JUCRA 2FA Changelog
====================

Version 0.1.6
8 September 2026

- Added an administrator-managed IP whitelist.
- Whitelist records store the IP address, separate comment, who added it and when it was added.
- Added delete controls for whitelist entries.
- Added exact IPv4 and IPv6 validation.
- Whitelisted IP addresses bypass the JUCRA 2FA code requirement.
- The login 2FA field remains visible but is disabled for whitelisted IPs.
- Login screen displays:
  "Your IP x.x.x.x is whitelisted. 2FA code not required."
- Uses REMOTE_ADDR only and does not trust spoofable forwarded-IP headers.
- Whitelisted users without active 2FA are not redirected to the setup page.
- Required/grace-period restrictions do not apply while using a whitelisted IP.

Version 0.1.5
8 September 2026

- Added JUCRA custom automatic update support.
- Update metadata is loaded from:
  https://www.jucra.com/apps/plugins/jucra-2fa/info.php
- Added changelog.txt to the plugin package.
- Added dedicated updater class to avoid conflicts with other JUCRA plugins.

Version 0.1.4
8 September 2026

- Changed the login field label to "JUCRA 2FA Code".
- Users without active 2FA are redirected to Users > JUCRA 2FA after login.
- Users with mandatory 2FA and an expired grace period can authenticate with
  their WordPress password but remain restricted to the JUCRA 2FA setup page
  until enrolment is completed.

Version 0.1.3
8 September 2026

- Added dedicated Users > JUCRA 2FA page.
- Removed the current user's full 2FA setup controls from profile.php.
- Kept administrator policy and reset controls when editing another user.
- Admin-bar 2FA status now links directly to the dedicated JUCRA 2FA page.

Version 0.1.2
8 September 2026

- Added red/green JUCRA 2FA status to the WordPress admin bar.
- Added administrator emergency reset for the current administrator.
- Self-reset requires the current WordPress password.
- Improved recovery-code warnings.

Version 0.1.1
8 September 2026

- Authenticator entries now use:
  domain.com - JUCRA 2FA
- WordPress username is used as the authenticator account name.
- Leading www. is removed automatically.

Version 0.1.0
8 September 2026

- Initial JUCRA 2FA release.
- Google Authenticator-compatible RFC 6238 TOTP.
- QR-code enrolment.
- Recovery codes.
- Encrypted TOTP secrets.
- Replay protection.
- Failed-code throttling.
- Global enforcement modes.
- Role-based enforcement.
- Per-user required/exempt overrides.
- Configurable grace period.
- WooCommerce login support.
