=== Circumflex Booking development changelog ===

== 1.6.0 ==

* Show an aggregate room-availability heatmap for the filtered location and room set, using yellow from 70 percent occupancy, red only when full, hatching elapsed time, and finding the best remaining period without meeting details.
* Distinguish rooms free for an entire selected period from point-in-time heatmap capacity, including an explicit explanation when staggered reservations leave no single room free throughout.
* Add compact meeting-length quick choices with longer options under “More”, while keeping the editable end time primary and preserving the chosen length when start time changes.
* Give authenticated room-booking users a private, read-only list of their next 50 active bookings, resolved only from the verified booking session and without customer data or internal identifiers in the response.
* Make every room selection action visually consistent and keep the room timeline limited to actual available, occupied and otherwise unavailable periods.
* Add exact from/to room booking, including off-grid times such as 10:33–17:22, with unchanged access, duration, buffer and conflict checks.
* Show duration-independent room availability timelines and text equivalents, without exposing meeting details.
* Match the room-finder design with compact theme-independent typography, a responsive search row, inline facilities, quiet advanced controls and clear room/time selection.
* Combine meeting-room discovery into one location-aware availability finder with browser-local home and favorites, known-room search, exact-time alternatives and a single confirmation form.
* Prefill bounded authenticated contact defaults without exposing authorization claims or storing contact details in browser preferences; retain server-side access, consent and verification checks.
* Resume the original protected booking automatically after compatible Pro sign-in, with a correlated cross-tab signal and a manual fallback that stores no booking data in the browser.
* Replace the unstyled protected-booking controls with a responsive, accessible access panel and hide it once access is granted.
* Add the opt-in API 17 resource catalog capability for compatible booking domains.
* Preserve physical resource identities while storing optional capacity, facilities and location atomically.
* Add shared-definition administration with explicit archiving, stale-edit checks and public booking entrance definitions.
* Enforce capacity, AND-facility and location requirements across tailored public pages and authoritative booking transactions.
* Add opt-in API 18 minute-precise resource duration independent of start steps, with explicit whole-day windows.
* Add API 19 consecutive daily sessions with atomic reservation, whole-booking changes and cancellation, and complete daily agreements in customer/admin views, email and exports.
* Extend portable configuration to format 10, retaining earlier formats and preserving newer local facts and time limits on legacy imports.
* Add schema 16 without rewriting legacy bookings, including an indexed authenticated-owner lookup, and fail closed when a required domain capability or database upgrade is unavailable.

== 1.5.19 ==

* State clearly on the final review screen that the request has not been sent and name the profile-specific submit action required to finish.
* Reflow the review summary from two columns to one based on the booking component's own width and prevent ordinary labels from breaking inside words.
* Split customer messages, notification delivery and email templates into skimmable settings cards, with templates collapsed until needed.
* Move service-specific buffers and deadlines into an advanced section whose collapsed summary shows the effective values, while opening the section before native validation focuses an invalid field.
* Keep Core's default profile behind a deliberate, confirmed return control after an add-on profile has been selected, without turning a temporary fallback into a permanent profile change.

== 1.5.18 ==

* Add an explicit customer-facing practitioner order with drag-and-drop and accessible move controls.
* Keep first-available grouping and automatic assignment in their existing fairness order.
* Include practitioner order in portable configuration and migrate existing sites without changing bookings or availability.
* Bundle the complete maintained Norwegian PHP and JavaScript runtime catalogs in the WordPress.org archive and fail release validation on untranslated or fuzzy Core messages.
* Translate plugin-list descriptions without mixed English and Airspace wording.

== 1.5.17 ==

* Let the secure customer portal use profile-specific wording while keeping the standard appointments profile unchanged.
* Keep Airspace email previews and linked Pro screens free of treatment-domain example wording.

== 1.5.16 ==

* Let administrators choose whether the standard appointments profile accepts one service or one or more services per booking, while add-on profiles such as Airspace retain their own rule.

