=== Speakers Bureau ===
Contributors: garryheath
Requires at least: 5.0
Tested up to: 6.4
Requires PHP: 7.0
Stable tag: 3.5.22

== Description ==

Speakers directory plugin for Rotary clubs: speaker registration, editable profiles,
a searchable/filterable directory, an interactive location map, and admin tools for
managing speakers, email templates, and geocoding.

Shortcodes:
* [speaker_list] - Display the speaker directory (layout, search, and filter options available)
* [speaker_map] - Interactive map of speaker locations
* [speaker_topics_index] - Index of all speaker topics
* [speaker_register] - Speaker registration form
* [speaker_edit] - Front-end profile editing form

== Installation ==

1. Upload the plugin ZIP via Plugins -> Add New -> Upload Plugin, then activate.
2. Create/confirm the pages that use the shortcodes above.
3. Go to Speakers Bureau -> Directory Options to configure layout, registration status,
   and geocoding settings.
4. Go to Speakers Bureau -> Email Templates to customize speaker/admin notification emails.

== Changelog ==

= 3.5.22 =
* Security/hardening pass from a deeper Plugin Check scan:
* Added a genuine CSRF nonce check to the front-end password-reset flow
  (both forms had none previously) and to the profile disable/enable
  toggle handler.
* Added wp_unslash() before sanitizing user input across 16 files (85
  spots) per WordPress coding standards - data-hygiene fix, not an active
  vulnerability.
* Reviewed all remaining nonce-verification warnings individually; false
  positives and low-risk read-only GET filters left as-is.

= 3.5.21 =
* Plugin Check cleanup pass - no functional/behavior changes:
* Switched 5 wp_redirect() calls to wp_safe_redirect() (all targets were
  already this site's own admin_url()/home_url(), not user-controlled).
* Fixed 40 text-domain mismatches and added the domain parameter to 12
  translation calls that were missing it (cosmetic i18n only).
* export-production-data.php and flush-rewrite-rules.php (one-off dev
  utility scripts) are excluded from the deployment ZIP going forward.

= 3.5.20 =
* Default speaker listing sort ([speaker_list] shortcode + speaker archive)
  now defaults to most recently updated instead of most recently published.
  Explicit "Newest" sort is unchanged.
* Fixed a search bug where Draft/Pending/Private speakers whose custom
  field data matched a search term could appear in front-end WordPress
  search results, even though clicking through wouldn't display anything.
* Settings page now shows the running plugin version in small print next
  to the page title.
* "Rotary Member:" field is now included, and marked Required, in the
  default form-field set seeded on brand-new installs. Does not alter
  the field configuration on any existing/already-configured site.
* One-time data cleanup (runs automatically once on the next admin page
  load after this update installs) corrects any existing speaker whose
  Rotary Member field was blank, missing, or a literal "0" so it instead
  reads "Not a Rotarian".

= 3.5.16 =
* Added "Send Reminder To" status checkboxes to the Profile Confirmation
  Reminder settings, so you can choose which speaker profile statuses
  (Published/Pending/Draft/Private) are eligible for the reminder email.
  Defaults to Published only.

= 3.5.15 =
* GHPDM compatibility fix: the update checker was pointed at an old, obsolete
  update URL - it now points at the correct GHPDM endpoint, which is why
  "check for updates" wasn't finding new releases.
* readme.txt rewritten in the format GHPDM's changelog parser expects.

= 3.5.14 =
* Rebuild Coordinates now shows a troubleshooting table of exactly which speakers were
  skipped or errored, with a direct edit link and the address on file for each.

= 3.5.13 =
* Fixed [speaker_map] showing no markers whenever any speaker's name, headline,
  organization, or topics contained a quote character - this broke the map's JSON data
  for all speakers, not just the one with the quote.

= 3.5.12 =
* Fixed [speaker_map] rendering empty whenever any speaker's data contained an
  apostrophe/single quote - the map's marker data attribute wasn't properly escaped
  for safe HTML embedding.

= 3.5.11 =
* Redesigned the background coordinate rebuild to avoid a server-to-server loopback
  request (which some hosts' firewalls block) in favor of fastcgi_finish_request(),
  with a polling-driven fallback for hosts that don't support it.

= 3.5.8 - 3.5.10 =
* Rebuild Coordinates is now throttled to 1 request per 1.2 seconds (previously up to
  4/second), fixing widespread geocoding failures caused by exceeding the map
  provider's usage limits.
* Rebuild Coordinates now skips speakers whose address hasn't changed since their last
  successful geocode, and runs as a background job with a live progress bar.
* Fixed the separate Bulk Geocode admin page to use the same throttling and skip logic.
* Removed dead/orphaned code from the old non-AJAX rebuild handler.

= 3.5.7 and earlier =
* See plugin file header comments for full historical changelog.

== Upgrade Notice ==

= 3.5.15 =
Fixes the update checker itself, plus everything in 3.5.11-3.5.14 (map/geocoding
bug fixes). Recommended for all sites.
