== Changelog ==

The versions before 1.0.0 were never published on WordPress.org: they were the development
of the plugin, distributed by hand to the sites it was being built on. They are kept here in
full, because what was decided and why is worth reading; the readme carries the versions the
directory has actually served.

= 0.9.5 =

* **A portfolio now says whether it belongs in the directory.** The page at the base address listed every active portfolio, and the only way out of it was to switch the page off for everybody. Each portfolio now carries its own answer — *Listed* or *Not listed*, beside the group in p-admin and under the address in the wp-admin editor — and every portfolio is born listed, the ones that already exist as well as the ones created from here. Out of the directory a portfolio is not hidden: its own address answers as it always did, and a block may still name it by hand. It is the listing that stops naming it. Where a site publishes no directory at all, both screens say so plainly instead of pretending, and the choice is still saved for the day it does — and the site's own switch is now on by default, so a new site has a directory unless it says otherwise. The word follows: what the settings and the manual called *the index* is *the directory* everywhere a person reads it — the page, the link at the top of every public page, and the field in *Settings → Addresses*.
* **The portfolio screen was rearranged to receive it.** The portfolio card is now the whole left column — what the portfolio *is* — and everything done to it is the right one: Design, collections, contributors, address and backup. A first visit opens the collections alone; the rest waits to be asked for, and whatever each person folds away is remembered as before.
* **Suspending from the list no longer opens the portfolio.** *Suspend* and *Reinstate* are row actions, and answering one carried the manager into the editor of that portfolio — somewhere they had not asked to go, and out of the list they were working through. The answer now lands back on the list, on the very view they were looking at: the filters, the search and the sort come back with it, so a run of suspensions is a run of clicks and not a road back each time. The same buttons in the editor's *Suspension* card stay in the editor, where they belong.
* **A contributor's e-mail address is no longer printed under their name.** The search that finds a person has always shown the address masked — enough to tell two people of the same name apart, not the address itself — but the row that person became printed it whole, so designating somebody and removing them again read out exactly what the search had refused to give. Those rows are masked now, for everybody: p-admin is where a portfolio is run, not where the site is managed, and a card that hides an address in its search while printing it in its own list teaches nobody anything. A whole address is read in wp-admin, which asks for a capability to open. What this buys is that an address is looked up deliberately, one at a time, instead of a list to sweep — it does not put one out of reach of whoever is set on it, and the manual now says that instead of promising more.
* The p-admin no longer zooms the page in when a field is touched. On an iPhone, Safari enlarges the whole page whenever a field whose text reads under 16 px takes focus, and the fields of this area follow the density of wp-admin — so a tap on the title, on the name of a collection or on a description jumped the page and pushed the rest of the screen out of sight, once per field. On a touch screen every field now reads at 16 px, the few boxes cut to the size of their digits growing just enough to hold it; with a mouse the density is the one it always had. Pinch zoom is untouched — the way to stop this is to lock the page, and a page a person cannot enlarge is one some people cannot read.
* **The address word waits for you to finish.** It is the one field whose save renames the folder the images live in, so it was never saved by a pause after typing — but a collection's was, and every 700 ms of thought renamed the folder again, left another redirect behind and redrew the screen under the fingers that were typing. And on either screen, an address half written travelled with the very next save of any other field, renaming the portfolio to a word nobody meant. Now the address word is saved when its card is left — moving to the field beside it is not leaving it — on Enter, or after seven seconds in which nothing at all happens, which is a field nobody is going to leave rather than a pause to think; on the portfolio and on the collection alike, and no other save ever carries it. Leaving the page saves it too, so an address typed and abandoned is not lost. When it does save while you are still in the box, the box keeps the focus and the caret.
* **A rename no longer redraws the screen you are working on.** Saving a new address word rebuilt the whole screen, which is how the box somebody had just moved to lost the focus and, on a phone, the keyboard with it. Only what actually shows an address is redrawn now — the page's own address, the *Address* card with its copy chip and QR code, the collections' rows, the thumbnails of a renamed collection — and the cards being filled in are left exactly as they are. Changing the order of a collection's images is lighter the same way: the grid reorders and nothing else moves.

= 0.9.4 =

* The two video fields in *Settings → Videos* now name each other instead of pointing. *Video services accepted* said the networks that answer nobody were "the field below", which was three fields off — the player's own settings sit in between — and the other field said nothing about where an address that does answer belongs. Each now gives the other's name, in every language.

