== Changelog ==

= 1.7.151 - 2026-09-11 =
* Resolved built-in Quick Sitemap descriptions through active Yoast, Rank Math, AIOSEO, or SEOPress metadata before WordPress excerpts and cleaned content.
* Preserved the public item filter, fixed 80-word and 200-token description budget, and separate 1000-token Content field.

= 1.7.150 - 2026-09-11 =
* Updated the public product description to explain how WordPress content and categories become a one-click hierarchical RAG Sitemap.
* Clarified that organized site growth keeps narrowing the retrieval path for lightweight models without embeddings, vector databases, or a GraphRAG indexing pipeline.

= 1.7.149 - 2026-09-09 =
* Changed the Floating Button default to disabled for fresh installs and missing settings across the frontend and Playground while preserving explicit saved settings.
* Rewrote and condensed the WordPress.org description to explain RAG Sitemap retrieval, Free and Premium boundaries, supported providers, local history, privacy, and source disclosures.

= 1.7.148 - 2026-09-08 =
* Corrected the Free README and Settings > Privacy suggestion to describe only the fixed local rate limit, 60-second HMAC transient, and redacted warning logs; removed Premium-only manual and temporary IP blocking claims.

= 1.7.147 - 2026-09-03 =
* Clarified the local dotLottie Web runtime license filename and reproducible build provenance.
* Restored execution-time limits from one finally block across success and failure paths.
* Hardened Basic Generator named-field admission and Quick Custom CSS final-candidate validation without changing their canonical behavior owners.

= 1.7.146 - 2026-09-01 =
* Preserved source identity when Pages and Posts share a category taxonomy, kept the primary legacy chunk path, and isolated only colliding secondary chunks.

= 1.7.145 - 2026-08-31 =
* Improve Quick Investigate handoff by preserving the base query and projecting one distinct refined query to subsequent RAG decisions.
* Apply the existing internal-route decision surface to every Quick mode, normalize witnessed Item and Category selections before fetch, and prevent successful Item or Subcategory routes from being selected again within the same request.
* Converge Category leaves in the same retrieval step and preserve valid public content while keeping internal RAG control lines out of the Final response context.

= 1.7.144 - 2026-08-31 =
* Decouple Quick Start's Default Language from Free Quick RAG artifact selection; Quick now reads only the Basic Generator's canonical `default/master-sitemap.txt` track and default cache while preserving chat language, Prompt language, custom uploads roots, and current-page fallback behavior.

= 1.7.143 - 2026-08-31 =
* Normalize a single witnessed Item to Recommend and a single witnessed Category to Deep Dive during the current decision, avoiding needless rescue, repeated Initial decisions, or selector-only hops while preserving mixed-selection, Investigate, allowlist, and bounded-navigation rules.

= 1.7.142 - 2026-08-31 =
* Restore Complete Quick's fixed Recommend, Deep Dive, and Investigate Main RAG reducer with four bounded navigation hops, witnessed-link enforcement, one calibrated rescue retry, last-valid convergence, and a single Final response owner.

= 1.7.141 - 2026-08-31 =
* Set Free Quick Final and browser history to named fixed six-turn policy constants and RAG history to a named fixed three-turn constant, while preserving complete-turn projection and raw-setting isolation.

= 1.7.140 - 2026-08-31 =
* Removed unused settings-shaped state and unreachable Free IP-block and Compacting remnants; Quick now expresses nonce, queue, thinking, SSE, and failover behavior at their runtime owners. Preserved the Preview pricing-plan mock example, fixed RAG budgets and provider behavior, and added regression and mutation guards for the Free and Premium boundary.

= 1.7.139 - 2026-08-31 =
* Remove the Quick RAG response profile selector and reject legacy or forged preset state while preserving the existing two-result runtime behavior.
* Retain the fixed 8,192-token BYOK request budget and the prior cleanup of inactive Quick Basic Chat and History Compacting paths.

= 1.7.137 - 2026-08-31 =
* Centralize Quick's conservative request budget to help AI API newcomers avoid unexpectedly high BYOK provider costs, without changing runtime behavior.

= 1.7.136 - 2026-08-31 =
* Remove an obsolete display-only Quick API card row without changing request budgeting.

= 1.7.135 - 2026-08-30 =
* Extend the configured Quick API credential placeholder from 12 to 36 fixed mask characters without exposing stored secret bytes or changing retain, replace, or remove semantics.

= 1.7.134 - 2026-08-30 =
* 已設定的 Quick API Key 恢復固定遮蔽顯示，未設定時維持空白；移除 configured／not configured 二元標籤，且真實 Key 仍不輸出至 HTML。

= 1.7.133 - 2026-08-30 =
* 將 Quick 瀏覽器 selection contract 對齊既有 Host v2，保留錯誤 owner 或 contract 在任何副作用前 reload 且不自動重送。

= 1.7.132 - 2026-08-30 =
* Upgraded the Host selector contract to v2 and kept Premium-unavailable requests fail-closed to Quick.
* Removed fresh-install legacy control-mode bytes and preserved existing legacy settings as inert migration input.

= 1.7.131 - 2026-08-29 =
* Make Quick API credentials write-only, preserve existing opaque secret bytes, and require explicit replace or allowed removal.
* Restrict the Quick save filter to owner-sanitized non-secret leaves without changing mode, Advanced data, routes, card identity, or unknown settings.
* Add the Neutral Host scalar secret contract used by both Quick and the separately installed Premium add-on.

= 1.7.130 - 2026-08-29 =
* Preserve the Trialware hardening and contextual pricing links while fixing the Free-only Quick Start browser/runtime warning discovered by the WordPress 7.1 matrix.

= 1.7.129 - 2026-08-29 =
* Clarify separately installed add-on ownership, remove outdated Trialware-related comments, preserve contextual pricing links, extend the existing Free boundary verifier against paid-lock controls, and retain all required disclosures within the 8,000-byte readme limit.

