From deb259c8d2ee09cdbd3856d93b12bb7cd0bceec6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 6 May 2026 15:33:40 +0530 Subject: [PATCH 01/15] chore(deps): bump rack from 3.2.5 to 3.2.6 (#13987) Bumps [rack](https://github.com/rack/rack) from 3.2.5 to 3.2.6.
Release notes

Sourced from rack's releases.

v3.2.6

Full Changelog: https://github.com/rack/rack/compare/v3.2.5...v3.2.6

Changelog

Sourced from rack's changelog.

[3.2.6] - 2026-04-01

Security

Commits

Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Sony Mathew --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index d85999b57..f4d0277b4 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -684,7 +684,7 @@ GEM activesupport (>= 3.0.0) raabro (1.4.0) racc (1.8.1) - rack (3.2.5) + rack (3.2.6) rack-attack (6.7.0) rack (>= 1.0, < 4) rack-contrib (2.5.0) From dd52f1d32b6cd81cd0de817e1b7c3ad30a963bcb Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 6 May 2026 15:37:32 +0530 Subject: [PATCH 02/15] chore(deps): bump rack-session from 2.1.1 to 2.1.2 (#14017) Bumps [rack-session](https://github.com/rack/rack-session) from 2.1.1 to 2.1.2.
Changelog

Sourced from rack-session's changelog.

v2.1.2

  • CVE-2026-39324 Don't fall back to unencrypted coder if encryptors are present.
Commits
  • 504367b Bump patch version.
  • f43638c Don't fall back to unencrypted coder if encryptors are present.
  • dadcfe6 Bump actions/checkout from 4 to 5 (#54)
  • 4eb9ea8 Add top level session spec to validate existing formats.
  • 8f94577 Add rails to external tests.
  • 38ea47d Allow the v2 encryptor to serialize messages with Marshal (#44)
  • 43f2e3a Fix compatibility with older Rubies.
  • 6a060b8 Support UTF-8 data when using the JSON serializer (#39)
  • 8ce0146 Fix auth_tag retrieval on JRuby (#32)
  • 7727185 Add AEAD encryption (#23)
  • See full diff in compare view

