=== Gradespace Core ===
Contributors: gradespace
Tags: business, settings, staff access, setup wizard, branded email
Requires at least: 6.8
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 0.5.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

The free back office every Gradespace kit runs on: settings in plain words, a Today screen, staff access, branded emails, a setup wizard and updates.

== Description ==

Gradespace Core is free. It is the shared back office for the Gradespace kits for WordPress (Clinic, Church and Music):

* **Settings in plain words**: your business name, logo, phones, address and opening hours, entered once and used everywhere.
* **A Today screen** with what needs doing, and count bubbles in the menu.
* **Staff access**: roles for your team, each seeing only what their job needs (choosing exactly what each role can do is a Pro feature).
* **Branded emails** with an on/off switch for each one and a log (the log is a Pro feature).
* **Sign-in protection** and a security log, a branded sign-in page, cookieless site stats (Pro), a cookie banner, and starter legal pages.
* **A setup wizard** that gets a new website ready in minutes.
* **Your kit licence** (Settings → Gradespace licence) and **automatic updates** for Core, your kit plugin and its theme.

Core itself needs no licence key. The key you receive when you buy a kit goes in Settings → Gradespace licence and covers that kit’s plugin and theme.

Kits come in three parts that work together, installed in this order:

1. **Gradespace Core** (free, this plugin).
2. **The kit plugin** (Gradespace Clinic, Church or Music).
3. **The kit theme** (the matching Gradespace theme).

== Installation ==

You need a WordPress website (WordPress 6.8 or later, PHP 8.0 or later) and to be signed in as an administrator.

First, download the three files from your licences page, https://thegradespace.com/account/licences (sign in with the email address you bought with). Leave them as .zip files: WordPress wants them that way. Gradespace Core on its own is also free to download from https://thegradespace.com/wordpress-kits.

Then install them **in this order**:

1. **Gradespace Core** (gradespace-core-….zip). In WordPress, go to **Plugins → Add New Plugin → Upload Plugin**, choose the file, click **Install Now**, then **Activate Plugin**. If the setup wizard opens, leave it for now: you’ll come back to it in step 4.
2. **Your kit plugin** (for example gradespace-clinic-….zip). The same again: **Plugins → Add New Plugin → Upload Plugin**, choose the file, **Install Now**, then **Activate Plugin**.
3. **Your kit theme** (for example gradespace-clinic-theme-….zip). Go to **Appearance → Themes → Add New Theme → Upload Theme**, choose the file, click **Install Now**, then **Activate**.
4. **Run the setup wizard.** It opens by itself; if it doesn’t, click **Continue setup** on the Dashboard. A few questions about your business, then starter pages and a menu. You can run it again later from **Settings → Run setup again** in your kit’s menu (Clinic, Church or Music school).
5. **Add your licence key.** Go to **Settings → Gradespace licence**, paste the key from your receipt email and click **Activate**. That switches on updates, and Pro or Agency features if your licence includes them.

New versions then arrive in **Dashboard → Updates** like any other plugin or theme.

(Older versions of WordPress say “Add New” instead of “Add New Plugin” and “Add New Theme”.)

A step-by-step guide with pictures, and staff guides to download as PDFs: https://thegradespace.com/wordpress-kits/getting-started

== Moving to another website ==

Your licence covers one live website at a time (an Agency licence covers five). To move it to a new website:

1. **Free it on the old website.** Go to **Settings → Gradespace licence** there and click **Deactivate on this website**. If the old website has already gone, sign in at https://thegradespace.com/account/licences and click **Remove site** next to it instead.
2. **Activate it on the new website.** Install as above, then paste the same key in **Settings → Gradespace licence** and click **Activate**.

Nothing you saved is deleted when you deactivate a key.

**Local and staging copies don’t count.** A copy on your own computer or a test address (localhost, anything ending in .local or .test, or a staging. or dev. sub-domain) can use your key without taking up your website. So you can build and try things on a copy, then go live.

== Frequently Asked Questions ==

= Do I need a licence for Gradespace Core? =

No. Core is free. The licence key is for your kit (Clinic, Church or Music) and covers its plugin and theme.

