Shivam Mishra
bd3a2b481b
fix: white alpha color
2024-12-11 16:03:38 +05:30
Shivam Mishra
f349a802d5
fix: download color
2024-12-11 16:03:35 +05:30
Shivam Mishra
b0824f3b67
fix: orientatation for chips
2024-12-11 16:03:31 +05:30
Shivam Mishra
1825989663
feat: add colors to text chip
2024-12-11 16:01:51 +05:30
Shivam Mishra
233cc8b868
feat: use woot-icons
2024-12-11 16:01:49 +05:30
Shivam Mishra
ea87274d61
feat: move icons outside
2024-12-11 16:00:45 +05:30
Shivam Mishra
64ba5857e0
feat: use lucide
2024-12-11 16:00:32 +05:30
Shivam Mishra
ed158716ba
fix: sender avatar
2024-12-06 18:53:50 +05:30
Shivam Mishra
97ae755783
fix: attachments check
2024-12-06 18:51:42 +05:30
Shivam Mishra
bcc03a79f7
feat: allow otions
2024-12-06 18:19:49 +05:30
Shivam Mishra
55952f5fe0
fix: pnpm
2024-12-06 18:19:43 +05:30
Shivam Mishra
be01ab63f7
Merge branch 'develop' of github.com:chatwoot/chatwoot into feat/message-bubble
2024-12-06 18:11:07 +05:30
Sivin Varghese and GitHub
1b430ffae2
fix: New compose conversation form ( #10548 )
2024-12-06 15:40:06 +05:30
Shivam Mishra
e7471b8e74
feat: add contact card
2024-12-06 14:36:24 +05:30
Sivin Varghese and GitHub
afb3e3e649
fix: Fix issues with contact routes in old navigation sidebar ( #10547 )
2024-12-05 22:46:57 -08:00
Shivam Mishra and GitHub
3fd585f40b
feat: Throttle meta request for large chat size ( #10518 )
...
For large accounts with huge volumes of messages, it can be very
wasteful to make the meta request so often. It also puts un-necessary
load on the DB bombarding it with so many requests. This PR fixes it by
throttling the requests to 5 seconds for all users with more than 1000
accessible chats.
### Why not cache this value in the backend?
Well, it's a bit tricky, since a user can have different permissions
over inboxes and can see different chats, maintaining a cache for each
of them is not effective, besides the requests will reach the server
anyway.
2024-12-05 22:35:30 -08:00
Shivam Mishra
9c6b78700c
fix: location
2024-12-06 10:45:26 +05:30
b116ab5ad3
feat(v4): Compose new conversation without multiple clicks ( #10545 )
...
---------
Co-authored-by: Pranav <pranav@chatwoot.com >
Co-authored-by: Pranav <pranavrajs@gmail.com >
2024-12-05 20:16:29 -08:00
67c90231b6
feat: Add compose conversation components ( #10457 )
...
Co-authored-by: Pranav <pranav@chatwoot.com >
Co-authored-by: Pranav <pranavrajs@gmail.com >
2024-12-05 16:31:47 -08:00
Sivin Varghese and GitHub
41106bccb7
chore: Fix issues with Contact pages ( #10544 )
2024-12-05 14:24:10 -08:00
cdff624a0a
feat: update notification settings ( #10529 )
...