[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=rack-session&package-manager=bundler&previous-version=2.1.1&new-version=2.1.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/chatwoot/chatwoot/network/alerts).
Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Sony Mathew --- Gemfile.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Gemfile.lock b/Gemfile.lock index f4d0277b4..bd21b7a36 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -699,7 +699,7 @@ GEM rack (>= 3.0.0, < 4) rack-proxy (0.7.7) rack - rack-session (2.1.1) + rack-session (2.1.2) base64 (>= 0.1.0) rack (>= 3.0.0) rack-test (2.1.0) From 8d7e926e06c815ecc40b51f448a2567c22f1ba94 Mon Sep 17 00:00:00 2001 From: Sojan Jose Date: Wed, 6 May 2026 16:33:16 +0530 Subject: [PATCH 03/15] fix: [Snyk] Security upgrade video.js from 7.18.1 to 7.21.1 (#13973) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg) ### Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project. #### Snyk changed the following file(s): - `package.json` #### Note for [zero-installs](https://yarnpkg.com/features/zero-installs) users If you are using the Yarn feature [zero-installs](https://yarnpkg.com/features/zero-installs) that was introduced in Yarn V2, note that this PR does not update the `.yarn/cache/` directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run `yarn` to update the contents of the `./yarn/cache` directory. If you are not using zero-install you can ignore this as your flow should likely be unchanged.
⚠️ Warning ``` Failed to update the yarn.lock, please update manually before merging. ```
#### Vulnerabilities that will be fixed with an upgrade: | | Issue | :-------------------------:|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | XML Injection
[SNYK-JS-XMLDOMXMLDOM-15869636](https://snyk.io/vuln/SNYK-JS-XMLDOMXMLDOM-15869636) --- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - Max score is 1000. Note that the real score may have changed since the PR was raised. > - This PR was automatically created by Snyk using the credentials of a real user. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: 🧐 [View latest project report](https://app.snyk.io/org/chatwoot/project/3ca3819e-26b5-4e23-ac65-184abd9a6f10?utm_source=github&utm_medium=referral&page=fix-pr) 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=github&utm_content=fix-pr-template) 🛠 [Adjust project settings](https://app.snyk.io/org/chatwoot/project/3ca3819e-26b5-4e23-ac65-184abd9a6f10?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read about Snyk's upgrade logic](https://docs.snyk.io/scan-with-snyk/snyk-open-source/manage-vulnerabilities/upgrade-package-versions-to-fix-vulnerabilities?utm_source=github&utm_content=fix-pr-template) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [XML Injection](https://learn.snyk.io/lesson/xxe/?loc=fix-pr) [//]: # 'snyk:metadata:{"breakingChangeRiskLevel":null,"FF_showPullRequestBreakingChanges":false,"FF_showPullRequestBreakingChangesWebSearch":false,"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"video.js","from":"7.18.1","to":"7.21.1"}],"env":"prod","issuesToFix":["SNYK-JS-XMLDOMXMLDOM-15869636","SNYK-JS-XMLDOMXMLDOM-15869636"],"prId":"a31a1fb5-a9f0-4513-9316-be8798abfd9c","prPublicId":"a31a1fb5-a9f0-4513-9316-be8798abfd9c","packageManager":"yarn","priorityScoreList":[null],"projectPublicId":"3ca3819e-26b5-4e23-ac65-184abd9a6f10","projectUrl":"https://app.snyk.io/org/chatwoot/project/3ca3819e-26b5-4e23-ac65-184abd9a6f10?