=== Frontend File Upload ===
Contributors: muneebkhan21
Donate link: https://www.fiverr.com/muneebk21
Tags: frontend, uploader, file
Requires at least: 5.0
Tested up to: 7.1
Requires PHP: 7.0
Stable tag: 1.4.0
License: GPLv2 or later
License URI: http://www.gnu.org/licenses/gpl-2.0.html

Allows users to upload files directly in WordPress Database from frontend.

== Description ==

Frontend File Uploader allows admins to add a simple form on frontend of WordPress website to enable their users to upload files directly in WordPress database.

Using this Shortcode: [ffu-shortcode]

Below are some salient features:

== Frontend File Uploader Features ==

*   Simple to use
*   100% responsive
*   No limitation on the number of files
*   Easy to add anywhere using a shortcode.
*   Drag-and-drop upload zone with a live progress bar.
*   Multi-file preview grid (image thumbnails, icons for other file types) before submitting.
*   Allowed file types and maximum file size are configurable from File Uploader > Settings.
*   You can manage the uploaded files in WordPress admin panel.

= Do you want to contribute? =

If you have ideas that can help us improve our plugin and user experience, please contact us at rmkhan1996@hotmail.com
A few notes about the sections above:

== Installation ==

1.  Download the plugin.
2.  Upload 'frontend-file-upload.zip' to the '/wp-content/plugins/' directory to your web server.
3.  Activate the plugin through the 'Plugins' menu in WordPress.
4.  Visit the plugin page for settings.

== Screenshots ==

1. **Frontend Display** - Frontend form to allow users to upload files. screenshot-1.jpg
2. **Backend Display** - Lists files uploaded by users. screenshot-2.jpg

== Changelog ==

= 1.4.0 =
UI polish, front-end and admin. No functional or breaking changes; markup
classes changed throughout, so any custom CSS overriding the plugin's old
class names will need to be updated.

* Improved: front-end upload form redesigned with a card layout, a
  dynamic "Accepted: ... Max size: ..." hint on the dropzone (reflects
  current settings), and an upload progress percentage readout.
* Improved: File Uploader admin list now uses WordPress's native list-table
  styling, adds an "Uploaded" date column, a select-all checkbox, a
  confirmation prompt before deleting, and an empty state when nothing's
  been uploaded yet.
* Fixed: the admin file list previously used invalid HTML (<head>/<body>
  inside a <table>) and a hardcoded MIME filter that predated the
  Settings page, so it silently excluded image uploads. Both are fixed.
* Fixed: the "Delete Selected" button used non-existent CSS classes and
  had no styling at all; now uses standard WP admin button styles and
  disables itself until a file is selected.
* Accessibility: the username field's label is now properly associated
  with its input, and the settings page's file-size field is now
  labeled.

= 1.3.0 =
Performance release. No breaking changes.

* Perf: the plugin's front-end CSS/JS no longer load on every page of the
  site. They're now only enqueued on pages where [ffu-shortcode] is
  actually rendered.
* Perf: the plugin's admin CSS/JS no longer load on every wp-admin screen.
  They're now scoped to the plugin's own File Uploader and Settings pages.
* Note: the upload flow already moved to async/AJAX with a progress bar in
  1.2.0, which covers the "avoid full-page reload" part of this release's
  performance work.

= 1.2.0 =
New functionality. No breaking changes for site visitors; if you customized
the plugin's markup, JS, or CSS in a child theme or override, note the
markup and script changes described below.

* New: drag-and-drop upload zone, alongside the existing click-to-browse
  file input.
* New: multi-file preview grid shown before submitting, with image
  thumbnails, a generic icon for other file types, and a per-file remove
  button.
* New: uploads now go over AJAX with a real progress bar, instead of a
  full-page form submission. The original full-page POST handler is kept
  as an automatic fallback if JavaScript is unavailable, so the form keeps
  working either way.
* New: File Uploader > Settings admin page to configure which file types
  are accepted and the maximum file size, replacing the previous hardcoded
  pdf/doc/docx and 5MB limit. Existing sites keep that same default
  behavior until the settings are changed.
* Dev note: the public JS file, form markup, and admin-ajax action names
  changed substantially in this release. If anything hooks into or
  overrides this plugin's front-end templates or scripts directly, it will
  need to be re-checked against the new markup.

= 1.1.0 =
Security hardening release. If you have anything scripted against the upload
form or the admin delete action, read the "Breaking changes" note below.

* Security: the upload handler previously ran on every front-end page load
  and accepted files from anyone, with no login, capability, or CSRF check.
  It now requires a valid nonce, so it only accepts submissions from the
  plugin's own form.
* Security: the "delete uploaded file" admin action was reachable by
  logged-out visitors and could delete any post or page by slug (not just
  attachments), bypassing WordPress's normal post-deletion process. It now
  requires a valid nonce, requires the `manage_options` capability, is no
  longer reachable while logged out, and only deletes actual attachments
  (via `wp_delete_attachment()`, which also removes the file from disk).
* Security: uploaded files are now validated server-side against their real
  content (not just file extension), independent of the `accept` attribute
  on the file input.
* Security: server-side maximum file size (5MB by default), enforced
  regardless of any client-side checks.
* Security: uploaded filenames are now randomized to prevent overwrite
  collisions and to stop uploaded files from being predictable/enumerable.
* Security: added a basic per-IP rate limit (10 uploads per 10 minutes) on
  the upload endpoint.
* Fix: the uploaded-by name field is now sanitized before being stored;
  previously it was written to the database unsanitized.
* Fix: corrected a truncated .docx MIME type (both in the form's `accept`
  attribute and in the admin file listing query) that meant .docx files
  were never actually matched by name.
* Fix: corrected an operator-precedence bug in the admin file-listing query.

= 1.0.0 =
Initial release.

== Upgrade Notice ==

= 1.1.0 =
Security release. Anonymous file upload and anonymous file deletion (both
unintended) are removed; the upload form now requires visiting the page it's
on (for a valid nonce), and deleting files now requires an administrator
account. Update as soon as possible.