= 1.7.128 - 2026-08-29 =
* 將 core selector request keys 改為完整專案前綴，保持 browser 與 server 的 request-local owner 契約一致。

= 1.7.127 - 2026-08-28 =
* 將 Free 收斂為完整且自包含的 Quick Core，移除 Premium-only runtime、設定控制面與資產載入路徑。
* 保留 Quick 的公開聊天、固定基礎 RAG、Preview、Playground、Preset、Store、Assets 與 Main Sitemap 行為。
* 忽略既有 Premium API card 與 Advanced response 欄位，避免殘留資料改變 Free 執行策略。

= 1.7.126 - 2026-08-28 =
* Render persisted terminal errors with a transcript-owned DOM identity so Queue and temporary status replacement cannot remove them after reload.
* Record confirmed transient API failures once in Error History even when API Control suspension is disabled; enabling API Control still owns the single suspension write.

= 1.7.125 - 2026-08-27 =
* Return the canonical sanitized projection for Chatbot UX, Chatbot UI, and Floating Button UI saves so the shared writer receives an array instead of a pre-commit fatal null value.

= 1.7.124 - 2026-08-27 =
* Preserve one safe typed terminal error across reload and retry while removing failed user tails from model history.
* Propagate terminal Throwable failures to the existing route/API Control owner, including model-error records without suspension.
* Add per-language model-not-found defaults and old-settings fallback without a write-back migration.
* Admit shared preview components only on their owning DOM surfaces and return stable shared-settings save diagnostics.

= 1.7.123 - 2026-08-27 =
* Right-align the static Quick Start status on the Free Dashboard without changing the Premium mode control.

= 1.7.122 - 2026-08-27 =
* Replace the Quick Setup Default API Profile Enabled pill with the shared checked-route visual.
* Keep the Quick marker static and non-form-like while preserving the fixed route payload and Advanced route state.

= 1.7.121 - 2026-08-27 =
* Remove Free-owned commercial entitlement routing so Premium controls and runtime providers register only after Premium license and compatibility admission.
* Keep the Free Basic Generator fully functional with automatic section titles, fixed content budgets, Main/default output, and TXT generation.
* Prevent Free generation and reset flows from deleting Premium-owned Advanced Sitemap settings or artifacts.
* Remove disabled or hidden paid form controls from Free administration while retaining only limited contextual Premium pricing links.

= 1.7.116 - 2026-08-25 =
* Add the Premium plans and pricing link to the Free-only Upgrade page while retaining direct Freemius checkout.

= 1.7.115 - 2026-08-25 =
* Add a Free-only Dashboard link to the external Premium plans and pricing page.

= 1.7.114 - 2026-08-23 =
* Renamed the Free plugin folder, main file, translation domain, and WordPress.org lookup slug to ragsitemap-chatbot without changing runtime identifiers or stored data.

= 1.7.110 - 2026-08-23 =
* Use long-prefixed Custom CSS response identifiers while preserving the shared validation and zero-mutation failure contract.
* Refine Retry pulse theme state, preset carriers, and generated button design guidance without changing the theme schema.
* Preserve the scoped WordPress asset loading and quarantined Analysis removal completed after the last paired release metadata.

= 1.7.105 - 2026-08-22 =
* Remove the quarantined Analysis settings, instrumentation, log/CSV writer, repository, admin-page, and retention contracts from Free.
* Keep legacy raw Analysis settings inert without a migration, cleanup, compatibility shim, or replacement event pipeline.
* Preserve the existing Debug writer, `{session_id}.log` filenames, viewer actions, path checks, and 90-day `.log` retention.

= 1.7.104 - 2026-08-22 =
* Add one Free-owned, token-aware Custom CSS admission policy shared by settings, presets, previews, and runtime output.
* Keep invalid legacy CSS at rest while excluding it from runtime styles, and preserve the last approved unsaved preview stylesheet.
* Move the 13 executable raw script and style blocks into scoped first-party assets or WordPress inline-data/style APIs.

= 1.7.103 - 2026-08-22 =
* Derive the RAG Sitemap reader root and site-relative path from one WordPress uploads snapshot.
* Support default, custom, and site-specific uploads locations without moving existing generated files.
* Reject unavailable, unmatched, outside-root, and symlinked local paths while preserving HTTP fetching.

= 1.7.102 - 2026-08-22 =
* Allowlist and sanitize Basic Generator request fields before Free/Premium extension filters and actions run.
* Pass only tab-owned or Quick Setup schema output to Admin and Quick Start save hooks instead of raw request arrays.
* Preserve the existing Premium Quick exclusion fields, storage ownership, hook names, and Free-only behavior.

= 1.7.101 - 2026-08-22 =
* Remove the arbitrary preset request, depth, variable-count, value-size, top-level, and key restrictions added in 1.7.99 and 1.7.100.
* Keep only the JSON structure and scalar-value validation needed before the existing preset sanitization and option mutation flow.
* Restore complete Debug and Conversation log reads plus the pre-change session sanitization/list behavior while retaining canonical-root and symlink read protection.

= 1.7.100 - 2026-08-21 =
* Bound both preset request-body reads to 256 KiB plus one limit-detection byte before JSON validation.
* Reject oversized preset requests without reading the complete body or mutating existing options.
* Preserve valid Chatbot UI and Floating Button preset payloads, storage, and responses.

= 1.7.99 - 2026-08-21 =
* Bound custom Chatbot UI and Floating Button preset JSON by request size, nesting depth, field count, canonical keys, scalar values, and top-level schema before any option mutation.
* Centralize Debug and Conversation log reads in the Free LogStorage owner with strict session IDs, canonical realpath containment, symlink rejection, and a five-megabyte response limit.
* Preserve the existing preset wire shape, option names, local log viewer responses, and Free/Premium/Analysis ownership boundaries.

