=== FoodPress ===
Author: Michael Gamble
Contributors: mikeisrain
Requires at least: 6.6
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 2.0.3
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Free restaurant menus, nested categories, flexible layouts and import/export. Extend with optional annual add-ons. Fresh implementation.

== FoodPress 2.0 ==
Install on a staging website first, configure your restaurant and verify your menu before publishing.
No original FoodPress or add-on implementation is included.

== Core updates ==
Core 2.0.3 adds free updates through WordPress Plugins and Dashboard > Updates.
Install this version manually once if upgrading from 2.0.2 or earlier. Future
releases appear in WordPress; use Update now or Enable auto-updates on the Plugins
page. Automatic installation follows your WordPress preferences and scheduled jobs.
FoodPress checks https://myfoodpress.com/api/updates/core for signed release metadata
and downloads the verified free Core ZIP from https://myfoodpress.com/download/core.
No license, customer account, menus or guest details are needed for Core updates.
The hosting service receives normal network request information, including IP address.
Paid add-on updates continue to require their existing current licenses.
Public demo mode does not contact the update service.

== Installation ==
1. Upload the FoodPress ZIP through Plugins > Add New > Upload Plugin.
2. Activate FoodPress.
3. Open FoodPress > Settings. Enter your restaurant name, hours, timezone and capacity.
4. Create menus/categories and dishes. Open Shortcode generator, choose filters/layout/style, preview and copy.
5. Paste into a WordPress Shortcode block on your existing page. Each embed has its own options.
6. To accept orders, install the matching FoodPress Ordering add-on, enable it under Tools, and configure Stripe.
7. Verify the full Stripe test-mode flow before considering live payments. Reservations can be enabled under Tools.

== Stripe ==
Use an existing Stripe account. This plugin does not create an account or collect card numbers.
Enter the secret key and webhook signing secret privately in FoodPress > Settings, or configure
FOODPRESS_STRIPE_SECRET_KEY and FOODPRESS_STRIPE_WEBHOOK_SECRET in wp-config.php.
Both credentials are required. Keep these values out of exports, source control and public demos.
The site must use HTTPS. Register the webhook URL shown in settings for:
- checkout.session.completed
- checkout.session.async_payment_succeeded
Order totals are calculated from saved menu prices. The return URL does not mark an order paid.
Only a verified webhook matching the order, Checkout Session, currency, amount and test/live mode can do so.
Stripe checkout uses card payment methods. Prices are final amounts; separate taxes, tips, delivery fees,
refunds, disputes, multi-location routing and stock quantities are not implemented in this alpha.
Issue any required refund in Stripe. Cancelling an order does not automatically refund it.

== Reservations ==
Weekly half-hour service schedules, holiday closures, party limits, seating duration, capacity, notice and advance-booking windows are configurable.
Times use the WordPress timezone. Capacity is guest-based across overlapping seating intervals.
Guests receive instant confirmation on screen; restaurant staff can see and cancel bookings in the admin area.
Closures preserve existing bookings and prevent new ones. Seating duration uses elapsed time across daylight-saving changes.
The optional Seating add-on assigns specific tables or individual seats; see below. Overnight service and SMS are not included.

== Notifications ==
Optional guest and restaurant emails cover confirmed payments, pickup-ready orders, reservation confirmations
and cancellations. Enable them in Settings, then set recipient routes, sender and reply-to in Email delivery.
Use the existing WordPress mail provider or configure FoodPress-only authenticated SMTP with TLS.
Seating notices include reference, time, timezone, party size, section/table/seat and payment status.
Notifications are disabled by default. Disabled events are not emailed retroactively when enabled later.
The durable queue deduplicates events, retries transport failures up to five times, and exposes a delivery log.
Up to five jobs run per batch. New and remaining ready jobs schedule another attempt after ten seconds,
with a five-minute recurring fallback. Busy restaurants should configure a reliable external WordPress cron.
WordPress cron depends on site traffic unless configured with an external scheduler. The "sent" state means
WordPress accepted the message, not that it reached an inbox. A crash after sending but before recording success
can cause a duplicate email on recovery. No raw message copies or recipient copies are stored in the queue.
Demo mode creates message previews and never invokes the plugin mail worker.