== 1.5.15 ==

* Make the administrative day/week capacity layer independent of a selected service and remove the confusing service selector from the calendar.
* Add a prominent Calendar for filter that shows every practitioner or resource by default and narrows bookings, free capacity and controlled public availability together.
* Present unreserved schedule periods as available capacity while keeping service duration and buffers authoritative in the actual booking flow.

== 1.5.14 ==

* Replace the administrative calendar's chronological cards with an ordinary day/week time grid and one track per practitioner or resource.
* Keep bookings visually primary while showing continuous publicly bookable periods and Pro-controlled public-availability holds as distinct background layers.
* Add daily-overview and all-details presets, hide rejected and cancelled records by default, remember each user's day/week/month choice, and keep month view booking-only.

== 1.5.13 ==

* Keep bookings across all services together in the administrative calendar while using an automatically selected active service only to calculate bookable time.
* Replace repeated start cards with continuous publicly bookable time ranges that already respect duration, buffers, reservations, and Pro controlled public availability.

== 1.5.12 ==

* Combine bookings and selected-service availability in the administrative calendar, keep Pro-held starts visibly available only internally, and prefill manual booking from a real open slot.

== 1.5.11 ==

* Replace visible notification event identifiers in settings and queue history with localized, profile-aware labels while preserving the stable internal keys.

== 1.5.10 ==

* Add extension API 16 so validated booking profiles can apply one bounded terminology document to explicitly registered extension text domains.
* Validate and limit registered domains while always retaining Core's own translation boundary and safe fallback behavior.

== 1.5.9 ==

* Hide inactive services, practitioners and schedule rules by default, with a URL-preserved control to reveal and manage them.
* Count and search deleted-service booking snapshots without requiring a current catalog row, and flag detached history before rescheduling.
* Preserve inactive unassigned practitioners in configuration export, serialize related catalog writes, and expand integrity checks for every logical relationship.

== 1.5.8 ==

* Keep booking and resource administration readable when deleting an obsolete service leaves inactive practitioners or exercise areas without assignments.
* Block service deletion when an active practitioner would lose its final assignment, and reject reactivation until a replacement service is assigned.
* Revise affected practitioner rows during service deletion so stale administration forms cannot overwrite the detached assignment state.

== 1.5.7 ==

* Make the optional inclusive end date independent of whether a date rule applies to one practitioner or every practitioner.
* Preserve existing individual one-day rules during the additive schema-10 migration, and treat an individual period as upcoming until its final date has passed.

== 1.5.6 ==

* Let either a closed or extra-open date rule apply to every practitioner or exercise area for one inclusive date period.
* Preserve existing shared closures as closed rules during the additive schema-9 migration, and keep closed time authoritative when shared rules overlap.

== 1.5.5 ==

* Move shared closures into the date-exception editor below the weekly schedule, where administrators can apply one closed rule to the selected practitioner or every practitioner.
* Retain the optional inclusive end date for all-practitioner closures and keep individual extra-opening rules unchanged.

== 1.5.4 ==

* Prefer the maintained bundled Norwegian catalog in manual installations, including network-activated multisite plugins and sites with an older global language pack.

== 1.5.3 ==

* Let administrators close one inclusive date period across every practitioner or exercise area with one shared rule, either for whole days or for the same time range on every date.
* Preserve existing one-day shared closures during the additive schema-8 migration, and list a period as upcoming until its final date has passed.

== 1.5.2 ==

* Add extension API 15 with an opt-in, profile-owned uppercase-code input policy, including browser constraints, normalization and matching server validation.
* Preserve the existing public payload and participant behavior for the appointments profile and every field that does not explicitly enable a policy.
* Add a separate self-contained ZIP for manual clean-site installations, with the maintained Norwegian PHP and JavaScript runtime catalogs bundled while the WordPress.org archive remains language-pack based.
* Let administrators close a whole day or time range across every practitioner or exercise area with one shared rule, while retaining existing bookings for explicit review.