= Where is my licence key? =

In your receipt email. You can also look it up at https://thegradespace.com/account/licences with the email address you bought with.

= What happens before I add a key? =

The kit runs in Starter mode so you can try it, but it doesn’t get updates or Pro features until you add your key.

= WordPress says the key is already in use on all its websites. =

Your licence is still active on another website. Deactivate it there (Settings → Gradespace licence), or remove that website at https://thegradespace.com/account/licences, then click Activate again.

= How do updates work? =

Once your key is active, new versions of Gradespace Core, the kit plugin and its theme appear in Dashboard → Updates. Click Update, as you would for any plugin. Updates are included for life.

= Is there a guide for my staff? =

Yes, one for each kit, as a PDF: https://thegradespace.com/wordpress-kits/getting-started

= Where can I get help? =

Email support@thegradespace.com with what you were doing, what you expected and a screenshot, and we’ll help.

== Copyright ==

Gradespace Core, Copyright Gradespace Ltd. Licensed under the GPLv2 or later.

== Changelog ==

= 0.5.1 =
* Security tab: Recent activity is shown in pages (10, 25 or 50 rows) instead of the last 100 in one list; the chart's 'Show as a table' scrolls in a box with its headings pinned.
* New filter `gsc_time_label` (label, H:i time, DateTimeImmutable): a site can write times its own way everywhere Core and the kits show them (e.g. “9:30 am”, “11:00 am” instead of “9:30am”, “11am”). Nothing changes without it.

= 0.5.0 =
* **Sign-in page photo** (Settings → Business → Sign-in page): an optional photo behind the panel beside the sign-in form, darkened with the brand colour so the words stay easy to read. On phones it becomes a short banner. None: the brand colour as before.
* **Line at the bottom of the panel** (same card): a small line such as your full name and area. Blank: the kit's usual line.
* The panel can list **what staff look after here**, each with an icon from Core's set. Filter `gsc_login_panel` gains `features` (a list of [icon name, text]), `photo` (an image URL) and `foot` (plain text); `facts`, `title`, `lead` and the Agency white-label words work as before. New helper `gsc_login_panel()`.
* **Sign-in switch**: new filter `gsc_login_switch` (a list of label, url, current). With two or more places, a segmented control (“Where do you want to sign in?”, the current one marked) shows above the sign-in form, e.g. “Website editor | Church app”.
* “← Back to website” now sits above the form on every screen (sign in, lost password, new password), so it is there on phones too; it left the panel's list.
* Icons: `layout` (page layout) and `cart` (shopping cart).
* Settings: a picture field with help text now shows its name and help (e.g. Search and sharing → Share picture).

