=== DTF Customizer ===
Contributors: todd
Tags: dtf, print-shop, customizer, mockup, upload
Requires at least: 6.0
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 0.3.6
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Guests upload artwork, position it on a product mockup (shirt, truck, car, …), lock a print-ready DTF design, and check out with WooCommerce.

== Description ==

DTF Customizer gives your print shop a guest-facing design tool:

* Guests upload a photo (JPEG/PNG/WebP), drag/scale/rotate it inside the print zones of an SVG product mockup, and hit **Continue** to lock the design.
* A locked design saves the original file, the exact placement transform, and a PNG preview — and emails both the guest and your shop.
* **WooCommerce checkout**: link a Medium to a purchasable product and locked designs go straight to the cart — with the design preview as the cart/order thumbnail and the design pinned to the order line item.
* Admins define **Mediums** (products) with a visual zone editor: pick a mockup image, drag out print zones, and set each zone's real printed width in inches — that drives all DPI math.
* **Onboarding**: on activation the plugin offers one-click sample content (a sample Medium with mockup and print zones) so you can try the flow immediately. Six sample SVG mockups (shirt, hoodie, cap, tote, truck, car) are bundled in `assets/mockups/`.
* Zero-config: everything ships with working defaults; global options live under **DTF Mediums → Settings**.

= Free vs Pro =

The free plugin is genuinely usable: guest upload, the full placement editor with live DPI readout, design locking with confirmation emails, and WooCommerce checkout — for **1 Medium with up to 2 print zones**.

The Pro build is a separate download from dtfgangsheetplugin.com and adds the print-shop money features:

* **Unlimited Mediums and print zones**
* **Quality gates** — per-Medium DPI floor; low-resolution uploads are warned about (guest must acknowledge) or blocked outright
* **Guest placement presets** (chest, pocket, centered, full)
* **Multiple decoration methods** per Medium (DTF, embroidery, …)
* **Stacked layers** — several images per print zone
* **Gang sheet builder** — a blank roll the guest packs freely, priced per size or per inch
* **Artwork upsell leads** — when quality is low, "Get help from our print shop" sends the request (uploaded file attached) to your inbox
* **White label** — removes the "Powered by" badge

Nothing in free is crippled at runtime: the free features work exactly as they do in Pro, without nags. The Pro features are not locked code inside this plugin — they are not in it at all. Pro ships an extra module that plugs into the extension points the free plugin exposes.

= Security =

Server-side hardening: files are re-validated with `wp_check_filetype_and_ext` + `getimagesize`, quarantined outside the media library until a design is locked, DPI rules are re-enforced server-side on submit, and all guest endpoints are rate-limited per IP (filterable via `dtfc_client_ip` for proxied/CDN setups).

**Customer files are private.** Everything under `uploads/dtfc/` is blocked from direct web access (a deny-all `.htaccess` is written automatically) and is only served through plugin endpoints: temp uploads via their unguessable 96-bit token, locked design files via a per-design 128-bit secret key. Design files are deleted from disk when a design is permanently deleted. SVG mockups are sanitized on upload with a whitelist parser (scripts, event handlers, external references, and embedded documents are stripped; unparseable files are rejected).

**Nginx users:** `.htaccess` has no effect on nginx — add this to your server block:

`location ~* /wp-content/uploads/dtfc/ { deny all; }`

== Installation ==

1. Upload the `dtf-customizer` folder to `/wp-content/plugins/`.
2. Activate the plugin — the onboarding notice offers one-click sample content, or:
3. Go to **DTF Mediums → Add New**, pick a mockup (one of the bundled SVGs from `assets/mockups/`, or your own), draw print zones, set printed widths, and publish.
4. Put `[dtf_customizer]` on any page (or `[dtf_customizer medium="123"]` to skip the product picker).
5. To sell designs, edit the Medium and link it to a WooCommerce product.
6. Locked designs appear under **DTF Designs**; confirmation/notification emails go to the guest and the site admin (or the address set in Settings).

== Frequently Asked Questions ==

= What image types can guests upload? =
JPEG, PNG, and WebP, up to 25 MB (filterable via `dtfc_max_upload_bytes`).