== 1.5.1 ==

* Add extension API 14 presentation controls so a vertical add-on can disable resource recommendations and next-start prompts, opt into a neutral exact-availability strip and replace time guidance with one direct question.
* Preserve the API 13 resource-overview presentation as the backward-compatible default for other add-ons.

== 1.5.0 ==

* Add extension API 13 with a bounded date–service–resource–time public workflow for vertical add-ons while Core retains authoritative availability, conflict checks and submission.
* Accept a same-origin, aggregate-only resource overview for recommendation context and fail safely back to exact available times when that optional aggregate cannot be loaded.

== 1.4.3 ==

* Let administrators drag weekly schedule periods into a clear display order, with accessible move buttons as a keyboard and no-JavaScript alternative.
* Add complete, reversible profile-recommended email templates for review before settings are saved, and omit empty optional detail rows from plain-text and HTML messages.
* Add extension API 12 so separately installed vertical profiles can provide bounded administration terminology without forking Core.
* Include protected WordPress email verification in Core Free while keeping SMS delivery and automatic confirmation in compatible external/Pro add-ons.
* Let administrators permanently delete inactive services and unused practitioners/resources while retaining immutable booking history and preventing deletion when resource history still depends on the record.
* Let administrators permanently remove inactive weekly periods and date exceptions after an explicit confirmation.
* Make it configurable whether the complete buffered interval must fit opening hours; when disabled, the session must fit while its full same-date buffer continues to block conflicts.

== 1.4.2 ==

* Adapt the public date picker to the configured booking window: show times directly for today-only booking, compact date cards for two to seven days, and the full calendar for longer windows.
* Allow a zero-day booking horizon when a site should offer appointments only on the current date.

== 1.4.1 ==

* Make dashboard links for all-time booking totals open the all-bookings view while keeping operational shortcuts focused on their intended time ranges.

== 1.4.0 ==

* Add extension API 10 with a site-wide catalog and explicit selector for validated booking profiles, including safe fallback when a selected add-on is unavailable.
* Add an optional participant identifier across booking storage, administration, search, CSV, notification context and WordPress privacy handling.
* Add a provider-neutral, protected contact-verification proof lifecycle for compatible add-ons; Circumflex Booking Free includes no SMS transport, settings or provider.
* Keep profile changes separate from services, resources, opening hours and existing bookings, and expose effective profile state in local diagnostics.
* Hide ended bookings by default in the administration, with upcoming, past and all views based on each booking's end time.

== 1.3.5 ==

* Hide past date exceptions by default while retaining them in dedicated past and all views.
* Sort date exceptions chronologically, with the newest past exception shown first and an optional date-order toggle.

== 1.3.4 ==

* Improve plain-language guidance across booking, customer self-service, administration, notifications, privacy, and diagnostics in English and Norwegian.
* Clarify that a month with no bookable appointments has no available times.

== 1.3.3 ==

* Shorten the start-time guidance in public booking and customer changes to plain language.

== 1.3.2 ==

* Present sliding booking choices as start times instead of calendar blocks, while keeping the complete appointment interval and availability state in each accessible name.
* Explain that an unavailable start may overlap an earlier reservation and is not itself evidence of a reservation covering the displayed appointment range.

== 1.3.1 ==

* Treat every add-on-held start as a complete reservation interval and make all overlapping public choices unavailable under the same rules as a real booking.
* Expose bounded treatment and buffer dimensions through extension API 8 so compatible add-ons can preserve their target and minimum after overlaps.

== 1.3.0 ==

* Add a versioned, customer-data-free public availability policy for compatible add-ons.
* Restrict add-on output to a validated subset of starts that Core calculated as available, and fail open if an extension fails or returns invalid data.
* Apply held public starts to both availability responses and the locked booking submission path without creating bookings or reservation rows.
* Keep administration and customer change flows on the actual calendar.

== 1.2.10 ==

* Keep advanced privacy, retention, and public-booking protection settings compact while showing their saved values.
* Preserve native browser validation by opening every containing settings or email-template panel before focus moves to an invalid field.

