diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile index 3fd4f1a31..9e8c36fdb 100644 --- a/.devcontainer/Dockerfile +++ b/.devcontainer/Dockerfile @@ -4,5 +4,15 @@ FROM ghcr.io/chatwoot/chatwoot_codespace:latest # Do the set up required for chatwoot app WORKDIR /workspace + +# Copy dependency files first for better caching +COPY package.json pnpm-lock.yaml ./ +COPY Gemfile Gemfile.lock ./ + +# Install dependencies (will be cached if files don't change) +RUN pnpm install --frozen-lockfile && \ + gem install bundler && \ + bundle install --jobs=$(nproc) + +# Copy source code after dependencies are installed COPY . /workspace -RUN yarn && gem install bundler && bundle install diff --git a/.devcontainer/Dockerfile.base b/.devcontainer/Dockerfile.base index fe31dc42e..2b74602b8 100644 --- a/.devcontainer/Dockerfile.base +++ b/.devcontainer/Dockerfile.base @@ -1,12 +1,16 @@ - -ARG VARIANT +ARG VARIANT="ubuntu-22.04" FROM mcr.microsoft.com/vscode/devcontainers/base:0-${VARIANT} +ENV DEBIAN_FRONTEND=noninteractive + ARG NODE_VERSION ARG RUBY_VERSION ARG USER_UID ARG USER_GID +ARG PNPM_VERSION="10.2.0" +ENV PNPM_VERSION ${PNPM_VERSION} +ENV RUBY_CONFIGURE_OPTS=--disable-install-doc # Update args in docker-compose.yaml to set the UID/GID of the "vscode" user. RUN if [ "$USER_GID" != "1000" ] || [ "$USER_UID" != "1000" ]; then \ @@ -15,61 +19,80 @@ RUN if [ "$USER_GID" != "1000" ] || [ "$USER_UID" != "1000" ]; then \ && chmod -R $USER_UID:$USER_GID /home/vscode; \ fi -RUN apt-get update && export DEBIAN_FRONTEND=noninteractive \ - && apt-get -y install --no-install-recommends \ - build-essential \ - libssl-dev \ - zlib1g-dev \ - gnupg2 \ - tar \ - tzdata \ - postgresql-client \ - libpq-dev \ - yarn \ - git \ - imagemagick \ - tmux \ - zsh \ - git-flow \ - npm \ - libyaml-dev +RUN NODE_MAJOR=$(echo $NODE_VERSION | cut -d. -f1) \ + && curl -fsSL https://deb.nodesource.com/setup_${NODE_MAJOR}.x | bash - \ + && apt-get update \ + && apt-get -y install --no-install-recommends \ + build-essential \ + libssl-dev \ + zlib1g-dev \ + gnupg \ + tar \ + tzdata \ + postgresql-client \ + libpq-dev \ + git \ + imagemagick \ + libyaml-dev \ + curl \ + ca-certificates \ + tmux \ + nodejs \ + && apt-get clean \ + && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* -# Install rbenv and ruby -RUN git clone https://github.com/rbenv/rbenv.git ~/.rbenv \ +# Install rbenv and ruby for root user first +RUN git clone --depth 1 https://github.com/rbenv/rbenv.git ~/.rbenv \ && echo 'export PATH="$HOME/.rbenv/bin:$PATH"' >> ~/.bashrc \ && echo 'eval "$(rbenv init -)"' >> ~/.bashrc ENV PATH "/root/.rbenv/bin/:/root/.rbenv/shims/:$PATH" -RUN git clone https://github.com/rbenv/ruby-build.git && \ +RUN git clone --depth 1 https://github.com/rbenv/ruby-build.git && \ PREFIX=/usr/local ./ruby-build/install.sh RUN rbenv install $RUBY_VERSION && \ rbenv global $RUBY_VERSION && \ rbenv versions -# Install overmind +# Set up rbenv for vscode user +RUN su - vscode -c "git clone --depth 1 https://github.com/rbenv/rbenv.git ~/.rbenv" \ + && su - vscode -c "echo 'export PATH=\"\$HOME/.rbenv/bin:\$PATH\"' >> ~/.bashrc" \ + && su - vscode -c "echo 'eval \"\$(rbenv init -)\"' >> ~/.bashrc" \ + && su - vscode -c "PATH=\"/home/vscode/.rbenv/bin:\$PATH\" rbenv install $RUBY_VERSION" \ + && su - vscode -c "PATH=\"/home/vscode/.rbenv/bin:\$PATH\" rbenv global $RUBY_VERSION" + +# Install overmind and gh in single layer RUN curl -L https://github.com/DarthSim/overmind/releases/download/v2.1.0/overmind-v2.1.0-linux-amd64.gz > overmind.gz \ && gunzip overmind.gz \ - && sudo mv overmind /usr/local/bin \ - && chmod +x /usr/local/bin/overmind - - -# Install gh -RUN curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \ - && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null \ - && sudo apt update \ - && sudo apt install gh + && mv overmind /usr/local/bin \ + && chmod +x /usr/local/bin/overmind \ + && curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \ + && echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | tee /etc/apt/sources.list.d/github-cli.list > /dev/null \ + && apt-get update \ + && apt-get install -y --no-install-recommends gh \ + && apt-get clean \ + && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* # Do the set up required for chatwoot app WORKDIR /workspace -COPY . /workspace +RUN chown vscode:vscode /workspace -# set up ruby -COPY Gemfile Gemfile.lock ./ -RUN gem install bundler && bundle install +# set up node js and pnpm in single layer +RUN npm install -g pnpm@${PNPM_VERSION} \ + && npm cache clean --force -# set up node js -RUN npm install n -g && \ - n $NODE_VERSION -RUN npm install --global yarn -RUN yarn +# Switch to vscode user +USER vscode +ENV PATH="/home/vscode/.rbenv/bin:/home/vscode/.rbenv/shims:$PATH" + +# Copy dependency files first for better caching +COPY --chown=vscode:vscode Gemfile Gemfile.lock package.json pnpm-lock.yaml ./ + +# Install dependencies as vscode user +RUN eval "$(rbenv init -)" \ + && gem install bundler -N \ + && bundle install --jobs=$(nproc) \ + && pnpm install --frozen-lockfile + +# Copy source code after dependencies are installed +COPY --chown=vscode:vscode . /workspace diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json index d2dac356b..c51338b51 100644 --- a/.devcontainer/devcontainer.json +++ b/.devcontainer/devcontainer.json @@ -23,15 +23,15 @@ // 5432 postgres // 6379 redis // 1025,8025 mailhog - "forwardPorts": [8025, 3000, 3035], + "forwardPorts": [8025, 3000, 3036], - "postCreateCommand": ".devcontainer/scripts/setup.sh && POSTGRES_STATEMENT_TIMEOUT=600s bundle exec rake db:chatwoot_prepare && yarn", + "postCreateCommand": ".devcontainer/scripts/setup.sh && POSTGRES_STATEMENT_TIMEOUT=600s bundle exec rake db:chatwoot_prepare && pnpm install", "portsAttributes": { "3000": { "label": "Rails Server" }, - "3035": { - "label": "Webpack Dev Server" + "3036": { + "label": "Vite Dev Server" }, "8025": { "label": "Mailhog UI" diff --git a/.devcontainer/docker-compose.base.yml b/.devcontainer/docker-compose.base.yml new file mode 100644 index 000000000..6932b5f10 --- /dev/null +++ b/.devcontainer/docker-compose.base.yml @@ -0,0 +1,18 @@ +# Docker Compose file for building the base image in GitHub Actions +# Usage: docker-compose -f .devcontainer/docker-compose.base.yml build base + +version: '3' + +services: + base: + build: + context: .. + dockerfile: .devcontainer/Dockerfile.base + args: + VARIANT: 'ubuntu-22.04' + NODE_VERSION: '23.7.0' + RUBY_VERSION: '3.4.4' + # On Linux, you may need to update USER_UID and USER_GID below if not your local UID is not 1000. + USER_UID: '1000' + USER_GID: '1000' + image: ghcr.io/chatwoot/chatwoot_codespace:latest diff --git a/.devcontainer/docker-compose.yml b/.devcontainer/docker-compose.yml index 21a9fe909..a9185ea09 100644 --- a/.devcontainer/docker-compose.yml +++ b/.devcontainer/docker-compose.yml @@ -5,19 +5,6 @@ version: '3' services: - base: - build: - context: .. - dockerfile: .devcontainer/Dockerfile.base - args: - VARIANT: 'ubuntu-22.04' - NODE_VERSION: '23.7.0' - RUBY_VERSION: '3.4.4' - # On Linux, you may need to update USER_UID and USER_GID below if not your local UID is not 1000. - USER_UID: '1000' - USER_GID: '1000' - image: base:latest - app: build: context: .. diff --git a/.devcontainer/scripts/setup.sh b/.devcontainer/scripts/setup.sh index 4ffee2d3a..6beb2ff57 100755 --- a/.devcontainer/scripts/setup.sh +++ b/.devcontainer/scripts/setup.sh @@ -2,12 +2,7 @@ cp .env.example .env sed -i -e '/REDIS_URL/ s/=.