=== glimana Publisher ===
Contributors: glimana
Tags: publishing, ai, content, scheduling
Requires at least: 5.9
Tested up to: 6.8
Requires PHP: 7.4
Stable tag: 1.6.0
License: GPLv2 or later

Receive articles written in glimana as drafts or scheduled posts.

== Description ==

Connects your site to glimana. Articles you approve in glimana arrive as drafts (recommended), pending review or scheduled posts.

Security:
* Only two REST endpoints (/glimana/v1/status and /glimana/v1/posts); both require an HMAC-SHA256 signature.
* Requests older than 5 minutes and reused nonces are rejected (replay protection).
* 10 invalid requests from an IP slow it down for 15 minutes (correctly signed requests always pass, so junk traffic cannot block publishing); at most 30 posts or updates per hour.
* Content is filtered with wp_kses_post; glimana cannot change settings and can only pick authors the admin allowed.
* Images (max 3, 1.5 MB each) are validated by content, re-encoded by the WordPress image editor and saved under a name the plugin chooses; arbitrary files cannot be uploaded.
* Immediate publishing is off by default.
* The connection secret is stored with autoload off and is never displayed again.

== Installation ==

1. Upload and activate the plugin.
2. In glimana open Settings → Publishing connections → Add WordPress site and copy the connection code (shown once).
3. In WordPress open Settings → glimana Publisher, paste the code, choose the post author and save.
4. Back in glimana click "Test connection".

== Changelog ==

= 1.6.0 =
* FAQPage structured data is no longer produced. Google retired the FAQ rich result in May 2026; the visible questions and answers stay in the post. The glimana_publisher_faq_schema filter no longer does anything, and FAQ data from older posts is left as it is.

= 1.5.0 =
* In-place update of posts glimana created: POST /posts?id= changes only title, content, excerpt, images, meta description and FAQ; the address, status, date, author and categories stay. The post id is part of the signed action.
* The invalid-request lockout no longer blocks correctly signed requests (behind a CDN many visitors can share one IP).
* An empty temporary file was left behind after each image import; it is now removed.

= 1.4.0 =
* Status lookup for glimana's archive: GET /posts?id= returns only id, status, URL and modified time of posts glimana created (never content). The post id is part of the signed action.

= 1.3.0 =

= 1.2.0 =
* Per-article author from an admin-defined allow-list (falls back to the default author).
* Stored connection code is shown masked (first and last characters) so you can see it is set.

= 1.1.1 =
* Endpoints are registered only after the site is connected; an unconfigured install exposes nothing.

= 1.1.0 =
* Article images: imported into the media library (type detected from content and re-encoded), cover set as featured image, alt text kept.

= 1.0.1 =
* Connection code field no longer triggers the browser password manager.

= 1.0.0 =
* First release.
