=== MentorKit LMS: earlier releases ===

See readme.txt for the current release.

= 1.33.0 =

* Added: MentorKit LMS → Logs (Beta) for site administrators, with publishing attempt timelines, time-limited debug logging and the `wp mklms logs` command.
* Added: LMS Managers and Editors can set the language a user's emails are sent in.
* Added: webhooks accept a custom signing secret and course results include their completion time.
* Changed: redesigned course and group analytics.
* Changed: the front-end admin bar is hidden for signed-in learners. A setting under Styles & assets turns this off.
* Changed: Editors and LMS Managers manage accounts on the MentorKit Users screen and can no longer open the core Users screens.
* Removed: hiding WordPress core update notices from non-administrators, and copying WooCommerce Shop Manager capabilities to Editors.
* Security: stricter permission checks on enrollments, group settings and quizzes, safer webhook and callback requests, and logs that no longer store personal data or credentials.

= 1.32.0 =

* Added: group leaders can be set to lead every group on the site, including new groups, without wp-admin access.
* Fixed: SCORM uploads and imports reject unsafe archives, and saved certificate templates keep non-ASCII text.

= 1.31.0 =

* Added: a documented helper for custom sites to link a learner straight to their course certificate.

= 1.30.0 =

* Added: course titles set in the LMS stay locked when MentorKit Creator republishes a course.
* Fixed: registration links no longer enroll people into inactive or closed B2B customer groups.

= 1.29.1 =

* Changed: group CSV exports use separate first and last name columns. Imports also accept localized headers and the legacy Name column.
* Fixed: background imports recheck permissions, prevent concurrent processing and resume from saved progress. Quoted CSV fields and Norwegian import messages are supported.

= 1.29.0 =

* Changed: personal messages use ordinary paragraphs and appear below the accept link in pending invitations. Saved templates are updated once.
* Fixed: dark theme profiles keep frontend dashboard text, inputs and controls readable.

= 1.28.0 =

* Fixed: course and group tab links work with Ask AI disabled and wait for the editor to load.
* Fixed: frontend buttons, including login buttons, show a visible keyboard focus outline.

= 1.27.4 =

* Fixed: successful Creator publish callbacks now return the saved course title so Linked Integrations and Publish History reflect renamed courses.
* Fixed: Free builds resolve dependencies for the declared PHP 8.3 minimum, preventing activation failures on PHP 8.4.1.
* Fixed: reopening the hidden setup wizard no longer triggers a PHP deprecation notice for a missing page title.

= 1.27.3 =

* Fixed: Creator course updates now report an error and preserve the existing package when WordPress cannot save the supplied title.
* Fixed: course and group URL bases save correctly from WordPress Settings > Permalinks and refresh rewrite rules immediately.
* Fixed: course completion and enrollment recalculate progress in every enrolled group containing the course.
* Added: administrators can reset course attempts from participant profiles. Resets clear stale browser progress, stop open players from restoring it, and recalculate affected group progress.
* Reorganized source folders while preserving installed plugin names.

= 1.27.2 =

* Fixed: course and group editor tabs wait until their click handler is ready, so an early Settings click is not lost.
* Fixed: deleting a WordPress account now removes its MentorKit progress, certificates, quiz attempts and answers, activity, manual-completion history, and recipient invitations.
* Multisite membership removal preserves learning history; actual account deletion cleans every site's tables. Other learners' records and administrator attribution remain intact.

= 1.27.1 =

* Fixed: filtering users by group now includes actual group members, including those without cached course access.

= 1.27.0 =

* Unified course, group, and main settings layouts with loading skeletons, clearer navigation, and reliable section links.
* Moved course package information into one settings card.
* Course product settings now follow the access mode, show current WooCommerce prices and tax class, and support creating or linking a product.
* Added separate Unlink and Delete product actions. Unlink preserves the product; Delete moves an unshared product to Trash.
* Product, course, and quiz selection uses searchable dropdowns with keyboard navigation and menus that remain visible outside settings cards.
* Fixed WooCommerce product links for drafts, discounted price labels, purchase availability, and per-seat pricing on group purchase buttons.
* Group customer settings respond to access changes, and release announcements can appear in the archive without opening a modal.
* Strengthened permission checks for related content, product changes, package publication, and quiz grading.
* Updated external-service disclosures and WordPress compatibility metadata.