= 1.7.98 - 2026-08-21 =
* Use https://ragsitemap.com/en/ for the Free Author URI and local plugin-information URL defaults while retaining the plugin-specific Plugin URI.
* Keep plugin behavior, bundled runtime files, settings, and Free/Premium boundaries unchanged.

= 1.7.97 - 2026-08-21 =
* Update the author website to the verified RAG Sitemap brand domain.
* Replace three broken bundled-library source links with verified version-specific upstream URLs.
* Keep plugin behavior, bundled runtime files, settings, and Free/Premium boundaries unchanged.

= 1.7.96 - 2026-08-16 =
* Document Cloudflare dashboard, documentation, and provider URL-classification strings as non-executable links for WordPress.org review tooling.

= 1.7.95 - 2026-08-16 =
* Remove the unused Quick `schema_version`, legacy flat request aliases, and retired global class aliases while preserving the current nested settings contract.
* Remove obsolete Prompt placeholder and History raw-key cleanup paths while preserving the current checkpoint schema, history limits, and atomic browser commit.
* Keep Free Quick, Basic Generator, provider routing, and the Free/Premium/Analysis extension boundaries unchanged.

= 1.7.94 - 2026-08-16 =
* Resolve the public browser history window from normalized effective enabled routes instead of always adding Max Extra Turns.
* Keep Quick Start and Advanced all-off at the Final Response History Limit; retain Final plus Extra when any eligible route can run Compacting.
* Reuse one Free Effective Settings projector for frontend localization and the REST config response without changing the browser wire contract.

= 1.7.93 - 2026-08-16 =
* Run History Compacting once as a synchronous route-attempt gate before Vision, Clue Desk, RAG, Scuba and Final, with complete-history fail-open through the shared retry owner.
* Persist one untrusted versioned checkpoint through the winning JSON/SSE response and the Free atomic Browser Turn Gate writer; stale candidates cannot partially save an assistant response.
* Give every non-Final history consumer one RAG-limit projection, keep Final independent, and clamp saved/effective RAG history limits to Final without changing Embed Image Description in History.
* Remove active scope, fixed-threshold, deferred collect and system-summary injection paths while preserving Free-only and Premium Vision/Clue extension composition.

= 1.7.92 - 2026-08-16 =
* Stop mapping structured `mode` and legacy URL fields while preserving malformed label, keyword, URL, query, Unicode, nested-field, allowlist, and rescue behavior.
* Validate selected Initial and Mode system Prompt templates before save and render; unavailable templates make no provider call and no longer receive embedded or appended replacement Prompt text.
* Remove the retired `session_clue_desk_snapshot` admission special case without changing the current Dossier, logging, queue, Vision, or routing contracts.
* Make Free Generator Kernel constants the sole owner of fixed Basic 200/1000 budgets and remove the compatibility keys from every Basic settings shape.

= 1.7.91 - 2026-08-15 =
* Remove unreleased settings migrations, retired Admin aliases, Quick navigation redirects, browser aliases, and zero-caller helpers.
* Use only HMAC operational state, current launch models, canonical Sitemap artifacts, and current reasoning controls.
* Preserve current RAG prompts, Custom Manual Model, Clue Desk request quarantine, and Free/Premium/Analysis contracts.

= 1.7.90 - 2026-08-15 =
* Stop preserving retired Scuba Recommend mode and rule keys during Prompt saves.
* Remove three unused legacy Mode defaults and eight zero-caller reasoning compatibility constants.
* Keep Main RAG Recommend, Deep Dive, Investigate, provider capability lookup, and Quick behavior unchanged.

= 1.7.89 - 2026-08-15 =
* Consolidate all witnessed Main RAG Item selections into the always-available Recommend executor.
* Remove Strict mode, Strict prompt assets, and both Strict/Recommend Hop #0 availability settings.
* Reject unavailable model-selected modes without aliases or compatibility translation.

= 1.7.88 - 2026-08-15 =
* Consume optional request-local Lightweight Chat Mode regular-plugin projection counts from the Premium-owned MU runtime.
* Log only the canonical projected/original regular-plugin counts when both diagnostics are available.
* Remove request RAM, peak-memory, active-theme, and regular-plugin-name diagnostics that could be mistaken for a memory benchmark.

= 1.7.85 - 2026-08-13 =
* Add bounded recent conversation turns to Clue Desk Review through the existing current-route Chat API port.
* Respect the route Conversation History switch and RAG Pipeline History Limit, including zero as disabled.
* Keep Review before compacting so Final Response History Limit and compacted summaries do not change the decision lifecycle.

= 1.7.84 - 2026-08-13 =
* Use the selected language homepage as the Playground current URL while preserving the real browser URL on the public chatbot.
* Keep the existing RAG, Rescue, Reactive Fallback, Clue Desk, and Scuba behavior unchanged.

= 1.7.83 - 2026-08-13 =
* Apply the Clue Desk LIST filter at every canonical Main and Scuba Current Map selection boundary.
* Distinguish container navigation from leaf retrieval so a known child never removes an entire Category.
* Retry sibling routes through the existing bounded rescue and declare no-new-clue only after deterministic root exhaustion.

= 1.7.82 - 2026-08-12 =
* Accept Playground forced-language values only when they exactly match a configured effective language key.
* Fall back to the existing URL/default language resolver for malformed, unknown, or non-string client values.

= 1.7.81 - 2026-08-12 =
* Remove the retired original-query shadow variable left behind by the Clue Desk query-projection fix.
* Replay the logged PCB Vision turn in the missing-query regression verifier, including containment of the legacy malformed refinement.

