Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a2b82111a7 | ||
|
|
15547fe2cd | ||
|
|
756aea3554 | ||
|
|
316d116cec | ||
|
|
ff5440173c | ||
|
|
abb5a4c4d8 | ||
|
|
37da4dd8ca |
@@ -1,65 +0,0 @@
|
|||||||
---
|
|
||||||
:position: before
|
|
||||||
:position_in_additional_file_patterns: before
|
|
||||||
:position_in_class: before
|
|
||||||
:position_in_factory: before
|
|
||||||
:position_in_fixture: before
|
|
||||||
:position_in_routes: before
|
|
||||||
:position_in_serializer: before
|
|
||||||
:position_in_test: before
|
|
||||||
:classified_sort: true
|
|
||||||
:exclude_controllers: true
|
|
||||||
:exclude_factories: true
|
|
||||||
:exclude_fixtures: true
|
|
||||||
:exclude_helpers: true
|
|
||||||
:exclude_scaffolds: true
|
|
||||||
:exclude_serializers: true
|
|
||||||
:exclude_sti_subclasses: false
|
|
||||||
:exclude_tests: true
|
|
||||||
:force: false
|
|
||||||
:format_markdown: false
|
|
||||||
:format_rdoc: false
|
|
||||||
:format_yard: false
|
|
||||||
:frozen: false
|
|
||||||
:grouped_polymorphic: false
|
|
||||||
:ignore_model_sub_dir: false
|
|
||||||
:ignore_unknown_models: false
|
|
||||||
:include_version: false
|
|
||||||
:show_check_constraints: false
|
|
||||||
:show_complete_foreign_keys: false
|
|
||||||
:show_foreign_keys: true
|
|
||||||
:show_indexes: true
|
|
||||||
:show_indexes_include: false
|
|
||||||
:simple_indexes: false
|
|
||||||
:sort: false
|
|
||||||
:timestamp: false
|
|
||||||
:trace: false
|
|
||||||
:with_comment: true
|
|
||||||
:with_column_comments: true
|
|
||||||
:with_table_comments: true
|
|
||||||
:position_of_column_comment: :with_name
|
|
||||||
:active_admin: false
|
|
||||||
:command:
|
|
||||||
:debug: false
|
|
||||||
:hide_default_column_types: json,jsonb,hstore
|
|
||||||
:hide_limit_column_types: integer,bigint,boolean
|
|
||||||
:timestamp_columns:
|
|
||||||
- created_at
|
|
||||||
- updated_at
|
|
||||||
:ignore_columns:
|
|
||||||
:ignore_routes:
|
|
||||||
:models: true
|
|
||||||
:routes: false
|
|
||||||
:skip_on_db_migrate: false
|
|
||||||
:target_action: :do_annotations
|
|
||||||
:wrapper:
|
|
||||||
:wrapper_close:
|
|
||||||
:wrapper_open:
|
|
||||||
:classes_default_to_s: []
|
|
||||||
:additional_file_patterns: []
|
|
||||||
:model_dir:
|
|
||||||
- app/models
|
|
||||||
- enterprise/app/models
|
|
||||||
:require: []
|
|
||||||
:root_dir:
|
|
||||||
- ''
|
|
||||||
@@ -1,23 +1,3 @@
|
|||||||
---
|
---
|
||||||
ignore:
|
ignore:
|
||||||
- CVE-2021-41098 # https://github.com/chatwoot/chatwoot/issues/3097 (update once azure blob storage is updated)
|
- CVE-2021-41098 # https://github.com/chatwoot/chatwoot/issues/3097 (update once azure blob storage is updated)
|
||||||
- GHSA-57hq-95w6-v4fc # Devise confirmable race condition — patched locally in User model (remove once on Devise 5+)
|
|
||||||
# Devise 5 is currently blocked by devise-secure_password/devise_token_auth/devise-two-factor.
|
|
||||||
# Chatwoot does not enable Timeoutable, so the timeout redirect path is not reachable.
|
|
||||||
- GHSA-jp94-3292-c3xv
|
|
||||||
# Rails 7.1 has no patched release for the Active Storage proxy range
|
|
||||||
# advisories. Chatwoot limits proxy range requests locally.
|
|
||||||
- CVE-2026-33658
|
|
||||||
# Rails 7.1 has no patched release for this Active Storage direct-upload
|
|
||||||
# advisory. Chatwoot filters internal metadata keys locally.
|
|
||||||
- CVE-2026-33173
|
|
||||||
- CVE-2026-33174
|
|
||||||
# Rails 7.1 has no patched release for these Rails advisories. These are not
|
|
||||||
# reachable through Chatwoot's current usage patterns and should be removed
|
|
||||||
# once we upgrade to Rails 7.2.3.1+.
|
|
||||||
- CVE-2026-33168
|
|
||||||
- CVE-2026-33169
|
|
||||||
- CVE-2026-33170
|
|
||||||
- CVE-2026-33176
|
|
||||||
- CVE-2026-33195
|
|
||||||
- CVE-2026-33202
|
|
||||||
|
|||||||
@@ -93,8 +93,8 @@ jobs:
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
mkdir -p ~/tmp
|
mkdir -p ~/tmp
|
||||||
curl -L https://repo1.maven.org/maven2/org/openapitools/openapi-generator-cli/7.19.0/openapi-generator-cli-7.19.0.jar > ~/tmp/openapi-generator-cli-7.19.0.jar
|
curl -L https://repo1.maven.org/maven2/org/openapitools/openapi-generator-cli/6.3.0/openapi-generator-cli-6.3.0.jar > ~/tmp/openapi-generator-cli-6.3.0.jar
|
||||||
java -jar ~/tmp/openapi-generator-cli-7.19.0.jar validate -i swagger/swagger.json
|
java -jar ~/tmp/openapi-generator-cli-6.3.0.jar validate -i swagger/swagger.json
|
||||||
|
|
||||||
# Bundle audit
|
# Bundle audit
|
||||||
- run:
|
- run:
|
||||||
@@ -144,7 +144,7 @@ jobs:
|
|||||||
# Backend tests with parallelization
|
# Backend tests with parallelization
|
||||||
backend-tests:
|
backend-tests:
|
||||||
<<: *defaults
|
<<: *defaults
|
||||||
parallelism: 20
|
parallelism: 18
|
||||||
steps:
|
steps:
|
||||||
- checkout
|
- checkout
|
||||||
- node/install:
|
- node/install:
|
||||||
|
|||||||
@@ -98,8 +98,6 @@ SMTP_OPENSSL_VERIFY_MODE=peer
|
|||||||
# Mail Incoming
|
# Mail Incoming
|
||||||
# This is the domain set for the reply emails when conversation continuity is enabled
|
# This is the domain set for the reply emails when conversation continuity is enabled
|
||||||
MAILER_INBOUND_EMAIL_DOMAIN=
|
MAILER_INBOUND_EMAIL_DOMAIN=
|
||||||
# Maximum time in seconds to process a single IMAP email
|
|
||||||
# EMAIL_PROCESSING_TIMEOUT_SECONDS=60
|
|
||||||
# Set this to the appropriate ingress channel with regards to incoming emails
|
# Set this to the appropriate ingress channel with regards to incoming emails
|
||||||
# Possible values are :
|
# Possible values are :
|
||||||
# relay for Exim, Postfix, Qmail
|
# relay for Exim, Postfix, Qmail
|
||||||
@@ -234,10 +232,6 @@ ANDROID_SHA256_CERT_FINGERPRINT=AC:73:8E:DE:EB:56:EA:CC:10:87:02:A7:65:37:7B:38:
|
|||||||
# Comma-separated list of trusted IPs that bypass Rack Attack throttling rules
|
# Comma-separated list of trusted IPs that bypass Rack Attack throttling rules
|
||||||
# RACK_ATTACK_ALLOWED_IPS=127.0.0.1,::1,192.168.0.10
|
# RACK_ATTACK_ALLOWED_IPS=127.0.0.1,::1,192.168.0.10
|
||||||
|
|
||||||
## SafeFetch private network access
|
|
||||||
## Keep disabled by default. Self-hosted installations can enable this to allow SafeFetch requests to private network URLs.
|
|
||||||
# SAFE_FETCH_ALLOW_PRIVATE_NETWORK=false
|
|
||||||
|
|
||||||
## Running chatwoot as an API only server
|
## Running chatwoot as an API only server
|
||||||
## setting this value to true will disable the frontend dashboard endpoints
|
## setting this value to true will disable the frontend dashboard endpoints
|
||||||
# CW_API_ONLY_SERVER=false
|
# CW_API_ONLY_SERVER=false
|
||||||
|
|||||||
@@ -1,195 +0,0 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
"""Sync triage GitHub security advisories to Linear issues."""
|
|
||||||
|
|
||||||
from __future__ import annotations
|
|
||||||
|
|
||||||
import os
|
|
||||||
import sys
|
|
||||||
from typing import Any
|
|
||||||
|
|
||||||
import requests
|
|
||||||
|
|
||||||
GITHUB_API = "https://api.github.com"
|
|
||||||
LINEAR_API = "https://api.linear.app/graphql"
|
|
||||||
|
|
||||||
SEVERITY_PRIORITY = {"critical": 1, "high": 2, "medium": 3, "low": 4}
|
|
||||||
SEVERITY_COLOR = {
|
|
||||||
"critical": 15548997,
|
|
||||||
"high": 15105570,
|
|
||||||
"medium": 15844367,
|
|
||||||
"low": 3066993,
|
|
||||||
}
|
|
||||||
DEFAULT_COLOR = 9807270
|
|
||||||
|
|
||||||
|
|
||||||
def required_env(name: str) -> str:
|
|
||||||
value = os.environ.get(name)
|
|
||||||
if not value:
|
|
||||||
sys.exit(f"Missing required env var: {name}")
|
|
||||||
return value
|
|
||||||
|
|
||||||
|
|
||||||
def fetch_triage_advisories(repo: str, token: str) -> list[dict[str, Any]]:
|
|
||||||
url: str | None = f"{GITHUB_API}/repos/{repo}/security-advisories"
|
|
||||||
params: dict[str, Any] | None = {"state": "triage", "per_page": 100}
|
|
||||||
headers = {
|
|
||||||
"Accept": "application/vnd.github+json",
|
|
||||||
"Authorization": f"Bearer {token}",
|
|
||||||
"X-GitHub-Api-Version": "2022-11-28",
|
|
||||||
}
|
|
||||||
advisories: list[dict[str, Any]] = []
|
|
||||||
while url:
|
|
||||||
r = requests.get(url, headers=headers, params=params, timeout=30)
|
|
||||||
r.raise_for_status()
|
|
||||||
advisories.extend(r.json())
|
|
||||||
next_link = r.links.get("next")
|
|
||||||
url = next_link["url"] if next_link else None
|
|
||||||
params = None
|
|
||||||
return advisories
|
|
||||||
|
|
||||||
|
|
||||||
def linear_call(query: str, variables: dict[str, Any], api_key: str) -> dict[str, Any]:
|
|
||||||
r = requests.post(
|
|
||||||
LINEAR_API,
|
|
||||||
headers={"Authorization": api_key},
|
|
||||||
json={"query": query, "variables": variables},
|
|
||||||
timeout=30,
|
|
||||||
)
|
|
||||||
r.raise_for_status()
|
|
||||||
return r.json()
|
|
||||||
|
|
||||||
|
|
||||||
def linear_issue_exists(ghsa_id: str, api_key: str) -> bool:
|
|
||||||
query = (
|
|
||||||
"query($q: String!) { issues(filter: {title: {contains: $q}}, first: 1) "
|
|
||||||
"{ nodes { id } } }"
|
|
||||||
)
|
|
||||||
resp = linear_call(query, {"q": ghsa_id}, api_key)
|
|
||||||
return len(resp.get("data", {}).get("issues", {}).get("nodes", [])) > 0
|
|
||||||
|
|
||||||
|
|
||||||
def linear_create_issue(input_data: dict[str, Any], api_key: str) -> dict[str, str] | None:
|
|
||||||
query = (
|
|
||||||
"mutation($input: IssueCreateInput!) { issueCreate(input: $input) "
|
|
||||||
"{ success issue { identifier url } } }"
|
|
||||||
)
|
|
||||||
resp = linear_call(query, {"input": input_data}, api_key)
|
|
||||||
create = resp.get("data", {}).get("issueCreate") or {}
|
|
||||||
if not create.get("success"):
|
|
||||||
return None
|
|
||||||
return create.get("issue")
|
|
||||||
|
|
||||||
|
|
||||||
def reporter_login(advisory: dict[str, Any]) -> str:
|
|
||||||
for credit in advisory.get("credits") or []:
|
|
||||||
user = (credit or {}).get("user") or {}
|
|
||||||
if user.get("login"):
|
|
||||||
return user["login"]
|
|
||||||
return "unknown"
|
|
||||||
|
|
||||||
|
|
||||||
def cvss_score(advisory: dict[str, Any]) -> str:
|
|
||||||
score = (advisory.get("cvss") or {}).get("score")
|
|
||||||
return str(score) if score is not None else "n/a"
|
|
||||||
|
|
||||||
|
|
||||||
def build_description(adv: dict[str, Any]) -> str:
|
|
||||||
return (
|
|
||||||
f"**GHSA:** {adv['ghsa_id']}\n"
|
|
||||||
f"**CVE:** {adv.get('cve_id') or 'n/a'}\n"
|
|
||||||
f"**Severity:** {adv.get('severity') or 'unknown'} (CVSS {cvss_score(adv)})\n"
|
|
||||||
f"**Reporter:** {reporter_login(adv)}\n"
|
|
||||||
f"**Reported:** {(adv.get('created_at') or '').split('T')[0]}\n"
|
|
||||||
f"**Advisory:** {adv['html_url']}\n\n"
|
|
||||||
f"---\n\n"
|
|
||||||
f"{adv.get('description') or 'No description provided.'}"
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
def post_discord(adv: dict[str, Any], issue: dict[str, str], webhook_url: str) -> None:
|
|
||||||
severity = adv.get("severity") or "unknown"
|
|
||||||
title = f"[{adv['ghsa_id']}] {adv['summary']}"[:250]
|
|
||||||
payload = {
|
|
||||||
"username": "GHSA Sync",
|
|
||||||
"embeds": [
|
|
||||||
{
|
|
||||||
"title": title,
|
|
||||||
"url": issue["url"],
|
|
||||||
"color": SEVERITY_COLOR.get(severity, DEFAULT_COLOR),
|
|
||||||
"fields": [
|
|
||||||
{"name": "Linear", "value": issue["identifier"], "inline": True},
|
|
||||||
{
|
|
||||||
"name": "Severity",
|
|
||||||
"value": f"{severity} (CVSS {cvss_score(adv)})",
|
|
||||||
"inline": True,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "Advisory",
|
|
||||||
"value": f"[GitHub]({adv['html_url']})",
|
|
||||||
"inline": True,
|
|
||||||
},
|
|
||||||
],
|
|
||||||
}
|
|
||||||
],
|
|
||||||
}
|
|
||||||
try:
|
|
||||||
requests.post(webhook_url, json=payload, timeout=10)
|
|
||||||
except requests.RequestException:
|
|
||||||
pass
|
|
||||||
|
|
||||||
|
|
||||||
def main() -> int:
|
|
||||||
repo = required_env("GITHUB_REPOSITORY")
|
|
||||||
gh_token = required_env("GHSA_READ_TOKEN")
|
|
||||||
linear_api_key = required_env("LINEAR_API_KEY")
|
|
||||||
team_id = required_env("LINEAR_TEAM_ID")
|
|
||||||
project_id = required_env("LINEAR_PROJECT_ID")
|
|
||||||
label_id = required_env("LINEAR_LABEL_ID")
|
|
||||||
discord_webhook = os.environ.get("DISCORD_WEBHOOK_URL") or None
|
|
||||||
|
|
||||||
advisories = fetch_triage_advisories(repo, gh_token)
|
|
||||||
print(f"Fetched {len(advisories)} triage advisories")
|
|
||||||
|
|
||||||
created = skipped = failed = 0
|
|
||||||
|
|
||||||
for adv in advisories:
|
|
||||||
ghsa_id = adv.get("ghsa_id")
|
|
||||||
if not ghsa_id:
|
|
||||||
failed += 1
|
|
||||||
continue
|
|
||||||
|
|
||||||
try:
|
|
||||||
if linear_issue_exists(ghsa_id, linear_api_key):
|
|
||||||
skipped += 1
|
|
||||||
continue
|
|
||||||
|
|
||||||
severity = adv.get("severity") or "unknown"
|
|
||||||
issue = linear_create_issue(
|
|
||||||
{
|
|
||||||
"title": f"[{ghsa_id}] {adv.get('summary', '')}",
|
|
||||||
"description": build_description(adv),
|
|
||||||
"teamId": team_id,
|
|
||||||
"projectId": project_id,
|
|
||||||
"labelIds": [label_id],
|
|
||||||
"priority": SEVERITY_PRIORITY.get(severity, 3),
|
|
||||||
},
|
|
||||||
linear_api_key,
|
|
||||||
)
|
|
||||||
except requests.RequestException:
|
|
||||||
failed += 1
|
|
||||||
continue
|
|
||||||
|
|
||||||
if not issue:
|
|
||||||
failed += 1
|
|
||||||
continue
|
|
||||||
|
|
||||||
created += 1
|
|
||||||
if discord_webhook:
|
|
||||||
post_discord(adv, issue, discord_webhook)
|
|
||||||
|
|
||||||
print(f"Created {created}, skipped {skipped}, failed {failed}")
|
|
||||||
return 1 if failed > 0 else 0
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
sys.exit(main())
|
|
||||||
@@ -11,9 +11,6 @@ concurrency:
|
|||||||
group: pr-${{ github.workflow }}-${{ github.head_ref }}
|
group: pr-${{ github.workflow }}-${{ github.head_ref }}
|
||||||
cancel-in-progress: true
|
cancel-in-progress: true
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
deployment_check:
|
deployment_check:
|
||||||
name: Check Deployment
|
name: Check Deployment
|
||||||
|
|||||||
@@ -8,9 +8,6 @@ on:
|
|||||||
branches:
|
branches:
|
||||||
- develop
|
- develop
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test:
|
test:
|
||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
|
|||||||
@@ -1,29 +0,0 @@
|
|||||||
name: Sync GHSA advisories to Linear
|
|
||||||
|
|
||||||
on:
|
|
||||||
schedule:
|
|
||||||
- cron: '0 4 * * *' # daily at 09:30 IST
|
|
||||||
workflow_dispatch: {}
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
sync:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- uses: actions/setup-python@v5
|
|
||||||
with:
|
|
||||||
python-version: '3.11'
|
|
||||||
- name: Install dependencies
|
|
||||||
run: pip install requests==2.32.3
|
|
||||||
- name: Sync advisories
|
|
||||||
env:
|
|
||||||
GHSA_READ_TOKEN: ${{ secrets.GHSA_READ_TOKEN }}
|
|
||||||
LINEAR_API_KEY: ${{ secrets.LINEAR_API_KEY }}
|
|
||||||
LINEAR_TEAM_ID: ${{ secrets.LINEAR_TEAM_ID }}
|
|
||||||
LINEAR_PROJECT_ID: ${{ secrets.LINEAR_PROJECT_ID }}
|
|
||||||
LINEAR_LABEL_ID: ${{ secrets.LINEAR_LABEL_ID }}
|
|
||||||
DISCORD_WEBHOOK_URL: ${{ secrets.DISCORD_WEBHOOK_URL }}
|
|
||||||
run: python3 .github/scripts/ghsa_linear_sync.py
|
|
||||||
@@ -10,9 +10,6 @@ concurrency:
|
|||||||
group: pr-${{ github.workflow }}-${{ github.head_ref }}
|
group: pr-${{ github.workflow }}-${{ github.head_ref }}
|
||||||
cancel-in-progress: true
|
cancel-in-progress: true
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
log_lines_check:
|
log_lines_check:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|||||||
@@ -14,9 +14,6 @@ on:
|
|||||||
- cron: "0 0 * * *"
|
- cron: "0 0 * * *"
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
nightly:
|
nightly:
|
||||||
runs-on: ubuntu-24.04
|
runs-on: ubuntu-24.04
|
||||||
|
|||||||
@@ -3,10 +3,6 @@ name: Publish Codespace Base Image
|
|||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
packages: write
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
publish-code-space-image:
|
publish-code-space-image:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|||||||
@@ -18,9 +18,6 @@ on:
|
|||||||
env:
|
env:
|
||||||
DOCKER_REPO: chatwoot/chatwoot
|
DOCKER_REPO: chatwoot/chatwoot
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -18,9 +18,6 @@ on:
|
|||||||
env:
|
env:
|
||||||
DOCKER_REPO: chatwoot/chatwoot
|
DOCKER_REPO: chatwoot/chatwoot
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -10,9 +10,6 @@ concurrency:
|
|||||||
group: pr-${{ github.workflow }}-${{ github.head_ref }}
|
group: pr-${{ github.workflow }}-${{ github.head_ref }}
|
||||||
cancel-in-progress: true
|
cancel-in-progress: true
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test:
|
test:
|
||||||
runs-on: ubuntu-22.04
|
runs-on: ubuntu-22.04
|
||||||
|
|||||||
@@ -7,9 +7,6 @@ on:
|
|||||||
- master
|
- master
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
test-build:
|
test-build:
|
||||||
strategy:
|
strategy:
|
||||||
|
|||||||
@@ -95,7 +95,6 @@ yarn-debug.log*
|
|||||||
.claude/settings.local.json
|
.claude/settings.local.json
|
||||||
.cursor
|
.cursor
|
||||||
.codex/
|
.codex/
|
||||||
.claude/
|
|
||||||
CLAUDE.local.md
|
CLAUDE.local.md
|
||||||
|
|
||||||
# Histoire deployment
|
# Histoire deployment
|
||||||
|
|||||||
@@ -68,15 +68,6 @@
|
|||||||
- Example: `feat(auth): add user authentication`
|
- Example: `feat(auth): add user authentication`
|
||||||
- Don't reference Claude in commit messages
|
- Don't reference Claude in commit messages
|
||||||
|
|
||||||
## PR Description Format
|
|
||||||
|
|
||||||
- Start with a short, user-facing paragraph describing the product change.