https://github.com/user-attachments/assets/52ecf3f8-0329-4268-906e-d6102338f4af
---------
Co-authored-by: Pranav <pranav@chatwoot.com >
Co-authored-by: Pranav <pranavrajs@gmail.com >
2024-12-05 19:05:04 +05:30
Shivam Mishra
685cf56819
feat: add support for unsupported
2024-12-05 17:37:50 +05:30
Shivam Mishra
e7fddee4dc
feat: add location bubble
2024-12-05 17:13:57 +05:30
Shivam Mishra
26b5c2c136
feat: setup instagram
2024-12-05 15:08:37 +05:30
Shivam Mishra
68f02e06b7
feat: add fixtures for IG
2024-12-05 14:26:31 +05:30
Shivam Mishra
c2021a86d2
feat: add ig bubble
2024-12-05 14:20:16 +05:30
Shivam Mishra
d610d3e0bb
fix: locale
2024-12-05 14:19:43 +05:30
Sivin Varghese and GitHub
d635be4b2a
fix: Fetch assignable agents in expanded layout ( #10540 )
2024-12-04 21:26:00 -08:00
Sivin Varghese and GitHub
f7b0d5dbe2
fix: Reset contact attributes when form is updated ( #10539 )
2024-12-04 21:25:28 -08:00
3edc0542cc
fix: Fix issue with profile picture not updating ( #10532 )
...
This PR resolves the issue with updating the profile picture in the profile settings.
**Cause of issue**
The issue can be reproduced with the old `ProfileAvatar.vue` component.
While the exact reason is unclear, it seems related to cases where the
file might be `null`.
**Solution**
Replaced the old `ProfileAvatar.vue` with `Avatar.vue` and tested it. It
works fine. I’ve attached a loom video below.
Fixes https://linear.app/chatwoot/issue/CW-3768/profile-picture-bug
Co-authored-by: Pranav <pranav@chatwoot.com >
Co-authored-by: Pranav <pranavrajs@gmail.com >
2024-12-04 15:02:29 -08:00
bf58a18af4
fix: Update contact details page errors ( #10536 )
...
Co-authored-by: Pranav <pranavrajs@gmail.com >
2024-12-04 13:58:53 -08:00
Shivam Mishra and GitHub
9b6830a610
fix: Update UI issues with sidebar ( #10535 )
...
This PR fixes a few UI issues with the sidebar
1. `z-index` issues with sidebar dropdowns
2. Move the event listener to the root of the dropdown container, it
allows more consistent behaviour of the trigger, earlier the click on
the trigger when the dropdown was open would cause the container to
re-render
3. Use `perserve-open` for the status switcher menu item in the profile
menu.
4. Use `sessionStorage` instead of `localStorage` to preserve sidebar
dropdown info. When opening the dashboard without directly going to a
specific route, any previous known item would get expanded even if it's
link was not active, this caused issues across tabs too, this fixes it.
5. Use `snakeCaseKeys` instead of `decamelize` we had two packages doing
the same thing
6. Update `vueuse` the new version is vue3 only
2024-12-04 13:48:12 -08:00
Shivam Mishra
59d5c91977
feat: simpler expandable check
2024-12-04 19:51:55 +05:30
Shivam Mishra
b78a272806
feat: better resize observer
2024-12-04 19:44:48 +05:30
Shivam Mishra
2456b90a75
feat: add quote extracter
2024-12-04 19:38:39 +05:30
Shivam Mishra
828a46e40b
feat: use sender
2024-12-04 18:39:41 +05:30
Shivam Mishra
4739d45376
feat: seprate email meta component
2024-12-04 18:38:21 +05:30
Shivam Mishra
12c239228a
feat: format email text content
2024-12-04 17:49:58 +05:30
Shivam Mishra
89956d006c
feat: common attachment chips
2024-12-04 17:46:57 +05:30
Shivam Mishra
b1e55bab9e
fix: fullwidth
2024-12-04 17:39:44 +05:30
Shivam Mishra
89f95742f8
fix: styling
2024-12-04 17:33:36 +05:30
Shivam Mishra
95674eb601
feat: more attachments
2024-12-04 17:32:50 +05:30
Shivam Mishra
5c863906e0
feat: add attachments
2024-12-04 17:31:21 +05:30
Shivam Mishra
e68f923a09
fix: first child margin
2024-12-04 17:31:17 +05:30
Shivam Mishra
30f368cbcd
feat: better story
2024-12-04 17:24:02 +05:30
Shivam Mishra
0a3840501e
feat: add error case
2024-12-04 17:08:06 +05:30
769b7171f4
feat(v4): Add new contact details screen ( #10504 )
...