= 1.7.80 - 2026-08-12 =
* Route validated Clue Desk `missing_clue_query` values through the existing Investigate `refined_query` state instead of replacing the RAG call query.
* Preserve the post-Vision `USER QUERY`, including uploaded-image descriptions, across Initial and shared Mode prompts.
* Reset refined-query state on every request and render at most one separate `REFINED USER QUERY` section.

= 1.7.79 - 2026-08-12 =
* Project each RAG call's selected query into the Initial and shared Mode user-message placeholders.
* Let validated Clue Desk `missing_clue_query` values reach retrieval while preserving the original request query for Final.

= 1.7.78 - 2026-08-11 =
* Replace the legacy Floating Button fallback with a fixed Default Dark baseline for clean installations.
* Centralize first-install, effective-setting, sanitizer, admin, and frontend defaults while keeping Modern Dark as an independent selectable preset.

= 1.7.77 - 2026-08-11 =
* Remove the Free Vision upgrade row's dashed top border and extra top padding while preserving both styles for Premium controls.

= 1.7.76 - 2026-08-11 =
* Document the conservative Quick request budget used to reduce unexpected BYOK provider costs for first-time AI API users.

= 1.7.75 - 2026-08-11 =
* Simplify the Free Default API Profile Vision upgrade affordance by removing the display-only primary and fallback selectors.

= 1.7.74 - 2026-08-11 =
* Add compatibility-registry contract v1 with named version sets for core and optional add-on contracts.
* Preserve the runtime 4, Clue Desk 2, Scuba Port 1, Generator 1, and Basic eligibility 1 contracts so the previous Premium remains compatible after updating Free first.

= 1.7.73 - 2026-08-11 =
* Rename the Clue Desk cross-turn request, response metadata, limits, and neutral runtime context contract from Snapshot to Dossier.
* Advance the shared server runtime contract to 4 and the Clue Desk runtime contract to 2 so incompatible Premium code stops before class loading.
* Drop the retired `session_clue_desk_snapshot` request field before full logging without parsing, translating, or forwarding it.

= 1.7.72 - 2026-08-10 =
* Restore prefix-preserving tail truncation for every RAG source inside the shared `AVAILABLE ITEMS` input-budget path.
* Snap recognizable RAG output back to the last complete unit boundary while retaining string-level tail truncation for unknown and single-unit fallback cases.
* Re-estimate the complete message payload after pruning without changing Desk Capacity, conversation-history removal, provider retry, or Premium lifecycle behavior.

= 1.7.71 - 2026-08-09 =
* Preserve the existing `1em` chat heading fallback without emitting undefined-index notices for incomplete UI settings.

= 1.7.70 - 2026-08-09 =
* Load the bundled dotLottie frontend runtime only when a configured Lottie floating-button asset will be rendered.
* Load the official DOMPurify 3.4.12 minified artifact while retaining its readable source and license in the package.
* Document line- and view-scoped Plugin Check prefix exceptions without changing public hooks, bootstrap symbols, or runtime behavior.

= 1.7.69 - 2026-08-09 =
* Standardize all Final provider default user-message templates on the canonical `{{query_section}}` placeholder.
* Retain legacy plain-query replacement support only for existing saved Custom Template compatibility.

= 1.7.68 - 2026-08-09 =
* Make clean installations use a fixed Default Dark chatbot appearance copied from the current Modern Dark values.
* Centralize activation, runtime, Live Preview, and reset defaults without loading the Modern Dark preset at runtime.
* Keep Default Dark and the selectable Modern Dark preset independent so each can evolve without changing the other.

= 1.7.67 - 2026-08-09 =
* Preserve Freemium schema 9 in every Admin settings save path after the Clue Desk migration.
* Add a regression assertion that rejects any Admin save path which writes an older schema version.
* Bundle the default bot and user avatar images used by clean installations.

= 1.7.66 - 2026-08-09 =
* Rename the optional paid pre-RAG evidence contract from Context Gate to Clue Desk across settings, runtime ports, provider review calls, request metadata, and canonical documentation.
* Add schema 9 migration to preserve the enabled state and capacity while retiring old feature and Prompt keys.
* Adopt Clue Cards, Desk Capacity, `missing_clue_query`, and the `reuse_clues`, `seek_more_clues`, and `set_clues_aside` decision contract without changing Free pipeline ownership.

= 1.7.65 - 2026-08-09 =
* Use the dedicated RAG Chatbot product page as the plugin URI and shorten the plugin description.

= 1.7.64 - 2026-08-09 =
* Use the plugin text domain for external add-on detail-link labels without changing link behavior.
* Document seven required, bounded Sitemap Generator query patterns with line-scoped Plugin Check exceptions without changing query behavior.

= 1.7.63 - 2026-08-08 =
* Redact Authorization, explicit credential fields, credential query parameters, known provider-key formats, and WordPress nonce values only in internal diagnostic copies.
* Preserve raw Exception data until retry, fallback, classification, and suspension TTL decisions finish; preserve HTTP status, RSC tokens, context, API card identities, and non-secret provider details in stored diagnostics.
* Keep public REST/SSE messages, provider requests, provider responses, route selection, and Analysis availability behavior unchanged, with focused Debug/API-history/suspension/conversation/CSV/export coverage.

= 1.7.62 - 2026-08-08 =
* Replace six whole-file PHPCS exception suppressions with narrowly scoped, documented line exceptions without changing runtime behavior.

= 1.7.61 - 2026-08-08 =
* Project exhausted-route failures through the existing localized error-message owner before they cross the public REST or SSE boundary.
* Keep raw exception text available to internal retry, suspension, and server logging without changing route selection, SSE framing, or terminal ownership.