|
|
||||||
- Add a `Closes` section with relevant issue links (GitHub, Linear, etc.).
|
|
||||||
- For feature PRs, add `How to test` from a product/UX standpoint.
|
|
||||||
- For bugfix PRs, use `How to reproduce` when helpful.
|
|
||||||
- Optionally add a `What changed` section for implementation highlights.
|
|
||||||
- Do not add a `How this was tested` section listing specs/commands.
|
|
||||||
|
|
||||||
## Project-Specific
|
## Project-Specific
|
||||||
|
|
||||||
- **Translations**:
|
- **Translations**:
|
||||||
|
|||||||
@@ -22,7 +22,6 @@ gem 'time_diff'
|
|||||||
gem 'tzinfo-data'
|
gem 'tzinfo-data'
|
||||||
gem 'valid_email2'
|
gem 'valid_email2'
|
||||||
gem 'email-provider-info'
|
gem 'email-provider-info'
|
||||||
gem 'gemoji'
|
|
||||||
# compress javascript config.assets.js_compressor
|
# compress javascript config.assets.js_compressor
|
||||||
gem 'uglifier'
|
gem 'uglifier'
|
||||||
##-- used for single column multiple binary flags in notification settings/feature flagging --##
|
##-- used for single column multiple binary flags in notification settings/feature flagging --##
|
||||||
@@ -41,8 +40,6 @@ gem 'json_refs'
|
|||||||
gem 'rack-attack', '>= 6.7.0'
|
gem 'rack-attack', '>= 6.7.0'
|
||||||
# a utility tool for streaming, flexible and safe downloading of remote files
|
# a utility tool for streaming, flexible and safe downloading of remote files
|
||||||
gem 'down'
|
gem 'down'
|
||||||
# SSRF-safe URL fetching
|
|
||||||
gem 'ssrf_filter', '~> 1.5'
|
|
||||||
# authentication type to fetch and send mail over oauth2.0
|
# authentication type to fetch and send mail over oauth2.0
|
||||||
gem 'gmail_xoauth'
|
gem 'gmail_xoauth'
|
||||||
# Lock net-smtp to 0.3.4 to avoid issues with gmail_xoauth2
|
# Lock net-smtp to 0.3.4 to avoid issues with gmail_xoauth2
|
||||||
@@ -85,11 +82,10 @@ gem 'barnes'
|
|||||||
gem 'devise', '>= 4.9.4'
|
gem 'devise', '>= 4.9.4'
|
||||||
gem 'devise-secure_password', git: 'https://github.com/chatwoot/devise-secure_password', branch: 'chatwoot'
|
gem 'devise-secure_password', git: 'https://github.com/chatwoot/devise-secure_password', branch: 'chatwoot'
|
||||||
gem 'devise_token_auth', '>= 1.2.3'
|
gem 'devise_token_auth', '>= 1.2.3'
|
||||||
gem 'rails-i18n', '~> 7.0'
|
|
||||||
# two-factor authentication
|
# two-factor authentication
|
||||||
gem 'devise-two-factor', '>= 5.0.0'
|
gem 'devise-two-factor', '>= 5.0.0'
|
||||||
# authorization
|
# authorization
|
||||||
gem 'jwt', '~> 2.10', '>= 2.10.3'
|
gem 'jwt'
|
||||||
gem 'pundit'
|
gem 'pundit'
|
||||||
|
|
||||||
# super admin
|
# super admin
|
||||||
@@ -133,9 +129,9 @@ gem 'sentry-ruby', require: false
|
|||||||
gem 'sentry-sidekiq', '>= 5.19.0', require: false
|
gem 'sentry-sidekiq', '>= 5.19.0', require: false
|
||||||
|
|
||||||
##-- background job processing --##
|
##-- background job processing --##
|
||||||
gem 'sidekiq', '~> 7.3', '>= 7.3.1'
|
gem 'sidekiq', '>= 7.3.1'
|
||||||
# We want cron jobs
|
# We want cron jobs
|
||||||
gem 'sidekiq-cron', '>= 2.4.0'
|
gem 'sidekiq-cron', '>= 1.12.0'
|
||||||
# for sidekiq healthcheck
|
# for sidekiq healthcheck
|
||||||
gem 'sidekiq_alive'
|
gem 'sidekiq_alive'
|
||||||
|
|
||||||
@@ -195,10 +191,10 @@ gem 'reverse_markdown'
|
|||||||
|
|
||||||
gem 'iso-639'
|
gem 'iso-639'
|
||||||
gem 'ruby-openai'
|
gem 'ruby-openai'
|
||||||
gem 'ai-agents', '>= 0.10.0'
|
gem 'ai-agents'
|
||||||
|
|
||||||
# TODO: Move this gem as a dependency of ai-agents
|
# TODO: Move this gem as a dependency of ai-agents
|
||||||
gem 'ruby_llm', '>= 1.14.1'
|
gem 'ruby_llm', '>= 1.8.2'
|
||||||
gem 'ruby_llm-schema'
|
gem 'ruby_llm-schema'
|
||||||
|
|
||||||
gem 'cld3', '~> 3.7'
|
gem 'cld3', '~> 3.7'
|
||||||
@@ -209,8 +205,6 @@ gem 'opentelemetry-exporter-otlp'
|
|||||||
|
|
||||||
gem 'shopify_api'
|
gem 'shopify_api'
|
||||||
|
|
||||||
gem 'firecrawl-sdk', '~> 1.0', require: 'firecrawl'
|
|
||||||
|
|
||||||
### Gems required only in specific deployment environments ###
|
### Gems required only in specific deployment environments ###
|
||||||
##############################################################
|
##############################################################
|
||||||
|
|
||||||
@@ -274,7 +268,6 @@ group :development, :test do
|
|||||||
gem 'seed_dump'
|
gem 'seed_dump'
|
||||||
gem 'shoulda-matchers'
|
gem 'shoulda-matchers'
|
||||||
gem 'simplecov', '>= 0.21', require: false
|
gem 'simplecov', '>= 0.21', require: false
|
||||||
gem 'skooma'
|
|
||||||
gem 'spring'
|
gem 'spring'
|
||||||
gem 'spring-watcher-listen'
|
gem 'spring-watcher-listen'
|
||||||
end
|
end
|
||||||
|
|||||||
+35
-61
@@ -108,8 +108,8 @@ GEM
|
|||||||
acts-as-taggable-on (12.0.0)
|
acts-as-taggable-on (12.0.0)
|
||||||
activerecord (>= 7.1, < 8.1)
|
activerecord (>= 7.1, < 8.1)
|
||||||
zeitwerk (>= 2.4, < 3.0)
|
zeitwerk (>= 2.4, < 3.0)
|
||||||
addressable (2.9.0)
|
addressable (2.8.7)
|
||||||
public_suffix (>= 2.0.2, < 8.0)
|
public_suffix (>= 2.0.2, < 7.0)
|
||||||
administrate (0.20.1)
|
administrate (0.20.1)
|
||||||
actionpack (>= 6.0, < 8.0)
|
actionpack (>= 6.0, < 8.0)
|
||||||
actionview (>= 6.0, < 8.0)
|
actionview (>= 6.0, < 8.0)
|
||||||
@@ -126,8 +126,8 @@ GEM
|
|||||||
jbuilder (~> 2)
|
jbuilder (~> 2)
|
||||||
rails (>= 4.2, < 7.2)
|
rails (>= 4.2, < 7.2)
|
||||||
selectize-rails (~> 0.6)
|
selectize-rails (~> 0.6)
|
||||||
ai-agents (0.10.0)
|
ai-agents (0.9.0)
|
||||||
ruby_llm (~> 1.14)
|
ruby_llm (~> 1.9.1)
|
||||||
annotaterb (4.20.0)
|
annotaterb (4.20.0)
|
||||||
activerecord (>= 6.0.0)
|
activerecord (>= 6.0.0)
|
||||||
activesupport (>= 6.0.0)
|
activesupport (>= 6.0.0)
|
||||||
@@ -166,7 +166,7 @@ GEM
|
|||||||
multi_json (~> 1)
|
multi_json (~> 1)
|
||||||
statsd-ruby (~> 1.1)
|
statsd-ruby (~> 1.1)
|
||||||
base64 (0.3.0)
|
base64 (0.3.0)
|
||||||
bcrypt (3.1.22)
|
bcrypt (3.1.20)
|
||||||
benchmark (0.4.1)
|
benchmark (0.4.1)
|
||||||
bigdecimal (3.2.2)
|
bigdecimal (3.2.2)
|
||||||
bindex (0.8.1)
|
bindex (0.8.1)
|
||||||
@@ -191,14 +191,11 @@ GEM
|
|||||||
coderay (1.1.3)
|
coderay (1.1.3)
|
||||||
commonmarker (0.23.10)
|
commonmarker (0.23.10)
|
||||||
concurrent-ruby (1.3.5)
|
concurrent-ruby (1.3.5)
|
||||||
connection_pool (2.5.5)
|
connection_pool (2.5.3)
|
||||||
crack (1.0.0)
|
crack (1.0.0)
|
||||||
bigdecimal
|
bigdecimal
|
||||||
rexml
|
rexml
|
||||||
crass (1.0.6)
|
crass (1.0.6)
|
||||||
cronex (0.15.0)
|
|
||||||
tzinfo
|
|
||||||
unicode (>= 0.4.4.5)
|
|
||||||
csv (3.3.0)
|
csv (3.3.0)
|
||||||
csv-safe (3.3.1)
|
csv-safe (3.3.1)
|
||||||
csv (~> 3.0)
|
csv (~> 3.0)
|
||||||
@@ -215,7 +212,7 @@ GEM
|
|||||||
logger
|
logger
|
||||||
msgpack
|
msgpack
|
||||||
datadog-ruby_core_source (3.4.1)
|
datadog-ruby_core_source (3.4.1)
|
||||||
date (3.5.1)
|
date (3.4.1)
|
||||||
debug (1.8.0)
|
debug (1.8.0)
|
||||||
irb (>= 1.5.0)
|
irb (>= 1.5.0)
|
||||||
reline (>= 0.3.1)
|
reline (>= 0.3.1)
|
||||||
@@ -301,7 +298,7 @@ GEM
|
|||||||
railties (>= 5.0.0)
|
railties (>= 5.0.0)
|
||||||
faker (3.2.0)
|
faker (3.2.0)
|
||||||
i18n (>= 1.8.11, < 2)
|
i18n (>= 1.8.11, < 2)
|
||||||
faraday (2.14.2)
|
faraday (2.14.1)
|
||||||
faraday-net_http (>= 2.0, < 3.5)
|
faraday-net_http (>= 2.0, < 3.5)
|
||||||
json
|
json
|
||||||
logger
|
logger
|
||||||
@@ -310,8 +307,8 @@ GEM
|
|||||||
faraday-mashify (1.0.0)
|
faraday-mashify (1.0.0)
|
||||||
faraday (~> 2.0)
|
faraday (~> 2.0)
|
||||||
hashie
|
hashie
|
||||||
faraday-multipart (1.2.0)
|
faraday-multipart (1.0.4)
|
||||||
multipart-post (~> 2.0)
|
multipart-post (~> 2)
|
||||||
faraday-net_http (3.4.2)
|
faraday-net_http (3.4.2)
|
||||||
net-http (~> 0.5)
|
net-http (~> 0.5)
|
||||||
faraday-net_http_persistent (2.1.0)
|
faraday-net_http_persistent (2.1.0)
|
||||||
@@ -339,7 +336,6 @@ GEM
|
|||||||
ffi-compiler (1.0.1)
|
ffi-compiler (1.0.1)
|
||||||
ffi (>= 1.0.0)
|
ffi (>= 1.0.0)
|
||||||
rake
|
rake
|
||||||
firecrawl-sdk (1.4.1)
|
|
||||||
flag_shih_tzu (0.3.23)
|
flag_shih_tzu (0.3.23)
|
||||||
foreman (0.87.2)
|
foreman (0.87.2)
|
||||||
fugit (1.11.1)
|
fugit (1.11.1)
|
||||||
@@ -353,7 +349,6 @@ GEM
|
|||||||
googleapis-common-protos-types (>= 1.3.1, < 2.a)
|
googleapis-common-protos-types (>= 1.3.1, < 2.a)
|
||||||
googleauth (~> 1.0)
|
googleauth (~> 1.0)
|
||||||
grpc (~> 1.36)
|
grpc (~> 1.36)
|
||||||
gemoji (4.1.0)
|
|
||||||
geocoder (1.8.1)
|
geocoder (1.8.1)
|
||||||
gli (2.22.2)
|
gli (2.22.2)
|
||||||
ostruct
|
ostruct
|
||||||
@@ -470,7 +465,7 @@ GEM
|
|||||||
rails-dom-testing (>= 1, < 3)
|
rails-dom-testing (>= 1, < 3)
|
||||||
railties (>= 4.2.0)
|
railties (>= 4.2.0)
|
||||||
thor (>= 0.14, < 2.0)
|
thor (>= 0.14, < 2.0)
|
||||||
json (2.19.5)
|
json (2.18.1)
|
||||||
json_refs (0.1.8)
|
json_refs (0.1.8)
|
||||||
hana
|
hana
|
||||||
json_schemer (0.2.24)
|
json_schemer (0.2.24)
|
||||||
@@ -478,12 +473,6 @@ GEM
|
|||||||
hana (~> 1.3)
|
hana (~> 1.3)
|
||||||
regexp_parser (~> 2.0)
|
regexp_parser (~> 2.0)
|
||||||
uri_template (~> 0.7)
|
uri_template (~> 0.7)
|
||||||
json_skooma (0.2.5)
|
|
||||||
bigdecimal
|
|
||||||
hana (~> 1.3)
|
|
||||||
regexp_parser (~> 2.0)
|
|
||||||
uri-idna (~> 0.2)
|
|
||||||
zeitwerk (~> 2.6)
|
|
||||||
judoscale-rails (1.8.2)
|
judoscale-rails (1.8.2)
|
||||||
judoscale-ruby (= 1.8.2)
|
judoscale-ruby (= 1.8.2)
|
||||||
railties
|
railties
|
||||||
@@ -491,7 +480,7 @@ GEM
|
|||||||
judoscale-sidekiq (1.8.2)
|
judoscale-sidekiq (1.8.2)
|
||||||
judoscale-ruby (= 1.8.2)
|
judoscale-ruby (= 1.8.2)
|
||||||
sidekiq (>= 5.0)
|
sidekiq (>= 5.0)
|
||||||
jwt (2.10.3)
|
jwt (2.10.1)
|
||||||
base64
|
base64
|
||||||
kaminari (1.2.2)
|
kaminari (1.2.2)
|
||||||
activesupport (>= 4.1.0)
|
activesupport (>= 4.1.0)
|
||||||
@@ -578,7 +567,7 @@ GEM
|
|||||||
uri (>= 0.11.1)
|
uri (>= 0.11.1)
|
||||||
net-http-persistent (4.0.2)
|
net-http-persistent (4.0.2)
|
||||||
connection_pool (~> 2.2)
|
connection_pool (~> 2.2)
|
||||||
net-imap (0.4.24)
|
net-imap (0.4.20)
|
||||||
date
|
date
|
||||||
net-protocol
|
net-protocol
|
||||||
net-pop (0.1.2)
|
net-pop (0.1.2)
|
||||||
@@ -594,14 +583,14 @@ GEM
|
|||||||
newrelic_rpm (9.6.0)
|
newrelic_rpm (9.6.0)
|
||||||
base64
|
base64
|
||||||
nio4r (2.7.3)
|
nio4r (2.7.3)
|
||||||
nokogiri (1.19.3)
|
nokogiri (1.18.9)
|
||||||
mini_portile2 (~> 2.8.2)
|
mini_portile2 (~> 2.8.2)
|
||||||
racc (~> 1.4)
|
racc (~> 1.4)
|
||||||
nokogiri (1.19.3-arm64-darwin)
|
nokogiri (1.18.9-arm64-darwin)
|
||||||
racc (~> 1.4)
|
racc (~> 1.4)
|
||||||
nokogiri (1.19.3-x86_64-darwin)
|
nokogiri (1.18.9-x86_64-darwin)
|
||||||
racc (~> 1.4)
|
racc (~> 1.4)
|
||||||
nokogiri (1.19.3-x86_64-linux-gnu)
|
nokogiri (1.18.9-x86_64-linux-gnu)
|
||||||
racc (~> 1.4)
|
racc (~> 1.4)
|
||||||
oauth (1.1.0)
|
oauth (1.1.0)
|
||||||
oauth-tty (~> 1.0, >= 1.0.1)
|
oauth-tty (~> 1.0, >= 1.0.1)
|
||||||
@@ -681,14 +670,14 @@ GEM
|
|||||||
method_source (~> 1.0)
|
method_source (~> 1.0)
|
||||||
pry-rails (0.3.9)
|
pry-rails (0.3.9)
|
||||||
pry (>= 0.10.4)
|
pry (>= 0.10.4)
|
||||||
public_suffix (7.0.5)
|
public_suffix (6.0.2)
|
||||||
puma (6.4.3)
|
puma (6.4.3)
|
||||||
nio4r (~> 2.0)
|
nio4r (~> 2.0)
|
||||||
pundit (2.3.0)
|
pundit (2.3.0)
|
||||||
activesupport (>= 3.0.0)
|
activesupport (>= 3.0.0)
|
||||||
raabro (1.4.0)
|
raabro (1.4.0)
|
||||||
racc (1.8.1)
|
racc (1.8.1)
|
||||||
rack (3.2.6)
|
rack (3.2.3)
|
||||||
rack-attack (6.7.0)
|
rack-attack (6.7.0)
|
||||||
rack (>= 1.0, < 4)
|
rack (>= 1.0, < 4)
|
||||||
rack-contrib (2.5.0)
|
rack-contrib (2.5.0)
|
||||||
@@ -703,7 +692,7 @@ GEM
|
|||||||
rack (>= 3.0.0, < 4)
|
rack (>= 3.0.0, < 4)
|
||||||
rack-proxy (0.7.7)
|
rack-proxy (0.7.7)
|
||||||
rack
|
rack
|
||||||
rack-session (2.1.2)
|
rack-session (2.1.1)
|
||||||
base64 (>= 0.1.0)
|
base64 (>= 0.1.0)
|
||||||
rack (>= 3.0.0)
|
rack (>= 3.0.0)
|
||||||
rack-test (2.1.0)
|
rack-test (2.1.0)
|
||||||
@@ -732,9 +721,6 @@ GEM
|
|||||||
rails-html-sanitizer (1.6.1)
|
rails-html-sanitizer (1.6.1)
|
||||||
loofah (~> 2.21)
|
loofah (~> 2.21)
|
||||||
nokogiri (>= 1.15.7, != 1.16.7, != 1.16.6, != 1.16.5, != 1.16.4, != 1.16.3, != 1.16.2, != 1.16.1, != 1.16.0.rc1, != 1.16.0)
|
nokogiri (>= 1.15.7, != 1.16.7, != 1.16.6, != 1.16.5, != 1.16.4, != 1.16.3, != 1.16.2, != 1.16.1, != 1.16.0.rc1, != 1.16.0)
|
||||||
rails-i18n (7.0.10)
|
|
||||||
i18n (>= 0.7, < 2)
|
|
||||||
railties (>= 6.0.0, < 8)
|
|
||||||
railties (7.1.5.2)
|
railties (7.1.5.2)
|
||||||
actionpack (= 7.1.5.2)
|
actionpack (= 7.1.5.2)
|
||||||
activesupport (= 7.1.5.2)
|
activesupport (= 7.1.5.2)
|
||||||
@@ -750,7 +736,7 @@ GEM
|
|||||||
ffi (~> 1.0)
|
ffi (~> 1.0)
|
||||||
redis (5.0.6)
|
redis (5.0.6)
|
||||||
redis-client (>= 0.9.0)
|
redis-client (>= 0.9.0)
|
||||||
redis-client (0.26.4)
|
redis-client (0.22.2)
|
||||||
connection_pool
|
connection_pool
|
||||||
redis-namespace (1.10.0)
|
redis-namespace (1.10.0)
|
||||||
redis (>= 4)
|
redis (>= 4)
|
||||||
@@ -839,17 +825,17 @@ GEM
|
|||||||
ruby2ruby (2.5.0)
|
ruby2ruby (2.5.0)
|
||||||
ruby_parser (~> 3.1)
|
ruby_parser (~> 3.1)
|
||||||
sexp_processor (~> 4.6)
|
sexp_processor (~> 4.6)
|
||||||
ruby_llm (1.15.0)
|
ruby_llm (1.9.2)
|
||||||
base64
|
base64
|
||||||
event_stream_parser (~> 1)
|
event_stream_parser (~> 1)
|
||||||
faraday (>= 1.10.0)
|
faraday (>= 1.10.0)
|
||||||
faraday-multipart (>= 1)
|
faraday-multipart (>= 1)
|
||||||
faraday-net_http (>= 1)
|
faraday-net_http (>= 1)
|
||||||
faraday-retry (>= 1)
|
faraday-retry (>= 1)
|
||||||
marcel (~> 1)
|
marcel (~> 1.0)
|
||||||
ruby_llm-schema (~> 0)
|
ruby_llm-schema (~> 0.2.1)
|
||||||
zeitwerk (~> 2)
|
zeitwerk (~> 2)
|
||||||
ruby_llm-schema (0.3.0)
|
ruby_llm-schema (0.2.5)
|
||||||
ruby_parser (3.20.0)
|
ruby_parser (3.20.0)
|
||||||
sexp_processor (~> 4.16)
|
sexp_processor (~> 4.16)
|
||||||
sass (3.7.4)
|
sass (3.7.4)
|
||||||
@@ -906,11 +892,10 @@ GEM
|
|||||||
logger
|
logger
|
||||||
rack (>= 2.2.4)
|
rack (>= 2.2.4)
|
||||||
redis-client (>= 0.22.2)
|
redis-client (>= 0.22.2)
|
||||||
sidekiq-cron (2.4.0)
|
sidekiq-cron (1.12.0)
|
||||||
cronex (>= 0.13.0)
|
fugit (~> 1.8)
|
||||||
fugit (~> 1.8, >= 1.11.1)
|
|
||||||
globalid (>= 1.0.1)
|
globalid (>= 1.0.1)
|
||||||
sidekiq (>= 6.5.0)
|
sidekiq (>= 6)
|
||||||
sidekiq_alive (2.5.0)
|
sidekiq_alive (2.5.0)
|
||||||
gserver (~> 0.0.1)
|
gserver (~> 0.0.1)
|
||||||
sidekiq (>= 5, < 9)
|
sidekiq (>= 5, < 9)
|
||||||
@@ -925,9 +910,6 @@ GEM
|
|||||||
simplecov_json_formatter (~> 0.1)
|
simplecov_json_formatter (~> 0.1)
|
||||||
simplecov-html (0.13.2)
|
simplecov-html (0.13.2)
|
||||||
simplecov_json_formatter (0.1.4)
|
simplecov_json_formatter (0.1.4)
|
||||||
skooma (0.3.7)
|
|
||||||
json_skooma (~> 0.2.5)
|
|
||||||
zeitwerk (~> 2.6)
|
|
||||||
slack-ruby-client (2.7.0)
|
slack-ruby-client (2.7.0)
|
||||||
faraday (>= 2.0.1)
|
faraday (>= 2.0.1)
|
||||||
faraday-mashify
|
faraday-mashify
|
||||||
@@ -951,7 +933,6 @@ GEM
|
|||||||
activesupport (>= 5.2)