== 1.2.9 ==

* Keep the customer receipt visible while publishing a customer-data-free `booking-received=1` virtual receipt URL after successful public submissions.
* Emit one PII-free `circumflex_booking_received` data-layer event per accepted submission for exact GA4/GTM measurement without loading an analytics service.
* Restore the receipt without repeating the conversion event, remove direct or stale success markers, and let the customer start another booking with fresh configuration.

== 1.2.8 ==

* Add bounded practitioner-editor hooks for compatible add-ons.
* Expose only internal and opaque practitioner identifiers, and isolate extension failures from ordinary practitioner management.
* Add a committed public-booking event that exposes only the initial status and technical practitioner identifiers.

== 1.2.7 ==

* Add a bounded booking-overview status hook for compatible add-ons.
* Expose only the booking ID, status, and row version, and isolate extension failures from the ordinary booking list.

== 1.2.6 ==

* Add a bounded booking-detail action hook for compatible add-ons.
* Expose only the booking ID, status, practitioner ID, and row version; add-ons must re-authorize submitted actions and load current state themselves.
* Isolate extension rendering failures so the ordinary booking actions remain available.

== 1.2.5 ==

* Let compatible add-ons add settings to the service editor without changing the free plugin's manual-approval default.
* Let a fail-closed add-on policy choose a pending or confirmed initial status from the complete locked service selection.
* Persist automatic confirmation, reservations, audit history, customer and staff confirmations, and reminders in the original booking transaction.
* Show customers a status-specific receipt instead of review wording after an automatically confirmed booking.

== 1.2.4 ==

* Send explicit browser, proxy, and LiteSpeed no-cache signals for public availability responses while retaining the bounded 60-second WordPress transient.
* Keep every Circumflex Booking REST route, including separately installed add-on routes in the shared namespace, out of LiteSpeed's page cache.

== 1.2.3 ==

* Retain the release-aware booking asset URL when LiteSpeed's query-string removal is enabled.
* Apply the no-optimization marker to the external booking bundle rather than its inline translation data.

== 1.2.2 ==

* Omit hidden service durations from the public catalog, availability summaries, and booking receipts while preserving server-side scheduling calculations.
* Exclude the public booking bundle from LiteSpeed rewriting and combine the plugin release with the build hash in public asset versions.
* Default to hiding minutes in the browser unless the current server response explicitly makes a valid duration public.

== 1.2.1 ==

* Preserve visible treatment minutes for existing services across the schema upgrade on every supported database.

== 1.2.0 ==

* Add a bounded, customer-data-free milestone API for optional booking-flow statistics in separately installed add-ons.
* Keep extension configuration small, isolate extension failures, and load add-on assets only where the public booking form is rendered.
* Return reliably to the top of each booking step in mobile Chrome while retaining accessible focus behavior.
* Let administrators show or hide each service's treatment minutes without changing availability calculations.

== 1.1.2 ==

* Keep the public privacy-policy link visible and underlined when host themes define conflicting normal, visited, hover, active, or focus link colors.
* Add a hostile-theme browser regression for the contact step on desktop and mobile.
* Let compatible add-ons show and enforce their phone-number guidance before the public review step.

== 1.1.1 ==

* Add a stable, PII-free notification extension API for separately installed channel add-ons.
* Add progressive administration hooks for per-action notification channel choices.

== 1.1.0 ==

* Add configurable, object-scoped approval and rejection of assigned booking and time-change requests for linked practitioners.
* Add four editable practitioner decision email templates, manager-decision notifications, and self-notification suppression.
* Add practitioner readiness guidance, a versioned least-privilege capability, configuration format 3, and security regression coverage.
* Explain every non-obvious booking setting and link the public consent step to the privacy policy page selected in WordPress.
* Make every dashboard setup step reflect active booking readiness and show the exact next action when incomplete.
* De-emphasize completed configuration, show Turnstile success only when fully configured and active, and explain how to publish the booking form on a normal WordPress page.
* Label the distinct top-level administration menu "CF Booking" while retaining the full product name elsewhere.