= 1.7.60 - 2026-08-07 =
* Serialize accepted chatbot turns across same-origin browser pages through the native Web Locks API while preserving one canonical request, response, and history lifecycle.
* Admit only the Free-owned turn-gate extension contract and keep Premium limited to decorating the pending history save before the canonical writer runs.
* Preserve the existing single-page behavior when Web Locks are unavailable and release ownership after request, queue, history, reset, expiry, or page-close terminal states.
* Add browser regression coverage for simultaneous tabs, followers, queue retry, nonce retry, JSON, SSE, history failures, reset recovery, owner close, expiry, Free-only, and unsupported-browser paths.

= 1.7.59 - 2026-08-06 =
* Resolve the current request language through the existing Free language-label owner before calling the Premium Context Gate module.
* Keep raw language codes exclusively in request and Snapshot scope identity instead of exposing them through Prompt placeholders.

= 1.7.58 - 2026-08-06 =
* Admit the exact unversioned Context Gate Snapshot envelope without adding a parallel request or validation owner.

= 1.7.57 - 2026-08-06 =
* Dispatch valid Context Gate thinking through the existing Free `send_thinking_event()` owner after the complete decision contract is validated.
* Keep invalid and fail-open Gate results browser-silent so they do not create a second SSE owner or prematurely lock route failover.

= 1.7.56 - 2026-08-05 =
* Pass the explicit Context Gate identifier into the canonical AI JSON parser so valid provider responses can reach Premium schema validation.
* Carry only an internal allowlisted fail-open reason back to the Free lifecycle owner and log it without exposing Snapshot, Prompt, URL, or signature content.
* Log only the prepared Gate message count and system/user byte sizes so template assembly is observable without recording its content.
* Keep valid reuse, augment, and retrieve decisions on the unchanged three-state mapping.

= 1.7.55 - 2026-08-05 =
* Add neutral scope, admission, framing, route-attempt metadata, and browser lifecycle contracts for the Premium Context Gate module.
* Keep the Free Complete Core as the only request, RAG, Final assembly, provider payload, token budget, retry, JSON/SSE terminal, history, and browser-shell owner.
* Extend the canonical Final token budget with Snapshot-aware whole-item pruning and capture Available Items from the exact payload object sent by all three providers.
* Confirm the unique SSE `[DONE]`, assistant-history persistence result, and post-history extension lifecycle before a Premium browser adapter may commit a candidate.

= 1.7.54 - 2026-08-05 =
* Use the validated server `REMOTE_ADDR` as the canonical visitor rate-limit identity and ignore forwarded headers.
* Store automatic rate-limit and temporary-block state under site-salted HMAC fingerprints, with safe legacy transient migration.
* Make the optional extended temporary block reachable with bounded rejection timestamps and preserve the latest shared block expiry.
* Remove visitor identifiers from rate-limit and temporary-block logs and document local IP handling.

= 1.7.49 - 2026-08-01 =
* Add an explicit value-based Scuba RAG step/rescue Port owned by the canonical Free handler.
* Return search journey, hop stack, current hop, and rescue count updates without crossing the product boundary by PHP reference.
* Add regression guards that reject by-reference methods in generic Premium runtime adapter manifests.

= 1.7.48 - 2026-07-29 =
* Add a neutral Basic eligibility contract for paid Quick policy projection, bounded deny IDs, and final writer vetoes.
* Apply one status, password, and deny policy across Basic planning, counts, queries, summaries, and chunk output.
* Preserve the Free-only published and password-free baseline while ignoring forged paid Checkbox fields.

= 1.7.47 - 2026-07-28 =
* Clarify the common purpose and trigger for configured AI provider requests while retaining one shared provider policy list.
* Remove Premium Vision image and file transmission wording from the Free External Services disclosure.
* Narrow the suggested Privacy Policy text to actual Free AI requests, optional Google Fonts and remote media browser requests, and local logging.

= 1.7.46 - 2026-07-28 =
* Let WordPress.org remain the sole source for Free plugin details, ratings, reviews, downloads, and active-install data.
* Keep the local product-information registry empty by default and reject the Free WordPress.org slug defensively.
* Limit separately hosted add-on details to their own changelog and remove all local review statistics and fallback tabs.

= 1.7.45 - 2026-07-28 =
* Use the WordPress default text domain explicitly for core plugin-detail and review labels.
* Align the public readme release window and version metadata with the WordPress.org submission checks.

= 1.7.44 - 2026-07-28 =
* Scope every Free Basic Generator post, count, summary, and taxonomy query to the translation plugin's primary language.
* Keep sites without a translation plugin on the unchanged WordPress query path.
* Add executable none/WPML/Polylang regression coverage for the canonical Main/default Sitemap track.

= 1.7.42 - 2026-07-27 =
* Store local logs under the WordPress uploads base directory at the plugin-specific `rag-sitemap-chatbot/logs` path.
* Keep Premium Debug Log viewing, downloading, clearing, and complete provider diagnostics on the shared canonical storage contract.
* Remove obsolete plugin-directory log migration and root-level legacy log lookup for the new-plugin storage baseline.

= 1.7.41 - 2026-07-27 =
* Restore full request diagnostics to their original visible level when Debug Logs are enabled.
* Make Debug Logs include debug, info, warning, and error entries by default so detailed RAG traces are not silently filtered.

= 1.7.40 - 2026-07-27 =
* Add centralized UTF-8 fallbacks for hosts without mbstring or iconv while preserving native behavior when those extensions are available.
* Repair Apache and IIS log-directory protection files before writes without changing diagnostic content.
* Document the validated Basic Generator empty-directory cleanup for WordPress Plugin Check.
* Synchronize the WordPress.org Stable tag with the released plugin version.

= 1.7.39 - 2026-07-27 =
* Remove the retired Cloudflare Gemma 3 model from selectable API card dropdowns while preserving existing cards through the Custom representation.

= 1.7.38 - 2026-07-27 =
* Match the Floating Button Lottie preview width to the button container instead of deriving it from Lottie Height.
* Use the same Lottie component creation path after reload and after selecting a file.