= 1.26.0 =

* Fixed: turning off self-registration now also removes the "Create Account" link from the login page.
* Added per-pull-request preview environments for internal development; no change to the plugin package.

= 1.25.0 =

* Fixed: accepting an invitation applies all of its access grants together and rolls them back if acceptance fails.

= 1.24.1 =

* Fixed the course and group editor tabs so they remain below the visible WordPress admin bar in fullscreen and realign with the admin menu after fullscreen closes.

= 1.24.0 =
* The leader of the issuing group can now open a participant's group certificate, scoped to members actually enrolled in it. Course certificates are unchanged.

= 1.23.0 =

* Added the `mklms_invoice_route_enabled` filter so integrations can disable the built-in invoice route without depending on hook priority.
* Course Creators can connect MentorKit Course Creator and publish new, owned, or assigned courses without receiving global LMS manager access.
* Package lists and publishing-job status are restricted to courses and jobs available to the connected Course Creator.
* Removed redundant WordPress core file loads from the authenticated WooCommerce and Astra installer actions.

= 1.22.1 =

* Removed third-party admin notice suppression.

= 1.22.0 =

* Invitations now provision the account at invite time, in a dormant state with no role or course access until activation.
* "Forgot password" activates an invited account with a branded set-password email instead of a dead end.
* Expired invitations offer sign-in, password reset, and a self-service revival of the expired invitation.
* Invitation and welcome emails carry a durable login link instead of the consumed one-time link.
* Invited, never-activated accounts stay out of member counts, seat maths, rosters, pickers, and exports, and are removed 7 days after the invitation expires.
* Upgrading links existing open invitations to provisioned accounts without sending mail or breaking already-sent links.
* Group invitations warn when the invited domain looks like a one-letter typo of the group's common domain.

= 1.21.0 =

* Standardized plugin-owned globals, hooks, shortcodes, admin routes, stored options, and browser objects under the `mklms`/`MKLMS` prefix and removed the deprecated shortcode aliases.
* Routed plugin styles and scripts through the WordPress asset APIs and tightened escaping at renderer boundaries.
* Delegated frontend authentication and password-reset sessions to WordPress core while preserving the themed learner flow.
* Reworked analytics access scoping so final database queries bind structured values through `$wpdb->prepare()` instead of interpolating SQL fragments.
* Made output-buffer closures explicit for static analysis and removed the retired theming callback path flagged in the previous package.

= 1.20.0 =

* Rebuilt global and group settings around the unified settings pane, including theming and webhook management.
* Removed the retired theming Settings API renderer and its string-only callback guard.
* Added shared-group ownership controls and tightened group-leader data scoping.
* Improved WordPress interoperability for authentication, asset loading, and static-analysis checks.
* Restored automatic certificate issuance and fixed several settings, routing, and access-control regressions.
* Added prefixed extension hooks around the login and registration forms and a filterable login URL.
* Fixed a REST permission gap that showed LMS Managers an error on every wp-admin screen.

= 1.19.0 =

* Added granular frontend theming tokens for links, buttons, highlights, gradients, shadows, and other visual roles.
* Expanded MentorKit user management with role filtering, account editing, password-reset links, group-leadership controls, and visibility for learners without enrollments.
* Redesigned the MentorKit Users archive and learner profile around safer role-aware administration workflows.
* Removed the command palette and aggressive menu-priority controls.
* Improved frontend performance by removing duplicate course/group scripts, scoping security and user-menu assets, deferring non-critical scripts, and loading the heavy certificate PDF renderer only after Download PDF is selected.
* Fixed manual course completion for sub-group members and corrected inconsistent button-radius defaults and Group Leader guidance.