|
activesupport (>= 5.2)
|
||||||
sprockets (>= 3.0.0)
|
sprockets (>= 3.0.0)
|
||||||
squasher (0.7.2)
|
squasher (0.7.2)
|
||||||
ssrf_filter (1.5.0)
|
|
||||||
stackprof (0.2.25)
|
stackprof (0.2.25)
|
||||||
statsd-ruby (1.5.0)
|
statsd-ruby (1.5.0)
|
||||||
stripe (18.0.1)
|
stripe (18.0.1)
|
||||||
@@ -966,7 +947,7 @@ GEM
|
|||||||
time_diff (0.3.0)
|
time_diff (0.3.0)
|
||||||
activesupport
|
activesupport
|
||||||
i18n
|
i18n
|
||||||
timeout (0.6.1)
|
timeout (0.4.3)
|
||||||
trailblazer-option (0.1.2)
|
trailblazer-option (0.1.2)
|
||||||
twilio-ruby (7.6.0)
|
twilio-ruby (7.6.0)
|
||||||
faraday (>= 0.9, < 3.0)
|
faraday (>= 0.9, < 3.0)
|
||||||
@@ -984,13 +965,11 @@ GEM
|
|||||||
unf (0.1.4)
|
unf (0.1.4)
|
||||||
unf_ext
|
unf_ext
|
||||||
unf_ext (0.0.8.2)
|
unf_ext (0.0.8.2)
|
||||||
unicode (0.4.4.5)
|
|
||||||
unicode-display_width (3.1.4)
|
unicode-display_width (3.1.4)
|
||||||
unicode-emoji (~> 4.0, >= 4.0.4)
|
unicode-emoji (~> 4.0, >= 4.0.4)
|
||||||
unicode-emoji (4.0.4)
|
unicode-emoji (4.0.4)
|
||||||
uniform_notifier (1.17.0)
|
uniform_notifier (1.17.0)
|
||||||
uri (1.1.1)
|
uri (1.1.1)
|
||||||
uri-idna (0.3.1)
|
|
||||||
uri_template (0.7.0)
|
uri_template (0.7.0)
|
||||||
valid_email2 (5.2.6)
|
valid_email2 (5.2.6)
|
||||||
activemodel (>= 3.2)
|
activemodel (>= 3.2)
|
||||||
@@ -1025,7 +1004,7 @@ GEM
|
|||||||
working_hours (1.4.1)
|
working_hours (1.4.1)
|
||||||
activesupport (>= 3.2)
|
activesupport (>= 3.2)
|
||||||
tzinfo
|
tzinfo
|
||||||
zeitwerk (2.7.5)
|
zeitwerk (2.7.4)
|
||||||
|
|
||||||
PLATFORMS
|
PLATFORMS
|
||||||
arm64-darwin-20
|
arm64-darwin-20
|
||||||
@@ -1045,7 +1024,7 @@ DEPENDENCIES
|
|||||||
administrate (>= 0.20.1)
|
administrate (>= 0.20.1)
|
||||||
administrate-field-active_storage (>= 1.0.3)
|
administrate-field-active_storage (>= 1.0.3)
|
||||||
administrate-field-belongs_to_search (>= 0.9.0)
|
administrate-field-belongs_to_search (>= 0.9.0)
|
||||||
ai-agents (>= 0.10.0)
|
ai-agents
|
||||||
annotaterb
|
annotaterb
|
||||||
attr_extras
|
attr_extras
|
||||||
audited (~> 5.4, >= 5.4.1)
|
audited (~> 5.4, >= 5.4.1)
|
||||||
@@ -1080,10 +1059,8 @@ DEPENDENCIES
|
|||||||
faker
|
faker
|
||||||
faraday_middleware-aws-sigv4
|
faraday_middleware-aws-sigv4
|
||||||
fcm
|
fcm
|
||||||
firecrawl-sdk (~> 1.0)
|
|
||||||
flag_shih_tzu
|
flag_shih_tzu
|
||||||
foreman
|
foreman
|
||||||
gemoji
|
|
||||||
geocoder
|
geocoder
|
||||||
gmail_xoauth
|
gmail_xoauth
|
||||||
google-cloud-dialogflow-v2 (>= 0.24.0)
|
google-cloud-dialogflow-v2 (>= 0.24.0)
|
||||||
@@ -1102,7 +1079,7 @@ DEPENDENCIES
|
|||||||
json_schemer
|
json_schemer
|
||||||
judoscale-rails
|
judoscale-rails
|
||||||
judoscale-sidekiq
|
judoscale-sidekiq
|
||||||
jwt (~> 2.10, >= 2.10.3)
|
jwt
|
||||||
kaminari
|
kaminari
|
||||||
koala
|
koala
|
||||||
letter_opener
|
letter_opener
|
||||||
@@ -1137,7 +1114,6 @@ DEPENDENCIES
|
|||||||
rack-mini-profiler (>= 3.2.0)
|
rack-mini-profiler (>= 3.2.0)
|
||||||
rack-timeout
|
rack-timeout
|
||||||
rails (~> 7.1)
|
rails (~> 7.1)
|
||||||
rails-i18n (~> 7.0)
|
|
||||||
redis
|
redis
|
||||||
redis-namespace
|
redis-namespace
|
||||||
responders (>= 3.1.1)
|
responders (>= 3.1.1)
|
||||||
@@ -1151,7 +1127,7 @@ DEPENDENCIES
|
|||||||
rubocop-rails
|
rubocop-rails
|
||||||
rubocop-rspec
|
rubocop-rspec
|
||||||
ruby-openai
|
ruby-openai
|
||||||
ruby_llm (>= 1.14.1)
|
ruby_llm (>= 1.8.2)
|
||||||
ruby_llm-schema
|
ruby_llm-schema
|
||||||
scout_apm
|
scout_apm
|
||||||
scss_lint
|
scss_lint
|
||||||
@@ -1162,17 +1138,15 @@ DEPENDENCIES
|
|||||||
sentry-sidekiq (>= 5.19.0)
|
sentry-sidekiq (>= 5.19.0)
|
||||||
shopify_api
|
shopify_api
|
||||||
shoulda-matchers
|
shoulda-matchers
|
||||||
sidekiq (~> 7.3, >= 7.3.1)
|
sidekiq (>= 7.3.1)
|
||||||
sidekiq-cron (>= 2.4.0)
|
sidekiq-cron (>= 1.12.0)
|
||||||
sidekiq_alive
|
sidekiq_alive
|
||||||
simplecov (>= 0.21)
|
simplecov (>= 0.21)
|
||||||
simplecov_json_formatter
|
simplecov_json_formatter
|
||||||
skooma
|
|
||||||
slack-ruby-client (~> 2.7.0)
|
slack-ruby-client (~> 2.7.0)
|
||||||
spring
|
spring
|
||||||
spring-watcher-listen
|
spring-watcher-listen
|
||||||
squasher
|
squasher
|
||||||
ssrf_filter (~> 1.5)
|
|
||||||
stackprof
|
stackprof
|
||||||
stripe (~> 18.0)
|
stripe (~> 18.0)
|
||||||
telephone_number
|
telephone_number
|
||||||
|
|||||||
@@ -40,12 +40,8 @@ run:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
force_run:
|
force_run:
|
||||||
@echo "Cleaning up Overmind processes..."
|
rm -f ./.overmind.sock
|
||||||
@lsof -ti:3036 2>/dev/null | xargs kill -9 2>/dev/null || true
|
rm -f tmp/pids/*.pid
|
||||||
@lsof -ti:3000 2>/dev/null | xargs kill -9 2>/dev/null || true
|
|
||||||
@rm -f ./.overmind.sock
|
|
||||||
@rm -f tmp/pids/*.pid
|
|
||||||
@echo "Cleanup complete"
|
|
||||||
overmind start -f Procfile.dev
|
overmind start -f Procfile.dev
|
||||||
|
|
||||||
force_run_tunnel:
|
force_run_tunnel:
|
||||||
|
|||||||
+1
-1
@@ -1 +1 @@
|
|||||||
4.14.1
|
4.10.1
|
||||||
|
|||||||
@@ -104,7 +104,7 @@ class ContactIdentifyAction
|
|||||||
# blank identifier or email will throw unique index error
|
# blank identifier or email will throw unique index error
|
||||||
# TODO: replace reject { |_k, v| v.blank? } with compact_blank when rails is upgraded
|
# TODO: replace reject { |_k, v| v.blank? } with compact_blank when rails is upgraded
|
||||||
@contact.discard_invalid_attrs if discard_invalid_attrs
|
@contact.discard_invalid_attrs if discard_invalid_attrs
|
||||||
@contact.save! if @contact.changed?
|
@contact.save!
|
||||||
enqueue_avatar_job
|
enqueue_avatar_job
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
@@ -44,11 +44,7 @@ class AccountBuilder
|
|||||||
end
|
end
|
||||||
|
|
||||||
def create_account
|
def create_account
|
||||||
@account = Account.create!(
|
@account = Account.create!(name: account_name, locale: I18n.locale)
|
||||||
name: account_name,
|
|
||||||
locale: I18n.locale,
|
|
||||||
custom_attributes: { 'onboarding_step' => 'account_details' }
|
|
||||||
)
|
|
||||||
Current.account = @account
|
Current.account = @account
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
@@ -29,9 +29,8 @@ class AgentBuilder
|
|||||||
user = User.from_email(email)
|
user = User.from_email(email)
|
||||||
return user if user
|
return user if user
|
||||||
|
|
||||||
@name = email.split('@').first if @name.blank?
|
|
||||||
temp_password = "1!aA#{SecureRandom.alphanumeric(12)}"
|
temp_password = "1!aA#{SecureRandom.alphanumeric(12)}"
|
||||||
User.create!(email: email, name: @name, password: temp_password, password_confirmation: temp_password)
|
User.create!(email: email, name: name, password: temp_password, password_confirmation: temp_password)
|
||||||
end
|
end
|
||||||
|
|
||||||
# Checks if the user needs confirmation.
|
# Checks if the user needs confirmation.
|
||||||
|
|||||||
@@ -1,6 +1,4 @@
|
|||||||
class Email::BaseBuilder
|
class Email::BaseBuilder
|
||||||
include EmailAddressParseable
|
|
||||||
|
|
||||||
pattr_initialize [:inbox!]
|
pattr_initialize [:inbox!]
|
||||||
|
|
||||||
private
|
private
|
||||||
@@ -41,7 +39,7 @@ class Email::BaseBuilder
|
|||||||
end
|
end
|
||||||
|
|
||||||
def business_name
|
def business_name
|
||||||
inbox.sanitized_business_name
|
inbox.business_name || inbox.sanitized_name
|
||||||
end
|
end
|
||||||
|
|
||||||
def account_support_email
|
def account_support_email
|
||||||
@@ -49,4 +47,8 @@ class Email::BaseBuilder
|
|||||||
# can save it in the format "Name <email@domain.com>"
|
# can save it in the format "Name <email@domain.com>"
|
||||||
parse_email(account.support_email)
|
parse_email(account.support_email)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def parse_email(email_string)
|
||||||
|
Mail::Address.new(email_string).address
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -105,19 +105,15 @@ class Messages::Facebook::MessageBuilder < Messages::Messenger::MessageBuilder
|
|||||||
end
|
end
|
||||||
|
|
||||||
def message_params
|
def message_params
|
||||||
content_attributes = {
|
|
||||||
in_reply_to_external_id: response.in_reply_to_external_id
|
|
||||||
}
|
|
||||||
content_attributes[:external_echo] = true if @outgoing_echo
|
|
||||||
|
|
||||||
{
|
{
|
||||||
account_id: conversation.account_id,
|
account_id: conversation.account_id,
|
||||||
inbox_id: conversation.inbox_id,
|
inbox_id: conversation.inbox_id,
|
||||||
message_type: @message_type,
|
message_type: @message_type,
|
||||||
status: @outgoing_echo ? :delivered : :sent,
|
|
||||||
content: response.content,
|
content: response.content,
|
||||||
source_id: response.identifier,
|
source_id: response.identifier,
|
||||||
content_attributes: content_attributes,
|
content_attributes: {
|
||||||
|
in_reply_to_external_id: response.in_reply_to_external_id
|
||||||
|
},
|
||||||
sender: @outgoing_echo ? nil : @contact_inbox.contact
|
sender: @outgoing_echo ? nil : @contact_inbox.contact
|
||||||
}
|
}
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -2,17 +2,12 @@ class Messages::Messenger::MessageBuilder
|
|||||||
include ::FileTypeHelper
|
include ::FileTypeHelper
|
||||||
|
|
||||||
def process_attachment(attachment)
|
def process_attachment(attachment)
|
||||||
# This check handles very rare case if there are multiple files to attach with only one unsupported file
|
# This check handles very rare case if there are multiple files to attach with only one usupported file
|
||||||
return if unsupported_file_type?(attachment['type'])
|
return if unsupported_file_type?(attachment['type'])
|
||||||
|
|
||||||
params = attachment_params(attachment)
|
attachment_obj = @message.attachments.new(attachment_params(attachment).except(:remote_file_url))
|
||||||
attachment_obj = @message.attachments.new(params.except(:remote_file_url))
|
|
||||||
attachment_obj.save!
|
attachment_obj.save!
|
||||||
if facebook_reel?(attachment)
|
attach_file(attachment_obj, attachment_params(attachment)[:remote_file_url]) if attachment_params(attachment)[:remote_file_url]
|
||||||
update_facebook_reel_content(attachment)
|
|
||||||
elsif params[:remote_file_url]
|
|
||||||
attach_file(attachment_obj, params[:remote_file_url])
|
|
||||||
end
|
|
||||||
fetch_story_link(attachment_obj) if attachment_obj.file_type == 'story_mention'
|
fetch_story_link(attachment_obj) if attachment_obj.file_type == 'story_mention'
|
||||||
fetch_ig_story_link(attachment_obj) if attachment_obj.file_type == 'ig_story'
|
fetch_ig_story_link(attachment_obj) if attachment_obj.file_type == 'ig_story'
|
||||||
fetch_ig_post_link(attachment_obj) if attachment_obj.file_type == 'ig_post'
|
fetch_ig_post_link(attachment_obj) if attachment_obj.file_type == 'ig_post'
|
||||||
@@ -28,14 +23,10 @@ class Messages::Messenger::MessageBuilder
|
|||||||
filename: attachment_file.original_filename,
|
filename: attachment_file.original_filename,
|
||||||
content_type: attachment_file.content_type
|
content_type: attachment_file.content_type
|
||||||
)
|
)
|
||||||
# The Attachment row is saved before the blob is attached, so the
|
|
||||||
# after_create_commit broadcast bails on `file.attached?`. Re-fire here
|
|
||||||
# for audio so the bubble updates without waiting on transcription.
|
|
||||||
attachment.message&.reload&.send_update_event if attachment.file_type.to_sym == :audio
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def attachment_params(attachment)
|
def attachment_params(attachment)
|
||||||
file_type = normalize_file_type(attachment['type'])
|
file_type = attachment['type'].to_sym
|
||||||
params = { file_type: file_type, account_id: @message.account_id }
|
params = { file_type: file_type, account_id: @message.account_id }
|
||||||
|
|
||||||
if [:image, :file, :audio, :video, :share, :story_mention, :ig_reel, :ig_post, :ig_story].include? file_type
|
if [:image, :file, :audio, :video, :share, :story_mention, :ig_reel, :ig_post, :ig_story].include? file_type
|
||||||
@@ -109,28 +100,6 @@ class Messages::Messenger::MessageBuilder
|
|||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
# Facebook may send attachment types that don't directly match our file_type enum.
|
|
||||||
# Map known aliases to their canonical enum values.
|
|
||||||
FACEBOOK_FILE_TYPE_MAP = { reel: :ig_reel }.freeze
|
|
||||||
|
|
||||||
def normalize_file_type(type)
|
|
||||||
sym = type.to_sym
|
|
||||||
FACEBOOK_FILE_TYPE_MAP.fetch(sym, sym)
|
|
||||||
end
|
|
||||||
|
|
||||||
# Facebook sends reel URLs as webpage links (facebook.com/reel/...) rather than
|
|
||||||
# direct video URLs. Downloading these yields HTML, not video content.
|
|
||||||
def facebook_reel?(attachment)
|
|
||||||
attachment['type'].to_sym == :reel
|
|
||||||
end
|
|
||||||
|
|
||||||
def update_facebook_reel_content(attachment)
|
|
||||||
url = attachment.dig('payload', 'url')
|
|
||||||
return if url.blank?
|
|
||||||
|
|
||||||
@message.update!(content: url) if @message.content.blank?
|
|
||||||
end
|
|
||||||
|
|
||||||
def unsupported_file_type?(attachment_type)
|
def unsupported_file_type?(attachment_type)
|
||||||
[:template, :unsupported_type, :ephemeral].include? attachment_type.to_sym
|
[:template, :unsupported_type, :ephemeral].include? attachment_type.to_sym
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -27,8 +27,6 @@ class NotificationBuilder
|
|||||||
return if notification_type == 'conversation_creation' && !user_subscribed_to_notification?
|
return if notification_type == 'conversation_creation' && !user_subscribed_to_notification?
|
||||||
# skip notifications for blocked conversations except for user mentions
|
# skip notifications for blocked conversations except for user mentions
|
||||||
return if primary_actor.contact.blocked? && notification_type != 'conversation_mention'
|
return if primary_actor.contact.blocked? && notification_type != 'conversation_mention'
|
||||||
# respect conversation access (inbox/team membership and custom-role permissions)
|
|
||||||
return unless user_can_access_conversation?
|
|
||||||
|
|
||||||
user.notifications.create!(
|
user.notifications.create!(
|
||||||
notification_type: notification_type,
|
notification_type: notification_type,
|
||||||
@@ -38,17 +36,4 @@ class NotificationBuilder
|
|||||||
secondary_actor: secondary_actor || current_user
|
secondary_actor: secondary_actor || current_user
|
||||||
)
|
)
|
||||||
end
|
end
|
||||||
|
|
||||||
def user_can_access_conversation?
|
|
||||||
conversation = primary_actor.is_a?(Conversation) ? primary_actor : primary_actor.try(:conversation)
|
|
||||||
return true if conversation.blank?
|
|
||||||
|
|
||||||
account_user = AccountUser.find_by(account_id: account.id, user_id: user.id)
|
|
||||||
return false if account_user.blank?
|
|
||||||
|
|
||||||
ConversationPolicy.new(
|
|
||||||
{ user: user, account: account, account_user: account_user },
|
|
||||||
conversation
|
|
||||||
).show?