*/=redis:\/\/localhost:6379/' .env sed -i -e '/POSTGRES_HOST/ s/=.*/=localhost/' .env sed -i -e '/SMTP_ADDRESS/ s/=.*/=localhost/' .env -sed -i -e "/FRONTEND_URL/ s/=.*/=https:\/\/$CODESPACE_NAME-3000.githubpreview.dev/" .env -sed -i -e "/WEBPACKER_DEV_SERVER_PUBLIC/ s/=.*/=https:\/\/$CODESPACE_NAME-3035.githubpreview.dev/" .env -# uncomment the webpacker env variable -sed -i -e '/WEBPACKER_DEV_SERVER_PUBLIC/s/^# //' .env -# fix the error with webpacker -echo 'export NODE_OPTIONS=--openssl-legacy-provider' >> ~/.zshrc +sed -i -e "/FRONTEND_URL/ s/=.*/=https:\/\/$CODESPACE_NAME-3000.app.github.dev/" .env # codespaces make the ports public -gh codespace ports visibility 3000:public 3035:public 8025:public -c $CODESPACE_NAME +gh codespace ports visibility 3000:public 3036:public 8025:public -c $CODESPACE_NAME diff --git a/.github/workflows/publish_codespace_image.yml b/.github/workflows/publish_codespace_image.yml index 647608473..5da4fda05 100644 --- a/.github/workflows/publish_codespace_image.yml +++ b/.github/workflows/publish_codespace_image.yml @@ -19,6 +19,5 @@ jobs: - name: Build the Codespace Base Image run: | - docker-compose -f .devcontainer/docker-compose.yml build base - docker tag base:latest ghcr.io/chatwoot/chatwoot_codespace:latest + docker compose -f .devcontainer/docker-compose.base.yml build base docker push ghcr.io/chatwoot/chatwoot_codespace:latest diff --git a/app/controllers/api/v1/accounts/agent_bots_controller.rb b/app/controllers/api/v1/accounts/agent_bots_controller.rb index 1422beea1..64c35d33d 100644 --- a/app/controllers/api/v1/accounts/agent_bots_controller.rb +++ b/app/controllers/api/v1/accounts/agent_bots_controller.rb @@ -29,6 +29,11 @@ class Api::V1::Accounts::AgentBotsController < Api::V1::Accounts::BaseController head :ok end + def reset_access_token + @agent_bot.access_token.regenerate_token + @agent_bot.reload + end + private def agent_bot diff --git a/app/controllers/api/v1/profiles_controller.rb b/app/controllers/api/v1/profiles_controller.rb index ae1a1fe30..141253d0d 100644 --- a/app/controllers/api/v1/profiles_controller.rb +++ b/app/controllers/api/v1/profiles_controller.rb @@ -38,6 +38,11 @@ class Api::V1::ProfilesController < Api::BaseController head :ok end + def reset_access_token + @user.access_token.regenerate_token + @user.reload + end + private def set_user diff --git a/app/javascript/dashboard/api/agentBots.js b/app/javascript/dashboard/api/agentBots.js index 6e59f38d3..de887f415 100644 --- a/app/javascript/dashboard/api/agentBots.js +++ b/app/javascript/dashboard/api/agentBots.js @@ -21,6 +21,10 @@ class AgentBotsAPI extends ApiClient { deleteAgentBotAvatar(botId) { return axios.delete(`${this.url}/${botId}/avatar`); } + + resetAccessToken(botId) { + return axios.post(`${this.url}/${botId}/reset_access_token`); + } } export default new AgentBotsAPI(); diff --git a/app/javascript/dashboard/api/auth.js b/app/javascript/dashboard/api/auth.js index dde817866..75e7e2953 100644 --- a/app/javascript/dashboard/api/auth.js +++ b/app/javascript/dashboard/api/auth.js @@ -102,4 +102,8 @@ export default { const urlData = endPoints('resendConfirmation'); return axios.post(urlData.url); }, + resetAccessToken() { + const urlData = endPoints('resetAccessToken'); + return axios.post(urlData.url); + }, }; diff --git a/app/javascript/dashboard/api/endPoints.js b/app/javascript/dashboard/api/endPoints.js