Co-authored-by: Pranav <pranavrajs@gmail.com >
2024-12-03 21:29:47 -08:00
Vishnu Narayanan and GitHub
d4b6f710bd
chore(heroku): Switch heroku stack to the latest stack heroku-24 ( #10085 )
...
# Pull Request Template
## Description
- Heroku has marked `heroku-20` stack as EOL by April 2025
- https://help.heroku.com/NPN275RK/heroku-20-end-of-life-faq
- https://devcenter.heroku.com/articles/heroku-24-stack
Fixes https://linear.app/chatwoot/issue/CW-3552/upgrade-heroku-stack-to-heroku-24
2024-12-02 18:53:59 -08:00
50e7ceb19b
chore(deps): bump rails-html-sanitizer from 1.6.0 to 1.6.1 ( #10528 )
...
Bumps
[rails-html-sanitizer](https://github.com/rails/rails-html-sanitizer )
from 1.6.0 to 1.6.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/rails/rails-html-sanitizer/releases ">rails-html-sanitizer's
releases</a>.</em></p>
<blockquote>
<h2>1.6.1 / 2024-12-02</h2>
<p>This is a performance and security release which addresses several
possible XSS vulnerabilities.</p>
<ul>
<li>
<p>The dependency on Nokogiri is updated to v1.15.7 or >=1.16.8.</p>
<p>This change addresses CVE-2024-53985 (<a
href="https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-w8gc-x259-rc7x ">https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-w8gc-x259-rc7x </a>).</p>
<p><em>Mike Dalessio</em></p>
</li>
<li>
<p>Disallowed tags will be pruned when they appear in foreign content
(i.e. SVG or MathML content),
regardless of the <code>prune:</code> option value. Previously,
disallowed tags were "stripped" unless the
gem was configured with the <code>prune: true</code> option.</p>
<p>The CVEs addressed by this change are:</p>
<ul>
<li>CVE-2024-53986 (<a
href="https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-638j-pmjw-jq48 ">https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-638j-pmjw-jq48 </a>)</li>
<li>CVE-2024-53987 (<a
href="https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-2x5m-9ch4-qgrr ">https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-2x5m-9ch4-qgrr </a>)</li>
</ul>
<p><em>Mike Dalessio</em></p>
</li>
<li>
<p>The tags "noscript", "mglyph", and
"malignmark" will not be allowed, even if explicitly added to
the allowlist. If applications try to allow any of these tags, a warning
is emitted and the tags
are removed from the allow-list.</p>
<p>The CVEs addressed by this change are:</p>
<ul>
<li>CVE-2024-53988 (<a
href="https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-cfjx-w229-hgx5 ">https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-cfjx-w229-hgx5 </a>)</li>
<li>CVE-2024-53989 (<a
href="https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-rxv5-gxqc-xx8g ">https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-rxv5-gxqc-xx8g </a>)</li>
</ul>
<p>Please note that we <em>may</em> restore support for allowing
"noscript" in a future release. We do not
expect to ever allow "mglyph" or "malignmark",
though, especially since browser support is minimal
for these tags.</p>
<p><em>Mike Dalessio</em></p>
</li>
<li>
<p>Improve performance by eliminating needless operations on attributes
that are being removed. <a
href="https://redirect.github.com/rails/rails-html-sanitizer/issues/188 ">#188</a></p>
<p><em>Mike Dalessio</em></p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/rails/rails-html-sanitizer/blob/main/CHANGELOG.md ">rails-html-sanitizer's
changelog</a>.</em></p>
<blockquote>
<h2>1.6.1 / 2024-12-02</h2>
<p>This is a performance and security release which addresses several
possible XSS vulnerabilities.</p>
<ul>
<li>
<p>The dependency on Nokogiri is updated to v1.15.7 or >=1.16.8.</p>