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,7 +1,6 @@
|
|||||||
class V2::ReportBuilder
|
class V2::ReportBuilder
|
||||||
include DateRangeHelper
|
include DateRangeHelper
|
||||||
include ReportHelper
|
include ReportHelper
|
||||||
|
|
||||||
attr_reader :account, :params
|
attr_reader :account, :params
|
||||||
|
|
||||||
DEFAULT_GROUP_BY = 'day'.freeze
|
DEFAULT_GROUP_BY = 'day'.freeze
|
||||||
|
|||||||
@@ -11,6 +11,10 @@ class V2::Reports::AgentSummaryBuilder < V2::Reports::BaseSummaryBuilder
|
|||||||
attr_reader :conversations_count, :resolved_count,
|
attr_reader :conversations_count, :resolved_count,
|
||||||
:avg_resolution_time, :avg_first_response_time, :avg_reply_time
|
:avg_resolution_time, :avg_first_response_time, :avg_reply_time
|
||||||
|
|
||||||
|
def fetch_conversations_count
|
||||||
|
account.conversations.where(created_at: range).group('assignee_id').count
|
||||||
|
end
|
||||||
|
|
||||||
def prepare_report
|
def prepare_report
|
||||||
account.account_users.map do |account_user|
|
account.account_users.map do |account_user|
|
||||||
build_agent_stats(account_user)
|
build_agent_stats(account_user)
|
||||||
|
|||||||
@@ -9,13 +9,37 @@ class V2::Reports::BaseSummaryBuilder
|
|||||||
private
|
private
|
||||||
|
|
||||||
def load_data
|
def load_data
|
||||||
results = data_source.summary
|
@conversations_count = fetch_conversations_count
|
||||||
|
load_reporting_events_data
|
||||||
|
end
|
||||||
|
|
||||||
@conversations_count = results.transform_values { |data| data[:conversations_count] }
|
def load_reporting_events_data
|
||||||
@resolved_count = results.transform_values { |data| data[:resolved_conversations_count] }
|
# Extract the column name for indexing (e.g., 'conversations.team_id' -> 'team_id')
|
||||||
@avg_resolution_time = results.transform_values { |data| data[:avg_resolution_time] }
|
index_key = group_by_key.to_s.split('.').last
|
||||||
@avg_first_response_time = results.transform_values { |data| data[:avg_first_response_time] }
|
|
||||||
@avg_reply_time = results.transform_values { |data| data[:avg_reply_time] }
|
results = reporting_events
|
||||||
|
.select(
|
||||||
|
"#{group_by_key} as #{index_key}",
|
||||||
|
"COUNT(CASE WHEN name = 'conversation_resolved' THEN 1 END) as resolved_count",
|
||||||
|
"AVG(CASE WHEN name = 'conversation_resolved' THEN #{average_value_key} END) as avg_resolution_time",
|
||||||
|
"AVG(CASE WHEN name = 'first_response' THEN #{average_value_key} END) as avg_first_response_time",
|
||||||
|
"AVG(CASE WHEN name = 'reply_time' THEN #{average_value_key} END) as avg_reply_time"
|
||||||
|
)
|
||||||
|
.group(group_by_key)
|
||||||
|
.index_by { |record| record.public_send(index_key) }
|
||||||
|
|
||||||
|
@resolved_count = results.transform_values(&:resolved_count)
|
||||||
|
@avg_resolution_time = results.transform_values(&:avg_resolution_time)
|
||||||
|
@avg_first_response_time = results.transform_values(&:avg_first_response_time)
|
||||||
|
@avg_reply_time = results.transform_values(&:avg_reply_time)
|
||||||
|
end
|
||||||
|
|
||||||
|
def reporting_events
|
||||||
|
@reporting_events ||= account.reporting_events.where(created_at: range)
|
||||||
|
end
|
||||||
|
|
||||||
|
def fetch_conversations_count
|
||||||
|
# Override this method
|
||||||
end
|
end
|
||||||
|
|
||||||
def group_by_key
|
def group_by_key
|
||||||
@@ -26,26 +50,7 @@ class V2::Reports::BaseSummaryBuilder
|
|||||||
# Override this method
|
# Override this method
|
||||||
end
|
end
|
||||||
|
|
||||||
def data_source
|
def average_value_key
|
||||||
@data_source ||= Reports::DataSource.for(
|
ActiveModel::Type::Boolean.new.cast(params[:business_hours]).present? ? :value_in_business_hours : :value
|
||||||
account: account,
|
|
||||||
metric: nil,
|
|
||||||
dimension_type: summary_dimension_type,
|
|
||||||
dimension_id: nil,
|
|
||||||
scope: nil,
|
|
||||||
range: range,
|
|
||||||
group_by: 'day',
|
|
||||||
timezone_offset: params[:timezone_offset],
|
|
||||||
business_hours: params[:business_hours]
|
|
||||||
)
|
|
||||||
end
|
|
||||||
|
|
||||||
def summary_dimension_type
|
|
||||||
{
|
|
||||||
'account_id' => 'account',
|
|
||||||
'user_id' => 'agent',
|
|
||||||
'inbox_id' => 'inbox',
|
|
||||||
'conversations.team_id' => 'team'
|
|
||||||
}.fetch(group_by_key.to_s)
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -31,24 +31,13 @@ class V2::Reports::BotMetricsBuilder
|
|||||||
end
|
end
|
||||||
|
|
||||||
def bot_resolutions_count
|
def bot_resolutions_count
|
||||||
# Exclude conversations that also had a handoff in the same range — handoff wins
|
account.reporting_events.joins(:conversation).select(:conversation_id).where(account_id: account.id, name: :conversation_bot_resolved,
|
||||||
account.reporting_events.joins(:conversation).select(:conversation_id)
|
created_at: range).distinct.count
|
||||||
.where(account_id: account.id, name: :conversation_bot_resolved, created_at: range)
|
|
||||||
.where.not(conversation_id: bot_handoff_conversation_ids_subquery)
|
|
||||||
.distinct.count
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def bot_handoffs_count
|
def bot_handoffs_count
|
||||||
account.reporting_events.joins(:conversation).select(:conversation_id)
|
account.reporting_events.joins(:conversation).select(:conversation_id).where(account_id: account.id, name: :conversation_bot_handoff,
|
||||||
.where(account_id: account.id, name: :conversation_bot_handoff, created_at: range)
|
created_at: range).distinct.count
|
||||||
.distinct.count
|
|
||||||
end
|
|
||||||
|
|
||||||
def bot_handoff_conversation_ids_subquery
|
|
||||||
account.reporting_events
|
|
||||||
.where(name: :conversation_bot_handoff, created_at: range)
|
|
||||||
.where.not(conversation_id: nil)
|
|
||||||
.select(:conversation_id)
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def bot_resolution_rate
|
def bot_resolution_rate
|
||||||
|
|||||||
@@ -3,10 +3,23 @@ class V2::Reports::Conversations::BaseReportBuilder
|
|||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def builder_class(metric)
|
AVG_METRICS = %w[avg_first_response_time avg_resolution_time reply_time].freeze
|
||||||
return unless Reports::ReportMetricRegistry.supported?(metric)
|
COUNT_METRICS = %w[
|
||||||
|
conversations_count
|
||||||
|
incoming_messages_count
|
||||||
|
outgoing_messages_count
|
||||||
|
resolutions_count
|
||||||
|
bot_resolutions_count
|
||||||
|
bot_handoffs_count
|
||||||
|
].freeze
|
||||||
|
|
||||||
V2::Reports::Timeseries::ReportBuilder
|
def builder_class(metric)
|
||||||
|
case metric
|
||||||
|
when *AVG_METRICS
|
||||||
|
V2::Reports::Timeseries::AverageReportBuilder
|
||||||
|
when *COUNT_METRICS
|
||||||
|
V2::Reports::Timeseries::CountReportBuilder
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def log_invalid_metric
|
def log_invalid_metric
|
||||||
|
|||||||
@@ -11,6 +11,15 @@ class V2::Reports::InboxSummaryBuilder < V2::Reports::BaseSummaryBuilder
|
|||||||
attr_reader :conversations_count, :resolved_count,
|
attr_reader :conversations_count, :resolved_count,
|
||||||
:avg_resolution_time, :avg_first_response_time, :avg_reply_time
|
:avg_resolution_time, :avg_first_response_time, :avg_reply_time
|
||||||
|
|
||||||
|
def load_data
|
||||||
|
@conversations_count = fetch_conversations_count
|
||||||
|
load_reporting_events_data
|
||||||
|
end
|
||||||
|
|
||||||
|
def fetch_conversations_count
|
||||||
|
account.conversations.where(created_at: range).group(group_by_key).count
|
||||||
|
end
|
||||||
|
|
||||||
def prepare_report
|
def prepare_report
|
||||||
account.inboxes.map do |inbox|
|
account.inboxes.map do |inbox|
|
||||||
build_inbox_stats(inbox)
|
build_inbox_stats(inbox)
|
||||||
@@ -31,4 +40,8 @@ class V2::Reports::InboxSummaryBuilder < V2::Reports::BaseSummaryBuilder
|
|||||||
def group_by_key
|
def group_by_key
|
||||||
:inbox_id
|
:inbox_id
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def average_value_key
|
||||||
|
ActiveModel::Type::Boolean.new.cast(params[:business_hours]) ? :value_in_business_hours : :value
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -6,6 +6,14 @@ class V2::Reports::TeamSummaryBuilder < V2::Reports::BaseSummaryBuilder
|
|||||||
attr_reader :conversations_count, :resolved_count,
|
attr_reader :conversations_count, :resolved_count,
|
||||||
:avg_resolution_time, :avg_first_response_time, :avg_reply_time
|
:avg_resolution_time, :avg_first_response_time, :avg_reply_time
|
||||||
|
|
||||||
|
def fetch_conversations_count
|
||||||
|
account.conversations.where(created_at: range).group(:team_id).count
|
||||||
|
end
|
||||||
|
|
||||||
|
def reporting_events
|
||||||
|
@reporting_events ||= account.reporting_events.where(created_at: range).joins(:conversation)
|
||||||
|
end
|
||||||
|
|
||||||
def prepare_report
|
def prepare_report
|
||||||
account.teams.map do |team|
|
account.teams.map do |team|
|
||||||
build_team_stats(team)
|
build_team_stats(team)
|
||||||
|
|||||||
@@ -0,0 +1,48 @@
|
|||||||
|
class V2::Reports::Timeseries::AverageReportBuilder < V2::Reports::Timeseries::BaseTimeseriesBuilder
|
||||||
|
def timeseries
|
||||||
|
grouped_average_time = reporting_events.average(average_value_key)
|
||||||
|
grouped_event_count = reporting_events.count
|
||||||
|
grouped_average_time.each_with_object([]) do |element, arr|
|
||||||
|
event_date, average_time = element
|
||||||
|
arr << {
|
||||||
|
value: average_time,
|
||||||
|
timestamp: event_date.in_time_zone(timezone).to_i,
|
||||||
|
count: grouped_event_count[event_date]
|
||||||
|
}
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
def aggregate_value
|
||||||
|
object_scope.average(average_value_key)
|
||||||
|
end
|
||||||
|
|
||||||
|
private
|
||||||
|
|
||||||
|
def event_name
|
||||||
|
metric_to_event_name = {
|
||||||
|
avg_first_response_time: :first_response,
|
||||||
|
avg_resolution_time: :conversation_resolved,
|
||||||
|
reply_time: :reply_time
|
||||||
|
}
|
||||||
|
metric_to_event_name[params[:metric].to_sym]
|
||||||
|
end
|
||||||
|
|
||||||
|
def object_scope
|
||||||
|
scope.reporting_events.where(name: event_name, created_at: range, account_id: account.id)
|
||||||
|
end
|
||||||
|
|
||||||
|
def reporting_events
|
||||||
|
@grouped_values = object_scope.group_by_period(
|
||||||
|
group_by,
|
||||||
|
:created_at,
|
||||||
|
default_value: 0,
|
||||||
|
range: range,
|
||||||
|
permit: %w[day week month year hour],
|
||||||
|
time_zone: timezone
|
||||||
|
)
|
||||||
|
end
|
||||||
|
|
||||||
|
def average_value_key
|
||||||
|
@average_value_key ||= params[:business_hours].present? ? :value_in_business_hours : :value
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -1,13 +1,12 @@
|
|||||||
class V2::Reports::Timeseries::BaseTimeseriesBuilder
|
class V2::Reports::Timeseries::BaseTimeseriesBuilder
|
||||||
include TimezoneHelper
|
include TimezoneHelper
|
||||||
include DateRangeHelper
|
include DateRangeHelper
|
||||||
|
|
||||||
DEFAULT_GROUP_BY = 'day'.freeze
|
DEFAULT_GROUP_BY = 'day'.freeze
|
||||||
|
|
||||||
pattr_initialize :account, :params
|
pattr_initialize :account, :params
|
||||||
|
|
||||||
def scope
|
def scope
|
||||||
case dimension_type.to_sym
|
case params[:type].to_sym
|
||||||
when :account
|
when :account
|
||||||
account
|
account
|
||||||
when :inbox
|
when :inbox
|
||||||
@@ -21,20 +20,6 @@ class V2::Reports::Timeseries::BaseTimeseriesBuilder
|
|||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def data_source
|
|
||||||
@data_source ||= Reports::DataSource.for(
|
|
||||||
account: account,
|
|
||||||
metric: params[:metric],
|
|
||||||
dimension_type: dimension_type,
|
|
||||||
dimension_id: params[:id],
|
|
||||||
scope: scope,
|
|
||||||
range: range,
|
|
||||||
group_by: group_by,
|
|
||||||
timezone_offset: params[:timezone_offset],
|
|
||||||
business_hours: params[:business_hours]
|
|
||||||
)
|
|
||||||
end
|
|
||||||
|
|
||||||
def inbox
|
def inbox
|
||||||
@inbox ||= account.inboxes.find(params[:id])
|
@inbox ||= account.inboxes.find(params[:id])
|
||||||
end
|
end
|
||||||
@@ -58,10 +43,4 @@ class V2::Reports::Timeseries::BaseTimeseriesBuilder
|
|||||||
def timezone
|
def timezone
|
||||||
@timezone ||= timezone_name_from_offset(params[:timezone_offset])
|
@timezone ||= timezone_name_from_offset(params[:timezone_offset])
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def dimension_type
|
|
||||||
(params[:type].presence || 'account').to_s
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -0,0 +1,78 @@
|
|||||||
|
class V2::Reports::Timeseries::CountReportBuilder < V2::Reports::Timeseries::BaseTimeseriesBuilder
|
||||||
|
def timeseries
|
||||||
|
grouped_count.each_with_object([]) do |element, arr|
|
||||||
|
event_date, event_count = element
|
||||||
|
|
||||||
|
# The `event_date` is in Date format (without time), such as "Wed, 15 May 2024".
|
||||||
|
# We need a timestamp for the start of the day. However, we can't use `event_date.to_time.to_i`
|
||||||
|
# because it converts the date to 12:00 AM server timezone.
|
||||||
|
# The desired output should be 12:00 AM in the specified timezone.
|
||||||
|
arr << { value: event_count, timestamp: event_date.in_time_zone(timezone).to_i }
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
def aggregate_value
|
||||||
|
object_scope.count
|
||||||
|
end
|
||||||
|
|
||||||
|
private
|
||||||
|
|
||||||
|
def metric
|
||||||
|
@metric ||= params[:metric]
|
||||||
|
end
|
||||||
|
|
||||||
|
def object_scope
|
||||||
|
send("scope_for_#{metric}")
|
||||||
|
end
|
||||||
|
|
||||||
|
def scope_for_conversations_count
|
||||||
|
scope.conversations.where(account_id: account.id, created_at: range)
|
||||||
|
end
|
||||||
|
|
||||||
|
def scope_for_incoming_messages_count
|
||||||
|
scope.messages.where(account_id: account.id, created_at: range).incoming.unscope(:order)
|
||||||
|
end
|
||||||
|
|
||||||
|
def scope_for_outgoing_messages_count
|
||||||
|
scope.messages.where(account_id: account.id, created_at: range).outgoing.unscope(:order)
|
||||||
|
end
|
||||||
|
|
||||||
|
def scope_for_resolutions_count
|
||||||
|
scope.reporting_events.where(
|
||||||
|
name: :conversation_resolved,
|
||||||
|
account_id: account.id,
|
||||||
|
created_at: range
|
||||||
|
)
|
||||||
|
end
|
||||||
|
|
||||||
|
def scope_for_bot_resolutions_count
|
||||||
|
scope.reporting_events.where(
|
||||||
|
name: :conversation_bot_resolved,
|
||||||
|
account_id: account.id,
|
||||||
|
created_at: range
|
||||||
|
)
|
||||||
|
end
|
||||||
|
|
||||||
|
def scope_for_bot_handoffs_count
|
||||||
|
scope.reporting_events.joins(:conversation).select(:conversation_id).where(
|
||||||
|
name: :conversation_bot_handoff,
|
||||||
|
account_id: account.id,
|
||||||
|
created_at: range
|
||||||
|
).distinct
|
||||||
|
end
|
||||||
|
|
||||||
|
def grouped_count
|
||||||
|
# IMPORTANT: time_zone parameter affects both data grouping AND output timestamps
|
||||||
|
# It converts timestamps to the target timezone before grouping, which means
|
||||||
|
# the same event can fall into different day buckets depending on timezone
|
||||||
|
# Example: 2024-01-15 00:00 UTC becomes 2024-01-14 16:00 PST (falls on different day)
|
||||||
|
@grouped_values = object_scope.group_by_period(
|
||||||
|
group_by,
|
||||||
|
:created_at,
|
||||||
|
default_value: 0,
|
||||||
|
range: range,
|
||||||
|
permit: %w[day week month year hour],
|
||||||
|
time_zone: timezone
|
||||||
|
).count
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
class V2::Reports::Timeseries::ReportBuilder < V2::Reports::Timeseries::BaseTimeseriesBuilder
|
|
||||||
def timeseries
|
|
||||||
data_source.timeseries
|
|
||||||
end
|
|
||||||
|
|
||||||
def aggregate_value
|
|
||||||
data_source.aggregate
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -34,10 +34,6 @@ class Api::V1::Accounts::AgentBotsController < Api::V1::Accounts::BaseController
|
|||||||
@agent_bot.reload
|
@agent_bot.reload
|
||||||
end
|
end
|
||||||
|
|
||||||
def reset_secret
|
|
||||||
@agent_bot.reset_secret!
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def agent_bot
|
def agent_bot
|
||||||
|
|||||||
@@ -1,59 +0,0 @@
|
|||||||
class Api::V1::Accounts::Articles::BulkActionsController < Api::V1::Accounts::BaseController
|
|
||||||
before_action :portal
|
|
||||||
before_action :check_authorization
|
|
||||||
before_action :set_articles, only: [:update_status, :update_category, :delete_articles]
|
|
||||||
|
|
||||||
def translate
|
|
||||||
head :not_implemented
|
|
||||||
end
|
|
||||||
|
|
||||||
def update_status
|
|
||||||
return render_could_not_create_error(I18n.t('portals.articles.no_articles_found')) if @articles.none?
|
|
||||||
return render_could_not_create_error(I18n.t('portals.articles.invalid_status')) unless Article.statuses.key?(params[:status])
|
|
||||||
|
|
||||||
ActiveRecord::Base.transaction do
|
|
||||||
@articles.find_each { |article| article.update!(status: params[:status]) }
|
|
||||||
end
|
|
||||||
head :ok
|
|
||||||
rescue ActiveRecord::RecordInvalid => e
|
|
||||||
render_could_not_create_error(e.message)
|
|
||||||
end
|
|
||||||
|
|
||||||
def update_category
|
|
||||||
return render_could_not_create_error(I18n.t('portals.articles.no_articles_found')) if @articles.none?
|
|
||||||
return render_could_not_create_error(I18n.t('portals.articles.category_not_found')) unless category_valid?
|
|
||||||
|
|
||||||
ActiveRecord::Base.transaction do
|
|
||||||
@articles.find_each { |article| article.update!(category_id: params[:category_id]) }
|
|
||||||
end
|
|
||||||
head :ok
|
|
||||||
rescue ActiveRecord::RecordInvalid => e
|
|
||||||
render_could_not_create_error(e.message)
|
|
||||||
end
|
|
||||||
|
|
||||||
def delete_articles
|
|
||||||
return render_could_not_create_error(I18n.t('portals.articles.no_articles_found')) if @articles.none?
|
|
||||||
|
|
||||||
@articles.destroy_all
|
|
||||||
head :ok
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def portal
|
|
||||||
@portal ||= Current.account.portals.find_by!(slug: params[:portal_id])
|
|
||||||
end
|
|
||||||
|
|
||||||
def check_authorization
|
|
||||||
authorize(Article, :create?)
|
|
||||||
end
|
|
||||||
|
|
||||||
def set_articles
|
|
||||||
@articles = @portal.articles.where(id: params[:ids])
|
|
||||||
end
|
|
||||||
|
|
||||||
def category_valid?
|
|
||||||
@portal.categories.exists?(id: params[:category_id])
|
|
||||||
end
|
|
||||||
end
|
|
||||||
Api::V1::Accounts::Articles::BulkActionsController.prepend_mod_with('Api::V1::Accounts::Articles::BulkActionsController')
|
|
||||||
@@ -40,7 +40,7 @@ class Api::V1::Accounts::ArticlesController < Api::V1::Accounts::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def reorder
|
def reorder
|
||||||
Article.update_positions(portal: @portal, positions_hash: params[:positions_hash])
|
Article.update_positions(params[:positions_hash])
|
||||||
head :ok
|
head :ok
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
class Api::V1::Accounts::CategoriesController < Api::V1::Accounts::BaseController
|
class Api::V1::Accounts::CategoriesController < Api::V1::Accounts::BaseController
|
||||||
before_action :portal
|
before_action :portal
|
||||||
before_action :check_authorization
|
before_action :check_authorization
|
||||||
before_action :fetch_category, except: [:index, :create, :reorder]
|
before_action :fetch_category, except: [:index, :create]
|
||||||
before_action :set_current_page, only: [:index]
|
before_action :set_current_page, only: [:index]
|
||||||
|
|
||||||
def index
|
def index
|
||||||
@@ -32,11 +32,6 @@ class Api::V1::Accounts::CategoriesController < Api::V1::Accounts::BaseControlle
|
|||||||
head :ok
|
head :ok
|
||||||
end
|
end
|
||||||
|
|
||||||
def reorder
|
|
||||||
Category.update_positions(portal: @portal, positions_hash: params[:positions_hash])
|
|
||||||
head :ok
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def fetch_category
|
def fetch_category
|
||||||
@@ -44,7 +39,7 @@ class Api::V1::Accounts::CategoriesController < Api::V1::Accounts::BaseControlle
|
|||||||
end
|
end
|
||||||
|
|
||||||
def portal
|
def portal
|
||||||
@portal ||= Current.account.portals.find_by!(slug: params[:portal_id])
|
@portal ||= Current.account.portals.find_by(slug: params[:portal_id])
|
||||||
end
|
end
|
||||||
|
|
||||||
def related_categories_records
|
def related_categories_records
|
||||||
|
|||||||
@@ -1,55 +0,0 @@
|
|||||||
module Api::V1::Accounts::Concerns::WhatsappHealthManagement
|
|
||||||
extend ActiveSupport::Concern
|
|
||||||
|
|
||||||
included do
|
|
||||||
skip_before_action :check_authorization, only: [:health, :register_webhook]
|
|
||||||
before_action :check_admin_authorization?, only: [:register_webhook]
|
|
||||||
before_action :validate_whatsapp_cloud_channel, only: [:health, :register_webhook]
|
|
||||||
end
|
|
||||||
|
|
||||||
def sync_templates
|
|
||||||
return render status: :unprocessable_entity, json: { error: 'Template sync is only available for WhatsApp channels' } unless whatsapp_channel?