index 31337b7fc..5409aac60 100644 --- a/app/javascript/dashboard/api/endPoints.js +++ b/app/javascript/dashboard/api/endPoints.js @@ -51,6 +51,9 @@ const endPoints = { resendConfirmation: { url: '/api/v1/profile/resend_confirmation', }, + resetAccessToken: { + url: '/api/v1/profile/reset_access_token', + }, }; export default page => { diff --git a/app/javascript/dashboard/api/specs/agentBots.spec.js b/app/javascript/dashboard/api/specs/agentBots.spec.js index c89dbfdf5..bf57804c0 100644 --- a/app/javascript/dashboard/api/specs/agentBots.spec.js +++ b/app/javascript/dashboard/api/specs/agentBots.spec.js @@ -9,5 +9,6 @@ describe('#AgentBotsAPI', () => { expect(AgentBotsAPI).toHaveProperty('create'); expect(AgentBotsAPI).toHaveProperty('update'); expect(AgentBotsAPI).toHaveProperty('delete'); + expect(AgentBotsAPI).toHaveProperty('resetAccessToken'); }); }); diff --git a/app/javascript/dashboard/components-next/button/ConfirmButton.story.vue b/app/javascript/dashboard/components-next/button/ConfirmButton.story.vue new file mode 100644 index 000000000..673661a74 --- /dev/null +++ b/app/javascript/dashboard/components-next/button/ConfirmButton.story.vue @@ -0,0 +1,41 @@ + + + diff --git a/app/javascript/dashboard/components-next/button/ConfirmButton.vue b/app/javascript/dashboard/components-next/button/ConfirmButton.vue new file mode 100644 index 000000000..854d5d452 --- /dev/null +++ b/app/javascript/dashboard/components-next/button/ConfirmButton.vue @@ -0,0 +1,99 @@ + + + + + diff --git a/app/javascript/dashboard/composables/usePolicy.js b/app/javascript/dashboard/composables/usePolicy.js index dc203cbac..a76ffbf1d 100644 --- a/app/javascript/dashboard/composables/usePolicy.js +++ b/app/javascript/dashboard/composables/usePolicy.js @@ -129,6 +129,7 @@ export function usePolicy() { return { checkPermissions, shouldShowPaywall, + isFeatureFlagEnabled, shouldShow, }; } diff --git a/app/javascript/dashboard/i18n/locale/en/agentBots.json b/app/javascript/dashboard/i18n/locale/en/agentBots.json index 194cfb999..d3a0bb991 100644 --- a/app/javascript/dashboard/i18n/locale/en/agentBots.json +++ b/app/javascript/dashboard/i18n/locale/en/agentBots.json @@ -62,7 +62,9 @@ "ACCESS_TOKEN": { "TITLE": "Access Token", "DESCRIPTION": "Copy the access token and save it securely", - "COPY_SUCCESSFUL": "Access token copied to clipboard" + "COPY_SUCCESSFUL": "Access token copied to clipboard", + "RESET_SUCCESS": "Access token regenerated successfully", + "RESET_ERROR": "Unable to regenerate access token. Please try again" }, "FORM": { "AVATAR": { diff --git a/app/javascript/dashboard/i18n/locale/en/settings.json b/app/javascript/dashboard/i18n/locale/en/settings.json index daced76dd..81b9c8a78 100644 --- a/app/javascript/dashboard/i18n/locale/en/settings.json +++ b/app/javascript/dashboard/i18n/locale/en/settings.json @@ -76,7 +76,12 @@ "ACCESS_TOKEN": { "TITLE": "Access Token", "NOTE": "This token can be used if you are building an API based integration", - "COPY": "Copy" + "COPY": "Copy", + "RESET": "Reset", + "CONFIRM_RESET": "Are you sure?", + "CONFIRM_HINT": "Click again to confirm", + "RESET_SUCCESS": "Access token regenerated successfully", + "RESET_ERROR": "Unable to regenerate access token. Please try again" }, "AUDIO_NOTIFICATIONS_SECTION": { "TITLE": "Audio Alerts", diff --git a/app/javascript/dashboard/modules/search/components/SearchView.vue b/app/javascript/dashboard/modules/search/components/SearchView.vue index bd48a3078..49efca67b 100644 --- a/app/javascript/dashboard/modules/search/components/SearchView.vue +++ b/app/javascript/dashboard/modules/search/components/SearchView.vue @@ -10,10 +10,8 @@ import { CONTACT_PERMISSIONS, PORTAL_PERMISSIONS, } from 'dashboard/constants/permissions.js'; -import { - getUserPermissions, - filterItemsByPermission, -} from 'dashboard/helper/permissionsHelper.js'; +import { usePolicy } from 'dashboard/composables/usePolicy'; +import { FEATURE_FLAGS } from 'dashboard/featureFlags'; import { CONVERSATION_EVENTS } from '../../../helper/AnalyticsHelper/events'; import Policy from 'dashboard/components/policy.vue'; @@ -39,8 +37,6 @@ const pages = ref({ articles: 1, }); -const currentUser = useMapGetter('getCurrentUser'); -const currentAccountId = useMapGetter('getCurrentAccountId'); const contactRecords = useMapGetter('conversationSearch/getContactRecords'); const conversationRecords = useMapGetter( 'conversationSearch/getConversationRecords' @@ -83,9 +79,7 @@ const filterConversations = filterByTab('conversations'); const filterMessages = filterByTab('messages'); const filterArticles = filterByTab('articles'); -const userPermissions = computed(() => - getUserPermissions(currentUser.value, currentAccountId.value) -); +const { shouldShow, isFeatureFlagEnabled } = usePolicy(); const TABS_CONFIG = { all: { @@ -111,47 +105,67 @@ const TABS_CONFIG = { }, articles: { permissions: [...ROLES, PORTAL_PERMISSIONS], + featureFlag: FEATURE_FLAGS.HELP_CENTER, count: () => mappedArticles.value.length, }, }; const tabs = computed(() => { - const configs = Object.entries(TABS_CONFIG).map(([key, config]) => ({ - key, - name: t(`SEARCH.TABS.${key.toUpperCase()}`), - count: config.count(), - showBadge: key !== 'all', - permissions: config.permissions, - })); - - return filterItemsByPermission( - configs, - userPermissions.value, - item => item.permissions - ); + return Object.entries(TABS_CONFIG) + .map(([key, config]) => ({ + key, + name: t(`SEARCH.TABS.${key.toUpperCase()}`), + count: config.count(), + showBadge: key !== 'all', + permissions: config.permissions, + featureFlag: config.featureFlag, + })) + .filter(config => { + // why the double check, glad you asked. + // Some features are marked as premium features, that means + // the feature will be visible, but a Paywall will be shown instead + // this works for pages and routes, but fails for UI elements like search here + // so we explicitly check if the feature is enabled + return ( + shouldShow(config.featureFlag, config.permissions, null) && + isFeatureFlagEnabled(config.featureFlag) + ); + }); }); const totalSearchResultsCount = computed(() => { - const permissionCounts = { - contacts: { + const permissionCounts = [ + { permissions: [...ROLES, CONTACT_PERMISSIONS], count: () => contacts.value.length, }, - conversations: { + { permissions: [...ROLES, ...CONVERSATION_PERMISSIONS], count: () => conversations.value.length + messages.value.length, }, - articles: { + { permissions: [...ROLES, PORTAL_PERMISSIONS], + featureFlag: FEATURE_FLAGS.HELP_CENTER, count: () => articles.value.length, }, - }; - return filterItemsByPermission( - permissionCounts, - userPermissions.value, - item => item.permissions, - (_, item) => item.count - ).reduce((total, count) => total + count(), 0); + ]; + + return permissionCounts + .filter(config => { + // why the double check, glad you asked. + // Some features are marked as premium features, that means + // the feature will be visible, but a Paywall will be shown instead + // this works for pages and routes, but fails for UI elements like search here + // so we explicitly check if the feature is enabled + return ( + shouldShow(config.featureFlag, config.permissions, null) && + isFeatureFlagEnabled(config.featureFlag) + ); + }) + .map(config => { + return config.count(); + }) + .reduce((sum, count) => sum + count, 0); }); const activeTabIndex = computed(() => { @@ -355,7 +369,9 @@ onUnmounted(() => { { const onCopyToken = async value => { await copyTextToClipboard(value); - useAlert(t('COMPONENTS.CODE.COPY_SUCCESSFUL')); + useAlert(t('AGENT_BOTS.ACCESS_TOKEN.COPY_SUCCESSFUL')); +}; + +const onResetToken = async () => { + const response = await store.dispatch( + 'agentBots/resetAccessToken', + props.selectedBot.id + ); + if (response) { + accessToken.value = response.access_token; + useAlert(t('AGENT_BOTS.ACCESS_TOKEN.RESET_SUCCESS')); + } else { + useAlert(t('AGENT_BOTS.ACCESS_TOKEN.RESET_ERROR')); + } }; const closeModal = () => { @@ -312,7 +325,18 @@ defineExpose({ dialogRef }); > {{ $t('AGENT_BOTS.ACCESS_TOKEN.TITLE') }} - + +
diff --git a/app/javascript/dashboard/routes/dashboard/settings/profile/AccessToken.vue b/app/javascript/dashboard/routes/dashboard/settings/profile/AccessToken.vue index abf547b69..5b0b43fac 100644 --- a/app/javascript/dashboard/routes/dashboard/settings/profile/AccessToken.vue +++ b/app/javascript/dashboard/routes/dashboard/settings/profile/AccessToken.vue @@ -1,14 +1,17 @@ diff --git a/app/javascript/dashboard/routes/dashboard/settings/profile/Index.vue b/app/javascript/dashboard/routes/dashboard/settings/profile/Index.vue index 45a060e05..eedcd21f1 100644 --- a/app/javascript/dashboard/routes/dashboard/settings/profile/Index.vue +++ b/app/javascript/dashboard/routes/dashboard/settings/profile/Index.vue @@ -181,6 +181,14 @@ export default { await copyTextToClipboard(value); useAlert(this.$t('COMPONENTS.CODE.COPY_SUCCESSFUL')); }, + async resetAccessToken() { + const success = await this.$store.dispatch('resetAccessToken'); + if (success) { + useAlert(this.$t('PROFILE_SETTINGS.FORM.ACCESS_TOKEN.RESET_SUCCESS')); + } else { + useAlert(this.$t('PROFILE_SETTINGS.FORM.ACCESS_TOKEN.RESET_ERROR')); + } + }, }, }; @@ -281,7 +289,11 @@ export default { ) " > - +
diff --git a/app/javascript/dashboard/store/modules/agentBots.js b/app/javascript/dashboard/store/modules/agentBots.js index 3e9931057..bd7bff5f0 100644 --- a/app/javascript/dashboard/store/modules/agentBots.js +++ b/app/javascript/dashboard/store/modules/agentBots.js @@ -172,6 +172,17 @@ export const actions = { commit(types.SET_AGENT_BOT_UI_FLAG, { isDisconnecting: false }); } }, + + resetAccessToken: async ({ commit }, botId) => { + try { + const response = await AgentBotsAPI.resetAccessToken(botId); + commit(types.EDIT_AGENT_BOT, response.data); + return response.data; + } catch (error) { + throwErrorMessage(error); + return null; + } + }, }; export const mutations = { diff --git a/app/javascript/dashboard/store/modules/auth.js b/app/javascript/dashboard/store/modules/auth.js index b790b2a80..f329fb009 100644 --- a/app/javascript/dashboard/store/modules/auth.js +++ b/app/javascript/dashboard/store/modules/auth.js @@ -213,6 +213,16 @@ export const actions = { } }, + resetAccessToken: async ({ commit }) => { + try { + const response = await authAPI.resetAccessToken(); + commit(types.SET_CURRENT_USER, response.data); + return true; + } catch (error) { + return false; + } + }, + resendConfirmation: async () => { try { await authAPI.resendConfirmation(); diff --git a/app/javascript/dashboard/store/modules/specs/agentBots/agentBots.spec.js b/app/javascript/dashboard/store/modules/specs/agentBots/agentBots.spec.js index b2fa47313..168c8f78c 100644 --- a/app/javascript/dashboard/store/modules/specs/agentBots/agentBots.spec.js +++ b/app/javascript/dashboard/store/modules/specs/agentBots/agentBots.spec.js @@ -170,4 +170,21 @@ describe('#actions', () => { ]); }); }); + describe('#resetAccessToken', () => { + it('sends correct actions if API is success', async () => { + const mockResponse = { + data: { ...agentBotRecords[0], access_token: 'new_token_123' }, + }; + axios.post.mockResolvedValue(mockResponse); + const result = await actions.resetAccessToken( + { commit }, + agentBotRecords[0].id + ); + + expect(commit.mock.calls).toEqual([ + [types.EDIT_AGENT_BOT, mockResponse.data], + ]); + expect(result).toBe(mockResponse.data); + }); + }); }); diff --git a/app/javascript/dashboard/store/modules/specs/auth/actions.spec.js b/app/javascript/dashboard/store/modules/specs/auth/actions.spec.js index 3de56b1fe..b5dfebe26 100644 --- a/app/javascript/dashboard/store/modules/specs/auth/actions.spec.js +++ b/app/javascript/dashboard/store/modules/specs/auth/actions.spec.js @@ -228,4 +228,20 @@ describe('#actions', () => { ); }); }); + + describe('#resetAccessToken', () => { + it('sends correct actions if API is success', async () => { + const mockResponse = { + data: { id: 1, name: 'John', access_token: 'new_token_123' }, + headers: { expiry: 581842904 }, + }; + axios.post.mockResolvedValue(mockResponse); + const result = await actions.resetAccessToken({ commit }); + + expect(commit.mock.calls).toEqual([ + [types.SET_CURRENT_USER, mockResponse.data], + ]); + expect(result).toBe(true); + }); + }); }); diff --git a/app/policies/agent_bot_policy.rb b/app/policies/agent_bot_policy.rb index 75c91dbf9..7461f6b2d 100644 --- a/app/policies/agent_bot_policy.rb +++ b/app/policies/agent_bot_policy.rb @@ -22,4 +22,8 @@ class AgentBotPolicy < ApplicationPolicy def avatar? @account_user.administrator? end + + def reset_access_token? + @account_user.administrator? + end end diff --git a/app/views/api/v1/accounts/agent_bots/reset_access_token.json.jbuilder b/app/views/api/v1/accounts/agent_bots/reset_access_token.json.jbuilder new file mode 100644 index 000000000..f647ac383 --- /dev/null +++ b/app/views/api/v1/accounts/agent_bots/reset_access_token.json.jbuilder @@ -0,0 +1 @@ +json.partial! 'api/v1/models/agent_bot', formats: [:json], resource: AgentBotPresenter.new(@agent_bot) diff --git a/app/views/api/v1/profiles/reset_access_token.json.jbuilder b/app/views/api/v1/profiles/reset_access_token.json.jbuilder new file mode 100644 index 000000000..0a4b4f9fa --- /dev/null +++ b/app/views/api/v1/profiles/reset_access_token.json.jbuilder @@ -0,0 +1 @@ +json.partial! 'api/v1/models/user', formats: [:json], resource: @user diff --git a/config/environments/development.rb b/config/environments/development.rb index 557000065..7f72e6d2f 100644 --- a/config/environments/development.rb +++ b/config/environments/development.rb @@ -62,6 +62,15 @@ Rails.application.configure do # Disable host check during development config.hosts = nil + + # GitHub Codespaces configuration + if ENV['CODESPACES'] + # Allow web console access from any IP + config.web_console.whitelisted_ips = %w(0.0.0.0/0 ::/0) + # Allow CSRF from codespace URLs + config.force_ssl = false + config.action_controller.forgery_protection_origin_check = false + end # customize using the environment variables config.log_level = ENV.fetch('LOG_LEVEL', 'debug').to_sym diff --git a/config/features.yml b/config/features.yml index eacbd0a72..131456c72 100644 --- a/config/features.yml +++ b/config/features.yml @@ -146,7 +146,7 @@ premium: true - name: chatwoot_v4 display_name: Chatwoot V4 - enabled: false + enabled: true - name: report_v4 display_name: Report V4 enabled: true diff --git a/config/routes.rb b/config/routes.rb index d1705d605..9841c7103 100644 --- a/config/routes.rb +++ b/config/routes.rb @@ -67,6 +67,7 @@ Rails.application.routes.draw do end resources :agent_bots, only: [:index, :create, :show, :update, :destroy] do delete :avatar, on: :member + post :reset_access_token, on: :member end resources :contact_inboxes, only: [] do collection do @@ -296,6 +297,7 @@ Rails.application.routes.draw do post :auto_offline put :set_active_account post :resend_confirmation + post :reset_access_token end end diff --git a/spec/controllers/api/v1/accounts/agent_bots_controller_spec.rb b/spec/controllers/api/v1/accounts/agent_bots_controller_spec.rb index b5cdff018..61fcf30ac 100644 --- a/spec/controllers/api/v1/accounts/agent_bots_controller_spec.rb +++ b/spec/controllers/api/v1/accounts/agent_bots_controller_spec.rb @@ -262,4 +262,55 @@ RSpec.describe 'Agent Bot API', type: :request do end end end + + describe 'POST /api/v1/accounts/{account.id}/agent_bots/:id/reset_access_token' do + context 'when it is an unauthenticated user' do + it 'returns unauthorized' do + post "/api/v1/accounts/#{account.id}/agent_bots/#{agent_bot.id}/reset_access_token" + + expect(response).to have_http_status(:unauthorized) + end + end + + context 'when it is an authenticated user' do + it 'regenerates the access token when administrator' do + old_token = agent_bot.access_token.token + + post "/api/v1/accounts/#{account.id}/agent_bots/#{agent_bot.id}/reset_access_token", + headers: admin.create_new_auth_token, + as: :json + + expect(response).to have_http_status(:success) + agent_bot.reload + expect(agent_bot.access_token.token).not_to eq(old_token) + json_response = response.parsed_body + expect(json_response['access_token']).to eq(agent_bot.access_token.token) + end + + it 'would not reset the access token when agent' do + old_token = agent_bot.access_token.token + + post "/api/v1/accounts/#{account.id}/agent_bots/#{agent_bot.id}/reset_access_token", + headers: agent.create_new_auth_token, + as: :json + + expect(response).to have_http_status(:unauthorized) + agent_bot.reload + expect(agent_bot.access_token.token).to eq(old_token) + end + + it 'would not reset access token for a global agent bot' do + global_bot = create(:agent_bot) + old_token = global_bot.access_token.token + + post "/api/v1/accounts/#{account.id}/agent_bots/#{global_bot.id}/reset_access_token", + headers: admin.create_new_auth_token, + as: :json + + expect(response).to have_http_status(:not_found) + global_bot.reload + expect(global_bot.access_token.token).to eq(old_token) + end + end + end end diff --git a/spec/controllers/api/v1/profiles_controller_spec.rb b/spec/controllers/api/v1/profiles_controller_spec.rb index 50404ad55..8af9e30c0 100644 --- a/spec/controllers/api/v1/profiles_controller_spec.rb +++ b/spec/controllers/api/v1/profiles_controller_spec.rb @@ -296,4 +296,32 @@ RSpec.describe 'Profile API', type: :request do end end end + + describe 'POST /api/v1/profile/reset_access_token' do + context 'when it is an unauthenticated user' do + it 'returns unauthorized' do + post '/api/v1/profile/reset_access_token' + + expect(response).to have_http_status(:unauthorized) + end + end + + context 'when it is an authenticated user' do + let(:agent) { create(:user, account: account, role: :agent) } + + it 'regenerates the access token' do + old_token = agent.access_token.token + + post '/api/v1/profile/reset_access_token', + headers: agent.create_new_auth_token, + as: :json + + expect(response).to have_http_status(:success) + agent.reload + expect(agent.access_token.token).not_to eq(old_token) + json_response = response.parsed_body + expect(json_response['access_token']).to eq(agent.access_token.token) + end + end + end end