<?xml version="1.0"?>
<ruleset name="Yatoon Booking System">
    <description>
        Coding standard for Yatoon Booking System.

        Replaces the blanket `phpcs:ignoreFile` headers that used to sit on 14
        view templates. Those suppressed every sniff in the file, including the
        security ones -- which is how 66 unescaped-output findings sat unseen.
        The exclusions below are narrow and deliberate: formatting conventions
        this codebase has not adopted, and rules that do not apply to a plugin
        using its own tables. Everything in WordPress.Security stays on.
    </description>

    <file>.</file>

    <exclude-pattern>/vendor/*</exclude-pattern>
    <exclude-pattern>/node_modules/*</exclude-pattern>
    <exclude-pattern>*.min.js</exclude-pattern>
    <exclude-pattern>*.min.css</exclude-pattern>
    <exclude-pattern>/languages/*</exclude-pattern>

    <arg name="extensions" value="php"/>
    <arg name="colors"/>
    <arg value="ps"/>

    <config name="minimum_wp_version" value="5.8"/>
    <config name="testVersion" value="7.4-"/>

    <rule ref="WordPress-Extra">
        <!--
            Formatting only. This codebase indents with spaces and does not use
            Yoda conditions or WPCS alignment rules. Enforcing them now would
            mean a 22,000-line whitespace diff across every template, which
            buys nothing and makes the next real change unreviewable. Revisit
            as a standalone formatting-only commit if desired.
        -->
        <exclude name="Generic.WhiteSpace.DisallowSpaceIndent"/>
        <exclude name="Generic.WhiteSpace.ScopeIndent"/>
        <exclude name="Universal.WhiteSpace.PrecisionAlignment"/>
        <exclude name="Generic.Formatting.MultipleStatementAlignment"/>
        <exclude name="WordPress.Arrays.MultipleStatementAlignment"/>
        <exclude name="WordPress.PHP.YodaConditions"/>
        <exclude name="Universal.Operators.DisallowShortTernary"/>
        <exclude name="PEAR.Functions.FunctionCallSignature"/>
        <exclude name="Squiz.ControlStructures.ControlSignature"/>
        <exclude name="WordPress.WhiteSpace.ControlStructureSpacing"/>
        <exclude name="WordPress.WhiteSpace.OperatorSpacing"/>
        <exclude name="WordPress.WhiteSpace.CastStructureSpacing"/>
        <exclude name="Generic.Functions.FunctionCallArgumentSpacing"/>
        <exclude name="NormalizedArrays.Arrays.ArrayBraceSpacing"/>
        <exclude name="Universal.WhiteSpace.CommaSpacing"/>
        <exclude name="WordPress.Arrays.ArrayDeclarationSpacing"/>
        <exclude name="Squiz.PHP.EmbeddedPhp"/>

        <!--
            The plugin owns 19 custom tables; every read is a deliberate direct
            query with its own caching strategy. These are asserted per-call
            with inline phpcs:ignore comments where the reasoning is specific.
        -->
        <exclude name="WordPress.DB.DirectDatabaseQuery.DirectQuery"/>
        <exclude name="WordPress.DB.DirectDatabaseQuery.NoCaching"/>
        <exclude name="WordPress.DB.DirectDatabaseQuery.SchemaChange"/>

        <!--
            View templates receive their variables from the including class,
            not from a global scope they define.
        -->
        <exclude name="WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound"/>
    </rule>

    <!--
        Security sniffs are the reason this file exists. Kept explicit and
        un-excluded so that adding a broad exclusion above can never silently
        turn them off.
    -->
    <rule ref="WordPress.Security.EscapeOutput"/>
    <rule ref="WordPress.Security.NonceVerification"/>
    <rule ref="WordPress.Security.ValidatedSanitizedInput"/>
    <rule ref="WordPress.Security.SafeRedirect"/>
    <rule ref="WordPress.DB.PreparedSQL"/>
    <rule ref="WordPress.DB.PreparedSQLPlaceholders"/>

    <!-- Every user-facing string must be translatable and use our domain. -->
    <rule ref="WordPress.WP.I18n">
        <properties>
            <property name="text_domain" type="array">
                <element value="yatoon-booking-system"/>
            </property>
        </properties>
    </rule>
</ruleset>