|
|
||||||
|
|
||||||
trigger_template_sync
|
|
||||||
render status: :ok, json: { message: 'Template sync initiated successfully' }
|
|
||||||
rescue StandardError => e
|
|
||||||
render status: :internal_server_error, json: { error: e.message }
|
|
||||||
end
|
|
||||||
|
|
||||||
def health
|
|
||||||
health_data = Whatsapp::HealthService.new(@inbox.channel).fetch_health_status
|
|
||||||
render json: health_data
|
|
||||||
rescue StandardError => e
|
|
||||||
Rails.logger.error "[INBOX HEALTH] Error fetching health data: #{e.message}"
|
|
||||||
render json: { error: e.message }, status: :unprocessable_entity
|
|
||||||
end
|
|
||||||
|
|
||||||
def register_webhook
|
|
||||||
Whatsapp::WebhookSetupService.new(@inbox.channel).register_callback
|
|
||||||
|
|
||||||
render json: { message: 'Webhook registered successfully' }, status: :ok
|
|
||||||
rescue StandardError => e
|
|
||||||
Rails.logger.error "[INBOX WEBHOOK] Webhook registration failed: #{e.message}"
|
|
||||||
render json: { error: e.message }, status: :unprocessable_entity
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def validate_whatsapp_cloud_channel
|
|
||||||
return if @inbox.channel.is_a?(Channel::Whatsapp) && @inbox.channel.provider == 'whatsapp_cloud'
|
|
||||||
|
|
||||||
render json: { error: 'Health data only available for WhatsApp Cloud API channels' }, status: :bad_request
|
|
||||||
end
|
|
||||||
|
|
||||||
def whatsapp_channel?
|
|
||||||
@inbox.whatsapp? || (@inbox.twilio? && @inbox.channel.whatsapp?)
|
|
||||||
end
|
|
||||||
|
|
||||||
def trigger_template_sync
|
|
||||||
if @inbox.whatsapp?
|
|
||||||
Channels::Whatsapp::TemplatesSyncJob.perform_later(@inbox.channel)
|
|
||||||
elsif @inbox.twilio? && @inbox.channel.whatsapp?
|
|
||||||
Channels::Twilio::TemplatesSyncJob.perform_later(@inbox.channel)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
class Api::V1::Accounts::Contacts::AttachmentsController < Api::V1::Accounts::Contacts::BaseController
|
|
||||||
RESULTS_PER_PAGE = 100
|
|
||||||
|
|
||||||
def index
|
|
||||||
conversations = Conversations::PermissionFilterService.new(
|
|
||||||
Current.account.conversations.where(contact_id: @contact.id),
|
|
||||||
Current.user,
|
|
||||||
Current.account
|
|
||||||
).perform
|
|
||||||
|
|
||||||
@attachments = Attachment.where(message_id: Message.where(conversation_id: conversations).select(:id))
|
|
||||||
.includes({ file_attachment: :blob }, message: [:conversation, :inbox, { sender: { avatar_attachment: :blob } }])
|
|
||||||
.order(created_at: :desc)
|
|
||||||
.page(params[:page])
|
|
||||||
.per(RESULTS_PER_PAGE)
|
|
||||||
@attachments_count = @attachments.total_count
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -5,7 +5,7 @@ class Api::V1::Accounts::ContactsController < Api::V1::Accounts::BaseController
|
|||||||
sort_on :phone_number, type: :string
|
sort_on :phone_number, type: :string
|
||||||
sort_on :last_activity_at, internal_name: :order_on_last_activity_at, type: :scope, scope_params: [:direction]
|
sort_on :last_activity_at, internal_name: :order_on_last_activity_at, type: :scope, scope_params: [:direction]
|
||||||
sort_on :created_at, internal_name: :order_on_created_at, type: :scope, scope_params: [:direction]
|
sort_on :created_at, internal_name: :order_on_created_at, type: :scope, scope_params: [:direction]
|
||||||
sort_on :company_name, internal_name: :order_on_company_name, type: :scope, scope_params: [:direction]
|
sort_on :company, internal_name: :order_on_company_name, type: :scope, scope_params: [:direction]
|
||||||
sort_on :city, internal_name: :order_on_city, type: :scope, scope_params: [:direction]
|
sort_on :city, internal_name: :order_on_city, type: :scope, scope_params: [:direction]
|
||||||
sort_on :country, internal_name: :order_on_country_name, type: :scope, scope_params: [:direction]
|
sort_on :country, internal_name: :order_on_country_name, type: :scope, scope_params: [:direction]
|
||||||
|
|
||||||
@@ -201,9 +201,7 @@ class Api::V1::Accounts::ContactsController < Api::V1::Accounts::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def fetch_contact
|
def fetch_contact
|
||||||
contact_scope = Current.account.contacts
|
@contact = Current.account.contacts.includes(contact_inboxes: [:inbox]).find(params[:id])
|
||||||
contact_scope = contact_scope.includes(contact_inboxes: [:inbox]) if @include_contact_inboxes
|
|
||||||
@contact = contact_scope.find(params[:id])
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def process_avatar_from_url
|
def process_avatar_from_url
|
||||||
|
|||||||
@@ -1,16 +0,0 @@
|
|||||||
class Api::V1::Accounts::Conversations::UnreadCountsController < Api::V1::Accounts::BaseController
|
|
||||||
before_action :ensure_unread_counts_enabled
|
|
||||||
|
|
||||||
def index
|
|
||||||
counts = ::Conversations::UnreadCounts::Counter.new(account: Current.account, user: Current.user).perform
|
|
||||||
render json: { payload: counts }
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def ensure_unread_counts_enabled
|
|
||||||
return if Current.account.feature_enabled?('conversation_unread_counts')
|
|
||||||
|
|
||||||
render json: { error: I18n.t('errors.conversations.unread_counts.feature_not_enabled') }, status: :forbidden
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -15,7 +15,7 @@ class Api::V1::Accounts::ConversationsController < Api::V1::Accounts::BaseContro
|
|||||||
end
|
end
|
||||||
|
|
||||||
def meta
|
def meta
|
||||||
result = conversation_finder.perform_meta_only
|
result = conversation_finder.perform
|
||||||
@conversations_count = result[:count]
|
@conversations_count = result[:count]
|
||||||
end
|
end
|
||||||
|
|
||||||
@@ -28,7 +28,7 @@ class Api::V1::Accounts::ConversationsController < Api::V1::Accounts::BaseContro
|
|||||||
def attachments
|
def attachments
|
||||||
@attachments_count = @conversation.attachments.count
|
@attachments_count = @conversation.attachments.count
|
||||||
@attachments = @conversation.attachments
|
@attachments = @conversation.attachments
|
||||||
.includes({ file_attachment: :blob }, message: [:inbox, { sender: { avatar_attachment: :blob } }])
|
.includes(:message)
|
||||||
.order(created_at: :desc)
|
.order(created_at: :desc)
|
||||||
.page(attachment_params[:page])
|
.page(attachment_params[:page])
|
||||||
.per(ATTACHMENT_RESULTS_PER_PAGE)
|
.per(ATTACHMENT_RESULTS_PER_PAGE)
|
||||||
@@ -107,7 +107,7 @@ class Api::V1::Accounts::ConversationsController < Api::V1::Accounts::BaseContro
|
|||||||
end
|
end
|
||||||
|
|
||||||
def toggle_typing_status
|
def toggle_typing_status
|
||||||
typing_status_manager = ::Conversations::TypingStatusManager.new(@conversation, Current.user, params)
|
typing_status_manager = ::Conversations::TypingStatusManager.new(@conversation, current_user, params)
|
||||||
typing_status_manager.toggle_typing_status
|
typing_status_manager.toggle_typing_status
|
||||||
head :ok
|
head :ok
|
||||||
end
|
end
|
||||||
@@ -116,8 +116,6 @@ class Api::V1::Accounts::ConversationsController < Api::V1::Accounts::BaseContro
|
|||||||
# High-traffic accounts generate excessive DB writes when agents frequently switch between conversations.
|
# High-traffic accounts generate excessive DB writes when agents frequently switch between conversations.
|
||||||
# Throttle last_seen updates to once per hour when there are no unread messages to reduce DB load.
|
# Throttle last_seen updates to once per hour when there are no unread messages to reduce DB load.
|
||||||
# Always update immediately if there are unread messages to maintain accurate read/unread state.
|
# Always update immediately if there are unread messages to maintain accurate read/unread state.
|
||||||
# Visiting a conversation should clear any unread inbox notifications for this conversation.
|
|
||||||
Notification::MarkConversationReadService.new(user: Current.user, account: Current.account, conversation: @conversation).perform
|
|
||||||
return update_last_seen_on_conversation(DateTime.now.utc, true) if assignee? && @conversation.assignee_unread_messages.any?
|
return update_last_seen_on_conversation(DateTime.now.utc, true) if assignee? && @conversation.assignee_unread_messages.any?
|
||||||
return update_last_seen_on_conversation(DateTime.now.utc, false) if !assignee? && @conversation.unread_messages.any?
|
return update_last_seen_on_conversation(DateTime.now.utc, false) if !assignee? && @conversation.unread_messages.any?
|
||||||
|
|
||||||
@@ -162,8 +160,6 @@ class Api::V1::Accounts::ConversationsController < Api::V1::Accounts::BaseContro
|
|||||||
# rubocop:disable Rails/SkipsModelValidations
|
# rubocop:disable Rails/SkipsModelValidations
|
||||||
@conversation.update_columns(updates)
|
@conversation.update_columns(updates)
|
||||||
# rubocop:enable Rails/SkipsModelValidations
|
# rubocop:enable Rails/SkipsModelValidations
|
||||||
|
|
||||||
::Conversations::UnreadCounts::Notifier.new(@conversation).perform
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def should_update_last_seen?
|
def should_update_last_seen?
|
||||||
|
|||||||
@@ -1,7 +1,6 @@
|
|||||||
class Api::V1::Accounts::CustomAttributeDefinitionsController < Api::V1::Accounts::BaseController
|
class Api::V1::Accounts::CustomAttributeDefinitionsController < Api::V1::Accounts::BaseController
|
||||||
before_action :fetch_custom_attributes_definitions, except: [:create]
|
before_action :fetch_custom_attributes_definitions, except: [:create]
|
||||||
before_action :fetch_custom_attribute_definition, only: [:show, :update, :destroy]
|
before_action :fetch_custom_attribute_definition, only: [:show, :update, :destroy]
|
||||||
before_action :check_authorization
|
|
||||||
DEFAULT_ATTRIBUTE_MODEL = 'conversation_attribute'.freeze
|
DEFAULT_ATTRIBUTE_MODEL = 'conversation_attribute'.freeze
|
||||||
|
|
||||||
def index; end
|
def index; end
|
||||||
|
|||||||
@@ -1,7 +1,6 @@
|
|||||||
class Api::V1::Accounts::InboxCsatTemplatesController < Api::V1::Accounts::BaseController
|
class Api::V1::Accounts::InboxCsatTemplatesController < Api::V1::Accounts::BaseController
|
||||||
before_action :fetch_inbox
|
before_action :fetch_inbox
|
||||||
before_action :validate_whatsapp_channel
|
before_action :validate_whatsapp_channel
|
||||||
before_action :validate_captain_enabled, only: [:analyze]
|
|
||||||
|
|
||||||
def show
|
def show
|
||||||
service = CsatTemplateManagementService.new(@inbox)
|
service = CsatTemplateManagementService.new(@inbox)
|
||||||
@@ -25,23 +24,6 @@ class Api::V1::Accounts::InboxCsatTemplatesController < Api::V1::Accounts::BaseC
|
|||||||
render json: { error: 'Template parameters are required' }, status: :unprocessable_entity
|
render json: { error: 'Template parameters are required' }, status: :unprocessable_entity
|
||||||
end
|
end
|
||||||
|
|
||||||
def analyze
|
|
||||||
template_params = extract_template_params
|
|
||||||
return render_missing_message_error if template_params[:message].blank?
|
|
||||||
|
|
||||||
result = CsatTemplateUtilityAnalysisService.new(
|
|
||||||
account: Current.account,
|
|
||||||
inbox: @inbox,
|
|
||||||
message: template_params[:message],
|
|
||||||
button_text: template_params[:button_text],
|
|
||||||
language: template_params[:language]
|
|
||||||
).perform
|
|
||||||
|
|
||||||
render json: result
|
|
||||||
rescue ActionController::ParameterMissing
|
|
||||||
render json: { error: 'Template parameters are required' }, status: :unprocessable_entity
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def fetch_inbox
|
def fetch_inbox
|
||||||
@@ -64,12 +46,6 @@ class Api::V1::Accounts::InboxCsatTemplatesController < Api::V1::Accounts::BaseC
|
|||||||
render json: { error: 'Message is required' }, status: :unprocessable_entity
|
render json: { error: 'Message is required' }, status: :unprocessable_entity
|
||||||
end
|
end
|
||||||
|
|
||||||
def validate_captain_enabled
|
|
||||||
return if Current.account.feature_enabled?('captain_integration')
|
|
||||||
|
|
||||||
render json: { error: 'Captain is required for template analysis' }, status: :forbidden
|
|
||||||
end
|
|
||||||
|
|
||||||
def render_template_creation_result(result)
|
def render_template_creation_result(result)
|
||||||
if result[:success]
|
if result[:success]
|
||||||
render_successful_template_creation(result)
|
render_successful_template_creation(result)
|
||||||
|
|||||||
@@ -4,14 +4,11 @@ class Api::V1::Accounts::InboxesController < Api::V1::Accounts::BaseController
|
|||||||
before_action :fetch_agent_bot, only: [:set_agent_bot]
|
before_action :fetch_agent_bot, only: [:set_agent_bot]
|
||||||
before_action :validate_limit, only: [:create]
|
before_action :validate_limit, only: [:create]
|
||||||
# we are already handling the authorization in fetch inbox
|
# we are already handling the authorization in fetch inbox
|
||||||
before_action :check_authorization, except: [:show]
|
before_action :check_authorization, except: [:show, :health]
|
||||||
|
before_action :validate_whatsapp_cloud_channel, only: [:health]
|
||||||
include Api::V1::Accounts::Concerns::WhatsappHealthManagement
|
|
||||||
|
|
||||||
def index
|
def index
|
||||||
@inboxes = policy_scope(Current.account.inboxes)
|
@inboxes = policy_scope(Current.account.inboxes.order_by_name.includes(:channel, { avatar_attachment: [:blob] }))
|
||||||
.includes(:channel, :portal, :working_hours, { avatar_attachment: :blob })
|
|
||||||
.order_by_name
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def show; end
|
def show; end
|
||||||
@@ -68,15 +65,31 @@ class Api::V1::Accounts::InboxesController < Api::V1::Accounts::BaseController
|
|||||||
head :ok
|
head :ok
|
||||||
end
|
end
|
||||||
|
|
||||||
def reset_secret
|
def destroy
|
||||||
return head :not_found unless @inbox.api?
|
if @inbox.present?
|
||||||
|
# Invalidate cache immediately so frontends don't serve stale data
|
||||||
@inbox.channel.reset_secret!
|
# while the async DeleteObjectJob is still in the queue.
|
||||||
|
Current.account.update_cache_key('inbox')
|
||||||
|
::DeleteObjectJob.perform_later(@inbox, Current.user, request.ip)
|
||||||
|
end
|
||||||
|
render status: :ok, json: { message: I18n.t('messages.inbox_deletetion_response') }
|
||||||
end
|
end
|
||||||
|
|
||||||
def destroy
|
def sync_templates
|
||||||
::DeleteObjectJob.perform_later(@inbox, Current.user, request.ip) if @inbox.present?
|
return render status: :unprocessable_entity, json: { error: 'Template sync is only available for WhatsApp channels' } unless whatsapp_channel?
|
||||||
render status: :ok, json: { message: I18n.t('messages.inbox_deletetion_response') }
|
|
||||||
|
trigger_template_sync
|
||||||
|
render status: :ok, json: { message: 'Template sync initiated successfully' }
|
||||||
|
rescue StandardError => e
|
||||||
|
render status: :internal_server_error, json: { error: e.message }
|
||||||
|
end
|
||||||
|
|
||||||
|
def health
|
||||||
|
health_data = Whatsapp::HealthService.new(@inbox.channel).fetch_health_status
|
||||||
|
render json: health_data
|
||||||
|
rescue StandardError => e
|
||||||
|
Rails.logger.error "[INBOX HEALTH] Error fetching health data: #{e.message}"
|
||||||
|
render json: { error: e.message }, status: :unprocessable_entity
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
private
|
||||||
@@ -87,7 +100,13 @@ class Api::V1::Accounts::InboxesController < Api::V1::Accounts::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def fetch_agent_bot
|
def fetch_agent_bot
|
||||||
@agent_bot = AgentBot.accessible_to(Current.account).find(params[:agent_bot]) if params[:agent_bot]
|
@agent_bot = AgentBot.find(params[:agent_bot]) if params[:agent_bot]
|
||||||
|
end
|
||||||
|
|
||||||
|
def validate_whatsapp_cloud_channel
|
||||||
|
return if @inbox.channel.is_a?(Channel::Whatsapp) && @inbox.channel.provider == 'whatsapp_cloud'
|
||||||
|
|
||||||
|
render json: { error: 'Health data only available for WhatsApp Cloud API channels' }, status: :bad_request
|
||||||
end
|
end
|
||||||
|
|
||||||
def create_channel
|
def create_channel
|
||||||
@@ -186,6 +205,18 @@ class Api::V1::Accounts::InboxesController < Api::V1::Accounts::BaseController
|
|||||||
def get_channel_attributes(channel_type)
|
def get_channel_attributes(channel_type)
|
||||||
channel_type.constantize.const_defined?(:EDITABLE_ATTRS) ? channel_type.constantize::EDITABLE_ATTRS.presence : []
|
channel_type.constantize.const_defined?(:EDITABLE_ATTRS) ? channel_type.constantize::EDITABLE_ATTRS.presence : []
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def whatsapp_channel?
|
||||||
|
@inbox.whatsapp? || (@inbox.twilio? && @inbox.channel.whatsapp?)
|
||||||
|
end
|
||||||
|
|
||||||
|
def trigger_template_sync
|
||||||
|
if @inbox.whatsapp?
|
||||||
|
Channels::Whatsapp::TemplatesSyncJob.perform_later(@inbox.channel)
|
||||||
|
elsif @inbox.twilio? && @inbox.channel.whatsapp?
|
||||||
|
Channels::Twilio::TemplatesSyncJob.perform_later(@inbox.channel)
|
||||||
|
end
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
Api::V1::Accounts::InboxesController.prepend_mod_with('Api::V1::Accounts::InboxesController')
|
Api::V1::Accounts::InboxesController.prepend_mod_with('Api::V1::Accounts::InboxesController')
|
||||||
|
|||||||
@@ -126,7 +126,7 @@ class Api::V1::Accounts::Integrations::LinearController < Api::V1::Accounts::Bas
|
|||||||
return unless @hook&.access_token
|
return unless @hook&.access_token
|
||||||
|
|
||||||
begin
|
begin
|
||||||
linear_client = Linear.new(@hook.access_token, refresh_token: @hook.settings&.[]('refresh_token'))
|
linear_client = Linear.new(@hook.access_token)
|
||||||
linear_client.revoke_token
|
linear_client.revoke_token
|
||||||
rescue StandardError => e
|
rescue StandardError => e
|
||||||
Rails.logger.error "Failed to revoke Linear token: #{e.message}"
|
Rails.logger.error "Failed to revoke Linear token: #{e.message}"
|
||||||
|
|||||||
@@ -18,16 +18,7 @@ class Api::V1::Accounts::LabelsController < Api::V1::Accounts::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def destroy
|
def destroy
|
||||||
label_title = @label.title
|
|
||||||
account_id = Current.account.id
|
|
||||||
label_deleted_at = Time.current
|
|
||||||
|
|
||||||
@label.destroy!
|
@label.destroy!
|
||||||
Labels::RemoveAssociationsJob.perform_later(
|
|
||||||
label_title: label_title,
|
|
||||||
account_id: account_id,
|
|
||||||
label_deleted_at: label_deleted_at
|
|
||||||
)
|
|
||||||
head :ok
|
head :ok
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
@@ -6,7 +6,8 @@ class Api::V1::Accounts::Microsoft::AuthorizationsController < Api::V1::Accounts
|
|||||||
{
|
{
|
||||||
redirect_uri: "#{base_url}/microsoft/callback",
|
redirect_uri: "#{base_url}/microsoft/callback",
|
||||||
scope: scope,
|
scope: scope,
|
||||||
state: state
|
state: state,
|
||||||
|
prompt: 'consent'
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
if redirect_url
|
if redirect_url
|
||||||
|
|||||||
@@ -41,9 +41,9 @@ class Api::V1::Accounts::NotificationsController < Api::V1::Accounts::BaseContro
|
|||||||
|
|
||||||
def destroy_all
|
def destroy_all
|
||||||
if params[:type] == 'read'
|
if params[:type] == 'read'
|
||||||
::Notification::DeleteNotificationJob.perform_later(Current.user, Current.account, type: :read)
|
::Notification::DeleteNotificationJob.perform_later(Current.user, type: :read)
|
||||||
else
|
else
|
||||||
::Notification::DeleteNotificationJob.perform_later(Current.user, Current.account, type: :all)
|
::Notification::DeleteNotificationJob.perform_later(Current.user, type: :all)
|
||||||
end
|
end
|
||||||
head :ok
|
head :ok
|
||||||
end
|
end
|
||||||
@@ -69,7 +69,7 @@ class Api::V1::Accounts::NotificationsController < Api::V1::Accounts::BaseContro
|
|||||||
end
|
end
|
||||||
|
|
||||||
def fetch_notification
|
def fetch_notification
|
||||||
@notification = current_user.notifications.where(account_id: Current.account.id).find(params[:id])
|
@notification = current_user.notifications.find(params[:id])
|
||||||
end
|
end
|
||||||
|
|
||||||
def set_current_page
|
def set_current_page
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ class Api::V1::Accounts::PortalsController < Api::V1::Accounts::BaseController
|
|||||||
@portal = Current.account.portals.build(portal_params.merge(live_chat_widget_params))
|
@portal = Current.account.portals.build(portal_params.merge(live_chat_widget_params))
|
||||||
@portal.custom_domain = parsed_custom_domain
|
@portal.custom_domain = parsed_custom_domain
|
||||||
@portal.save!
