=== UXD Textbook OER Theme ===
Version: 2.0.0
A WordPress theme for publishing open textbooks (adoption package)
Augusta University Professional Writing and Rhetoric Program
Funded by an Affordable Learning Georgia Transformation Grant

== REQUIREMENTS ==
* Self-hosted WordPress 6.0+ (or WordPress.com Business/Commerce plan —
  lower WordPress.com tiers do NOT allow custom theme uploads)
* PHP 7.4+
* No plugins required. ACF is optional (see PLUGINS below).

== INSTALLATION ==
1. Zip this folder (uxdtextbook-theme.zip already is).
2. WordPress admin → Appearance → Themes → Add New → Upload Theme.
3. Upload the zip and click Activate.
4. Settings → Reading → "Your homepage displays" → A static page is NOT
   required. Leave "Your latest posts" selected: the theme's
   front-page.php overrides it and renders the landing page.
5. Settings → Permalinks → choose "Post name" and Save (this flushes
   rewrite rules so /chapters/ URLs work).
6. Settings → General → set Site Title ("User Research Methods" or
   similar) and Tagline; both appear in the header and hero.

== ADDING CONTENT ==
CHAPTERS
* Admin → Chapters → Add New Chapter.
* Write content with H2 headings for major sections. The sidebar table
  of contents is generated automatically from H2s — never skip from
  H1 to H3 (this is also an accessibility requirement).
* Fill in the Chapter Details box (right sidebar):
  - Chapter number — REQUIRED. Controls ordering on the landing page
    and prev/next navigation.
  - Authors, Course(s), Version, DOI as available.
  - PDF URL: upload the chapter PDF to Media Library, copy its URL,
    paste here. The download button appears automatically.
* Add an Excerpt (one to two sentences) — it becomes the chapter-card
  description on the landing page.

PAGES (About, Contributors, Accessibility Statement, etc.)
* Admin → Pages → Add New. Every published page automatically appears
  in the "About this book" section of the landing page AND in the
  fallback header menu. Add an Excerpt for a card description.
* Use Page Attributes → Order to control listing order.

CONCEPTS & TERMS (glossary, at /concepts/)
* Admin → Concepts & Terms → Add New Concept.
* Title = the concept; body = the definition (paragraphs, lists, and
  links all work).
* Entries alphabetize and letter-group automatically on /concepts/.
  Individual entry URLs redirect to that consolidated page, so the
  glossary always reads as one document.
* Definitions must follow project reference rules: real, verifiable
  sources with genuine in-text attribution.

UX Q&A (at /ux-qa/)
* Admin → UX Q&A → Add New Question.
* Title = the question; body = the answer.
* Control display order with Page Attributes → Order (lower numbers
  first); ties sort alphabetically.
* Rendered as native expand/collapse (<details>/<summary>) — keyboard
  accessible with no JavaScript.

CONTRIBUTOR INTEREST FORM (QUALTRICS)
* Build the interest survey in Augusta University's Qualtrics. Before
  publishing it, run Qualtrics' own checker: Tools → Review → Check
  Survey Accessibility, and fix everything it flags. Prefer simple
  question types (text entry, single/multiple choice); avoid matrix
  tables and timed questions, which are hostile to screen readers.
* Get the anonymous survey link (Distributions → Anonymous Link).
* In WordPress: create a Page (e.g., "Contribute") → set its Template
  to "Contributor Interest Form" → paste the survey URL into the
  "Qualtrics Form" box → publish. Your call-for-contributors text in
  the page body renders above the form link.
* Display mode: the default is a prominent LINK to the survey — this
  is the more accessible option, because Qualtrics' own page handles
  zoom, mobile layout, and focus correctly. Tick "Embed the survey"
  only if you strongly prefer an on-page form; embed mode always
  includes a full-page link as an escape hatch.
* Responses live in Qualtrics, under institutional data governance —
  nothing is stored in WordPress.
* Add the form page (or the survey itself) to the "embedded
  third-party content" item of your Accessibility Statement.

MENUS (optional)
* The header builds itself from your pages until you create a menu.
  For manual control: Appearance → Menus → assign to "Primary Menu".

== ACCESSIBILITY: WHAT THE THEME COVERS AND WHAT IT CANNOT ==
This theme is built to WCAG 2.1 AA: skip link, landmark regions,
visible focus indicators, contrast-verified palette, keyboard-operable
navigation, reduced-motion support, aria-current on navigation,
accessible names on all nav regions, and print styles.

IMPORTANT: a theme cannot make a SITE compliant. Compliance depends on
the content you publish. Editors must:
* Write alt text for every image (decorative images: empty alt).
* Maintain heading hierarchy (H2 → H3, never skipped levels).
* Ensure linked PDFs are themselves accessible (tagged, with reading
  order — export from Word with "Document structure tags" enabled).
* Use descriptive link text ("Download Chapter 3 PDF", not "click here").
* Caption any video content.
After launch, run WAVE (wave.webaim.org) and Deque axe audits, fix
findings, and publish an Accessibility Statement page.

== SECURITY ==
THEME DESIGN (what the code enforces)
* Zero public write endpoints: the theme accepts no front-end form
  submissions, registers no AJAX or REST write routes, and runs no
  inline JavaScript. All visitor-facing pages are read-only.
* All admin input is nonce-verified, capability-checked, and
  sanitized; all output is escaped.
* The Qualtrics URL only accepts https addresses on qualtrics.com or
  augusta.edu (subdomains included) — a compromised editor account
  cannot point or embed the contribute page at an arbitrary external
  site. Extend hosts via the 'uxtb_qx_allowed_hosts' filter.
* The survey iframe is sandboxed and sends a restricted referrer.
* Student/contributor content passes through WordPress's kses
  filtering automatically for any user role below Editor — scripts
  and dangerous markup are stripped from their posts at save time.

OPERATIONAL HARDENING (what only the site owner can do — the theme
cannot protect a site with weak operations):
1. Add to wp-config.php: define( 'DISALLOW_FILE_EDIT', true );
   This removes the admin Theme/Plugin file editors — the single most
   common path from a stolen password to full site takeover.
2. Give student contributors the CONTRIBUTOR role (can draft, cannot
   publish or upload files). Reserve Administrator for yourself alone;
   a graduate assistant who publishes can be an Editor.
3. Enable two-factor authentication for all Editor+ accounts
   (Wordfence Login Security or Two-Factor plugin) and use long
   passphrases. Never use "admin" as a username.
4. Keep WordPress core, the theme, and all plugins updated. Enable
   auto-updates for minor core releases (on by default).
5. Run your planned stack: Really Simple SSL (force HTTPS),
   UpdraftPlus (scheduled OFF-SITE backups — a backup stored only on
   the same server dies with the server).
6. Limit login attempts (Limit Login Attempts Reloaded or Wordfence)
   and disable XML-RPC if nothing uses it.
7. Remove unused themes and plugins entirely — deactivated code is
   still attackable code.

== RECOMMENDED PLUGINS (optional) ==
* Advanced Custom Fields — only if you want a richer editing UI; the
  theme's native Chapter Details box uses the same meta keys
  (chapter_number, chapter_authors, chapter_pdf, chapter_doi,
  chapter_version, chapter_course), so ACF fields named identically
  will interoperate.
* Yoast SEO, W3 Total Cache, UpdraftPlus, Really Simple SSL — as
  previously planned for the site.

== LICENSE ==
GPL v2 or later. Content published with the theme is intended for
CC BY 4.0 licensing per the ALG grant.
