a content hash plus protocol fields, but not the title, author, URL, WordPress post ID, or body. Private proof status and artifacts require the site's secret. Publishing the post later creates a separate public proof.

= Which WordPress states are archived automatically? =
In full-text archive mode, meaningful saves of draft, pending, scheduled, private, and published posts create immutable local versions and queue their corresponding hash proof. Actual publication of a scheduled or previously private post creates a separate public version. Autosaves, revisions, auto-drafts, trash changes, and no-change saves do not create versions. Sites outside full-text archive mode retain the legacy opt-in draft/private submission behavior.

= Where are snapshots and proof files stored? =
Exact full-text snapshot bytes are stored in the WordPress database. Frozen manifest and `.ots` artifacts are stored locally under the uploads directory. Authorized users can download the snapshot, manifest, and finalized OTS from the WordPress dashboard. If you purchase a separate hosted plan, proofs may also be hosted by the Clockdo service (manifest + `.ots` only; never the local full-text snapshot).

The plugin applies restrictive directory/file permissions and writes Apache deny rules. nginx does not read `.htaccess`; nginx operators must explicitly deny `/wp-content/uploads/clockdo-ots-private/` (or move that directory outside the web root).

= Will this affect SEO? =
Meta tags do not duplicate content. If you enable a public footer link, consider `rel="nofollow"` by default.

== Privacy ==

This plugin may process and store locally:
* WordPress post metadata (post ID, URL, timestamps),
* immutable full-text snapshots containing post title, body, excerpt, slug, author ID, status, and audit timestamps when full-text archive mode is enabled,
* deterministic hashes (SHA-256),
* proof IDs/statuses,
* proof artifacts written to local disk under `wp-content/uploads/clockdo-ots-private/`.

Outbound requests:
* This plugin connects to a remote timestamping API (configured by you) to request proofs.
* Full-text archive v3 submissions upload only a manifest commitment; the exact snapshot and post body remain in the local WordPress database. Public manifests may include already-public identity fields such as URL, title, author, and timestamps.
* Legacy export workflows may upload `export.json`, including post content when the operator explicitly enables that older combination of settings.
* Private and draft submissions upload a hash-only manifest. They do not upload the title, author, URL, WordPress post ID, or post body.
* A SHA-256 commitment is an integrity fingerprint, not encryption. It reveals when two committed snapshots are equal, and low-entropy content may be guessable by testing candidate text.

Public disclosure:
* If you enable meta injection or public verify links, your public pages may expose a hash/canonicalization identifier and a verification link.

See the included docs (for operators):
* `assets/docs/privacy.md`
* `assets/docs/third_party_services.md`
* `assets/docs/data_deletion_uninstall.md`

== Third Party Services ==

This plugin connects to the following external services:

1. **Clockdo Timestamping API** (`ots-api.clockdo.com`)
   * Used to register sites, submit timestamp requests, and check proof status.
   * Endpoints called: `/api/v1/public/sites`, `/api/v1/public/site-stamps`, `/api/v1/site/me`, `/api/v1/proofs/{proof_id}`, and authenticated manifest/OTS artifact paths.
   * Data sent for registration: site domain.
   * Data sent for public proofs: post URL, SHA-256 hash, and manifest/export JSON according to settings.
   * Data sent for private/draft proofs: Site ID, SHA-256 content commitment, event/visibility/source-status fields, canonicalization version, and idempotency key. The per-site secret authenticates the request.
   * Service homepage: [https://ots.clockdo.com](https://ots.clockdo.com)
   * Privacy policy: [https://ots.clockdo.com/privacy](https://ots.clockdo.com/privacy)
   * Terms of service: [https://ots.clockdo.com/terms](https://ots.clockdo.com/terms)

2. **Clockdo Verification Page** (`ots-verify.clockdo.com`)
   * If public verify links are enabled, post pages may link to this domain for independent proof verification.

All outbound connections are made via the WordPress HTTP API (`wp_remote_post` / `wp_remote_get`).
The API Base URL is configurable; the above domains are defaults.

See also: `assets/docs/third_party_services.md`

== Uninstall ==

Ordinary uninstall removes plugin settings, transient queue state, legacy batch tables, and mutable display metadata. It deliberately retains the immutable `ots_post_snapshots` and `ots_post_proofs` audit tables, including any full-text snapshots, and it may leave proof files under `wp-content/uploads/clockdo-ots-private/`.

For irreversible full deletion, first make and verify a backup, then follow `assets/docs/data_deletion_uninstall.md` to remove the two retained tables and the private uploads directory explicitly.

== Screenshots ==

1. Admin dashboard: proof stats and recent submissions.
2. Post list column: proof status and quick actions.
3. Settings page: API base, site ID, public options.

== Changelog ==

= 0.1.3 =

* First public release after 0.1.1; it consolidates the unpublished 0.1.2 development line and internal 0.1.3 release candidates.
* Archive every meaningful draft, pending, scheduled, private, and public save as exact immutable snapshot bytes in full-text mode.
* Bind frozen single-snapshot-v3 and bulk-v3 manifests to snapshot and content hashes without uploading private article metadata or full text.
* Add authenticated per-version snapshot, manifest, and finalized OTS downloads while retaining immutable proof history independently from current article visibility.
* Add a unified public/private submission state machine, generation-aware ownership, durable outboxes, leases, watchdogs, idempotent retries, and accepted-Proof-ID recovery.
* Keep accepted recovery pending until the exact Proof ID and idempotency key are present in durable local history; conflicting audit identities fail closed.
* Freeze the additive v1 API contract, capability negotiation, wire statuses, request limits, canonicalization identifiers, and artifact digest bindings.
* Make historical legacy aggregate proofs read-only, preserve their exact body-only hash semantics, and require bulk-v3 for new auditable full-text batches.
* Verify local and downloaded manifests, exports, snapshots, and OTS targets against the durable proof commitment, failing closed on mismatches.
* Harden database upgrades, private status/artifact access, file migration, network handling, logs, cleanup, and long-running proof status recovery.

= 0.1.1 =
* Harden the initial public proof workflow, local storage, request validation, and admin display before the private protocol release.

= 0.1.0 =
* Internal pre-directory MVP: record generation, proof requests, dashboard UI, local storage, optional public meta/link. This version was not a WordPress.org release.

== Disclaimer ==

This plugin provides timestamping and verification tooling. It is not legal advice, not a certification service, and does not determine ownership.