|
@portal.save!
|
||||||
process_attached_logo if params[:blob_id].present?
|
process_attached_logo
|
||||||
end
|
end
|
||||||
|
|
||||||
def update
|
def update
|
||||||
@@ -61,8 +61,9 @@ class Api::V1::Accounts::PortalsController < Api::V1::Accounts::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def process_attached_logo
|
def process_attached_logo
|
||||||
blob = ActiveStorage::Blob.find_signed(params[:blob_id].to_s)
|
blob_id = params[:blob_id]
|
||||||
@portal.logo.attach(blob) if blob
|
blob = ActiveStorage::Blob.find_signed(blob_id)
|
||||||
|
@portal.logo.attach(blob)
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
private
|
||||||
@@ -78,9 +79,7 @@ class Api::V1::Accounts::PortalsController < Api::V1::Accounts::BaseController
|
|||||||
def portal_params
|
def portal_params
|
||||||
params.require(:portal).permit(
|
params.require(:portal).permit(
|
||||||
:id, :color, :custom_domain, :header_text, :homepage_link,
|
:id, :color, :custom_domain, :header_text, :homepage_link,
|
||||||
:name, :page_title, :slug, :archived,
|
:name, :page_title, :slug, :archived, { config: [:default_locale, { allowed_locales: [] }] }
|
||||||
{ config: [:default_locale, :layout, { allowed_locales: [] }, { draft_locales: [] },
|
|
||||||
{ social_profiles: %i[facebook x instagram linkedin youtube tiktok github whatsapp] }] }
|
|
||||||
)
|
)
|
||||||
end
|
end
|
||||||
|
|
||||||
@@ -89,7 +88,7 @@ class Api::V1::Accounts::PortalsController < Api::V1::Accounts::BaseController
|
|||||||
return {} unless permitted_params.key?(:inbox_id)
|
return {} unless permitted_params.key?(:inbox_id)
|
||||||
return { channel_web_widget_id: nil } if permitted_params[:inbox_id].blank?
|
return { channel_web_widget_id: nil } if permitted_params[:inbox_id].blank?
|
||||||
|
|
||||||
inbox = Current.account.inboxes.find(permitted_params[:inbox_id])
|
inbox = Inbox.find(permitted_params[:inbox_id])
|
||||||
return {} unless inbox.web_widget?
|
return {} unless inbox.web_widget?
|
||||||
|
|
||||||
{ channel_web_widget_id: inbox.channel.id }
|
{ channel_web_widget_id: inbox.channel.id }
|
||||||
@@ -100,8 +99,6 @@ class Api::V1::Accounts::PortalsController < Api::V1::Accounts::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def parsed_custom_domain
|
def parsed_custom_domain
|
||||||
return @portal.custom_domain if @portal.custom_domain.blank?
|
|
||||||
|
|
||||||
domain = URI.parse(@portal.custom_domain)
|
domain = URI.parse(@portal.custom_domain)
|
||||||
domain.is_a?(URI::HTTP) ? domain.host : @portal.custom_domain
|
domain.is_a?(URI::HTTP) ? domain.host : @portal.custom_domain
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ class Api::V1::Accounts::UploadController < Api::V1::Accounts::BaseController
|
|||||||
elsif params[:external_url].present?
|
elsif params[:external_url].present?
|
||||||
create_from_url
|
create_from_url
|
||||||
else
|
else
|
||||||
render_error(I18n.t('errors.upload.missing_input'), :unprocessable_entity)
|
render_error('No file or URL provided', :unprocessable_entity)
|
||||||
end
|
end
|
||||||
|
|
||||||
render_success(result) if result.is_a?(ActiveStorage::Blob)
|
render_success(result) if result.is_a?(ActiveStorage::Blob)
|
||||||
@@ -19,21 +19,35 @@ class Api::V1::Accounts::UploadController < Api::V1::Accounts::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def create_from_url
|
def create_from_url
|
||||||
SafeFetch.fetch(params[:external_url].to_s) do |result|
|
uri = parse_uri(params[:external_url])
|
||||||
create_and_save_blob(result.tempfile, result.filename, result.content_type)
|
return if performed?
|
||||||
|
|
||||||
|
fetch_and_process_file_from_uri(uri)
|
||||||
|
end
|
||||||
|
|
||||||
|
def parse_uri(url)
|
||||||
|
uri = URI.parse(url)
|
||||||
|
validate_uri(uri)
|
||||||
|
uri
|
||||||
|
rescue URI::InvalidURIError, SocketError
|
||||||
|
render_error('Invalid URL provided', :unprocessable_entity)
|
||||||
|
nil
|
||||||
|
end
|
||||||
|
|
||||||
|
def validate_uri(uri)
|
||||||
|
raise URI::InvalidURIError unless uri.is_a?(URI::HTTP) || uri.is_a?(URI::HTTPS)
|
||||||
|
end
|
||||||
|
|
||||||
|
def fetch_and_process_file_from_uri(uri)
|
||||||
|
uri.open do |file|
|
||||||
|
create_and_save_blob(file, File.basename(uri.path), file.content_type)
|
||||||
end
|
end
|
||||||
rescue SafeFetch::HttpError => e
|
rescue OpenURI::HTTPError => e
|
||||||
render_error(I18n.t('errors.upload.fetch_failed_with_message', message: e.message), :unprocessable_entity)
|
render_error("Failed to fetch file from URL: #{e.message}", :unprocessable_entity)
|
||||||
rescue SafeFetch::FetchError
|
rescue SocketError
|
||||||
render_error(I18n.t('errors.upload.fetch_failed'), :unprocessable_entity)
|
render_error('Invalid URL provided', :unprocessable_entity)
|
||||||
rescue SafeFetch::FileTooLargeError
|
|
||||||
render_error(I18n.t('errors.upload.file_too_large'), :unprocessable_entity)
|
|
||||||
rescue SafeFetch::UnsupportedContentTypeError
|
|
||||||
render_error(I18n.t('errors.upload.unsupported_content_type'), :unprocessable_entity)
|
|
||||||
rescue SafeFetch::Error
|
|
||||||
render_error(I18n.t('errors.upload.invalid_url'), :unprocessable_entity)
|
|
||||||
rescue StandardError
|
rescue StandardError
|
||||||
render_error(I18n.t('errors.upload.unexpected'), :internal_server_error)
|
render_error('An unexpected error occurred', :internal_server_error)
|
||||||
end
|
end
|
||||||
|
|
||||||
def create_and_save_blob(io, filename, content_type)
|
def create_and_save_blob(io, filename, content_type)
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
class Api::V1::Accounts::WorkingHoursController < Api::V1::Accounts::BaseController
|
||||||
|
before_action :check_authorization
|
||||||
|
before_action :fetch_webhook, only: [:update]
|
||||||
|
|
||||||
|
def update
|
||||||
|
@working_hour.update!(working_hour_params)
|
||||||
|
end
|
||||||
|
|
||||||
|
private
|
||||||
|
|
||||||
|
def working_hour_params
|
||||||
|
params.require(:working_hour).permit(:inbox_id, :open_hour, :open_minutes, :close_hour, :close_minutes, :closed_all_day)
|
||||||
|
end
|
||||||
|
|
||||||
|
def fetch_working_hour
|
||||||
|
@working_hour = Current.account.working_hours.find(params[:id])
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -30,20 +30,9 @@ class Api::V1::AccountsController < Api::BaseController
|
|||||||
locale: account_params[:locale],
|
locale: account_params[:locale],
|
||||||
user: current_user
|
user: current_user
|
||||||
).perform
|
).perform
|
||||||
enqueue_branding_enrichment
|
|
||||||
if @user
|
if @user
|
||||||
# Authenticated users (dashboard "add account") and api_only signups
|
send_auth_headers(@user)
|
||||||
# need the full response with account_id. API-only deployments have no
|
render 'api/v1/accounts/create', format: :json, locals: { resource: @user }
|
||||||
# frontend to handle the email confirmation flow, so they need auth
|
|
||||||
# tokens to proceed.
|
|
||||||
# Unauthenticated web signup returns only the email — no session is
|
|
||||||
# created until the user confirms via the email link.
|
|
||||||
if current_user || api_only_signup?
|
|
||||||
send_auth_headers(@user)
|
|
||||||
render 'api/v1/accounts/create', format: :json, locals: { resource: @user }
|
|
||||||
else
|
|
||||||
render json: { email: @user.email }
|
|
||||||
end
|
|
||||||
else
|
else
|
||||||
render_error_response(CustomExceptions::Account::SignupFailed.new({}))
|
render_error_response(CustomExceptions::Account::SignupFailed.new({}))
|
||||||
end
|
end
|
||||||
@@ -58,7 +47,6 @@ class Api::V1::AccountsController < Api::BaseController
|
|||||||
@account.assign_attributes(account_params.slice(:name, :locale, :domain, :support_email))
|
@account.assign_attributes(account_params.slice(:name, :locale, :domain, :support_email))
|
||||||
@account.custom_attributes.merge!(custom_attributes_params)
|
@account.custom_attributes.merge!(custom_attributes_params)
|
||||||
@account.settings.merge!(settings_params)
|
@account.settings.merge!(settings_params)
|
||||||
@account.custom_attributes.delete('onboarding_step') if @account.custom_attributes['onboarding_step'] == 'account_details'
|
|
||||||
@account.custom_attributes['onboarding_step'] = 'invite_team' if @account.custom_attributes['onboarding_step'] == 'account_update'
|
@account.custom_attributes['onboarding_step'] = 'invite_team' if @account.custom_attributes['onboarding_step'] == 'account_update'
|
||||||
@account.save!
|
@account.save!
|
||||||
end
|
end
|
||||||
@@ -71,17 +59,6 @@ class Api::V1::AccountsController < Api::BaseController
|
|||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def enqueue_branding_enrichment
|
|
||||||
email = account_params[:email].presence || @user&.email
|
|
||||||
return if email.blank?
|
|
||||||
|
|
||||||
Account::BrandingEnrichmentJob.perform_later(@account.id, email)
|
|
||||||
Redis::Alfred.set(format(Redis::Alfred::ACCOUNT_ONBOARDING_ENRICHMENT, account_id: @account.id), '1', ex: 30)
|
|
||||||
rescue StandardError => e
|
|
||||||
# Enrichment is optional — never let queue/Redis failures abort signup
|
|
||||||
ChatwootExceptionTracker.new(e).capture_exception
|
|
||||||
end
|
|
||||||
|
|
||||||
def ensure_account_name
|
def ensure_account_name
|
||||||
# ensure that account_name and user_full_name is present
|
# ensure that account_name and user_full_name is present
|
||||||
# this is becuase the account builder and the models validations are not triggered
|
# this is becuase the account builder and the models validations are not triggered
|
||||||
@@ -111,7 +88,7 @@ class Api::V1::AccountsController < Api::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def custom_attributes_params
|
def custom_attributes_params
|
||||||
params.permit(:industry, :company_size, :timezone, :referral_source, :user_role, :website)
|
params.permit(:industry, :company_size, :timezone)
|
||||||
end
|
end
|
||||||
|
|
||||||
def settings_params
|
def settings_params
|
||||||
@@ -123,16 +100,7 @@ class Api::V1::AccountsController < Api::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def check_signup_enabled
|
def check_signup_enabled
|
||||||
raise ActionController::RoutingError, 'Not Found' unless GlobalConfigService.account_signup_enabled?
|
raise ActionController::RoutingError, 'Not Found' if GlobalConfigService.load('ENABLE_ACCOUNT_SIGNUP', 'false') == 'false'
|
||||||
end
|
|
||||||
|
|
||||||
def api_only_signup?
|
|
||||||
# CW_API_ONLY_SERVER is the canonical flag for API-only deployments.
|
|
||||||
# ENABLE_ACCOUNT_SIGNUP='api_only' is a legacy sentinel for the same purpose.
|
|
||||||
# Read ENABLE_ACCOUNT_SIGNUP raw from InstallationConfig because GlobalConfig.get
|
|
||||||
# typecasts it to boolean, coercing 'api_only' to true.
|
|
||||||
ActiveModel::Type::Boolean.new.cast(ENV.fetch('CW_API_ONLY_SERVER', false)) ||
|
|
||||||
InstallationConfig.find_by(name: 'ENABLE_ACCOUNT_SIGNUP')&.value.to_s == 'api_only'
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def validate_captcha
|
def validate_captcha
|
||||||
|
|||||||
@@ -8,8 +8,7 @@ class Api::V1::NotificationSubscriptionsController < Api::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def destroy
|
def destroy
|
||||||
notification_subscription = current_user.notification_subscriptions
|
notification_subscription = NotificationSubscription.where(["subscription_attributes->>'push_token' = ?", params[:push_token]]).first
|
||||||
.where(["subscription_attributes->>'push_token' = ?", params[:push_token]]).first
|
|
||||||
notification_subscription.destroy! if notification_subscription.present?
|
notification_subscription.destroy! if notification_subscription.present?
|
||||||
head :ok
|
head :ok
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -2,8 +2,8 @@ class Api::V1::Profile::MfaController < Api::BaseController
|
|||||||
before_action :check_mfa_feature_available
|
before_action :check_mfa_feature_available
|
||||||
before_action :check_mfa_enabled, only: [:destroy, :backup_codes]
|
before_action :check_mfa_enabled, only: [:destroy, :backup_codes]
|
||||||
before_action :check_mfa_disabled, only: [:create, :verify]
|
before_action :check_mfa_disabled, only: [:create, :verify]
|
||||||
before_action :validate_password, only: [:destroy]
|
|
||||||
before_action :validate_otp, only: [:verify, :backup_codes, :destroy]
|
before_action :validate_otp, only: [:verify, :backup_codes, :destroy]
|
||||||
|
before_action :validate_password, only: [:destroy]
|
||||||
|
|
||||||
def show; end
|
def show; end
|
||||||
|
|
||||||
@@ -48,8 +48,7 @@ class Api::V1::Profile::MfaController < Api::BaseController
|
|||||||
def validate_otp
|
def validate_otp
|
||||||
authenticated = Mfa::AuthenticationService.new(
|
authenticated = Mfa::AuthenticationService.new(
|
||||||
user: current_user,
|
user: current_user,
|
||||||
otp_code: mfa_params[:otp_code],
|
otp_code: mfa_params[:otp_code]
|
||||||
backup_code: mfa_params[:backup_code]
|
|
||||||
).authenticate
|
).authenticate
|
||||||
|
|
||||||
return if authenticated
|
return if authenticated
|
||||||
@@ -64,6 +63,6 @@ class Api::V1::Profile::MfaController < Api::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def mfa_params
|
def mfa_params
|
||||||
params.permit(:otp_code, :backup_code, :password)
|
params.permit(:otp_code, :password)
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ class Api::V1::Widget::ContactsController < Api::V1::Widget::BaseController
|
|||||||
contact = @contact
|
contact = @contact
|
||||||
end
|
end
|
||||||
|
|
||||||
@contact_inbox.update(hmac_verified: true) if should_verify_hmac?
|
@contact_inbox.update(hmac_verified: true) if should_verify_hmac? && valid_hmac?
|
||||||
|
|
||||||
identify_contact(contact)
|
identify_contact(contact)
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -43,15 +43,7 @@ class Api::V1::Widget::MessagesController < Api::V1::Widget::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def set_conversation
|
def set_conversation
|
||||||
return unless conversation.nil?
|
@conversation = create_conversation if conversation.nil?
|
||||||
|
|
||||||
@conversation = create_conversation
|
|
||||||
apply_labels if permitted_params[:labels].present?
|
|
||||||
end
|
|
||||||
|
|
||||||
def apply_labels
|
|
||||||
valid_labels = inbox.account.labels.where(title: permitted_params[:labels]).pluck(:title)
|
|
||||||
@conversation.update_labels(valid_labels) if valid_labels.present?
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def message_finder_params
|
def message_finder_params
|
||||||
@@ -72,21 +64,10 @@ class Api::V1::Widget::MessagesController < Api::V1::Widget::BaseController
|
|||||||
|
|
||||||
def permitted_params
|
def permitted_params
|
||||||
# timestamp parameter is used in create conversation method
|
# timestamp parameter is used in create conversation method
|
||||||
# custom_attributes and labels are applied when a new conversation is created alongside the first message
|
params.permit(:id, :before, :after, :website_token, contact: [:name, :email], message: [:content, :referer_url, :timestamp, :echo_id, :reply_to])
|
||||||
params.permit(
|
|
||||||
:id, :before, :after, :website_token,
|
|
||||||
contact: [:name, :email],
|
|
||||||
message: [:content, :referer_url, :timestamp, :echo_id, :reply_to],
|
|
||||||
custom_attributes: {},
|
|
||||||
labels: []
|
|
||||||
)
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def set_message
|
def set_message
|
||||||
# `conversation.messages.find` would be simpler, but `conversation` is `conversations.last`,
|
@message = @web_widget.inbox.messages.find(permitted_params[:id])
|
||||||
# which means a visitor with more than one open thread could not edit a message in any
|
|
||||||
# but their most recent one. Scoping across all of the visitor's conversations keeps the
|
|
||||||
# happy path correct for that future multi-conversation widget flow.
|
|
||||||
@message = Message.where(conversation_id: conversations.select(:id)).find(permitted_params[:id])
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -3,15 +3,15 @@ class Api::V2::Accounts::SummaryReportsController < Api::V1::Accounts::BaseContr
|
|||||||
before_action :prepare_builder_params, only: [:agent, :team, :inbox, :label, :channel]
|
before_action :prepare_builder_params, only: [:agent, :team, :inbox, :label, :channel]
|
||||||
|
|
||||||
def agent
|
def agent
|
||||||
render_report_with(V2::Reports::AgentSummaryBuilder, type: :agent)
|
render_report_with(V2::Reports::AgentSummaryBuilder)
|
||||||
end
|
end
|
||||||
|
|
||||||
def team
|
def team
|
||||||
render_report_with(V2::Reports::TeamSummaryBuilder, type: :team)
|
render_report_with(V2::Reports::TeamSummaryBuilder)
|
||||||
end
|
end
|
||||||
|
|
||||||
def inbox
|
def inbox
|
||||||
render_report_with(V2::Reports::InboxSummaryBuilder, type: :inbox)
|
render_report_with(V2::Reports::InboxSummaryBuilder)
|
||||||
end
|
end
|
||||||
|
|
||||||
def label
|
def label
|
||||||
@@ -38,9 +38,8 @@ class Api::V2::Accounts::SummaryReportsController < Api::V1::Accounts::BaseContr
|
|||||||
}
|
}
|
||||||
end
|
end
|
||||||
|
|
||||||
def render_report_with(builder_class, type: nil)
|
def render_report_with(builder_class)
|
||||||
builder_params = type.present? ? @builder_params.merge(type: type) : @builder_params
|
builder = builder_class.new(account: Current.account, params: @builder_params)
|
||||||
builder = builder_class.new(account: Current.account, params: builder_params)
|
|
||||||
render json: builder.build
|
render json: builder.build
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|||||||
@@ -58,7 +58,7 @@ class Api::V2::AccountsController < Api::BaseController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def check_signup_enabled
|
def check_signup_enabled
|
||||||
raise ActionController::RoutingError, 'Not Found' unless GlobalConfigService.account_signup_enabled?
|
raise ActionController::RoutingError, 'Not Found' if GlobalConfigService.load('ENABLE_ACCOUNT_SIGNUP', 'false') == 'false'
|
||||||
end
|
end
|
||||||
|
|
||||||
def validate_captcha
|
def validate_captcha
|
||||||
|
|||||||
@@ -1,18 +0,0 @@
|
|||||||
# Unauthenticated endpoint for resending confirmation emails during signup.
|
|
||||||
# This is a standalone controller (not on DeviseOverrides::ConfirmationsController)
|
|
||||||
# because OmniAuth middleware intercepts all POST /auth/* routes as provider
|
|
||||||
# callbacks, and Devise controller filters cause 307 redirects for custom actions.
|
|
||||||
# Inherits from ActionController::API to avoid both issues entirely.
|
|
||||||
# Rate-limited by Rack::Attack (IP + email) and gated by hCaptcha.
|
|
||||||
class Auth::ResendConfirmationsController < ActionController::API
|
|
||||||
def create
|
|
||||||
return head(:ok) unless ChatwootCaptcha.new(params[:h_captcha_client_response]).valid?
|
|
||||||
|
|
||||||
email = params[:email]
|
|
||||||
return head(:ok) unless email.is_a?(String)
|
|
||||||
|
|
||||||
user = User.from_email(email.strip.downcase)
|
|
||||||
user&.send_confirmation_instructions unless user&.confirmed?
|
|
||||||
head :ok
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
module AccessTokenAuthHelper
|
module AccessTokenAuthHelper
|
||||||
BOT_ACCESSIBLE_ENDPOINTS = {
|
BOT_ACCESSIBLE_ENDPOINTS = {
|
||||||
'api/v1/accounts/conversations' => %w[toggle_status toggle_typing_status toggle_priority create update custom_attributes],
|
'api/v1/accounts/conversations' => %w[toggle_status toggle_priority create update custom_attributes],
|
||||||
'api/v1/accounts/conversations/messages' => ['create'],
|
'api/v1/accounts/conversations/messages' => ['create'],
|
||||||
'api/v1/accounts/conversations/assignments' => ['create']
|
'api/v1/accounts/conversations/assignments' => ['create']
|
||||||
}.freeze
|
}.freeze
|
||||||
@@ -28,7 +28,7 @@ module AccessTokenAuthHelper
|
|||||||
|
|
||||||
def validate_bot_access_token!
|
def validate_bot_access_token!
|
||||||
return if Current.user.is_a?(User)
|
return if Current.user.is_a?(User)
|
||||||
return if @resource.is_a?(AgentBot) && agent_bot_accessible?
|
return if agent_bot_accessible?