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","pr-warning-shown"],"type":"auto","upgrade":["SNYK-JS-XMLDOMXMLDOM-15869636"],"vulns":["SNYK-JS-XMLDOMXMLDOM-15869636"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}' --------- Co-authored-by: snyk-bot Co-authored-by: Sony Mathew <2040199+sony-mathew@users.noreply.github.com> --- package.json | 2 +- pnpm-lock.yaml | 85 ++++++++++++++++++++------------------------------ 2 files changed, 35 insertions(+), 52 deletions(-) diff --git a/package.json b/package.json index 35e09cfbc..1fbef2b1f 100644 --- a/package.json +++ b/package.json @@ -94,7 +94,7 @@ "tinykeys": "^3.0.0", "turbolinks": "^5.2.0", "urlpattern-polyfill": "^10.0.0", - "video.js": "7.18.1", + "video.js": "7.21.1", "videojs-record": "4.5.0", "videojs-wavesurfer": "3.8.0", "virtua": "^0.48.6", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index d76d0a061..b018dbdfe 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -206,8 +206,8 @@ importers: specifier: ^10.0.0 version: 10.0.0 video.js: - specifier: 7.18.1 - version: 7.18.1 + specifier: 7.21.1 + version: 7.21.1 videojs-record: specifier: 4.5.0 version: 4.5.0 @@ -441,10 +441,6 @@ packages: engines: {node: '>=6.0.0'} hasBin: true - '@babel/runtime@7.25.6': - resolution: {integrity: sha512-VBj9MYyDb9tuLq7yzqjgzt6Q+IBQLrGZfdjOekyEirZPHxXWoTSGUTMrpsfi58Up73d13NfYLv8HT9vmznjzhQ==} - engines: {node: '>=6.9.0'} - '@babel/runtime@7.26.7': resolution: {integrity: sha512-AOPI3D+a8dXnja+iwsUqGRjr1BbZIe771sXdapOtYI531gSqpi92vXivKcq2asu/DFpdl1ceFAKZyRzK2PCVcQ==} engines: {node: '>=6.9.0'} @@ -1386,17 +1382,14 @@ packages: '@ungap/structured-clone@1.2.0': resolution: {integrity: sha512-zuVdFrMJiuCDQUMCzQaD6KL28MjnqqN8XnAqiEq9PNm/hCPTSGfrXCOfwj1ow4LFb/tNymJPwsNbVePc1xFqrQ==} + deprecated: Potential CWE-502 - Update to 1.3.1 or higher - '@videojs/http-streaming@2.13.1': - resolution: {integrity: sha512-1x3fkGSPyL0+iaS3/lTvfnPTtfqzfgG+ELQtPPtTvDwqGol9Mx3TNyZwtSTdIufBrqYRn7XybB/3QNMsyjq13A==} + '@videojs/http-streaming@2.15.1': + resolution: {integrity: sha512-/uuN3bVkEeJAdrhu5Hyb19JoUo3CMys7yf2C1vUjeL1wQaZ4Oe8JrZzRrnWZ0rjvPgKfNLPXQomsRtgrMoRMJQ==} engines: {node: '>=8', npm: '>=5'} peerDependencies: video.js: ^6 || ^7 - '@videojs/vhs-utils@3.0.4': - resolution: {integrity: sha512-hui4zOj2I1kLzDgf8QDVxD3IzrwjS/43KiS8IHQO0OeeSsb4pB/lgNt1NG7Dv0wMQfCccUpMVLGcK618s890Yg==} - engines: {node: '>=8', npm: '>=5'} - '@videojs/vhs-utils@3.0.5': resolution: {integrity: sha512-PKVgdo8/GReqdx512F+ombhS+Bzogiofy1LgAj4tN8PfdBx3HSS7V5WfJotKTqtOWGwVfSWsrYN/t09/DSryrw==} engines: {node: '>=8', npm: '>=5'} @@ -1570,8 +1563,8 @@ packages: '@vueuse/shared@12.0.0': resolution: {integrity: sha512-3i6qtcq2PIio5i/vVYidkkcgvmTjCqrf26u+Fd4LhnbBmIT6FN8y6q/GJERp8lfcB9zVEfjdV0Br0443qZuJpw==} - '@xmldom/xmldom@0.7.13': - resolution: {integrity: sha512-lm2GW5PkosIzccsaZIz7tp8cPADSIlIHWDFTR1N0SzfinhhYgeIQjFMz4rYzanCScr3DqQLeomUDArp6MWKm+g==} + '@xmldom/xmldom@0.8.13': + resolution: {integrity: sha512-KRYzxepc14G/CEpEGc3Yn+JKaAeT63smlDr+vjB8jRfgTBBI9wRj/nkQEO+ucV8p8I9bfKLWp37uHgFrbntPvw==} engines: {node: '>=10.0.0'} deprecated: this version has critical issues, please update to the latest version @@ -1618,8 +1611,8 @@ packages: activestorage@5.2.8: resolution: {integrity: sha512-bueFOxBGIAUdrjbLyBZ8Xlkcecy8vr05sCk5VV37BbFi+RehPoEjfvKX3iYYPY7RFVhl+L43W9/ZbN3xNNLPtQ==} - aes-decrypter@3.1.2: - resolution: {integrity: sha512-42nRwfQuPRj9R1zqZBdoxnaAmnIFyDi0MNyTVhjdFOd8fifXKKRfwIHIZ6AMn1or4x5WONzjwRTbTWcsIQ0O4A==} + aes-decrypter@3.1.3: + resolution: {integrity: sha512-VkG9g4BbhMBy+N5/XodDeV6F02chEk9IpgRTq/0bS80y4dzy79VH2Gtms02VXomf3HmyRe3yyJYkJ990ns+d6A==} agent-base@6.0.2: resolution: {integrity: sha512-RZNwNclF7+MS/8bDg70amg32dyeZGZxiDuQmZxKLAlQjr3jGyLx+4Kkk58UO7D2QdgFIQCovuSuZESne6RG6XQ==} @@ -3197,8 +3190,8 @@ packages: resolution: {integrity: sha512-Jo6dJ04CmSjuznwJSS3pUeWmd/H0ffTlkXXgwZi+eq1UCmqQwCh+eLsYOYCwY991i2Fah4h1BEMCx4qThGbsiA==} engines: {node: '>=10'} - m3u8-parser@4.7.0: - resolution: {integrity: sha512-48l/OwRyjBm+QhNNigEEcRcgbRvnUjL7rxs597HmW9QSNbyNvt+RcZ9T/d9vxi9A9z7EZrB1POtZYhdRlwYQkQ==} + m3u8-parser@4.8.0: + resolution: {integrity: sha512-UqA2a/Pw3liR6Df3gwxrqghCP17OpPlQj6RBPLYygf/ZSQ4MoSgvdvhvt35qV+3NaaA0FSZx93Ix+2brT1U7cA==} magic-string@0.30.11: resolution: {integrity: sha512-+Wri9p0QHMy+545hKww7YAu5NyzF8iomPL/RQazugQ9+Ez4Ic3mERMd8ZTX5rfK944j+560ZJi8iAwgak1Ac7A==} @@ -3309,8 +3302,8 @@ packages: mlly@1.8.1: resolution: {integrity: sha512-SnL6sNutTwRWWR/vcmCYHSADjiEesp5TGQQ0pXyLhW5IoeibRlF/CbSLailbB3CNqJUk9cVJ9dUDnbD7GrcHBQ==} - mpd-parser@0.21.0: - resolution: {integrity: sha512-NbpMJ57qQzFmfCiP1pbL7cGMbVTD0X1hqNgL0VYP1wLlZXLf/HtmvQpNkOA1AHkPVeGQng+7/jEtSvNUzV7Gdg==} + mpd-parser@0.22.1: + resolution: {integrity: sha512-fwBebvpyPUU8bOzvhX0VQZgSohncbgYwUyJJoTSNpmy7ccD2ryiCvM7oRkn/xQH5cv73/xU7rJSNCLjdGFor0Q==} hasBin: true mri@1.2.0: @@ -4497,8 +4490,8 @@ packages: utrie@1.0.2: resolution: {integrity: sha512-1MLa5ouZiOmQzUbjbu9VmjLzn1QLXBhwpUa7kdLUQK+KQ5KA9I1vk5U4YHe/X2Ch7PYnJfWuWT+VbuxbGwljhw==} - video.js@7.18.1: - resolution: {integrity: sha512-mnXdmkVcD5qQdKMZafDjqdhrnKGettZaGSVkExjACiylSB4r2Yt5W1bchsKmjFpfuNfszsMjTUnnoIWSSqoe/Q==} + video.js@7.21.1: + resolution: {integrity: sha512-AvHfr14ePDHCfW5Lx35BvXk7oIonxF6VGhSxocmTyqotkQpxwYdmt4tnQSV7MYzNrYHb0GI8tJMt20NDkCQrxg==} videojs-font@3.2.0: resolution: {integrity: sha512-g8vHMKK2/JGorSfqAZQUmYYNnXmfec4MLhwtEFS+mMs2IDY398GLysy6BH6K+aS1KMNu/xWZ8Sue/X/mdQPliA==} @@ -4981,10 +4974,6 @@ snapshots: dependencies: '@babel/types': 7.26.0 - '@babel/runtime@7.25.6': - dependencies: - regenerator-runtime: 0.14.1 - '@babel/runtime@7.26.7': dependencies: regenerator-runtime: 0.14.1 @@ -5919,22 +5908,16 @@ snapshots: '@ungap/structured-clone@1.2.0': {} - '@videojs/http-streaming@2.13.1(video.js@7.18.1)': + '@videojs/http-streaming@2.15.1(video.js@7.21.1)': dependencies: '@babel/runtime': 7.26.7 - '@videojs/vhs-utils': 3.0.4 - aes-decrypter: 3.1.2 + '@videojs/vhs-utils': 3.0.5 + aes-decrypter: 3.1.3 global: 4.4.0 - m3u8-parser: 4.7.0 - mpd-parser: 0.21.0 + m3u8-parser: 4.8.0 + mpd-parser: 0.22.1 mux.js: 6.0.1 - video.js: 7.18.1 - - '@videojs/vhs-utils@3.0.4': - dependencies: - '@babel/runtime': 7.26.7 - global: 4.4.0 - url-toolkit: 