== Import and export ==
V2 JSON menu schemas 2 and 3 (current export) only. Preview before applying. Matching UUIDs update items; new UUIDs add items.
Repeated imports do not duplicate dishes. Currency must match. Other dishes are preserved.
The import is transactional and menu writes are serialized. Up to 1000 dishes / 2 MB per import.
Image references are preserved; images are not downloaded or embedded in exports.
No old plugin code, credentials, executable settings, order history or guest details are imported.
Legacy data conversion is not yet implemented.

== Demo mode ==
FOODPRESS_DEMO must be explicitly defined as boolean true by the demo host. Activation alone never enables it.
It enables synthetic restaurant seeding and simulated payment results, disables Stripe credentials/webhooks,
and labels the frontend/admin as a demo. Never enable this constant on a real restaurant website.
The published demonstration uses an isolated temporary WordPress Playground for each visitor.

== Data and privacy ==
Restaurant data is stored in fpv2_ WordPress tables. Public endpoints cannot list orders or reservations.
Order receipts require a random secret token. All admin actions require manage_options and a WordPress nonce.
Guest contact details are collected only for order/booking management. No newsletters are sent.
WordPress Tools > Export Personal Data and Erase Personal Data include FoodPress orders and reservations.
Erasure removes guest contact details, notes and receipt access from completed/cancelled orders and past/cancelled
reservations, retaining order totals and booking history. Active orders and upcoming confirmed reservations are
retained and reported so the administrator can finish service and repeat the request. This does not erase data
held separately by Stripe or the mail provider. No automated retention period is enabled.
Deactivation/removal preserves restaurant records. Deactivation removes the FoodPress email cron event.
Review the suggested WordPress privacy-policy text and set an appropriate restaurant retention policy.

== Design and agency branding ==
Design Studio offers five presets, 23 semantic colors, 12 typography/spacing controls, local font stacks
or a licensed WOFF2 font from your media library, logos, hero imagery, card/list layouts, button styles,
shadows and Lucide/Heroicons/text-only icon choices. Preview draft changes before publishing.
Use the native Restaurant block or the existing shortcode to place the working restaurant on a page.
Agency branding changes the product/dashboard name, logo, support links, plugin-list display and footer credit.
The internal FoodPress plugin path, data tables, routes and version remain stable. No vendor account is created.
Brand profiles exclude credentials and restaurant/customer records; agency details require explicit opt-in.
Image URLs remain references; custom font files must be uploaded and selected again on the destination site.
Reseller commercial terms are not finalized. Annual license validation and vendor updates are implemented; live sales and private release assets require vendor configuration.

== Shortcode generator ==
FoodPress > Shortcode generator is the main publishing workflow. Select your menu and optional category filters,
choose layout and per-embed appearance, preview actual dishes, and copy the resulting shortcode.
Paste it into a Shortcode block on any existing WordPress page; its theme/header/footer remain in place.
Each shortcode keeps its explicit options. Omitted design options inherit Design Studio. Updating a dish
updates all matching embeds. No shortcode generator action saves global design or changes published pages.
Example: [foodpress view="menu" ordering="off" layout="accordion" featured_display="hidden"]
Featured slider: [foodpress view="menu" ordering="off" layout="slider" featured="yes" limit="3"]
Advanced shortcode options are currently in the dashboard generator. The native Menu block also supports basic embeds.

== Menus, layouts and optional ordering ==
Create menus and nested categories in Menus & categories; assign dishes in Dishes.
Use up to six levels (a menu and five category levels), with cycle and orphan protection.
Design Studio includes cards, list, compact, accordion, horizontal tabs, vertical tabs and slideshow layouts.
Feature dishes in a slider or cards. Specials have optional date ranges and a badge; they do not alter prices.
The Restaurant block selects a menu/category and layout. Multiple menu embeds are supported.
The shortcode accepts menu="SECTION-UUID", view="menu", layout="tabs", ordering="off", and class="my-menu".
Menu-only installations have no cart or checkout. Online ordering requires the separate FoodPress Ordering add-on.
Install FoodPress Core first, then the matching Ordering add-on if desired; configure both services in Tools.
UPGRADING FROM EARLIER V2: activate the Ordering add-on to resume new checkout requests. Existing orders,
Stripe configuration, receipts and in-flight webhook confirmations are preserved. Reservations retain their setting.
Fresh core installations have reservations off. The public demo includes the add-on with both services enabled.
Menu JSON schema version 3 includes hierarchy, featured flags and specials. Schema version 2 is still accepted.
Original legacy FoodPress import remains unimplemented. This V2 compatibility uses only newly authored code.