|
||||||
|
|
||||||
render_unauthorized('Access to this endpoint is not authorized for bots')
|
render_unauthorized('Access to this endpoint is not authorized for bots')
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -2,10 +2,6 @@
|
|||||||
# This concern handles the token verification step.
|
# This concern handles the token verification step.
|
||||||
|
|
||||||
module MetaTokenVerifyConcern
|
module MetaTokenVerifyConcern
|
||||||
CHANNEL_APP_SECRET_KEYS = %w[app_secret app_secret_key client_secret api_secret].freeze
|
|
||||||
META_SIGNATURE_HEADER = 'X-Hub-Signature-256'.freeze
|
|
||||||
META_SIGNATURE_PREFIX = 'sha256='.freeze
|
|
||||||
|
|
||||||
def verify
|
def verify
|
||||||
service = is_a?(Webhooks::WhatsappController) ? 'whatsapp' : 'instagram'
|
service = is_a?(Webhooks::WhatsappController) ? 'whatsapp' : 'instagram'
|
||||||
if valid_token?(params['hub.verify_token'])
|
if valid_token?(params['hub.verify_token'])
|
||||||
@@ -18,53 +14,6 @@ module MetaTokenVerifyConcern
|
|||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def verify_meta_signature!
|
|
||||||
return unless meta_signature_verification_required?
|
|
||||||
return if valid_meta_signature?
|
|
||||||
|
|
||||||
head :unauthorized
|
|
||||||
end
|
|
||||||
|
|
||||||
def valid_meta_signature?
|
|
||||||
signature = request.headers[META_SIGNATURE_HEADER]
|
|
||||||
return false unless signature&.start_with?(META_SIGNATURE_PREFIX)
|
|
||||||
|
|
||||||
meta_app_secrets.any? do |secret|
|
|
||||||
next false if secret.blank?
|
|
||||||
|
|
||||||
expected_signature = "#{META_SIGNATURE_PREFIX}#{OpenSSL::HMAC.hexdigest('SHA256', secret, meta_request_body)}"
|
|
||||||
ActiveSupport::SecurityUtils.secure_compare(expected_signature, signature)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
def meta_request_body
|
|
||||||
@meta_request_body ||= request.raw_post
|
|
||||||
end
|
|
||||||
|
|
||||||
def meta_app_secrets
|
|
||||||
raise 'Overwrite this method in your controller'
|
|
||||||
end
|
|
||||||
|
|
||||||
def meta_signature_verification_required?
|
|
||||||
true
|
|
||||||
end
|
|
||||||
|
|
||||||
def channel_meta_app_secrets(channel)
|
|
||||||
return [] if channel.blank?
|
|
||||||
|
|
||||||
secrets = []
|
|
||||||
secrets << channel.app_secret if channel.respond_to?(:app_secret)
|
|
||||||
secrets.concat(provider_config_meta_app_secrets(channel))
|
|
||||||
secrets.compact_blank.uniq
|
|
||||||
end
|
|
||||||
|
|
||||||
def provider_config_meta_app_secrets(channel)
|
|
||||||
return [] unless channel.respond_to?(:provider_config)
|
|
||||||
|
|
||||||
provider_config = channel.provider_config.to_h.with_indifferent_access
|
|
||||||
CHANNEL_APP_SECRET_KEYS.filter_map { |key| provider_config[key].presence }
|
|
||||||
end
|
|
||||||
|
|
||||||
def valid_token?(_token)
|
def valid_token?(_token)
|
||||||
raise 'Overwrite this method your controller'
|
raise 'Overwrite this method your controller'
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -80,17 +80,10 @@ class DashboardController < ActionController::Base
|
|||||||
IS_ENTERPRISE: ChatwootApp.enterprise?,
|
IS_ENTERPRISE: ChatwootApp.enterprise?,
|
||||||
AZURE_APP_ID: GlobalConfigService.load('AZURE_APP_ID', ''),
|
AZURE_APP_ID: GlobalConfigService.load('AZURE_APP_ID', ''),
|
||||||
GIT_SHA: GIT_HASH,
|
GIT_SHA: GIT_HASH,
|
||||||
ALLOWED_LOGIN_METHODS: allowed_login_methods,
|
ALLOWED_LOGIN_METHODS: allowed_login_methods
|
||||||
ACTIVE_PLATFORM_BANNERS: active_platform_banners
|
|
||||||
}
|
}
|
||||||
end
|
end
|
||||||
|
|
||||||
def active_platform_banners
|
|
||||||
return [] unless ChatwootApp.chatwoot_cloud?
|
|
||||||
|
|
||||||
PlatformBanner.active.order(created_at: :desc).as_json(only: %i[id banner_message banner_type updated_at])
|
|
||||||
end
|
|
||||||
|
|
||||||
def allowed_login_methods
|
def allowed_login_methods
|
||||||
methods = ['email']
|
methods = ['email']
|
||||||
methods << 'google_oauth' if GlobalConfigService.load('ENABLE_GOOGLE_OAUTH_LOGIN', 'true').to_s != 'false'
|
methods << 'google_oauth' if GlobalConfigService.load('ENABLE_GOOGLE_OAUTH_LOGIN', 'true').to_s != 'false'
|
||||||
|
|||||||
@@ -10,12 +10,7 @@ class DeviseOverrides::OmniauthCallbacksController < DeviseTokenAuth::OmniauthCa
|
|||||||
private
|
private
|
||||||
|
|
||||||
def sign_in_user
|
def sign_in_user
|
||||||
# Capture before skip_confirmation! sets confirmed_at, which would
|
|
||||||
# make oauth_user_needs_password_reset? return false and skip the
|
|
||||||
# password reset for persisted unconfirmed users.
|
|
||||||
needs_password_reset = oauth_user_needs_password_reset?
|
|
||||||
@resource.skip_confirmation! if confirmable_enabled?
|
@resource.skip_confirmation! if confirmable_enabled?
|
||||||
set_random_password_if_oauth_user if needs_password_reset
|
|
||||||
|
|
||||||
# once the resource is found and verified
|
# once the resource is found and verified
|
||||||
# we can just send them to the login page again with the SSO params
|
# we can just send them to the login page again with the SSO params
|
||||||
@@ -25,10 +20,7 @@ class DeviseOverrides::OmniauthCallbacksController < DeviseTokenAuth::OmniauthCa
|
|||||||
end
|
end
|
||||||
|
|
||||||
def sign_in_user_on_mobile
|
def sign_in_user_on_mobile
|
||||||
# See comment in sign_in_user for why this is captured before skip_confirmation!
|
|
||||||
needs_password_reset = oauth_user_needs_password_reset?
|
|
||||||
@resource.skip_confirmation! if confirmable_enabled?
|
@resource.skip_confirmation! if confirmable_enabled?
|
||||||
set_random_password_if_oauth_user if needs_password_reset
|
|
||||||
|
|
||||||
# once the resource is found and verified
|
# once the resource is found and verified
|
||||||
# we can just send them to the login page again with the SSO params
|
# we can just send them to the login page again with the SSO params
|
||||||
@@ -45,7 +37,6 @@ class DeviseOverrides::OmniauthCallbacksController < DeviseTokenAuth::OmniauthCa
|
|||||||
return redirect_to login_page_url(error: 'business-account-only') unless validate_signup_email_is_business_domain?
|
return redirect_to login_page_url(error: 'business-account-only') unless validate_signup_email_is_business_domain?
|
||||||
|
|
||||||
create_account_for_user
|
create_account_for_user
|
||||||
set_random_password_if_oauth_user
|
|
||||||
token = @resource.send(:set_reset_password_token)
|
token = @resource.send(:set_reset_password_token)
|
||||||
frontend_url = ENV.fetch('FRONTEND_URL', nil)
|
frontend_url = ENV.fetch('FRONTEND_URL', nil)
|
||||||
redirect_to "#{frontend_url}/app/auth/password/edit?config=default&reset_password_token=#{token}"
|
redirect_to "#{frontend_url}/app/auth/password/edit?config=default&reset_password_token=#{token}"
|
||||||
@@ -60,7 +51,8 @@ class DeviseOverrides::OmniauthCallbacksController < DeviseTokenAuth::OmniauthCa
|
|||||||
end
|
end
|
||||||
|
|
||||||
def account_signup_allowed?
|
def account_signup_allowed?
|
||||||
GlobalConfigService.account_signup_enabled?
|
# set it to true by default, this is the behaviour across the app
|
||||||
|
GlobalConfigService.load('ENABLE_ACCOUNT_SIGNUP', 'false') != 'false'
|
||||||
end
|
end
|
||||||
|
|
||||||
def resource_class(_mapping = nil)
|
def resource_class(_mapping = nil)
|
||||||
@@ -90,15 +82,6 @@ class DeviseOverrides::OmniauthCallbacksController < DeviseTokenAuth::OmniauthCa
|
|||||||
Avatar::AvatarFromUrlJob.perform_later(@resource, auth_hash['info']['image'])
|
Avatar::AvatarFromUrlJob.perform_later(@resource, auth_hash['info']['image'])
|
||||||
end
|
end
|
||||||
|
|
||||||
def oauth_user_needs_password_reset?
|
|
||||||
@resource.present? && (@resource.new_record? || !@resource.confirmed?)
|
|
||||||
end
|
|
||||||
|
|
||||||
def set_random_password_if_oauth_user
|
|
||||||
# Password must satisfy secure_password requirements (uppercase, lowercase, number, special char)
|
|
||||||
@resource.update(password: "#{SecureRandom.hex(16)}aA1!") if @resource.persisted?
|
|
||||||
end
|
|
||||||
|
|
||||||
def default_devise_mapping
|
def default_devise_mapping
|
||||||
'user'
|
'user'
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -25,14 +25,6 @@ class DeviseOverrides::SessionsController < DeviseTokenAuth::SessionsController
|
|||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def render_create_error_not_confirmed
|
|
||||||
render_error(
|
|
||||||
:unauthorized,
|
|
||||||
I18n.t('devise_token_auth.sessions.not_confirmed', email: @resource.email),
|
|
||||||
error_code: 'user_not_confirmed'
|
|
||||||
)
|
|
||||||
end
|
|
||||||
|
|
||||||
def find_user_for_authentication
|
def find_user_for_authentication
|
||||||
return nil unless params[:email].present? && params[:password].present?
|
return nil unless params[:email].present? && params[:password].present?
|
||||||
|
|
||||||
|
|||||||
@@ -2,8 +2,6 @@ class Linear::CallbacksController < ApplicationController
|
|||||||
include Linear::IntegrationHelper
|
include Linear::IntegrationHelper
|
||||||
|
|
||||||
def show
|
def show
|
||||||
return redirect_to(safe_linear_redirect_uri) if params[:code].blank? || account_id.blank?
|
|
||||||
|
|
||||||
@response = oauth_client.auth_code.get_token(
|
@response = oauth_client.auth_code.get_token(
|
||||||
params[:code],
|
params[:code],
|
||||||
redirect_uri: "#{base_url}/linear/callback"
|
redirect_uri: "#{base_url}/linear/callback"
|
||||||
@@ -12,7 +10,7 @@ class Linear::CallbacksController < ApplicationController
|
|||||||
handle_response
|
handle_response
|
||||||
rescue StandardError => e
|
rescue StandardError => e
|
||||||
Rails.logger.error("Linear callback error: #{e.message}")
|
Rails.logger.error("Linear callback error: #{e.message}")
|
||||||
redirect_to safe_linear_redirect_uri
|
redirect_to linear_redirect_uri
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
private
|
||||||
@@ -33,19 +31,22 @@ class Linear::CallbacksController < ApplicationController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def handle_response
|
def handle_response
|
||||||
raise ArgumentError, 'Missing access token in Linear OAuth response' if parsed_body['access_token'].blank?
|
hook = account.hooks.new(
|
||||||
|
|
||||||
hook = account.hooks.find_or_initialize_by(app_id: 'linear')
|
|
||||||
hook.assign_attributes(
|
|
||||||
access_token: parsed_body['access_token'],
|
access_token: parsed_body['access_token'],
|
||||||
status: 'enabled',
|
status: 'enabled',
|
||||||
settings: merged_integration_settings(hook.settings)
|
app_id: 'linear',
|
||||||
|
settings: {
|
||||||
|
token_type: parsed_body['token_type'],
|
||||||
|
expires_in: parsed_body['expires_in'],
|
||||||
|
scope: parsed_body['scope']
|
||||||
|
}
|
||||||
)
|
)
|
||||||
|
# You may wonder why we're not handling the refresh token update, since the token will expire only after 10 years, https://github.com/linear/linear/issues/251
|
||||||
hook.save!
|
hook.save!
|
||||||
redirect_to linear_redirect_uri
|
redirect_to linear_redirect_uri
|
||||||
rescue StandardError => e
|
rescue StandardError => e
|
||||||
Rails.logger.error("Linear callback error: #{e.message}")
|
Rails.logger.error("Linear callback error: #{e.message}")
|
||||||
redirect_to safe_linear_redirect_uri
|
redirect_to linear_redirect_uri
|
||||||
end
|
end
|
||||||
|
|
||||||
def account
|
def account
|
||||||
@@ -53,47 +54,19 @@ class Linear::CallbacksController < ApplicationController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def account_id
|
def account_id
|
||||||
return @account_id if instance_variable_defined?(:@account_id)
|
return unless params[:state]
|
||||||
|
|
||||||
@account_id = params[:state].present? ? verify_linear_token(params[:state]) : nil
|
verify_linear_token(params[:state])
|
||||||
end
|
end
|
||||||
|
|
||||||
def linear_redirect_uri
|
def linear_redirect_uri
|
||||||
"#{ENV.fetch('FRONTEND_URL', nil)}/app/accounts/#{account.id}/settings/integrations/linear"
|
"#{ENV.fetch('FRONTEND_URL', nil)}/app/accounts/#{account.id}/settings/integrations/linear"
|
||||||
end
|
end
|
||||||
|
|
||||||
def safe_linear_redirect_uri
|
|
||||||
return base_url if account_id.blank?
|
|
||||||
|
|
||||||
linear_redirect_uri
|
|
||||||
rescue StandardError
|
|
||||||
base_url
|
|
||||||
end
|
|
||||||
|
|
||||||
def parsed_body
|
def parsed_body
|
||||||
@parsed_body ||= @response.response.parsed
|
@parsed_body ||= @response.response.parsed
|
||||||
end
|
end
|
||||||
|
|
||||||
def integration_settings
|
|
||||||
{
|
|
||||||
token_type: parsed_body['token_type'],
|
|
||||||
expires_in: parsed_body['expires_in'],
|
|
||||||
expires_on: expires_on,
|
|
||||||
scope: parsed_body['scope'],
|
|
||||||
refresh_token: parsed_body['refresh_token']
|
|
||||||
}.compact
|
|
||||||
end
|
|
||||||
|
|
||||||
def merged_integration_settings(existing_settings)
|
|
||||||
existing_settings.to_h.with_indifferent_access.merge(integration_settings)
|
|
||||||
end
|
|
||||||
|
|
||||||
def expires_on
|
|
||||||
return if parsed_body['expires_in'].blank?
|
|
||||||
|
|
||||||
(Time.current.utc + parsed_body['expires_in'].to_i.seconds).to_s
|
|
||||||
end
|
|
||||||
|
|
||||||
def base_url
|
def base_url
|
||||||
ENV.fetch('FRONTEND_URL', 'http://localhost:3000')
|
ENV.fetch('FRONTEND_URL', 'http://localhost:3000')
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ class Platform::Api::V1::AgentBotsController < PlatformController
|
|||||||
before_action :validate_platform_app_permissible, except: [:index, :create]
|
before_action :validate_platform_app_permissible, except: [:index, :create]
|
||||||
|
|
||||||
def index
|
def index
|
||||||
@resources = @platform_app.platform_app_permissibles.where(permissible_type: 'AgentBot').includes(:permissible)
|
@resources = @platform_app.platform_app_permissibles.where(permissible_type: 'AgentBot').all
|
||||||
end
|
end
|
||||||
|
|
||||||
def show; end
|
def show; end
|
||||||
|
|||||||
@@ -1,101 +0,0 @@
|
|||||||
class Platform::Api::V1::EmailChannelMigrationsController < PlatformController
|
|
||||||
before_action :set_account
|
|
||||||
before_action :validate_account_permissible
|
|
||||||
before_action :validate_feature_flag
|
|
||||||
before_action :validate_params
|
|
||||||
|
|
||||||
def create
|
|
||||||
results = migrate_email_channels
|
|
||||||
render json: { results: results }, status: :ok
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def set_account
|
|
||||||
@account = Account.find(params[:account_id])
|
|
||||||
end
|
|
||||||
|
|
||||||
def validate_account_permissible
|
|
||||||
return if @platform_app.platform_app_permissibles.find_by(permissible: @account)
|
|
||||||
|
|
||||||
render json: { error: 'Non permissible resource' }, status: :unauthorized
|
|
||||||
end
|
|
||||||
|
|
||||||
def validate_feature_flag
|
|
||||||
return if ActiveModel::Type::Boolean.new.cast(ENV.fetch('EMAIL_CHANNEL_MIGRATION', false))
|
|
||||||
|
|
||||||
render json: { error: 'Email channel migration is not enabled' }, status: :forbidden
|
|
||||||
end
|
|
||||||
|
|
||||||
def validate_params
|
|
||||||
return render json: { error: 'Missing migrations parameter' }, status: :unprocessable_entity if migration_params.blank?
|
|
||||||
|
|
||||||
return unless migration_params.size > MAX_MIGRATIONS
|
|
||||||
|
|
||||||
return render json: { error: "Too many migrations (max #{MAX_MIGRATIONS})" },
|
|
||||||
status: :unprocessable_entity
|
|
||||||
end
|
|
||||||
|
|
||||||
def migrate_email_channels
|
|
||||||
migration_params.map { |entry| migrate_single(entry) }
|
|
||||||
end
|
|
||||||
|
|
||||||
MAX_MIGRATIONS = 25
|
|
||||||
SUPPORTED_PROVIDERS = %w[google microsoft].freeze
|
|
||||||
|
|
||||||
def migrate_single(entry)
|
|
||||||
validate_provider!(entry[:provider])
|
|
||||||
|
|
||||||
ActiveRecord::Base.transaction do
|
|
||||||
channel = create_channel(entry)
|
|
||||||
inbox = create_inbox(channel, entry)
|
|
||||||
|
|
||||||
{ email: entry[:email], inbox_id: inbox.id, channel_id: channel.id, status: 'success' }
|
|
||||||
end
|
|
||||||
rescue StandardError => e
|
|
||||||
{ email: entry[:email], status: 'error', message: e.message }
|
|
||||||
end
|
|
||||||
|
|
||||||
def create_channel(entry)
|
|
||||||
Channel::Email.create!(
|
|
||||||
account_id: @account.id,
|
|
||||||
email: entry[:email],
|
|
||||||
provider: entry[:provider],
|
|
||||||
provider_config: entry[:provider_config]&.to_h,
|
|
||||||
imap_enabled: entry.fetch(:imap_enabled, true),
|
|
||||||
imap_address: entry[:imap_address] || default_imap_address(entry[:provider]),
|
|
||||||
imap_port: entry[:imap_port] || 993,
|
|
||||||
imap_login: entry[:imap_login] || entry[:email],
|
|
||||||
imap_enable_ssl: entry.fetch(:imap_enable_ssl, true)
|
|
||||||
)
|
|
||||||
end
|
|
||||||
|
|
||||||
def create_inbox(channel, entry)
|
|
||||||
@account.inboxes.create!(
|
|
||||||
name: entry[:inbox_name] || "Migrated #{entry[:provider]&.capitalize}: #{entry[:email]}",
|
|
||||||
channel: channel
|
|
||||||
)
|
|
||||||
end
|
|
||||||
|
|
||||||
def validate_provider!(provider)
|
|
||||||
return if SUPPORTED_PROVIDERS.include?(provider)
|
|
||||||
|
|
||||||
raise ArgumentError, "Unsupported provider '#{provider}'. Must be one of: #{SUPPORTED_PROVIDERS.join(', ')}"
|
|
||||||
end
|
|
||||||
|
|
||||||
def default_imap_address(provider)
|
|
||||||
case provider
|
|
||||||
when 'google' then 'imap.gmail.com'
|
|
||||||
when 'microsoft' then 'outlook.office365.com'
|
|
||||||
else ''
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
def migration_params
|
|
||||||
params.permit(migrations: [
|
|
||||||
:email, :provider, :inbox_name,
|
|
||||||
:imap_enabled, :imap_address, :imap_port, :imap_login, :imap_enable_ssl,
|
|
||||||
{ provider_config: {} }
|
|
||||||
])[:migrations]
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -24,10 +24,6 @@ class Public::Api::V1::InboxesController < PublicController
|
|||||||
def set_conversation
|
def set_conversation
|
||||||
return if params[:conversation_id].blank?
|
return if params[:conversation_id].blank?
|
||||||
|
|
||||||
@conversation = if @contact_inbox.hmac_verified?
|
@conversation = @contact_inbox.contact.conversations.find_by!(display_id: params[:conversation_id])
|
||||||
@contact_inbox.contact.conversations.find_by!(display_id: params[:conversation_id])
|
|
||||||
else
|
|
||||||
@contact_inbox.conversations.find_by!(display_id: params[:conversation_id])
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,15 +1,11 @@
|
|||||||
class Public::Api::V1::Portals::ArticlesController < Public::Api::V1::Portals::BaseController
|
class Public::Api::V1::Portals::ArticlesController < Public::Api::V1::Portals::BaseController
|
||||||
before_action :ensure_custom_domain_request, only: [:show, :index, :show_markdown]
|
before_action :ensure_custom_domain_request, only: [:show, :index]
|
||||||
before_action :portal
|
before_action :portal
|
||||||
before_action :set_portal_layout
|
|
||||||
before_action :set_view_variant
|
|
||||||
before_action :ensure_portal_feature_enabled
|
|
||||||
before_action :set_category, except: [:index, :show, :tracking_pixel]
|
before_action :set_category, except: [:index, :show, :tracking_pixel]
|
||||||
before_action :set_article, only: [:show, :show_markdown]
|
before_action :set_article, only: [:show]
|
||||||
layout 'portal'
|
layout 'portal'
|
||||||
|
|
||||||
def index
|
def index
|
||||||
@search_query = list_params[:query]
|
|
||||||
@articles = @portal.articles.published.includes(:category, :author)
|
@articles = @portal.articles.published.includes(:category, :author)
|
||||||
|
|
||||||
@articles = @articles.where(locale: permitted_params[:locale]) if permitted_params[:locale].present?