2.2.5 + video.js: 7.21.1 '@videojs/vhs-utils@3.0.5': dependencies: @@ -6213,7 +6196,7 @@ snapshots: transitivePeerDependencies: - typescript - '@xmldom/xmldom@0.7.13': {} + '@xmldom/xmldom@0.8.13': {} abab@2.0.6: {} @@ -6248,7 +6231,7 @@ snapshots: dependencies: spark-md5: 3.0.2 - aes-decrypter@3.1.2: + aes-decrypter@3.1.3: dependencies: '@babel/runtime': 7.26.7 '@videojs/vhs-utils': 3.0.5 @@ -8106,7 +8089,7 @@ snapshots: dependencies: yallist: 4.0.0 - m3u8-parser@4.7.0: + m3u8-parser@4.8.0: dependencies: '@babel/runtime': 7.26.7 '@videojs/vhs-utils': 3.0.5 @@ -8220,11 +8203,11 @@ snapshots: pkg-types: 1.3.1 ufo: 1.6.3 - mpd-parser@0.21.0: + mpd-parser@0.22.1: dependencies: '@babel/runtime': 7.26.7 '@videojs/vhs-utils': 3.0.5 - '@xmldom/xmldom': 0.7.13 + '@xmldom/xmldom': 0.8.13 global: 4.4.0 mri@1.2.0: {} @@ -9526,17 +9509,17 @@ snapshots: dependencies: base64-arraybuffer: 1.0.2 - video.js@7.18.1: + video.js@7.21.1: dependencies: - '@babel/runtime': 7.25.6 - '@videojs/http-streaming': 2.13.1(video.js@7.18.1) + '@babel/runtime': 7.26.7 + '@videojs/http-streaming': 2.15.1(video.js@7.21.1) '@videojs/vhs-utils': 3.0.5 '@videojs/xhr': 2.6.0 - aes-decrypter: 3.1.2 + aes-decrypter: 3.1.3 global: 4.4.0 keycode: 2.2.1 - m3u8-parser: 4.7.0 - mpd-parser: 0.21.0 + m3u8-parser: 4.8.0 + mpd-parser: 0.22.1 mux.js: 6.0.1 safe-json-parse: 4.0.0 videojs-font: 3.2.0 @@ -9547,7 +9530,7 @@ snapshots: videojs-record@4.5.0: dependencies: recordrtc: 5.6.2 - video.js: 7.18.1 + video.js: 7.21.1 videojs-wavesurfer: 3.8.0 webrtc-adapter: 9.0.1 @@ -9557,7 +9540,7 @@ snapshots: videojs-wavesurfer@3.8.0: dependencies: - video.js: 7.18.1 + video.js: 7.21.1 wavesurfer.js: 7.8.6 virtua@0.48.6(vue@3.5.12(typescript@5.6.2)): From 815593eec9c25fde840333c1b3b610be566eb042 Mon Sep 17 00:00:00 2001 From: Sivin Varghese <64252451+iamsivin@users.noreply.github.com> Date: Wed, 6 May 2026 17:33:23 +0530 Subject: [PATCH 04/15] feat: display conversation ID conversation view (#14381) --- .../conversation/ConversationHeader.vue | 22 ++++++++++++++++++- .../i18n/locale/en/conversation.json | 1 + 2 files changed, 22 insertions(+), 1 deletion(-) diff --git a/app/javascript/dashboard/components/widgets/conversation/ConversationHeader.vue b/app/javascript/dashboard/components/widgets/conversation/ConversationHeader.vue index 4edfd643c..4a46afe73 100644 --- a/app/javascript/dashboard/components/widgets/conversation/ConversationHeader.vue +++ b/app/javascript/dashboard/components/widgets/conversation/ConversationHeader.vue @@ -13,6 +13,8 @@ import { conversationListPageURL } from 'dashboard/helper/URLHelper'; import { snoozedReopenTime } from 'dashboard/helper/snoozeHelpers'; import { useInbox } from 'dashboard/composables/useInbox'; import { useI18n } from 'vue-i18n'; +import { copyTextToClipboard } from 'shared/helpers/clipboard'; +import { useAlert } from 'dashboard/composables'; const props = defineProps({ chat: { @@ -91,6 +93,15 @@ const hasMultipleInboxes = computed( ); const hasSlaPolicyId = computed(() => props.chat?.sla_policy_id); + +const copyConversationId = async () => { + try { + await copyTextToClipboard(String(props.chat.id)); + useAlert(t('CONVERSATION.HEADER.COPY_ID_SUCCESS')); + } catch (error) { + // error + } +};