=== BBA Secure File Downloads ===
Contributors: sofrustrate
Tags: downloads, secure download, file download, media library, shortcode
Requires at least: 5.8
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.0.9
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Serve Media Library files through a controlled download endpoint, and place download buttons anywhere with a shortcode.

== Description ==
BBA Secure File Downloads lets you select files from the Media Library and generate a stable File ID for each file. Then you can place a download button anywhere using:

[bbasfd_download id="FILE_ID"]

The download is served through a controlled endpoint instead of exposing the direct file URL.

Looking for the PRO version?
https://bigbad.agency/portfolio/wordpress-plugins/secure-file-downloads-for-wordpress/

== Installation ==
1. Upload the plugin folder to /wp-content/plugins/ or install via Plugins.
2. Activate the plugin.
3. Go to Secure Downloads → Files and add your files.
4. Copy the shortcode and paste it into a page/post.

== Usage ==
Shortcode:
* [bbasfd_download id="FILE_ID"]
Optional:
* text="Get the free plugin"
* class="my-css-class"

== FAQ ==
= How many secure files can I create on the free version? =
Unlimited. The free version does not cap the number of secure File IDs you can create. PRO does not "unlock more files" — instead it adds analytics (who downloaded what, and when), per-file password protection, and per-file download limits (cap the number of times a specific file can be downloaded).

= Does it work with Elementor? =
Yes. Use Elementor’s Shortcode widget with the [bbasfd_download] shortcode.

= Where can I get the PRO version? =
You can learn more about the PRO version here:
https://bigbad.agency/portfolio/wordpress-plugins/secure-file-downloads-for-wordpress/

== Screenshots ==
1. The Files screen — pick any file already in your Media Library, get a stable numeric File ID and a ready-to-copy shortcode.
2. Settings — set the default download button text used when a shortcode does not specify its own.
3. The built-in "How It Works" guide explains the security model and what the optional Pro add-on adds (download analytics, password protection, per-file download limits).
4. The shortcode renders a download link on the front end; the real /wp-content/uploads/ file URL never appears in your page HTML.

== Changelog ==

= 1.0.9 - 2026-07-23 =
* Fix: the built-in "How to Use" help page showed the wrong shortcode ([secure_download]); it now correctly shows [bbasfd_download].
* New: added "Getting Started" and "How It Works" help pages in the admin so first-time setup and the security model are documented in-plugin.
* Change: removed the unused "Default link expiry" setting, which described a capability the current product does not ship.
* Docs: corrected the FAQ (the free version has never capped the number of files) and added screenshot captions.

= 1.0.8 - 2026-05-21 =
* Compatibility bump. Re-verified against current WordPress release.
* Raised Requires PHP floor to 7.4 (PHP 7.0-7.3 are EOL).
* No functional changes.

= 1.0.7 =
* Security: Validate the download nonce before touching any other request input.
* Security: Add clear permission hooks for download authorization.
* Compliance: Document raw/binary output in the download endpoint for scanners.

= 1.0.2 =
* Fix: Plugin Check compliance (admin enqueue without direct $_GET access, readme headers).


= 1.0.1 =
* Fix: add nonce to download links and validate in handler.
* Fix: use WP_Filesystem for file reads (Plugin Check compliance).
* Fix: wp_unslash() before sanitization for request values.
* Fix: translators comment for placeholder strings.
* Meta: bump Tested up to.

= 1.0.0 =
* Initial release: Files UI, Settings, How to Use, Help/About, shortcode, and secure download endpoint.