= 0.4.0 =
* **Demo mode** (new module `demo`, for public demo websites only): on only when wp-config.php has `define( 'GSC_DEMO_MODE', true );` (optional `GSC_DEMO_KIT`), and no effect anywhere else.
  * **No email ever leaves the website**: every email (branded, WordPress, WooCommerce) is answered as sent without sending and written to the email log as **“Demo — not sent”**; PHPMailer is a dead end as a backstop. The email log says it's a demo.
  * **“Look around the admin”**: a button on the sign-in page and in the demo bar, and `/demo-login`, sign a visitor in as the demo staff member (login `demo`, role **Demo staff** with every staff ability of the kit except deleting records for good) with no password, behind a signed token and a limit per address. Password sign-in, password resets and application passwords are refused for that account; a demo visit lasts four hours.
  * **Guard rails** for the demo account: no plugins, themes, users, roles, profile, passwords, licence, exports, imports, uploads, site options, tools, file editor, setup wizard, staff access, email-log clearing or IP blocking (403 “Not in the demo”, and those menu items are hidden). Settings screens open, but Save says **“Saving is switched off in the demo”**. The website's public pages, menus, templates, styles, products and the kit's public content can't be changed or deleted (REST 403, classic screens 403, and a backstop that keeps the stored fields); new public content is saved as a draft; categories and other terms can be added but not renamed or deleted. Private staff records (appointments, patients, prescriptions, lessons, students, visits, prayer, messages, orders, stock, the till) work in full.
  * **Design & colours** in the demo is kept per browser (a session cookie): a visitor's choice shows on the demo website for them only, with “Go back to the usual look”. New filter `gsc_design_saved`.
  * **Demo bar** (“Demo website — resets every night · Look around the admin · Buy this kit”, linking to thegradespace.com/wordpress-kits/<kit>), fixed at the bottom of the website and at the top of the admin, hidden for the rest of the session with ×; `noindex, nofollow` (meta and `X-Robots-Tag`), robots.txt disallows everything, no sitemaps, comments off.
  * **Limits**: form posts and REST writes from one address (bookings, contact, Plan a visit, cart and checkout) are limited to 40 an hour (200 for the shared demo account) and 1,500 an hour for the whole site, on top of each form's own limits and honeypot.
  * **Nightly reset**: `wp gradespace demo reset --kit=<clinic|church|music> --yes` empties the website (content, visitors' accounts, the kits' tables and settings; keeps administrators, the licence and the sample photos) and runs the kit's own setup wizard again with sample answers and every starter-content importer, then the demo's sample records dated from today, the demo account, the design and the licence (`GSC_LICENCE_KEYS`). Idempotent; a few seconds. `wp gradespace demo status` reports the kit, last reset, licence, demo account, emails and counts. Hooks for a deployment's sample business and records: `gsc_demo_profile`, `gsc_demo_before_setup`, `gsc_demo_seed`; also `gsc_demo_store_url`, `gsc_demo_denied_caps`, `gsc_demo_blocked_actions`, `gsc_demo_excluded_abilities`, `gsc_demo_keep_options`, `gsc_demo_keep_posts`.
* `gsc_demo_on()` helper (always available).

= 0.3.4 =
* Plugins screen: no more “This plugin has not been tested with your current version of WordPress” on point releases. “Tested up to 7.1” now covers 7.1.1, 7.1.2 and so on, as it does for plugins from WordPress.org.

= 0.3.3 =
* Settings, licence and Design & colours screens use the full width of the screen (they stopped at about 1,100px, so the tab bar scrolled on wide screens). Design cards and colour palettes spread across one row.

= 0.3.2 =
* Added readme with installation steps.

= 0.3.1 =
* Sign-in credit: **Pro and Agency** licences can now choose to hide the “Website by Gradespace” line under the staff sign-in form (a switch on Settings → Licence; off = the credit is shown). Starter (and no key) always shows it. New feature `core:hide_credit` (Pro).
* The white-label panel heading and text stay **Agency** only (`core:white_label`). A Pro licence sees the credit switch in a “Sign-in page” card, with an Agency upgrade card for the panel words; saving as Pro keeps any stored words untouched (and they aren't applied).
* Upgrade cards show the kits' launch prices (Starter £69, Pro £139, Agency £389, VAT-inclusive), so “Upgrade to Pro for £70” etc.