= 0.9.3 =

* **A video on Instagram, Facebook or LinkedIn now has a place in a collection.** Those networks answer no plugin about an address — Meta only answers applications registered with Meta, LinkedIn publishes nothing to answer with — so there was no way to fetch a title or a thumbnail, and the feature simply did not exist. Now there is a second way to add a video: **Link a video** takes the address and a picture of your own, in one press, and the card takes its place among the images with the same caption, the same order and the same rules. It opens the video in a new tab, marked with an arrow that leaves rather than a play triangle, because there is no player and it should not promise one. Those networks are never contacted by your site — not when the video is added, not when a visitor looks at the collection — so nothing of theirs runs on your pages and no visitor is handed to them before they choose to go. Which networks are accepted is a list in *Settings → Videos* that you may edit.
* **A cover no longer moves under a finger that was only scrolling, and can now go in closer.** On a phone, dragging the page with a finger over the cover moved the cover instead: the box had taken the touch for itself. The picture is now **locked** whenever the screen opens, and the padlock at its corner hands it back — locked, the page scrolls over it like over anything else; open, the box takes a ring and the picture is yours to place. With it open there is also a **zoom**: pinch with two fingers, or turn the wheel, and the crop closes in around the point you framed, up to three times the box — enough to make a face or a detail the whole cover. The keyboard does the same: the arrows place it, + and − zoom, 0 comes back. A cover that goes in closer asks the browser for a bigger file, so the sharpness is the picture's own.
* **The cover you chose is the cover visitors see, whichever collection it came from.** A cover picked from a collection that is not shown was quietly dropped and the first shown collection lent its own instead. Choosing a cover is a deliberate act, so it now holds: that one image answers at its address like any public one, while the collection it lives in stays closed — its page and its other images are still a 404 to a visitor.
* **A collection now offers the portfolio it belongs to.** The page of a collection named nothing above it: a visitor handed that address had no way on to the rest, and the only way back was the browser's own. Above the title there is now an arrow and the name of the portfolio, which opens it. Each collection decides for itself, in its Design card — *Offer visitors the whole portfolio*, on for every collection, new and existing. Switch it off for a collection you hand out on its own and its page stops naming the rest; nothing is hidden either way, the portfolio's address goes on working for whoever has it, and a portfolio that is inactive or suspended is never offered.
* The portfolio page shows its cover the way its owner placed it: the hero was the one box that kept its own answer — the whole picture, centred — and ignored the crop and the focal point chosen in p-admin. And a video embed that draws nothing now says so to whoever can fix it, instead of leaving a silent gap on the page.

= 0.9.2 =

* **A public portfolio page wears the icon of this site.** The pages the plugin writes carried the plugin's own icon in the browser tab. A portfolio, a collection and the index are pages of the site, and now wear whatever icon the site configured — the same one every other page shows, and none where the site configured none. The area keeps its own: p-admin, the sign-in, the terms and the message pages are the plugin's doors.
* **The tiles / carousel switch stopped being a headline.** It opened the collection from the left, wider than anything on the page that is not a photograph. It is a preference of whoever is looking, so it moved to the right, aligned with the edge of the grid, and became two icons a third of the size. The name of each view is still there — read aloud by a screen reader, shown as a tooltip on a hover — and on a touch screen the buttons grow to a size a thumb finds.
* The six boxes of the Licensing screen read as two rows of three, and the Spanish speaks of the visitor the same way everywhere.

= 0.9.1 =
* **A link now chooses its own tab.** In the simple HTML editor — the descriptions, the content terms, the sentence of the sign-in page — the link button opens a small panel with the address and an *Open in a new tab* switch, instead of the browser's bare question. Until now every link was forced into a new tab whatever was written; the switch starts on, so nothing changes for whoever does not touch it. With the cursor inside a link, the panel opens it already filled in and changes that link — its address, its tab — instead of leaving two.
* **A photo already in a collection is not added again by dragging it.** Dragging a photo inside the grid was handing the browser's own copy of the thumbnail to the upload zone, which stored it as a new image, smaller and slightly different every time. The photos of the page are no longer draggable — a photo is moved by the handle at the top of its card, and only by it — and a photo of this site dropped on the upload zone, dragged from wherever, is refused with a line that says why.