= 1.16.1 =

* Sentry error reporting is now opt-in and disabled by default. A new setup wizard step and a new Settings → Privacy tab let administrators turn it on or off at any time.
* The setup wizard no longer skips back past the error reporting step after the Insights step.
* The Setup wizard menu visibility setting keeps your choice instead of resetting itself when other settings are saved.

= 1.16.0 =

* Login and registration pages now work in every language when using Polylang, including language-prefixed URLs.
* Course and group listings can optionally show default-language content when a translation is missing.
* Swedish, Danish and Finnish translations of the learner-facing interface.
* Course and group edit screens show a "Language versions" overview with the status of every translation.
* Course access restrictions are now copied to translations, so a restricted course stays restricted in every language.
* Local development installs no longer send error reports tagged as a live site.

= 1.15.1 =

* Standalone quiz URLs (/quiz/{slug}) now work immediately after updating — no manual permalink flush needed.

= 1.15.0 =

* New quiz and exam system: exam mode with random question draw, time limits, retake limits, a manual grading (review) workflow, and result emails to learners.
* New Questions library in wp-admin for managing the shared question bank, with search, filters and inline editing.
* Quizzes can be opened at their own /quiz/{slug} URL and added as ordered steps in groups.
* Course pages show a step timeline (Content → Exam → Certificate), consistent exam labels, clearer status pills, and a "Take exam" call-to-action once content is done.
* New course and group settings panes consolidating access, visibility, certificates, WooCommerce and more into one place.
* Optional course setting to lock quizzes until the course content is completed.
* Security hardening: the quiz answer key is no longer readable via the public REST API, quiz reports respect group-leader scoping, and the content lock is enforced on submit.
* Many integrity fixes to exam scoring, attempt handling, quiz reports and CSV export accuracy.
* Upgrade note: flush permalinks once (Settings → Permalinks) so /quiz/{slug} URLs resolve.

= 1.14.1 =

* Added inline controls for activating or deactivating optional email templates, with required-template safeguards and live status updates.
* Isolated settings saves by tab to prevent unrelated settings from being submitted or changed together.
* Refreshed rewrite rules only when URL slugs actually change and fixed the nested archive-conflict form.
* Replaced course and group datepickers with styled native date controls while preserving ISO date storage and malformed legacy values for correction.

= 1.14.0 =

* Redesigned invitations so an invite reserves a seat and sends a single-use link, while the invitee creates or completes their own account before access is granted.
* Added mandatory email verification for self-registration, including safe resend and recovery flows. Accounts are no longer logged in until their email address is proven.
* Removed passwordless sign-in, customer cohorts, group-leader/B2B workflows, and optional core-login lockdown. Core WordPress login stays available by default.
* Removed post-purchase auto-login. SCORM order completion still grants access.
* Improved translated course and group access, player return URLs, certificate lookup, and Norwegian auth/invitation copy.
* Completed WordPress.org compliance hardening for prefixed code identifiers, nonces, localized browser objects, and release packaging.

* Prefixed all shortcode tags with `mklms_` (for example `mklms_player`, `mklms_user_certificates`) for WordPress.org Plugin Check compliance. The old tags (`scorm_*`, `guest_only`, `logged_in_only`, `mentorkit_user_menu`) remain registered as back-compat aliases, so existing pages keep working.

= 1.7.0 =

* Added separate packages of the free plugin for WordPress.org and for temporary direct distribution.
* Added a conflict guard so the WordPress.org and directly distributed builds cannot be active at the same time.
* Added update packaging for the temporary direct-distribution build and a bridge release that moves sites to the WordPress.org build.

= 1.6.0 =

* Added setup wizard demo content imports with progress tracking.
* Added course and group Excerpt editor support.
* Shared the background SCORM download queue and redacted sensitive download logs.

= 1.5.0 =

* Added the Freemius Insights consent step to the MentorKit setup wizard.
* Routed Freemius opt-in, pending activation, and skip flows back into onboarding.

= 1.4.0 =

* Added canonical WordPress.org readme metadata.
* Added Freemius Insights lifecycle analytics disclosure.
