=== MaliUred Cjenik ===
Contributors: maliured
Tags: shortcode, prices
Requires at least: 6.0
Tested up to: 7.0
Stable tag: 1.0.0
Requires PHP: 7.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Publishes MaliUred price-list snapshots (CSV and XML) with the [maliured_cjenik] shortcode.

== Description ==

MaliUred Cjenik prints a company's public price list on a WordPress page. Product and service snapshots stay on the MaliUred server. This plugin only lists them.

The visitor's browser does not call the API. WordPress fetches the list with `wp_safe_remote_get` and stores the response for 15 minutes. There is no account and no token.

The on-page labels are Croatian, because this is the public price-list publication used in Croatia. Every string is passed through the `maliured-cjenik` text domain, so it can be translated. Text from the API is escaped with `esc_html`. File URLs are escaped with `esc_url`.

= Settings =

Under **Settings → MaliUred cjenik**:

* **Ime tvrtke** — the company name exactly as it is written in MaliUred, including spaces. Example: `Demo tvrtka`.
* **Adresa API-ja** — the API origin. Default: `https://app.maliured.hr`. A trailing slash is removed when the value is saved. Only an `http` or `https` origin is kept.

In MaliUred, “Objavi cjenik javno” has to be turned on. Otherwise the API answers that the public price list was not found, and that sentence is shown on the page.

= Shortcode =

* `[maliured_cjenik]` — the last 30 days, every branch, newest snapshot first. The heading is “Objava cjenika”.
* `[maliured_cjenik datum="2026-09-26"]` — that calendar day. The heading is “Objava cjenika - 26. 9. 2026.”. Products are the snapshot from that day. Services are the latest snapshot created on or before that day, because a service snapshot is not repeated when the price did not change.
* `[maliured_cjenik datum="danas"]` — the calendar day on which the page is viewed, in the site timezone. The date is resolved on each request, then cached like any other day.

The date must be `YYYY-MM-DD`, or the word `danas`. Anything else is rejected in WordPress and is not sent to the API.

= What a row contains =

Each branch heading is the branch label and address. **Proizvodi** and **Usluge** are omitted when that list is empty. A row shows the date as `26. 9. 2026. 07:00`, the CSV file name linked to `csv_url`, and an **XML** link to `xml_url`. The row with `aktualno: true` is marked as the current snapshot.

The markup is wrapped in `maliured-cjenik`, and the stylesheet only targets that class.

== External services ==

This plugin connects to the MaliUred application in order to display a public price list.

The host is the one saved in the settings. The default is `https://app.maliured.hr`.

The request runs on the WordPress server when a page that contains the shortcode is rendered. It does not run in the visitor's browser, and it does not run on activation.

* Without a date: `GET {origin}/api/v1/cjenik/{company}`
* With a date: `GET {origin}/api/v1/cjenik/{company}/{YYYY-MM-DD}`

The company name is URL-encoded. The only data sent is that name and, when the shortcode has `datum`, the date. No token, account, cookie, or visitor IP is added by the plugin. The response is cached in a transient for 15 minutes. The cache key includes the company name, the API origin, and the date.

Service: [https://app.maliured.hr](https://app.maliured.hr)
Site: [https://maliured.hr](https://maliured.hr)
Terms: [https://maliured.hr/uvjeti-i-odredbe/](https://maliured.hr/uvjeti-i-odredbe/)

== Installation ==

1. Upload the `maliured-cjenik` folder to `/wp-content/plugins/`, or install the zip through **Plugins → Add New → Upload Plugin**. The zip must contain the folder `maliured-cjenik/` with `maliured-cjenik.php` inside it.
2. Activate **MaliUred Cjenik**.
3. Open **Settings → MaliUred cjenik** and save the company name.
4. Put `[maliured_cjenik]` on a page.

No account is created and nothing is called during activation.

== Frequently Asked Questions ==

= Does the visitor's browser call MaliUred? =

No. PHP calls the API with `wp_safe_remote_get` (timeout 10 seconds). The page receives HTML only.

= What does “Javni cjenik nije pronađen.” mean? =

The company name does not match MaliUred, or “Objavi cjenik javno” is turned off. The sentence is shown as text, not as JSON.

= What does “Nema cjenika za taj datum.” mean? =

There is no snapshot for the `datum` on the shortcode. That sentence is shown as text.

= How fresh is the list? =

The response is cached for 15 minutes. The morning product snapshot is created around 07:00, so a longer cache is not used. Pages that contain the shortcode set `DONOTCACHEPAGE` so a full-page cache does not keep the HTML past that window.

= Can two shortcodes on the site share a cache entry? =

No. The transient key includes the company name, the API origin, and the date. An empty date and a specific date are different keys.

== Changelog ==

= 1.0.0 =
* First release. Settings page, `[maliured_cjenik]` shortcode, and a 15-minute server-side cache.

== Upgrade Notice ==

= 1.0.0 =
First release.