= 1.7.36 - 2026-07-27 =
* Give every new API card an immutable generated ID used by storage, routing, ordering, status, and runtime lookup.
* Store the editable API Keys tab title separately as `display_name`, preserving capitalization, spaces, and localized text.
* Keep routing selections stable when an API card display name changes.

= 1.7.34 - 2026-07-26 =
* Add Google Gemini 3.6 Flash and Gemini 3.5 Flash Lite in the documented Google model order.
* Use human-readable Google model labels and model-specific Auto Lowest thinking levels.
* Omit deprecated sampling parameters for Google Gemini 3.6 Flash, 3.5 Flash, and 3.5 Flash Lite payloads.

= 1.7.33 - 2026-07-26 =
* Remove the heading underlines from Generate the Sitemap and Choose content sources in the Basic Generator.
* Remove the top padding and divider above Choose content sources while preserving its 28px spacing.

= 1.7.32 - 2026-07-26 =
* Display the Quick Start RAG Sitemap tab title in red in its normal, hover, and active states.

= 1.7.31 - 2026-07-26 =
* Add the canonical model-scoped capability strategy for the Cerebras `gemma-4-31b` Image Inputs public preview.
* Keep all other Cerebras, Google, gateway, and OpenAI-compatible Vision payload strategies unchanged.

= 1.7.30 - 2026-07-26 =
* Change the Traditional Chinese Vision-failure model instruction to the canonical English prompt.
* Migrate only the unchanged legacy Chinese default while preserving administrator-customized prompt text.

= 1.7.29 - 2026-07-26 =
* Prevent collapsed required API Key fields from silently blocking API card saves through native browser validation.
* Route Quick Start and Advanced required-field failures through the shared visible validation flow, which expands the card, highlights and focuses the field, and reports the error beside Save.

= 1.7.28 - 2026-07-26 =
* Rename the Quick Start submenu page title and menu label to Quick Start Setting.
* Keep the Quick Start page slug, internal heading, control mode, and add-on ordering unchanged.

= 1.7.27 - 2026-07-26 =
* Add a locked Free Quick Start upgrade affordance for excluding specific Sitemap content.
* Explain that Premium can exclude selected posts, pages, categories, and taxonomy terms without adding Free form fields.

= 1.7.26 - 2026-07-26 =
* Simplify the Quick request-budget explanation for first-time AI API users.
* Remove the obsolete display-only token input and runtime note.

= 1.7.25 - 2026-07-26 =
* Embed the Free Basic RAG Sitemap Generator as a real Quick Start tab.
* Keep the standalone RAG Sitemap submenu only in effective Advanced mode.
* Redirect the former Quick-mode Generator URL to the embedded tab without mixing Quick Start and Generator save payloads.

= 1.7.24 - 2026-07-26 =
* Preserve the Floating Button image aspect ratio in the shared admin preview after saving and reloading.
* Match the preview image sizing model to Playground and frontend rendering.

= 1.7.23 - 2026-07-26 =
* Rename the Direct Sitemap routing option to Skip RAG API.
* Clarify that this mode sends the filtered RAG Sitemap directly to the RAG Chat API.

= 1.7.22 - 2026-07-26 =
* Fix Quick/Basic content-source ordering to always show and generate Page first, Post second, then other public sources.
* Normalize older saved source arrays to the same canonical order.

= 1.7.21 - 2026-07-26 =
* Add a divider above the first Premium Quick Sitemap exclusion control.
* Keep the second exclusion control in the same visual group without another divider.

= 1.7.20 - 2026-07-26 =
* Move the two Quick Sitemap exclusion controls behind neutral Premium extension hooks.
* Keep Free Quick exclusions empty and ignore forged exclusion fields while retaining the standard taxonomy tree.
* Let licensed Premium Quick project paid exclusions into the shared Basic Generator.

= 1.7.19 - 2026-07-26 =
* Remove Automatic section title inputs from Quick/Basic content-source cards.
* Ignore submitted, stored, or filtered `custom_titles` and always use standard automatic headings.
* Leave Premium Advanced Sitemap controls and runtime unchanged.

= 1.7.18 - 2026-07-26 =
* Remove Content length settings and token-limit inputs from the Quick/Basic Sitemap Generator.
* Ignore submitted or previously stored Quick content budgets and enforce the fixed 200/1,000 defaults.
* Leave Premium Advanced Sitemap controls and runtime unchanged.

= 1.7.17 - 2026-07-26 =
* Restore the pre-split standard taxonomy tree in the Free Basic Generator.
* Generate top-level category and nested subcategory chunks with `Rag_Category_Link` progressive retrieval.
* Restore standard section-title and post/term exclusion controls without enabling Custom Master Sitemap.
* Preserve direct item chunks and basic WooCommerce price output inside the standard Quick path.
* Keep Custom Master Sitemap, custom packages/branches, multilingual output, Output Field, and JSON-LD exclusive to Premium Advanced.

= 1.7.16 - 2026-07-26 =
* Remove the border from the Basic Generator's Generate panel.
* Leave the Premium Advanced Sitemap module and its controls unchanged.

= 1.7.15 - 2026-07-26 =
* Add a divider above Choose content sources in the Basic Generator.
* Leave the Premium Advanced Sitemap module and its controls unchanged.

= 1.7.14 - 2026-07-26 =
* Remove the divider above Exclude specific content in the Basic Generator.
* Replace the Content length settings frame and background with a single divider above the section.
* Leave the Premium Advanced Sitemap module and its controls unchanged.

= 1.7.13 - 2026-07-26 =
* Put the Basic Generator's primary Generate action first.
* Remove the numbered step badges from the Basic Generator.
* Keep Content length settings visible instead of placing them in a disclosure control.
* Leave the Premium Advanced Sitemap module and its controls unchanged.