= 0.9.0 =
* **A first install starts with content terms already written.** Plain words about what may be published, what may not, that the site may remove what does not belong, and that a showcase is not a backup. They grant nobody any licence over the images: whether an organisation may reuse what is published belongs to that organisation, not to a clause a plugin shipped. Edit them, or replace them entirely, in Settings.
* **The sign-in page is yours to word.** The sentence under the name of the site is a field now, written in the same simple HTML editor as the terms. Beside it, the name of the area and — greyed out, because it belongs to WordPress — the title of the site, in the order the page prints them.
* **The two doors are never both closed.** The password form cannot be switched off while no alternative sign-in is configured, and emptying the alternative brings the form back. Whichever way somebody tries it, the sign-in page keeps a way in.
* **The settings say what a field is doing.** The button label greys out when a shortcode is drawing its own button, and says why; an address left without a label warns that no button will be printed at all.
* The settings cards are arranged in two columns of their own, and the licensing screen carries the addresses of the plugin and of its author.
* Portuguese was revised end to end: one word for each thing, *portefólio* throughout, and the spelling of the current agreement.

= 0.8.2 =
* **What a refused visitor reads is now yours to write.** A new field beside the domain list holds the sentence somebody sees when they sign in and are then turned away. Write `{domain}` where their own domain should appear, and tell them who to ask — that page is where they stop. Left empty, the sentence the plugin ships is used, in the language of the site.
* **Both refusals now call the area by the name this site gave it.** They said "the portfolio area" whatever the site had renamed it to; they now use the address word, as the settings beside them already did.

= 0.8.1 =
* **A refusal at the door of the portfolio area now says which of the two it is.** Somebody who signs in successfully and is then turned away by the e-mail domain list is told so, and told which domain — their own, read from the address they signed in with. The list of domains the site allows is never disclosed to them. The same sentence comes back from the API, so a refusal in the middle of an operation is not a silent 403.
* **An entry point drawn by a single sign-on plugin now looks like the page it is on.** The button such a plugin prints carries its own classes, which mean nothing here, and it landed as a bare link in the middle of the sign-in card. It is dressed by what the element is, so any provider's markup arrives looking right.

= 0.8.0 =
* **An upload no longer depends on how the server was built.** A HEIC photo is decoded on the device — by the browser, and where the browser cannot, by a decoder fetched only when such a photo appears — so a server whose image library was built without HEIC stops being a wall. The server conversion stays as the faster path where it exists.
* **A photo too big for one request is sliced, never made smaller.** On a host stuck at a low upload limit the photo used to lose quality, silently. Now the browser sends it in slices and puts it back together on the server, at the quality it had.
* **A modest server says why, instead of showing a blank page.** Decoding a large photo where memory and time are short could end the request outright. The plugin now asks for the head-room WordPress itself asks for, refuses a photo it knows it cannot handle with the numbers in view, and leaves nobody looking at a blank page.
* **Sign in through a single sign-on provider alone.** The alternative sign-in of the portfolio area accepts a shortcode as well as an address, which is what providers whose entry address expires need — every OAuth flow does — so the plugin serves any of them without knowing which. And the username and password form can be switched off, for a site that signs in through its provider only; with no provider configured the form is shown anyway, so the page is never left with no way in.
* **E-mail domains allowed in the portfolio area.** A list of domains, one per line, beside the roles that are already excluded there. Empty, which is the default, restricts nobody. With a list, only accounts whose e-mail ends in one of those domains get in — through the door, through the API, and in the list of people who can be named contributors. Administrators are never kept out.
* The settings cards are arranged in one column beside the plugin's own card, and a first visit finds them closed except the content terms and the permissions grid. Cards you have opened or closed yourself stay as you left them.

= 0.7.1 =
* **The address of the portfolio area can no longer be a word WordPress answers itself.** Named `admin`, `dashboard` or `login`, the area was never reached: WordPress redirects those three addresses to wp-admin or to its own sign-in before the plugin sees the request. The Addresses fields now refuse them and say why, keeping the address in use; a site that already had one of them goes back to its default word.