== 1.0.2 ==

* Sanitize administrative request values when they are acquired and protect the pattern with a regression test.
* Confirm that every shipped feature is available without a license key or payment.
* Prepare WordPress.org language-pack delivery by excluding generated locale files from the release ZIP while retaining the translation template.
* Label the distinct top-level administration menu "CF Booking" while retaining the full product name elsewhere.

== 1.0.1 ==

* Clarify that MySQL 8.0 and MariaDB 10.11 are the tested and supported production baseline, not a database-version activation check.
* Report older database versions as a warning while keeping the plugin active.

== 1.0.0 ==

* First stable release of the customer booking, availability, manual approval, administration, and secure self-service workflows.
* Include responsive email notifications, configurable site identity, reminders, privacy tools, anti-spam controls, and Norwegian translation.
* Support shortcode, dynamic Gutenberg block, and optional Elementor embedding on WordPress 6.8+ with PHP 8.3+.

== 1.0.0-rc.9 ==

* Add a configurable email-header identity with safe WordPress site-title and hostname fallbacks instead of the plugin product name.
* Separate business cancellation from customer self-cancellation so each customer email has accurate terminology and its own editable template.
* Export the new setting in configuration format 2 while retaining backward-compatible format 1 imports.

== 1.0.0-rc.8 ==

* Clarify booking and cancellation deadline labels and contextual help without changing minute-based storage or configuration contracts.
* Prepare the public source, unique plugin URL, WordPress.org metadata, privacy disclosures, screenshots, and reproducible build instructions.
* Preserve the bundled Norwegian translation while keeping all source strings ready for WordPress language packs.

== 1.0.0-rc.7 ==

* Show minimum booking notice and cancellation deadline in decimal hours while preserving the existing minute-based storage and configuration contracts.
* Replace the editable service sort number with a complete drag-and-drop service order and accessible move-button fallback.
* Append new services predictably and protect complete reordering with capability, nonce, row locking, optimistic concurrency, audit, and cache invalidation.

== 1.0.0-rc.6 ==

* Give all twelve customer and internal notifications one responsive, accessible HTML design using the site identity and configured booking color.
* Preserve safe editable text templates and include their exact rendered content as PHPMailer's plain-text alternative.
* Add a sandboxed visual preview, plain-text preview, multipart test send, and complete all twelve event choices in administration.

== 1.0.0-rc.5 ==

* Dispatch the bounded notification worker through a signed, non-blocking same-site endpoint so email does not wait behind unrelated WP-Cron work.
* Keep the request-unique cron event and five-minute worker as durable fallbacks, clearing only the matching event after a successful direct start.
* Record the worker source in the PII-free heartbeat and test that the direct loopback completes while WordPress' shared cron lock is held.

== 1.0.0-rc.4 ==

* Refresh WordPress' request-local cron option caches at shutdown before deciding whether a consumed immediate event must be re-armed.
* Schedule the request event even when loopback cron is disabled, retaining server cron and the five-minute recovery worker.
* Extend the isolated regression with a stale autoloaded cron-cache reproduction.

== 1.0.0-rc.3 ==

* Give each enqueue request a non-sensitive unique cron argument so a notification cannot coalesce with another request's in-flight single event.
* Re-arm the request-owned event at shutdown if another loopback consumed it before the newly committed row became visible.
* Add a process-isolated regression for cross-request event ownership and shutdown re-arming.

== 1.0.0-rc.2 ==

* Trigger immediately due notification work through a non-blocking WordPress cron loopback while retaining the five-minute recovery worker.
* Preserve customer-receipt and internal-submission notices when a booking is reviewed before the first queue run, with stable event ordering.
* Clarify the internal notification template as a historical received event.