= 1.7.12 - 2026-07-25 =
* Make the Free Basic Generator TXT-only and stop publishing `master-sitemap.json`.
* Rename the Basic output action from View TXT to View RAG Sitemap.
* Remove legacy Basic JSON staging/status UI and delete a stale default JSON artifact on the next Basic generation or reset.
* Keep Premium Advanced JSON/JSON-LD ownership unchanged.

= 1.7.11 - 2026-07-25 =
* Normalize Basic Sitemap site identity, post titles, excerpts, and content as plain text before TXT/JSON publication.
* Decode HTML5 named entities and bounded double-encoded entities such as `&amp;#039;` without leaving entity text in generated artifacts.
* Add regression coverage for Site, Page, Description, and JSON item output.

= 1.7.8 - 2026-07-25 =
* Synchronized the WordPress.org Stable tag and bundled public changelog with the Free plugin's existing 1.7.8 header and runtime version constant.
* This metadata correction adds no settings migration and does not change runtime behavior.
* Changed the Plugins-screen and local plugin-information developer display name from Mark to RAG Sitemap, linked to `https://ragsitemap.com/`.

= 1.7.7 - 2026-07-25 =
* Added a local Plugins-screen details link and WordPress plugin-information response sourced from the bundled readme.
* Exposed the Free Description, Installation, FAQ, Changelog, Screenshots, and Reviews sections without inventing rating counts.
* Added product and Mark author website metadata to the installed plugin row.
* Added a neutral add-on product-information registry so independently installed add-ons can expose only their own sections.

= 1.7.0 - 2026-07-25 =
* Split RAG Sitemap into a Free Generator Kernel/Main-only Basic Generator and a versioned Premium Advanced module slot.
* Keep the Free `rag-map-config` menu and common batch dispatcher canonical.
* Remove multilingual, custom master/package/branch, Output Field, JSON-LD, and Site Excerpt implementation from the Free package.

= 1.6.14 - 2026-07-25 =

* Fixed: Quick Start no longer clears the displayed Vision API selection after save when Vision and RAG Chat reference the same API card.
* Storage: The shared `profile_default_api.vision` value remains the canonical source and is projected back into the explicit Quick Start Vision selector.
* Regression: Covered the Vision selector reload mapping in the Freemium boundary verification.

= 1.6.13 - 2026-07-25 =

* UX: Reordered existing and newly added Cloudflare Quick Start cards to Model, Account ID, then API Key.
* Compliance: Kept the conditional Terms and License row immediately after Model while aligning the primary field order with Advanced.

= 1.6.12 - 2026-07-25 =

* UX: Replaced the old Cloudflare credential hints with direct Workers AI dashboard paths for copying the Account ID and creating/copying a Workers AI API Token.
* Parity: Added the same linked instructions to existing and newly added Cloudflare cards in Quick Start and Advanced.

= 1.6.11 - 2026-07-25 =

* Changed: Restored `@cf/openai/gpt-oss-20b` as a selectable Cloudflare-hosted model.
* Ordering: Placed `gpt-oss-20b` between `kimi-k2.6` and `gpt-oss-120b` in the Cloudflare dropdown.

= 1.6.10 - 2026-07-25 =

* Changed: Reordered the selectable Cloudflare-hosted model catalog to the curated product sequence.
* Compatibility: Moved `@cf/openai/gpt-oss-20b` to `legacy_supported`; it is hidden from new dropdown selections while existing cards retain the exact outbound ID through Custom.

= 1.6.9 - 2026-07-25 =

* New: Added `@cf/ibm-granite/granite-4.0-h-micro` as a Cloudflare-hosted text-generation and function-calling preset.
* New: Added `@cf/nvidia/nemotron-3-120b-a12b` as a Cloudflare-hosted text-generation, function-calling, and reasoning preset.
* Policy: Granite is text-only without a reasoning control; Nemotron is text-only and uses `chat_template_kwargs.enable_thinking`, with Auto Lowest disabling thinking.
* Compliance: A Terms and License page link alone does not create a required checkbox; neither new model was added to the exact `5016` agreement registry.

= 1.6.8 - 2026-07-25 =

* Changed: Cloudflare API-card dropdowns now expose only models marked Cloudflare-hosted in Cloudflare's official filtered catalog.
* UX: Added a Quick Start and Advanced model-row notice explaining that Workers AI free allocation applies only to Cloudflare-hosted models, with a link to the official filtered catalog.
* Compatibility: Retained `openai/gpt-5-nano`, `openai/gpt-5.4-nano`, and `google/gemini-3.1-flash-lite` in the permanent model ledger as non-selectable legacy entries so existing cards remain editable through Custom.

= 1.6.7 - 2026-07-25 =

* Fix: Moved Cloudflare model Terms and License synchronization into the shared admin-script scope so Quick Start and Advanced model changes no longer raise a JavaScript ReferenceError.
* UX: Added a browser alert plus the existing inline validation state when a selected model requires acknowledgement and the checkbox is not accepted.
* Fix: Restored the Terms and License row after selecting either exact registered Llama 3.2 model, including after a previous save or a switch from a model that does not require acknowledgement.
* Policy: Continued to source required acknowledgement exclusively from the exact model-terms registry; unrelated Cloudflare and Custom models do not show the checkbox.

= 1.6.6 - 2026-07-23 =

* Architecture: Defined Free Core as the stable assembly foundation rather than the owner of paid implementations.
* Architecture: Added explicit Vision and Scuba module interfaces plus complete pre-registration method/property capability manifests.
* Architecture: Premium blocks attach through named versioned slots without replacing Free handlers, REST, storage, provider payload, transport, SSE, or RAG-step owners.
* Reliability: Added independent one-block-at-a-time assembly coverage for Advanced Projection, Route Orchestration, Vision, and Scuba.
* Parity: Added executable comparison against the pre-split working baseline covering artifacts, 91 hooks, 5 REST routes, PHP methods, browser responsibilities, prompts, and module isolation.
* Compatibility: Runtime extension contract version 3 pairs Free 1.6.6 with Premium 0.3.5; no pre-release compatibility alias or migration shim is provided.