= 0.7.0 =
* **Back up every portfolio at once.** One file holding one backup per portfolio — each of them an ordinary backup — plus an index naming what is inside. Portfolios with no images are in it too, for their collections and their designations. Handed such a file, the restore says what it is and asks which portfolio to take out of it.
* **The same collection twice on one page.** The zone a gallery draws answers to the collection's name — that is how a screen reader lists it and jumps to it — and two galleries of one collection answered to the same name. The second now says which view it is, tiles or carousel; a page that does not repeat a collection is unchanged.

= 0.6.0 =
Backup and restore.

* **Back up a portfolio, or one collection, as a zip.** It holds the manifest, the master of every image and the originals that were kept — not the sizes the gallery derives, which are rebuilt when the backup is restored, so the file is about half the size. Videos hosted elsewhere travel as their address and their stored thumbnail.
* **Without personal data**, if you tick the box: the owner's name and e-mail, the address of whoever uploaded each image and the device file names are left out, and so is the list of contributors. Captions and observations stay.
* **The owner backs up their own portfolio** from the portfolio area, or one of its collections; a contributor does not. In wp-admin, two new permissions: one to back up any portfolio, one to restore.
* **Restore as a new portfolio, or into an existing one.** A restore never deletes anything: a collection whose address is taken gets a suffix, an image whose content is already in the collection is skipped, and there is no *replace*. A new portfolio is created inactive, so nothing reaches the public site before somebody has looked at it.
* **Read before written.** The file is checked entry by entry before a single byte is extracted, each file is verified against the hash the backup carries, the people with no account on this site are listed, and what would not fit the limits is refused with the numbers in view.
* The backup file lives in a private folder and is deleted from the server after a day; it is downloaded through a link that only works for whoever built it.
* The Tools card of wp-admin now separates its three tools, and the portfolio fields filter as they are typed instead of being lists to scroll.

= 0.5.0 =
Feature complete for a first release: everything described above works and is covered by tests. What it has not had yet is a run on real phones and tablets, screenshots, and use on a site other than the one it was built on — that is what stands between this and 1.0.0.

* **Portfolios, collections, images.** Personal portfolios created by their own users, assigned portfolios created by the site staff, collections that can be visible or hidden, images with caption, observation and capture time.
* **The portfolio area (p-admin).** The plugin's own sign-in page over the WordPress login, the content terms to accept before publishing, and the whole of a portfolio's administration on a page built for a phone first: uploads from the camera or the picker, folder drag-and-drop on a desktop, touch reorder, covers placed by dragging the picture.
* **Private storage.** Images live outside the Media Library, in a folder the plugin serves itself after checking who may see each one; the master and three derived sizes are recorded per image, camera metadata is stripped, and originals are kept only on request, under a name of their own.
* **Public pages.** An index of portfolios, a page presenting each portfolio with its collections as cards, and a gallery per collection as tiles or a carousel, with a lightbox, a search that filters as you type, and Open Graph tags for when an address is shared.
* **Three blocks and their shortcodes**, for showing a collection, the collections of a portfolio, or the descriptions of either, inside any page of the theme.
* **wp-admin.** The portfolios list with search, filters, sorting and the storage report; the editor with identification, state, owner, group, limits, contributors, suspension and deletion; permissions by role with a rule that stops a role granting more than it holds; the regeneration of the derived sizes in batches.
* **Limits at four levels** — site, portfolio, collection, contributor — for storage and number of images, where no level grants more than the level above it.
* **Privacy.** The personal data exporter and eraser of WordPress, the suggested privacy policy paragraphs, a last-activity record, and a retention rule that warns the owner a long time before deleting an unused personal portfolio and lets them keep it with one button.
* **Security.** Every REST route behind a permission callback, authorisation per object, 404 instead of 403 for what a visitor may not know about, a sign-in throttled per address and per address-and-username, uploads checked by content and by dimensions, and a sentinel that says in Settings whether the web server is handing out the private folder.
* **Videos hosted elsewhere.** A video from YouTube, Vimeo, Dailymotion or TikTok added by its address becomes an item of the collection beside the images, with its thumbnail stored locally and the player loaded only when a visitor presses play. A video on a network that answers no plugin — Instagram, Facebook, LinkedIn — is added as its address plus a picture chosen by whoever adds it, and its card opens in a new tab without that network ever being contacted.
* **Accessibility and languages.** Keyboard, screen readers, reduced motion and AA contrast; interface in English, Portuguese and Spanish, chosen independently of the WordPress language.
