=== BenWorldwide Error Display ===
Contributors: benworldwide
Requires at least: 6.0
Requires PHP: 7.4
Stable tag: 2.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Switch the real WordPress debug constants in wp-config.php.

== Install or upgrade ==
1. Open Plugins > Add New Plugin > Upload Plugin.
2. Upload benworldwide-error-display-2.0.0.zip.
3. If version 1 is installed, choose Replace current with uploaded. Activate if needed.
4. Open Error Display from the sidebar, dashboard button, or top admin bar.
5. Choose Active and click Apply to wp-config.php.
6. On the next page, check the confirmation and the actual values of all three constants.
7. Click Generate a test warning. A labeled intentional warning should appear in Recent errors.
8. Reproduce your problem, then select Inactive and apply when finished.

== What the toggle changes ==
Active writes these real definitions before WordPress loads:
  define( 'WP_DEBUG', true );
  define( 'WP_DEBUG_DISPLAY', true );
  define( 'WP_DEBUG_LOG', true );
Inactive writes false for all three.

Existing literal boolean/0/1 definitions are updated in place. Missing definitions are
inserted before the wp-settings.php bootstrap. Comments and unrelated settings are
preserved. The next request verifies the effective constants; a mismatch is reported.
Merely installing or upgrading does not change wp-config.php. The status comes from
WP_DEBUG on the running request, not a saved plugin option.

Version 1's timer, administrator-only display, and emergency constant no longer control
debugging. Version 2 uses real site-wide debug constants, with no timer. Debugging stays
as saved even if this plugin is deactivated or deleted. Switch Inactive before removal.

== File editing safeguards ==
The editor uses the wp-config.php actually included by PHP. It parses PHP without executing
it, checks the proposed syntax, stages the edit beside the original, preserves Unix owner,
group and permission bits, and replaces the file with a rename. It invalidates OPcache
when supported and verifies the written bytes. It does not change server permissions.
An empty .bww-ed-config.lock file is used to coordinate plugin saves and is retained.
The temporary .php staging file is cleaned up normally; it is not a backup. No backups
are created. Server ACLs/security labels are outside the editor's portability guarantees.

Editing requires a writable file AND directory, PHP tokenizer, and permission to preserve
file ownership. Read-only hosting, file-modification policies, symbolic links, custom
log paths, environment-based or conditional definitions, duplicate definitions, and
nonstandard bootstrap layouts produce an error instead of an attempted rewrite.
Use the hosting file manager for those configurations. Do not loosen permissions to 777.
Avoid other simultaneous manual config edits; the lock coordinates this plugin's saves,
and a content check catches intervening edits before replacement.

POST actions require administrator permissions, update_core capability, and a valid nonce.
On multisite only a super administrator can use the controls from a site's dashboard.
The config change affects the WHOLE NETWORK; recent captured entries are per-site.
DISALLOW_FILE_MODS and DISALLOW_FILE_EDIT are respected for config changes.

== Error display and logging ==
Active enables WordPress's normal debugging, including debug-only notices. Error details
can be visible to all visitors, and wp-content/debug.log may contain sensitive data and
may be web-accessible depending on host rules. Use temporarily and switch off afterward.
No administrator-only public display promise is made for this version.

WordPress controls where errors are displayed. AJAX/REST requests and fatal-error recovery
screens may not show raw errors; PHP/host settings or other plugins can also affect output.
WP_DEBUG_LOG relies on PHP being able to write its log. Startup errors before the debug
configuration takes effect still need the host log. An empty viewer is not proof that no
errors occurred. The test warning confirms the plugin capture path only.

The private Recent errors viewer captures errors after this plugin loads, while WP_DEBUG
is enabled. It retains 100 entries, up to 30 per request, and respects PHP @ suppression.
Messages are escaped for display. Fatal capture is best effort and requires enough memory
and a working database. Concurrent writes or another handler may lose/intercept entries.
Use the WordPress/server log for earlier failures or fuller diagnostics.

Clear captured errors clears only this plugin's database entries, not debug.log or server
logs. Turning Inactive does not erase old logs, stop independent server logging, fix errors,
or suppress another application's custom output. PHP host display settings can still matter.
The plugin retains earlier database entries and version 1 options; no automatic deletion.

== If the dashboard crashes ==
Use the WordPress Recovery Mode email if available. Otherwise use the hosting file manager
or SFTP to rename the failing plugin folder inside wp-content/plugins/.
To turn debugging off without the dashboard, edit the three existing debug definitions
in wp-config.php to false, before the wp-settings.php require. Do not add duplicates.
Renaming this plugin does NOT undo its saved wp-config.php edits.

== Validation for this release ==
PHP syntax checks; 26 configuration tests including actual fixture-file replacements and
fresh-process evaluation of all three true/false constants; isolated plugin tests for
permissions, nonces, multisite restrictions, malformed submissions, test-warning capture,
HTML escaping and clearing. No running WordPress site was available for end-to-end testing.

== Changelog ==
= 2.0.0 =
Replaced runtime display overrides with actual wp-config.php editing and next-request
verification. Added an intentional test-warning action and guarded atomic file updates.
Removed the runtime-only timer and audience controls to match real WordPress debug behavior.

= 1.0.0 =
Initial release.