= 0.3.0 =
* **Licences** (new required module `licence`): Settings → Licence (also Settings → Gradespace licence in WordPress's own menu) with one key per installed kit: Activate, Recheck, Deactivate, a status card (tier, websites used/allowed, lifetime, last checked), plain messages for every server answer (invalid, limit, revoked, product mismatch, server unreachable), buy and upgrade links (upgrades go through `admin-post.php` so the key never appears in a page). Keys are kept in `gsc_licences` (not autoloaded), shown as their last four characters, administrators only. Kits register with `gsc_register_kit()`; `gsc_licence_tier()`, `gsc_has_feature()`, `gsc_licence_upsell()`, `gsc_licence_rest_check()`, `gsc_licence_require()`, `gsc_licence_badge()`; filters `gsc_licence_tier`, `gsc_has_feature`, `gsc_licence_dev_site`; constants `GSC_LICENCE_API`, `GSC_LICENCE_KEYS`, `GSC_LICENCE_DEV_SITE`.
* Paying customers are never locked out: a verified tier is kept and re-checked weekly; an unreachable server (or rate limit, or server error) keeps the last known tier; only a definite revoked/invalid answer downgrades. Test copies (localhost, *.local, *.test, staging.*, dev.*) use the key's tier without taking up a website.
* Without a key a kit runs in Starter mode for evaluation, with a notice ("add your licence key to get updates") and no updates.
* Pro modules need a Pro (or Agency) kit licence: Staff access matrix, Email log and Site stats (visitors) show an upgrade card instead, keep a "Pro" badge in the menu, and their handlers answer 403. Nothing is deleted: the saved access keeps applying, emails are still logged and visits still counted, the staff list and the security tab stay available.
* Agency: white-label sign-in (own panel heading and text; hide the new "Website by Gradespace" credit under the sign-in form).
* Updates come from the licence API's per-site manifest (site address plus the kit keys in `X-Gradespace-Keys`); a `null` download link shows "Add your licence key to update" under the plugin row and as a notice on Themes and Dashboard → Updates; just before installing, the manifest is fetched again so signed download links never expire mid-update. `GSC_UPDATES_MANIFEST` still overrides (a local file only offers kit updates with a verified key). View details reads `last_updated` and `homepage`.
* GSCookie: when it's active, Core's cookie banner steps aside, gated embeds and `gscConsent` follow GSCookie's choices (new `consent-bridge.js`), the cookie policy text refers to it, and Settings → Privacy says so. Core's admin styles for `.gsc-card`, `.gsc-grid`, `.gsc-pill`, `.gsc-status` are scoped to `body.gsc-ui` (Core and kit screens, the Dashboard), and GSCookie's screens are no longer mistaken for Core's.
* Settings tabs can print their own forms (`'form' => false`).

= 0.2.1 =
* Contact form messages: review before deleting is now the default. A new setting (Settings → Contact → "When messages are due": review or delete automatically, `forms_retention_mode`) keeps old messages until someone deletes them; Messages → Due for review lists the ones older than the review period, and administrators delete the ticked ones with "Delete selected" after typing DELETE. Sites that want the old nightly deletion choose "Delete them automatically". The contact form's small print follows the choice.
* Email log: administrators can delete ticked entries, clear the "not sent" entries or clear the whole log (each asks first). The failed-emails count, the Settings bubble and the Today warning update straight away.
* Dialogs: `gsc_register_bulk_confirm()` asks before a bulk action on a list screen, optionally with a word to type.
* Post fields: a field panel can be kept to people with a capability (`cap`): others don't see it, can't change it and don't get its values from the REST API. New field type `posts` (several posts, ticked) with `gsc_field_ids()`.

= 0.2.0 =
* New modules for the Church and Music kits, off until a kit (or site) turns them on:
  * **Locations**: many locations with a colour pair each, their own pages, "belongs to" pages and a location binding source.
  * **SEO**: meta descriptions, link previews (Open Graph/Twitter) and structured data; steps aside when an SEO plugin is active.
  * **Redirects**: 301s from old addresses, managed in Settings → Redirects.
  * **Share buttons** block.
  * **Fields**: declarative post fields with editor sidebar panels (weekly hours and days-off field types).
  * **Forms**: a contact form block with spam guards and limits, private Messages with an unread count, retention and privacy export/erase.
  * **Icons**: an icon set and block, and a shared editor script for server-rendered blocks.
* Email footer: the address prints on one line whatever line endings were typed.

= 0.1.0 =
* First release, from a tested, live clinic build.
* Settings: a declarative API for tabs, cards and fields, with Business, Contact and Email tabs built in.
* Business menu with a Today screen, panels and count bubbles; a toolbar item for staff.
* Staff access: roles and plain-words abilities, the matrix screen and a staff list.
* Branded emails with a switch per email, SMTP, a test email and an email log.
* Sign-in protection, a security log with IP blocking, limits on registrations and password resets, XML-RPC off.
* Site stats without cookies; a branded two-panel sign-in page; on-brand dialogs and a contact sheet.
* Design styles and colour palettes for themes that support them.
* Setup wizard with starter-content importers; automatic updates from the Gradespace update server; View details.
