=== Studix Course Connector ===
Contributors: maorcdx
Tags: woocommerce, lms, online courses, course access, mailing list
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 2.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Sell Studix courses in WooCommerce: a paid order opens the course for the buyer, and forms add leads to Studix mailing lists.

== Description ==

[Studix](https://studix.co.il) is a platform for selling and teaching online courses, developed and operated by [Cloudix](https://cdx.co.il). This is its official WooCommerce connector: it links a WooCommerce shop to your Studix account, so a course sold in the shop opens by itself.

**When somebody buys a linked product:**

* Studix opens the course for the buyer's email address. A new buyer gets a student account; somebody who already studies with you gets the course added to the account they have.
* Studix emails the buyer how to sign in. The plugin sends no email of its own.
* A note on the order says the course was opened, or says why it was not.
* Each order line is handled once, however many times WooCommerce reports the payment, so the buyer gets one welcome email.

**Also included:**

* **Access length per product** — lifetime, one year, 90, 30 or 7 days.
* **Refunds** — a fully refunded or cancelled order closes the course again (optional).
* **Mailing lists, with consent** — link a product to a Studix mailing list and checkout shows a marketing checkbox. Only buyers who tick it are added. Works on both the classic and the block checkout.
* **Sign-up forms** — a `[studix_form id="1"]` shortcode that adds visitors to a Studix mailing list, protected against bots and floods.
* **Elementor Pro forms** — a "Studix mailing list" action for Actions After Submit.
* **Activity log** — every course opened or closed and every sign-up, with a "Try again" button for anything that failed.
* **Connection test** — checks the key before you save it, and tells you which permission is missing, if any.
* Compatible with WooCommerce High-Performance Order Storage (HPOS) and the block checkout.

You need a Studix account with at least one course, and an API key created in Studix under API keys.

== External services ==

This plugin connects to the Studix API at `https://studix.co.il/api`, run by Studix, the platform your courses are hosted on. It cannot work without it: opening a course and adding someone to a mailing list both happen in Studix.

What is sent, and when:

* **When an order is paid** (or marked Completed, if you choose that): the buyer's billing email, first and last name and phone, and the id of the Studix course the product is linked to.
* **When a fully refunded or cancelled order had opened a course**: the Studix student id and course id, so the course can be closed.
* **When a buyer ticked the marketing checkbox, or somebody submits a Studix sign-up form or an Elementor form using the Studix action**: the email, and the name and phone if given, and the tags you set.
* **On the plugin's admin screens**: your API key and secret, to list your courses and mailing lists and to test the connection.

Every request carries your API key and secret. Nothing is sent to any other service.

* Studix terms of use: https://studix.co.il/p/terms
* Studix privacy policy: https://studix.co.il/p/privacy-policy

== Installation ==

1. Install and activate the plugin. WooCommerce is needed for selling courses; the sign-up forms work without it.
2. In Studix, open **API keys** and create a key with the permissions **Read**, **Manage course access** and **Manage mailing lists**. Copy the key and the secret — Studix shows the secret only once.
3. In WordPress, open **Studix → Connection**, paste both, click **Test connection**, and save.
4. Open **Studix → Course links** and choose which product opens which course, and for how long.
5. Place a test order. The order note says the course was opened, and the buyer receives the Studix welcome email.

The full guide, with screenshots: https://studix.co.il/api-docs#woo-install

== Frequently Asked Questions ==

= Does the buyer need to create an account in Studix? =

No. Studix creates the student account from the order's billing email and emails the buyer how to sign in. A buyer who already has one keeps it.

= When exactly does the course open? =

By default, as soon as WooCommerce records the payment. If you take bank transfers or want to check orders first, choose "Only when I mark the order Completed" on the Connection screen.

= An order was paid but the course did not open. What now? =

Open the order: a note says why (for example, a key without the "Manage course access" permission). Fix the cause, then click **Try again** in **Studix → Activity log**, or choose **Open the Studix course again** in the order's actions.

= Are buyers added to my mailing list automatically? =

Only if you link the product to a list **and** the buyer ticks the marketing checkbox at checkout. The box is never ticked in advance.

= Is my API secret shown anywhere? =

No. It is never printed back on the settings screen, and the optional debug log records only which call was made and its status code. It is stored in your site's database; to keep it out of the database, define it in wp-config.php instead: `define( 'STUDIX_CC_API_SECRET', '...' );`

= What personal data does the plugin keep? =

The activity log records the email of each buyer and sign-up, and the name and phone only while a failed call waits for **Try again**. Successful rows are deleted after 90 days and the rest after a year. The log is included in WordPress's **Tools → Export Personal Data** and **Erase Personal Data**.

= Can a sign-up form be flooded? =

Each visitor can submit a form five times in ten minutes, and each form accepts at most 60 sign-ups an hour from everybody together (change it with the `studix_cc_form_hourly_limit` filter). A hidden field turns away most bots. Somebody who unsubscribed is not added back by a form.

= I used version 1.x. Do I need to set anything up again? =

No. Your key, product links, forms and Elementor mappings are moved over when you update, and pages using the old `[scc_form]` shortcode keep working.

== Screenshots ==

1. The connection screen: your Studix API key, and when a course opens.
2. Course links: which product opens which course, for how long, and an optional mailing list.
3. The activity log: every course opened or closed, and every buyer added to a list.

== Changelog ==

= 2.0.1 =
A security review against the OWASP Top 10.

* Fixed: a failed "close the course" after a refund had no Try again, and the retry handler would have opened the course instead of closing it.
* Fixed: a refund of a line opened by version 1.x was skipped without a note; it is now written to the order and the log.
* Fixed: a refund no longer closes a course the buyer also holds through another paid order, or bought directly in Studix.
* Fixed: requests to Studix no longer follow redirects, which would have sent the API secret to the new address, and only https is accepted.
* Fixed: sign-up forms now have a per-form hourly limit, count an IPv6 visitor by network, and do not re-add somebody who unsubscribed.
* Fixed: the Elementor action accepts only your own Studix lists, and shows them only to administrators.
* Fixed: the debug log no longer records subscriber email addresses.
* New: the activity log is included in WordPress's personal data export and erasure, and old rows are removed automatically.
* New: the API secret can be defined in wp-config.php as STUDIX_CC_API_SECRET.
* Fixed: uninstalling on a multisite network removes the API key and secret from every site.

= 2.0.0 =
* Rebuilt for the WordPress.org plugin directory: English strings with a Hebrew translation, escaping and nonces throughout, prepared queries, prefixed names.
* Fixed: an order was processed twice, opening the course twice and sending the buyer two welcome emails.
* Fixed: an order with an empty buyer name was refused, so the buyer paid and got no course.
* Fixed: buyers were never added to the mailing list; they are now added, but only with the new marketing checkbox ticked.
* Fixed: the API secret was written to the PHP error log on every request.
* Fixed: sign-up forms showed no fields and never submitted.
* Fixed: the site crashed when WooCommerce was switched off.
* New: close the course on a full refund or cancellation.
* New: the connection test checks the key's permissions before you save it.
* New: "Try again" in the activity log and "Open the Studix course again" on the order.
* New: HPOS and block checkout compatibility.

= 1.0.0 =
* First release.

== Upgrade Notice ==

= 2.0.1 =
Security and privacy fixes from an OWASP Top 10 review. Recommended for everyone.

= 2.0.0 =
Fixes duplicate welcome emails and buyers left without a course. Your settings and links are carried over.