<p>This change addresses CVE-2024-53985 (GHSA-w8gc-x259-rc7x).</p>
<p><em>Mike Dalessio</em></p>
</li>
<li>
<p>Disallowed tags will be pruned when they appear in foreign content
(i.e. SVG or MathML content),
regardless of the <code>prune:</code> option value. Previously,
disallowed tags were "stripped" unless the
gem was configured with the <code>prune: true</code> option.</p>
<p>The CVEs addressed by this change are:</p>
<ul>
<li>CVE-2024-53986 (GHSA-638j-pmjw-jq48)</li>
<li>CVE-2024-53987 (GHSA-2x5m-9ch4-qgrr)</li>
</ul>
<p><em>Mike Dalessio</em></p>
</li>
<li>
<p>The tags "noscript", "mglyph", and
"malignmark" will not be allowed, even if explicitly added to
the allowlist. If applications try to allow any of these tags, a warning
is emitted and the tags
are removed from the allow-list.</p>
<p>The CVEs addressed by this change are:</p>
<ul>
<li>CVE-2024-53988 (GHSA-cfjx-w229-hgx5)</li>
<li>CVE-2024-53989 (GHSA-rxv5-gxqc-xx8g)</li>
</ul>
<p>Please note that we <em>may</em> restore support for allowing
"noscript" in a future release. We do not
expect to ever allow "mglyph" or "malignmark",
though, especially since browser support is minimal
for these tags.</p>
<p><em>Mike Dalessio</em></p>
</li>
<li>
<p>Improve performance by eliminating needless operations on attributes
that are being removed. <a
href="https://redirect.github.com/rails/rails-html-sanitizer/issues/188 ">#188</a></p>
<p><em>Mike Dalessio</em></p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/5e96b19bbb934284e675109851bd82429622bb6e "><code>5e96b19</code></a>
version bump to v1.6.1</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/383cc7c17f5a6aafed79adff1c419da31a414878 "><code>383cc7c</code></a>
doc: update CHANGELOG with assigned CVEs</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/a7b0cfe103ff5d8b17d77fb3660589522dd6bcad "><code>a7b0cfe</code></a>
Combine the noscript/mglyph prevention blocks</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/5658335ede931a47d02b8aa4d3b5800bd3184158 "><code>5658335</code></a>
Merge branch 'h1-2509647-noscript' into
flavorjones-2024-security-fixes</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/65fb72f07e875b401bbec479c2a5a3d3b10ad338 "><code>65fb72f</code></a>
Merge branch 'h1-2519936-mglyph-foster-parenting' into
flavorjones-2024-secur...</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/3fe22a8b892361c8463f50f4f4a5d08e299c62a2 "><code>3fe22a8</code></a>
Merge branch 'h1-2519936-foreign-ns-confusion' into
flavorjones-2024-security...</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/d7a94c125209a9611308fbfdb7420a8786d7e80f "><code>d7a94c1</code></a>
Merge branch 'h1-2503220-nokogiri-serialization' into
flavorjones-2024-securi...</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/3fd6e650f991ce687961da45038b77504114d237 "><code>3fd6e65</code></a>
doc: update CHANGELOG</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/16251735e36ebdc302e2f90f2a39cad56879414f "><code>1625173</code></a>
fix: disallow 'noscript' from safe lists</li>
<li><a
href="https://github.com/rails/rails-html-sanitizer/commit/a0a3e8b76b696446ffc6bffcff3bc7b7c6393c72 "><code>a0a3e8b</code></a>
fix: disallow 'mglyph' and 'malignmark' from safe lists</li>
<li>Additional commits viewable in <a
href="https://github.com/rails/rails-html-sanitizer/compare/v1.6.0...v1.6.1 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/chatwoot/chatwoot/network/alerts ).
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pranav <pranav@chatwoot.com >
2024-12-02 18:23:58 -08:00
Sivin Varghese and GitHub
062587487a
feat: Improve Contact list ( #10522 )
2024-12-02 18:23:41 -08:00