Vishnu Narayanan and GitHub
1e7218d439
fix: compare HMAC identity hashes securely ( #14945 )
...
This switches widget and public inbox HMAC identity checks from direct
string equality to constant-time comparison with a length guard.
Fixes
[https://linear.app/chatwoot/issue/CW-6937 ](https://linear.app/chatwoot/issue/CW-6937 )
Fixes
[https://linear.app/chatwoot/issue/CW-7464 ](https://linear.app/chatwoot/issue/CW-7464 )
Fixes
[https://linear.app/chatwoot/issue/CW-7227 ](https://linear.app/chatwoot/issue/CW-7227 )
2026-07-07 17:37:22 +05:30
c8bfbadae2
fix: validate identifier hash on widget contact update ( #14884 )
...
## Description
The widget contact update endpoint (`PATCH /api/v1/widget/contact`)
applied updates that set an `identifier` without validating the
`identifier_hash`, unlike `set_user`, which already does. This change
runs the same validation on the update path whenever an `identifier` is
supplied, keeping identity validation consistent across the widget
contact endpoints.
Anonymous updates that don't pass an identifier (prechat
name/email/phone and custom attributes) keep working unchanged,
including on inboxes with mandatory identity validation.
Fixes https://linear.app/chatwoot/issue/CW-7118
---------
Co-authored-by: Shivam Mishra <scm.mymail@gmail.com >
Co-authored-by: Sivin Varghese <64252451+iamsivin@users.noreply.github.com >
2026-07-07 16:40:19 +05:30
Alexander Udovichenko and GitHub
412b72db7c
fix: Delete double hmac check ( #12464 )
...
## Description
When hmac identity check is enabled according to
[this](https://www.chatwoot.com/hc/user-guide/articles/1677587479-how-to-enable-identity-validation-in-chatwoot )
I found out, that it checked twice.
If `should_verify_hmac? -> true` then hmac checked in `before_action`
and we don't need to do it again later.
This perfomance related and PR fixes this.
2026-03-13 02:30:17 -07:00
Sojan Jose and GitHub
e4b159dd54
chore: Fix contact model silently discarding invalid attributes ( #4994 )
...
fixes : #4775
2022-07-08 13:58:09 +05:30
f71980bd95
chore: Enhance contact merge action for identified users ( #4886 )
...
- Discard conflicting keys
- Do not merge if there is already an identified contact
Co-authored-by: Pranav Raj S <pranav@chatwoot.com >
2022-06-23 15:48:56 +05:30
Muhsin Keloth and GitHub
46c1734ba1
feat: Add additional attributes in setUser method ( #3958 )
2022-02-28 12:10:55 +05:30
Pranav Raj S and GitHub
2f63ebb8a6
fix: Add fixes for sentry errors ( #3522 )
...
- Add fixes for sentry errors
2021-12-09 11:50:28 +05:30
Muhsin Keloth and GitHub
a2764e5c1d
chore: Update deleteCustomAttribute method in SDK ( #3334 )
2021-11-15 14:56:35 +05:30
sarzynski and GitHub
b3e313a200
fix: Ensure HMAC mandatory when enabled ( #3350 )
...
Add missing condition checking if HMAC is mandatory.
Fixes #3349
2021-11-11 09:48:38 +05:30
Aswin Dev P.S and GitHub
9e052fd5b2
chore: Set phone_number through Website SDK ( #2803 )
...
Fixes : #2599
2021-08-13 17:26:09 +05:30
Nithin David Thomas and GitHub
3043ee5058
Fix: Hide prechat for sessions inititated with setUser ( #1914 )
2021-03-20 17:44:20 +05:30
freddii and GitHub
229fcc18b7
chore: fixed typos in code comments ( #1701 )
2021-01-28 10:39:37 +05:30
b6e8173b24
feat: HMAC verification for web widget ( #1643 )
...
* feat: HMAC verification for web widget. Let you verify the authenticated contact via HMAC on the web widget to prevent data tampering.
* Add docs for identity-validation
Co-authored-by: Pranav Raj S <pranav@chatwoot.com >
2021-01-17 22:44:03 +05:30
cdd385b269
feat: Custom Attributes for contacts ( #1158 )
...
Co-authored-by: Pranav Raj Sreepuram <pranavrajs@gmail.com >
2020-08-21 19:30:27 +05:30
Sojan Jose and GitHub
051871a3cd
Chore: Code Cleanup in API controllers ( #932 )
...
* Chore: Code Cleanup in API controllers
* Remove unnecessary scoping for accounts controller
2020-06-07 13:58:05 +05:30
cb22b396eb
Feature: Website SDK ( #653 )
...
Add SDK functions
Co-authored-by: Sojan <sojan@pepalo.com >
2020-04-03 13:04:58 +05:30