= 1.6.5 - 2026-07-23 =

* Architecture: Free now always instantiates its canonical OpenAI-compatible, Google-native, or Claude-native handler.
* Architecture: Added a request-local neutral runtime context and independent Vision/Scuba module providers; optional modules no longer subclass or replace provider handlers.
* Reliability: An unavailable or incompatible Premium module now fails closed at its own port without changing the base Chat/RAG class or route.
* Test: Added all-provider composition, disabled-module, by-reference state, helper-call, incompatible-contract, and cross-provider loading coverage.
* Compatibility: Runtime extension contract version 2 requires Free 1.6.5 with Premium 0.3.4; no pre-release alias or migration shim is provided.

= 1.6.4 - 2026-07-23 =

* Fix: Avoided `wp_unschedule_hook()` and cron-option rewrites when the Debug enabled state and duration are unchanged during an API Setting save.
* Security: Removed complete Advanced settings and API-card payloads from browser console logging.
* Test: Added provider-family isolation and disabled Premium runtime boundary coverage as part of the extraction regression repair.

= 1.6.3 - 2026-07-23 =

* Fix: Isolated admin component initialization so an unavailable optional UI dependency cannot disable API card actions, settings tabs, or Quick Start and Advanced save handlers.
* Fix: Initialized critical settings-page controls before optional editors and preview helpers.
* Security: Added POST fallbacks to all shared settings forms so a JavaScript failure cannot place API settings or key fields in the request URL or trigger a 414 response.
* Test: Added regression checks for POST form fallbacks, protected critical-control boot order, and the browser-ready marker.

= 1.6.2 - 2026-07-23 =

* Fix: Keep Quick Start selected after the Dashboard mode switch reloads.
* Fix: Ignore stale browser-restored radio state instead of treating it as a new mode-change request that writes Advanced back to storage.

= 1.6.1 - 2026-07-23 =

* Fix: Prevented Cloudflare model-license controls from terminating the admin page before Add API, Routing, and footer scripts could render.
* Compatibility: Replaced the unavailable `required()` template helper with a WordPress 5.8-compatible literal HTML attribute.

= 1.6.0 - 2026-07-22 =

* Architecture: Added versioned settings-projection, route-orchestration, handler-adapter, pre/post-RAG enrichment, RAG post-processing, prompt-source, and browser-extension contracts.
* Changed: Free now executes exactly one selected Chat/RAG route while retaining admission, queueing, payload builders, provider transport, retry, SSE, RAG rescue, and Direct Sitemap degradation.
* Changed: Moved configured route/API-card fallback sequencing and Advanced raw-to-effective projection into Premium.
* Changed: Moved uploaded-image Vision, RAG-context image URL scanning, Vision prompts/payload policy, and browser attachment processing into Premium.
* Changed: Moved Scuba Diving prompts, decision loop, and post-RAG runtime into Premium without duplicating the Free provider or RAG pipeline.
* Compatibility: No legacy alias or database migration shim was introduced for the new runtime contracts.

= 1.5.33 - 2026-07-22 =

* New: Added verified Cloudflare presets for `openai/gpt-5-nano`, `openai/gpt-5.4-nano`, `google/gemini-3.1-flash-lite`, and `@cf/meta/llama-3.1-8b-instruct-fp8`.
* Changed: Isolated the new publisher-prefixed Cloudflare models from OpenAI/Google native controls while retaining the shared Chat Completions transport.

= 1.5.32 - 2026-07-22 =

* New: Added `@cf/meta/llama-3.2-11b-vision-instruct` to the selectable Cloudflare model catalog.
* Changed: Cloudflare dropdown labels now omit the `@cf/<publisher>/` prefix while preserving exact outbound model IDs.

= 1.5.31 - 2026-07-22 =

* Changed: Removed pre-release `ApiCardSchema` model-terms compatibility constants so `ApiModelTermsRegistry` remains the only model-terms source.

= 1.5.30 - 2026-07-22 =

* New: Added `ApiModelTermsRegistry` as the single exact model-ID source for license URLs, required acknowledgement, and provider agreement transport.
* New: Added exact agreement policy for Cloudflare Llama 3.2 3B and 11B Vision model IDs.
* Changed: Quick Start, Advanced, server save validation, and Cloudflare runtime now consume the same model terms registry.
* Security: Cloudflare `5016` handling now fails closed for unknown or non-exact model IDs and never sends `prompt=agree` without a registered policy plus explicit administrator acceptance.

= 1.5.29 - 2026-07-22 =

* New: Added a required Terms and License checkbox with the official Meta Llama 3.2 license link to Cloudflare API cards in Quick Start and Advanced settings.
* Security: Added server-side consent validation and prevented the Cloudflare Llama 3.2 agreement request from running unless an administrator explicitly accepted the license.

= 1.5.28 - 2026-07-22 =

* Changed: Moved Google Sheets synchronization settings, consent-facing UI, Apps Script instructions, and remote POST runtime to the separate Analysis add-on.
* Changed: Reduced the Free `conversation_log` schema to local logging and CSV export only.
* New: Added a provider-neutral completed-conversation CSV row hook for independently installed export add-ons.

= 1.5.27 - 2026-07-22 =

* New: Added a WordPress.org-compliant readme with external-service disclosures, privacy guidance, and bundled-source references.
* New: Added this standalone changelog for detailed release notes.
* Fix: Preserved Advanced route order and enabled-route selection when Quick Start settings are saved.
* Tweak: Kept the shared Quick Start profile protected from removal while allowing Advanced settings to control its position and enabled state.