== Seating add-on ==
Install and activate FoodPress Seating, enable reservations under Tools, then open Seating chart.
Drag and drop sections, round/rectangular tables and individual seats, or use coordinates and arrow keys.
Set section/resource online availability and capacity. Publish the plan on the restaurant page or with [foodpress_seating].
Each table is booked whole; individual seats have capacity one. Do not model the same physical place twice.
One plan per WordPress site, up to 12 sections and 100 objects. Daily service hours apply.
Reservations can be free, a deposit or a full reservation payment, per booking or guest. Stripe keys and verified
webhook are required on real HTTPS sites. Payment sessions last 35 minutes; seating holds last 37 minutes.
Expired holds release automatically. A late payment for unavailable seating requires staff review and a manual refund or resolution.
Existing unassigned reservations block their overlapping interval on the chart until resolved.
Cancelling releases seating but does not refund a payment. Deposit balances are handled by the restaurant.
Tables and seats with upcoming confirmed bookings cannot be removed or have their capacity/type/section changed.
Seating bookings participate in WordPress privacy export/erasure; active service, unsettled payments and payment reviews retain contact details.

== Changelog ==
= 2.0.2 =
* Reduce ordered dish quantities directly from menu cards using the new minus button.
* Keep duplicate dish cards and bag totals synchronized; remove the final item at zero.
* Accessible labels, touch targets and keyboard focus for quantity controls.
* Compatible with the existing 2.0.1 add-ons and bundle installers.

= 2.0.1 =
* Branding update: Michael Gamble author credit and matching product thumbnails, icons and banners.
* Preserve agency White Label presentation and all existing restaurant/license behavior.

= 2.0.0 =
Private release candidate. License renewal supports verified Stripe Checkout links for canceled subscriptions.
The existing key remains the renewal identity; installed features continue after license expiration.


= 2.0.0-alpha.28 =
Separate glowing status lights for add-on activation and license eligibility.
Text labels and gray disabled states keep plugin and license status distinct.

= 2.0.0-alpha.27 =
Clear renewal action for expired add-on licenses, keeping the existing key.
Demo renewal stays offline; installed features continue after expiration.

= 2.0.0-alpha.26 =
* Show each website's registration date and updates/support valid-through date on real and simulated add-on license cards.
* Preserve registration dates through checks and renewals; retain verified historical dates after expiration without granting update access.

= 2.0.0-alpha.25 =
* Add isolated license activation, expiration, renewal and website-release scenarios to the temporary demo. Sample keys never authorize real updates or billing.

= 2.0.0-alpha.24 =
* Keep restaurant-preview and manager links inside the temporary WordPress demo so they do not open broken standalone tabs.
* Normal WordPress installations retain their existing new-tab preview behavior.

= 2.0.0-alpha.23 =
* Optional free-core dish ratings with email verification before submission, moderation, private contacts and shortcode visibility.
* One-time expiring codes, request throttles, duplicate prevention and WordPress privacy tools. Demo email verification stays simulated.

= 2.0.0-alpha.22 =
* Save checkout prices, item availability and currency under the same lock used by menu edits and imports.
* Release the menu lock before Stripe requests; preserve original totals and idempotency on payment retries.

= 2.0.0-alpha.21 =
* Field-by-field menu import review with additions, updates, unchanged records and category-impact warnings.
* Confirmation rejects stale menus/currencies; previews are owner-scoped, expire after 15 minutes and can be discarded.
* Earlier V2 flat exports receive a complete structure preview before any menu write. No historical executable code is used.
* Restaurant currency updates share the menu write lock to prevent prices being reinterpreted during import.
= 2.0.0-alpha.20 =
* Assigned-seat payment review queue with explicit staff confirmation or closure, conflict rechecks, durable decision metadata and deduplicated notices.
* Private review notes participate in WordPress personal-data export and erasure; resolution never issues or verifies refunds.

= 2.0.0-alpha.19 =
* Search all order/reservation history by reference, date, status and payment state with bounded pagination.
* Align fulfillment controls with forward-only server rules, preserve filter context and reject malformed record IDs.

= 2.0.0-alpha.18 =
* Show delivery health, overdue attempts, scheduled checks and bounded notification-log filters.
* Schedule failed-message retries at their backoff time, retaining the five-minute cron fallback.

= 2.0.0-alpha.17 =
* Keep the FoodPress or agency sidebar logo inside its icon slot on every WordPress admin screen.