== 1.0.0-rc.1 ==

* Add a six-case WordPress/PHP/MySQL/MariaDB compatibility gate, deterministic release packaging, checksums, and a dependency/license/source trace.
* Add upgrade, backup/restore, concurrency, DST, realistic-volume performance, and full current-platform regression gates.
* Extend browser accessibility through contact, review, and optional Turnstile submission, and isolate pressed-state colors from theme overrides.

== 0.11.0-beta.1 ==

* Add WordPress privacy export/erasure, bounded automatic anonymization, retention controls, and privacy Site Health monitoring.
* Add optional fail-closed Cloudflare Turnstile, filtered CSV with spreadsheet-formula protection, and versioned configuration preview/import/export.
* Add scoped dashboard distributions, local diagnostics without personal data, queue pause, global customer-token revocation, and explicit permanent-uninstall cleanup.

== 0.10.0-beta.1 ==

* Add one shared renderer behind the shortcode, a dynamic Block API v3 Gutenberg block, and a conditionally registered Elementor widget.
* Add accessible adaptive color pairs, keyboard focus management, non-color states, and calendar/list date views.
* Improve theme isolation, responsive layouts, reduced-motion and forced-color behavior, plus handle-specific JavaScript translations.

== 0.9.0-alpha.1 ==

* Add private purpose-bound customer links for side-effect-free booking viewing, self-service cancellation, and one pending time-change proposal.
* Add customer change availability that keeps the original reservation while a proposed slot is held for manual approval.
* Add administration approval/rejection, customer and internal notifications, same-origin mutation protection, token rotation, and isolated end-to-end coverage.

== 0.8.0-alpha.1 ==

* Add editable plain-text notification templates, strict placeholders, synthetic previews, and test email delivery.
* Add a bounded idempotent email queue with five-minute cron processing, explicit retry policy, unknown-delivery protection, administration, and Site Health diagnostics.
* Add configurable version-bound reminders that are cancelled and rescheduled when relevant booking state changes.

== 0.7.0-alpha.1 ==

* Add bounded day, week, and month administration calendars plus server-side booking filters and stable pagination.
* Add explicit desktop drag-and-drop confirmation with mobile/keyboard fallback, object scope, optimistic concurrency, and fresh conflict checks.
* Add scoped operational dashboard counters, upcoming bookings, and quick links for blocks and extra availability.

== 0.6.0-alpha.1 ==

* Add an object-scoped booking list and detail view with explicit approval, rejection, cancellation, completion, and no-show actions.
* Add confirmed manual bookings, safe schedule changes, service/practitioner changes, and five-minute duration overrides with mandatory conflict checks.
* Add separately authorized internal notes, explicit audited terminal-status correction, optimistic concurrency, and transactional customer events.

== 0.5.0-alpha.1 ==

* Add a responsive, translatable `[circumflex_booking]` customer flow with conditional practitioner choice.
* Add gray unavailable times, strict public REST contracts, atomic pending bookings, service snapshots, and reservations.
* Add protected anti-spam counters, pending limits, honeypot and form-timing controls, readable references, and transactional outbox events.

== 0.4.0-alpha.1 ==

* Add weekly schedules, closures, extra-open dates, manual blocks, and a generated-time debugger.
* Add DST-aware slot generation, multi-service buffers, booking windows, and cached public availability.
* Add deterministic first-available allocation with stable transactional locking and schema version 3.

== 0.3.0-alpha.1 ==

* Add native, responsive administration for services, practitioners, and global booking settings.
* Add least-privilege Booking Manager and Practitioner roles with versioned capabilities.
* Add inherited service defaults, optimistic edit protection, transactional audit events, and schema version 2.

== 0.2.0-alpha.1 ==

* Add versioned InnoDB schema, integrity inspection, guarded reset, and data-preserving lifecycle behavior.
* Add transaction, resource-lock, reservation, status, time, service aggregation, and secure token primitives.
* Add database and domain test coverage, including real concurrent reservation verification.

== 0.1.0-alpha.1 ==

* Add the plugin bootstrap, requirement checks, Norwegian language pack, and admin status page.
* Add local build, test, and quality tooling.