= How is DPI calculated? =
Each zone has a printed width in inches. Effective DPI = source pixels covering the zone width ÷ printed inches. It updates live as the guest scales, and is re-verified server-side at lock time.

= Does it require WooCommerce? =
No. Without WooCommerce you still get the full upload → place → lock → email flow; with WooCommerce active, locked designs can be added to the cart and purchased.

= Do abandoned uploads pile up? =
No. Uploads land in a quarantine directory (outside the media library) and are purged after 48 hours unless the guest locks a design.

= Are customer uploads publicly visible? =
No. The upload directory denies all direct web access; files stream only through tokenized plugin endpoints (temp uploads) or key-protected endpoints (locked designs). Nothing is listable or guessable. On nginx, add the `deny all` rule from the Description section.

= Does uninstalling delete my data? =
Only if you opt in. **Settings → Delete all data on uninstall** is off by default; when enabled, uninstall removes designs, mediums, options, and the `uploads/dtfc/` directory.

== Changelog ==

= 0.3.6 =
* Pro: license keys are now issued by dtfgangsheetplugin.com (DGSP-…); the plugin validates against that server by default. Older DTFC-… keys keep working.
* Pro: in-dashboard updates. With a valid key saved, new Pro versions show up under Plugins like any other update. The Lite build never contacts the product site.
* Header: `Update URI` set so WordPress.org can never replace the Pro build.
* Pro: a license check that cannot reach the key's issuer (older DTFC-… keys are proxied) no longer switches Pro features off — it is treated like an unreachable server and retried.
* Free build: the Pro features are no longer shipped as locked code. Everything Pro (gang sheets, quality gate, presets, decoration methods, layers, upsell leads, the license client and the updater) moved into a separate `pro/` module that only the Pro download contains; the free plugin exposes extension points instead. The tier is still fixed at build time (a `DTFC_TIER` constant in wp-config.php or a `dtfc_feature_enabled` filter cannot raise it).
* Settings: the notification inbox is now "Print-shop notification email" (`notify_email`); the old `upsell_email` value and per-Medium override are read as a fallback, so nothing needs re-entering.

= 0.3.5 =
* Fixed: the customizer failed to load on block themes (every WordPress default theme since 5.9), showing only "Something went wrong." Block themes render post content before `wp_head`, so the shortcode ran before assets were registered and `wp_localize_script()` silently dropped the editor config. Assets are now registered from the shortcode as well.

= 0.3.4 =
* Gang sheet builder: fixed sizes plus auto-length pricing, server-side amount computation, claim-hash cart binding.

= 0.3.2 =
* Lite/Pro split: feature gating baked at build time (`DTFC_Features`), separate build artifacts; the paid build is listed as "DTF Customizer Pro", the free build as "DTF Customizer".
* Version/header sync and release tooling.

= 0.3.0 =
* Global **Settings** screen (upsell inbox, default quality mode, default DPI floor, uninstall data removal) — plugin now runs with zero configuration and no site-specific hardcoding.
* **Onboarding**: activation notice with one-click sample Medium + mockup + print zones.
* Four new bundled mockups: hoodie, cap, tote, car.

= 0.2.6 =
* **WooCommerce integration**: Mediums link to purchasable products; locked designs add to cart with the design preview as the cart/order thumbnail and design metadata on the order line item.
* Admin order screen links back to the DTF Design.

= 0.2.4 =
* Guest placement presets (chest, pocket, centered, full) with admin-configurable availability.
* Multiple decoration methods per Medium.
* Admin list-table polish for Mediums and Designs (previews, zone counts, production file links).

= 0.2.0 =
* Security: whitelist-based SVG sanitizer on upload (scripts, event handlers, external refs, DOCTYPE/entities stripped or rejected).
* Security: `uploads/dtfc/` is no longer web-accessible — deny-all `.htaccess` plus tokenized (tmp) and key-protected (design) streaming endpoints.
* Design files are deleted from disk when a design post is permanently deleted.

= 0.1.0 =
* Initial release: Medium CPT + visual zone editor, guest upload/placement editor, DPI quality gates (off/warn/block), design locking with email confirmations, low-quality artwork upsell leads.

== Upgrade Notice ==

= 0.3.2 =
First release with the Lite/Pro split. Existing installs keep all features (they are the Pro build).