= 2.0.0-alpha.15 =
* Keep shortcode preview styles and layout scripts inside the isolated preview document so WordPress Playground displays them correctly.

= 2.0.0-alpha.14 =
* Apply rate limits and private response headers to every capitalization of a WordPress REST route.

= 2.0.0-alpha.13 =
* Serialize guest rate counters; separate submission, receipt and availability budgets.
* Count authorized REST dispatches once, independently of repeated permission checks.
* Require authentic bounded JSON uploads and POST-only administrator actions.
* Restrict Stripe checkout responses and redirects; fail closed if checkout cannot be saved.
* Mark sensitive REST responses private/no-store and add nosniff and rate retry headers.

= 2.0.0-alpha.12 =
Visible per-item quantities beside Add, synchronized across featured/category copies and bag controls. Added button feedback, item-limit feedback and accessible quantity announcements.

= 2.0.0-alpha.11 =
Free core menu publishing, styles scoped to menu containers, late shortcode styles, and repeat-safe/dynamic
initialization for menu and add-on controls. Block reservation controls now match shortcodes.
Automated coexistence checks cover Elementor, WooCommerce, classic/block themes and reusable patterns.
= 2.0.0-alpha.9 =
Generated menu shortcodes can include enabled reservations and Seating alongside Ordering and White Label.
Explicit per-embed reservation controls preserve menu-only defaults and the existing full restaurant view.
Booking forms in the generator preview are inert. Combined add-ons are tested across all eight menu layouts.
= 2.0.0-alpha.8 =
Menu-first shortcode generator with actual-dish preview, category/featured/special/dietary filters, sorting/limits,
per-embed colors/fonts/visibility, copy controls and a dish slider. Public demo now starts on an ordinary WordPress
page with multiple shortcodes. Existing full restaurant and optional add-on flows remain available.
= 2.0.0-alpha.7 =
Optional Seating builder and table/seat reservations, free/deposit/full reservation payments, protected payment holds,
guest/staff notices, email routing and FoodPress-only SMTP, prompt bounded notification draining, and Seating licenses.
= 2.0.0-alpha.6 =
Annual add-on licensing, signed update leases and private release delivery. Expiration stops updates/support only.
= 2.0.0-alpha.5 =
Menu-first core, separate optional Ordering add-on, nested menus/categories, seven interactive layouts,
featured sliders, dated specials, per-embed block settings, and transactional hierarchy transfer.
Earlier V2 flat menu data migrates with stable identities. Ordering now needs the separately activated add-on.
= 2.0.0-alpha.4 =
Visual Design Studio, portable brand profiles, agency identity, local fonts and bundled icon packs,
with a native WordPress restaurant block. Existing menu, ordering and reservation flows remain integrated.
= 2.0.0-alpha.3 =
Restore the original FoodPress fork-and-knife plate icon in tomato red, as requested by its owner.
Only the original artwork is reused. All V2 plugin implementation remains newly authored.
= 2.0.0-alpha.2 =
Notification queue and demo previews, WordPress personal-data tools, weekly schedules and closure dates,
daylight-saving-aware seatings, forward-only order fulfillment, and malformed-input hardening.
Behavioral tests passed on WordPress 7.1.1/PHP 8.3 and the WordPress 6.6 maintenance series/PHP 8.1.

== Annual add-on licensing ==
Ordering, Reservations, Seating and White Label use separate annual licenses for updates and support. Register the key under FoodPress > Licenses. Installed add-ons keep working after expiration, including ordering, agency branding and settings. Renew to restore updates and support. Purchase availability and terms are shown at myfoodpress.com. Licensed update downloads are verified before installation. The public demo uses simulated licenses and cannot make real purchases. Network-wide add-on activation is unsupported; license each website separately.

== Alpha.11 theme and Reservations package ==
Core menus, shortcode generation, restaurant styling and import/export are free.
Online bookings now require the separately activated Reservations or Seating add-on.
Earlier alpha bookings/settings are preserved; activate either package to resume.
Use [foodpress_reservations] for a booking-only page. Reservations currently offers
free-to-guest bookings; general deposits/payments remain planned. Seating includes
booking capability and optional payments for assigned tables/seats.
The optional FoodPress Restaurant block theme and starter ZIP are separate downloads.
Changing themes preserves FoodPress data. See myfoodpress.com for launch updates.
