=== Upload Multiple Media by API ===
Contributors: sandeepjainlive
Tags: rest api, media upload, multiple upload, api, headless wordpress
Requires at least: 5.0
Tested up to: 7.1
Requires PHP: 5.6
Stable tag: 1.6.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Upload multiple media files through the WordPress REST API with optional authentication, duplicate detection, detailed responses and upload limits.
== Video Tutorial ==

Learn how to upload multiple media files through the WordPress REST API:

https://www.youtube.com/watch?v=fQXgVQaLEF0

== REST API ==

POST /wp-json/mmbyapi/v1/upload-multiple-images

File field:
mmbyapi_file_upload[]

Optional field:
post_id
mmbyapi_alt_texts[]
== Features ==

* Optional authentication using WordPress authentication/Application Passwords.
* Backward-compatible public mode when authentication is disabled.
* Detailed per-file JSON responses.
* Duplicate detection using a content hash.
* Maximum files per request setting.
* Maximum individual file size setting.
* Allowed MIME type settings.
* Optional post attachment.
* Optional ALT text for each uploaded image.

== Use Cases ==

* Headless WordPress websites using Next.js, React, Vue or other frontend frameworks.
* iOS and Android applications that need to upload multiple media files to WordPress.
* React Native and other JavaScript-based applications communicating with WordPress through the REST API.
* Custom frontend applications that need programmatic multi-file media uploads.
* WooCommerce applications that need to upload product, gallery or supporting media through an API-driven workflow.
* Backend integrations, automation tools and custom services that need to send multiple media files to WordPress.
* Multisite and enterprise WordPress projects requiring controlled API-based media uploads.
* Content publishing workflows where uploaded media needs to be optionally attached to an existing WordPress post.
* AI-powered applications and external services that need to send generated images or supported media to WordPress.
* Decoupled WordPress architectures where WordPress acts as the CMS and media backend while the frontend is hosted separately.

== Authentication ==

Authentication is OFF by default for backward compatibility.

When enabled, the caller must be authenticated and have the WordPress upload_files capability.

Application Password example:

curl -i -u "USERNAME:APPLICATION_PASSWORD" \
  -F "mmbyapi_file_upload[]=@/path/to/image1.jpg" \
  -F "mmbyapi_file_upload[]=@/path/to/image2.jpg" \
  "https://example.com/wp-json/mmbyapi/v1/upload-multiple-images"

== Response ==

Successful uploads return attachment information including attachment ID, URL, MIME type, file size, image dimensions when available, ALT text, and a content hash.
Duplicate uploads return the existing attachment with `duplicate: true`.

If some files fail and others succeed, the endpoint returns HTTP 207 with per-file results.

== Duplicate detection ==

Duplicate detection is enabled by default. The plugin calculates a SHA-256 hash of each uploaded file and stores it as attachment metadata. Uploading identical file content returns the existing Media Library attachment instead of creating a second attachment. Renaming a file does not bypass duplicate detection.

== Compatibility fixes ==

The 1.6.0 settings allow-list correctly validates MIME types against WordPress MIME values. PNG, JPEG/JPG, GIF and WebP remain enabled by default. Duplicate detection also works when the same file is included more than once in a single API request.

== Changelog ==

= 1.6.1 =
* Added optional ALT text support for uploaded images.
* Added per-image ALT text support through the REST API.
* Included ALT text in per-file API responses.

= 1.6.0 =
* Added optional REST API authentication.
* Added admin settings page.
* Added upload_files capability check.
* Added detailed per-file API responses.
* Added duplicate detection using a content hash.
* Added maximum files per request setting.
* Added maximum file size setting.
* Added allowed MIME type settings.
* Added optional post_id support.
* Preserved the existing endpoint and field name.

= 1.5.1 =
* Fixed multiple-file handling for multipart/form-data requests.
* Improved upload error handling.