|
@articles = @articles.where(locale: permitted_params[:locale]) if permitted_params[:locale].present?
|
||||||
@@ -23,13 +19,6 @@ class Public::Api::V1::Portals::ArticlesController < Public::Api::V1::Portals::B
|
|||||||
|
|
||||||
def show
|
def show
|
||||||
@og_image_url = helpers.set_og_image_url(@portal.name, @article.title)
|
@og_image_url = helpers.set_og_image_url(@portal.name, @article.title)
|
||||||
@parsed_content = render_article_content(@article.content.to_s)
|
|
||||||
end
|
|
||||||
|
|
||||||
def show_markdown
|
|
||||||
return head :not_found unless @article&.published?
|
|
||||||
|
|
||||||
render plain: @article.content.to_s, content_type: 'text/markdown; charset=utf-8'
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def tracking_pixel
|
def tracking_pixel
|
||||||
@@ -71,6 +60,7 @@ class Public::Api::V1::Portals::ArticlesController < Public::Api::V1::Portals::B
|
|||||||
|
|
||||||
def set_article
|
def set_article
|
||||||
@article = @portal.articles.find_by(slug: permitted_params[:article_slug])
|
@article = @portal.articles.find_by(slug: permitted_params[:article_slug])
|
||||||
|
@parsed_content = render_article_content(@article.content)
|
||||||
end
|
end
|
||||||
|
|
||||||
def set_category
|
def set_category
|
||||||
@@ -83,9 +73,7 @@ class Public::Api::V1::Portals::ArticlesController < Public::Api::V1::Portals::B
|
|||||||
end
|
end
|
||||||
|
|
||||||
def list_params
|
def list_params
|
||||||
@list_params ||= params.permit(:query, :locale, :sort, :status, :page, :per_page).tap do |permitted|
|
params.permit(:query, :locale, :sort, :status, :page, :per_page)
|
||||||
permitted[:query] = permitted[:query].to_s.strip.presence
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def permitted_params
|
def permitted_params
|
||||||
|
|||||||
@@ -7,8 +7,6 @@ class Public::Api::V1::Portals::BaseController < PublicController
|
|||||||
around_action :set_locale
|
around_action :set_locale
|
||||||
after_action :allow_iframe_requests
|
after_action :allow_iframe_requests
|
||||||
|
|
||||||
PORTAL_LAYOUTS = %w[classic documentation].freeze
|
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def show_plain_layout
|
def show_plain_layout
|
||||||
@@ -19,14 +17,6 @@ class Public::Api::V1::Portals::BaseController < PublicController
|
|||||||
@theme_from_params = params[:theme] if %w[dark light].include?(params[:theme])
|
@theme_from_params = params[:theme] if %w[dark light].include?(params[:theme])
|
||||||
end
|
end
|
||||||
|
|
||||||
def set_portal_layout
|
|
||||||
@portal_layout = PORTAL_LAYOUTS.include?(@portal&.layout) ? @portal.layout : 'classic'
|
|
||||||
end
|
|
||||||
|
|
||||||
def set_view_variant
|
|
||||||
request.variant = :documentation if @portal_layout == 'documentation' && !@is_plain_layout_enabled
|
|
||||||
end
|
|
||||||
|
|
||||||
def portal
|
def portal
|
||||||
@portal ||= Portal.find_by!(slug: params[:slug], archived: false)
|
@portal ||= Portal.find_by!(slug: params[:slug], archived: false)
|
||||||
end
|
end
|
||||||
@@ -52,7 +42,7 @@ class Public::Api::V1::Portals::BaseController < PublicController
|
|||||||
article_locale = if article.category.present?
|
article_locale = if article.category.present?
|
||||||
article.category.locale
|
article.category.locale
|
||||||
else
|
else
|
||||||
article.locale
|
article.portal.default_locale
|
||||||
end
|
end
|
||||||
@locale = validate_and_get_locale(article_locale)
|
@locale = validate_and_get_locale(article_locale)
|
||||||
I18n.with_locale(@locale, &)
|
I18n.with_locale(@locale, &)
|
||||||
|
|||||||
@@ -1,18 +1,11 @@
|
|||||||
class Public::Api::V1::Portals::CategoriesController < Public::Api::V1::Portals::BaseController
|
class Public::Api::V1::Portals::CategoriesController < Public::Api::V1::Portals::BaseController
|
||||||
before_action :ensure_custom_domain_request, only: [:show, :index]
|
before_action :ensure_custom_domain_request, only: [:show, :index]
|
||||||
before_action :portal
|
before_action :portal
|
||||||
before_action :set_portal_layout
|
|
||||||
before_action :set_view_variant
|
|
||||||
before_action :ensure_portal_feature_enabled
|
|
||||||
before_action :set_category, only: [:show]
|
before_action :set_category, only: [:show]
|
||||||
before_action :load_category_articles, only: [:show], if: -> { @portal_layout == 'documentation' }
|
|
||||||
layout 'portal'
|
layout 'portal'
|
||||||
|
|
||||||
def index
|
def index
|
||||||
respond_to do |format|
|
@categories = @portal.categories.order(position: :asc)
|
||||||
format.html { redirect_to public_portal_locale_path(@portal.slug, params[:locale]), status: :moved_permanently }
|
|
||||||
format.json { @categories = @portal.categories.order(position: :asc) }
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def show
|
def show
|
||||||
@@ -27,9 +20,4 @@ class Public::Api::V1::Portals::CategoriesController < Public::Api::V1::Portals:
|
|||||||
Rails.logger.info "Category: not found for slug: #{params[:category_slug]}"
|
Rails.logger.info "Category: not found for slug: #{params[:category_slug]}"
|
||||||
render_404 && return if @category.blank?
|
render_404 && return if @category.blank?
|
||||||
end
|
end
|
||||||
|
|
||||||
def load_category_articles
|
|
||||||
@articles = @category.articles.published.order(:position).includes(:author)
|
|
||||||
@category_authors = @articles.filter_map(&:author).uniq
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,11 +1,7 @@
|
|||||||
class Public::Api::V1::PortalsController < Public::Api::V1::Portals::BaseController
|
class Public::Api::V1::PortalsController < Public::Api::V1::Portals::BaseController
|
||||||
before_action :ensure_custom_domain_request, only: [:show]
|
before_action :ensure_custom_domain_request, only: [:show]
|
||||||
before_action :redirect_to_portal_with_locale, only: [:show]
|
|
||||||
before_action :portal
|
before_action :portal
|
||||||
before_action :set_portal_layout
|
before_action :redirect_to_portal_with_locale, only: [:show]
|
||||||
before_action :set_view_variant
|
|
||||||
before_action :ensure_portal_feature_enabled
|
|
||||||
before_action :load_home_data, only: [:show], if: -> { @portal_layout == 'documentation' }
|
|
||||||
layout 'portal'
|
layout 'portal'
|
||||||
|
|
||||||
def show
|
def show
|
||||||
@@ -28,31 +24,6 @@ class Public::Api::V1::PortalsController < Public::Api::V1::Portals::BaseControl
|
|||||||
def redirect_to_portal_with_locale
|
def redirect_to_portal_with_locale
|
||||||
return if params[:locale].present?
|
return if params[:locale].present?
|
||||||
|
|
||||||
portal
|
|
||||||
redirect_to "/hc/#{@portal.slug}/#{@portal.default_locale}"
|
redirect_to "/hc/#{@portal.slug}/#{@portal.default_locale}"
|
||||||
end
|
end
|
||||||
|
|
||||||
def load_home_data
|
|
||||||
base_articles = @portal.articles.published.where(locale: @locale).includes(:author, :category)
|
|
||||||
@visible_categories = @portal.categories
|
|
||||||
.where(locale: @locale)
|
|
||||||
.joins(:articles).where(articles: { status: :published })
|
|
||||||
.order(position: :asc)
|
|
||||||
.group('categories.id')
|
|
||||||
@popular_topics = @visible_categories.first(3)
|
|
||||||
@featured = base_articles.order_by_views.limit(6)
|
|
||||||
@category_contributors = build_category_contributors(@visible_categories)
|
|
||||||
end
|
|
||||||
|
|
||||||
def build_category_contributors(categories)
|
|
||||||
category_ids = categories.map(&:id)
|
|
||||||
return {} if category_ids.empty?
|
|
||||||
|
|
||||||
@portal.articles
|
|
||||||
.published
|
|
||||||
.where(locale: @locale, category_id: category_ids)
|
|
||||||
.includes(:author)
|
|
||||||
.group_by(&:category_id)
|
|
||||||
.transform_values { |articles| articles.filter_map(&:author).uniq.first(3) }
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -18,11 +18,4 @@ class PublicController < ActionController::Base
|
|||||||
Please send us an email at support@chatwoot.com with the custom domain name and account API key"
|
Please send us an email at support@chatwoot.com with the custom domain name and account API key"
|
||||||
}, status: :unauthorized and return
|
}, status: :unauthorized and return
|
||||||
end
|
end
|
||||||
|
|
||||||
def ensure_portal_feature_enabled
|
|
||||||
return unless ChatwootApp.chatwoot_cloud?
|
|
||||||
return if @portal.account.feature_enabled?('help_center')
|
|
||||||
|
|
||||||
render 'public/api/v1/portals/not_active', status: :payment_required
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ class SuperAdmin::AppConfigsController < SuperAdmin::ApplicationController
|
|||||||
if errors.any?
|
if errors.any?
|
||||||
redirect_to super_admin_app_config_path(config: @config), alert: errors.join(', ')
|
redirect_to super_admin_app_config_path(config: @config), alert: errors.join(', ')
|
||||||
else
|
else
|
||||||
redirect_to super_admin_settings_path, flash: success_flash
|
redirect_to super_admin_settings_path, notice: "App Configs - #{@config.titleize} updated successfully"
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
@@ -58,21 +58,6 @@ class SuperAdmin::AppConfigsController < SuperAdmin::ApplicationController
|
|||||||
%w[ENABLE_ACCOUNT_SIGNUP FIREBASE_PROJECT_ID FIREBASE_CREDENTIALS WEBHOOK_TIMEOUT MAXIMUM_FILE_UPLOAD_SIZE WIDGET_TOKEN_EXPIRY]
|
%w[ENABLE_ACCOUNT_SIGNUP FIREBASE_PROJECT_ID FIREBASE_CREDENTIALS WEBHOOK_TIMEOUT MAXIMUM_FILE_UPLOAD_SIZE WIDGET_TOKEN_EXPIRY]
|
||||||
)
|
)
|
||||||
end
|
end
|
||||||
|
|
||||||
def success_notice
|
|
||||||
message = "#{@config.titleize} settings updated successfully"
|
|
||||||
return message unless restart_required_config_saved?
|
|
||||||
|
|
||||||
"#{message.delete_suffix('.')}. Restart Chatwoot web and worker processes to apply this change everywhere."
|
|
||||||
end
|
|
||||||
|
|
||||||
def success_flash
|
|
||||||
restart_required_config_saved? ? { success: success_notice } : { notice: success_notice }
|
|
||||||
end
|
|
||||||
|
|
||||||
def restart_required_config_saved?
|
|
||||||
params.fetch('app_config', {}).keys.intersect?(InstallationConfig::RESTART_REQUIRED_CONFIG_KEYS)
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|
||||||
SuperAdmin::AppConfigsController.prepend_mod_with('SuperAdmin::AppConfigsController')
|
SuperAdmin::AppConfigsController.prepend_mod_with('SuperAdmin::AppConfigsController')
|
||||||
|
|||||||
@@ -25,29 +25,6 @@ class SuperAdmin::InstallationConfigsController < SuperAdmin::ApplicationControl
|
|||||||
resource_class.editable
|
resource_class.editable
|
||||||
end
|
end
|
||||||
|
|
||||||
def create
|
|
||||||
resource = new_resource(resource_params)
|
|
||||||
authorize_resource(resource)
|
|
||||||
|
|
||||||
if resource.save
|
|
||||||
redirect_to after_resource_created_path(resource), flash: success_flash(resource)
|
|
||||||
else
|
|
||||||
render :new, locals: {
|
|
||||||
page: Administrate::Page::Form.new(dashboard, resource)
|
|
||||||
}, status: :unprocessable_entity
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
def update
|
|
||||||
if requested_resource.update(resource_params)
|
|
||||||
redirect_to after_resource_updated_path(requested_resource), flash: success_flash(requested_resource)
|
|
||||||
else
|
|
||||||
render :edit, locals: {
|
|
||||||
page: Administrate::Page::Form.new(dashboard, requested_resource)
|
|
||||||
}, status: :unprocessable_entity
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
# Override `resource_params` if you want to transform the submitted
|
# Override `resource_params` if you want to transform the submitted
|
||||||
# data before it's persisted. For example, the following would turn all
|
# data before it's persisted. For example, the following would turn all
|
||||||
# empty values into nil values. It uses other APIs such as `resource_class`
|
# empty values into nil values. It uses other APIs such as `resource_class`
|
||||||
@@ -65,20 +42,6 @@ class SuperAdmin::InstallationConfigsController < SuperAdmin::ApplicationControl
|
|||||||
.transform_values { |value| value == '' ? nil : value }.merge(locked: false)
|
.transform_values { |value| value == '' ? nil : value }.merge(locked: false)
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def success_flash(resource)
|
|
||||||
message = translate_with_resource('update.success')
|
|
||||||
message = translate_with_resource('create.success') if action_name == 'create'
|
|
||||||
return { notice: message } unless restart_required_config?(resource)
|
|
||||||
|
|
||||||
{ success: "#{message.delete_suffix('.')}. Restart Chatwoot web and worker processes to apply this change everywhere." }
|
|
||||||
end
|
|
||||||
|
|
||||||
def restart_required_config?(resource)
|
|
||||||
resource.name.in?(InstallationConfig::RESTART_REQUIRED_CONFIG_KEYS)
|
|
||||||
end
|
|
||||||
|
|
||||||
# See https://administrate-prototype.herokuapp.com/customizing_controller_actions
|
# See https://administrate-prototype.herokuapp.com/customizing_controller_actions
|
||||||
# for more information
|
# for more information
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
class SuperAdmin::PlatformBannersController < SuperAdmin::ApplicationController
|
|
||||||
before_action :ensure_chatwoot_cloud
|
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def ensure_chatwoot_cloud
|
|
||||||
raise ActionController::RoutingError, 'Not Found' unless ChatwootApp.chatwoot_cloud?
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -1,68 +0,0 @@
|
|||||||
class SuperAdmin::PushDiagnosticsController < SuperAdmin::ApplicationController
|
|
||||||
def show
|
|
||||||
@query = params[:user_query].to_s.strip
|
|
||||||
@user = resolve_user(@query)
|
|
||||||
@subscriptions = @user ? @user.notification_subscriptions.order(:id) : []
|
|
||||||
@results = []
|
|
||||||
end
|
|
||||||
|
|
||||||
def create
|
|
||||||
@user = User.find_by(id: params[:user_id])
|
|
||||||
return redirect_to super_admin_push_diagnostics_path, alert: I18n.t('super_admin.push_diagnostics.user_not_found') if @user.nil?
|
|
||||||
|
|
||||||
ids = parsed_subscription_ids
|
|
||||||
if ids.empty?
|
|
||||||
return redirect_to super_admin_push_diagnostics_path(user_query: @user.id),
|
|
||||||
alert: I18n.t('super_admin.push_diagnostics.no_subscriptions_to_test')
|
|
||||||
end
|
|
||||||
|
|
||||||
run_test_and_render(ids)
|
|
||||||
end
|
|
||||||
|
|
||||||
def destroy_subscriptions
|
|
||||||
user = User.find_by(id: params[:user_id])
|
|
||||||
return redirect_to super_admin_push_diagnostics_path, alert: I18n.t('super_admin.push_diagnostics.user_not_found') if user.nil?
|
|
||||||
|
|
||||||
ids = parsed_subscription_ids
|
|
||||||
if ids.empty?
|
|
||||||
return redirect_to super_admin_push_diagnostics_path(user_query: user.id),
|
|
||||||
alert: I18n.t('super_admin.push_diagnostics.no_subscriptions_to_delete')
|
|
||||||
end
|
|
||||||
|
|
||||||
deleted_count = user.notification_subscriptions.where(id: ids).destroy_all.size
|
|
||||||
log_super_admin_action("deleted #{deleted_count} subscriptions for user #{user.id}: #{ids}")
|
|
||||||
redirect_to super_admin_push_diagnostics_path(user_query: user.id),
|
|
||||||
notice: I18n.t('super_admin.push_diagnostics.subscriptions_deleted', count: deleted_count)
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def run_test_and_render(ids)
|
|
||||||
@query = @user.id.to_s
|
|
||||||
@subscriptions = @user.notification_subscriptions.order(:id)
|
|
||||||
@results = Notification::PushTestService.new(
|
|
||||||
user: @user, subscription_ids: ids,
|
|
||||||
title: params[:push_title], body: params[:push_body]
|
|
||||||
).perform
|
|
||||||
|
|
||||||
log_super_admin_action("test sent for user #{@user.id} subscriptions #{ids}")
|
|
||||||
render :show
|
|
||||||
end
|
|
||||||
|
|
||||||
def log_super_admin_action(message)
|
|
||||||
Rails.logger.info(
|
|
||||||
"[SuperAdmin] push diagnostics #{message} " \
|
|
||||||
"(actor_id=#{current_super_admin&.id}, actor_email=#{current_super_admin&.email})"
|
|
||||||
)
|
|
||||||
end
|
|
||||||
|
|
||||||
def resolve_user(query)
|
|
||||||
return if query.blank?
|
|
||||||
|
|
||||||
query.match?(/\A\d+\z/) ? User.find_by(id: query) : User.from_email(query)
|
|
||||||
end
|
|
||||||
|
|
||||||
def parsed_subscription_ids
|
|
||||||
Array(params[:subscription_ids]).reject(&:blank?).map(&:to_i)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -1,12 +1,7 @@
|
|||||||
class SwaggerController < ApplicationController
|
class SwaggerController < ApplicationController
|
||||||
def respond
|
def respond
|
||||||
if Rails.env.development? || Rails.env.test?
|
if Rails.env.development? || Rails.env.test?
|
||||||
swagger_root = Rails.root.join('swagger')
|
render inline: Rails.root.join('swagger', derived_path).read
|
||||||
file_path = swagger_root.join(derived_path).cleanpath
|
|
||||||
|
|
||||||
return head :not_found unless file_path.to_s.start_with?("#{swagger_root}/") && file_path.file?
|
|
||||||
|
|
||||||
render inline: file_path.read
|
|
||||||
else
|
else
|
||||||
head :not_found
|
head :not_found
|
||||||
end
|
end
|
||||||
@@ -16,8 +11,8 @@ class SwaggerController < ApplicationController
|
|||||||
|
|
||||||
def derived_path
|
def derived_path
|
||||||
params[:path] ||= 'index.html'
|
params[:path] ||= 'index.html'
|
||||||
path = Rack::Utils.clean_path_info(params[:path]).delete_prefix('/')
|
path = Rack::Utils.clean_path_info(params[:path])
|
||||||
path << ".#{Rack::Utils.clean_path_info(params[:format]).delete_prefix('/')}" unless path.ends_with?(params[:format].to_s)
|
path << ".#{Rack::Utils.clean_path_info(params[:format])}" unless path.ends_with?(params[:format].to_s)
|
||||||
path
|
path
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -31,11 +31,7 @@ class Twilio::CallbackController < ApplicationController
|
|||||||
:Latitude,
|
:Latitude,
|
||||||
:Longitude,
|
:Longitude,
|
||||||
:MessageType,
|
:MessageType,
|
||||||
:ProfileName,
|
:ProfileName
|
||||||
:ExternalUserId,
|
|
||||||
:ParentExternalUserId,
|
|
||||||
:ProfileUsername,
|
|
||||||
:Username
|
|
||||||
)
|
)
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,8 +1,6 @@
|
|||||||
class Webhooks::InstagramController < ActionController::API
|
class Webhooks::InstagramController < ActionController::API
|
||||||
include MetaTokenVerifyConcern
|
include MetaTokenVerifyConcern
|
||||||
|
|
||||||
before_action :verify_meta_signature!, only: :events
|
|
||||||
|
|
||||||
def events
|
def events
|
||||||
Rails.logger.info('Instagram webhook received events')
|
Rails.logger.info('Instagram webhook received events')
|
||||||
if params['object'].casecmp('instagram').zero?
|
if params['object'].casecmp('instagram').zero?
|
||||||
@@ -41,38 +39,4 @@ class Webhooks::InstagramController < ActionController::API
|
|||||||
token == GlobalConfigService.load('IG_VERIFY_TOKEN', '') ||
|
token == GlobalConfigService.load('IG_VERIFY_TOKEN', '') ||
|
||||||
token == GlobalConfigService.load('INSTAGRAM_VERIFY_TOKEN', '')
|
token == GlobalConfigService.load('INSTAGRAM_VERIFY_TOKEN', '')
|
||||||
end
|
end
|
||||||
|
|
||||||
def meta_app_secrets
|
|
||||||
[
|
|
||||||
*instagram_channel_meta_app_secrets,
|
|
||||||
GlobalConfigService.load('INSTAGRAM_APP_SECRET', nil),
|
|
||||||
GlobalConfigService.load('FB_APP_SECRET', nil)
|
|
||||||
]
|
|
||||||
end
|
|
||||||
|
|
||||||
def instagram_channel_meta_app_secrets
|
|
||||||
instagram_channels_from_payload.flat_map { |channel| channel_meta_app_secrets(channel) }
|
|
||||||
end
|
|
||||||
|
|
||||||
def instagram_channels_from_payload
|
|
||||||
Array(params.to_unsafe_hash[:entry]).flat_map do |entry|
|
|
||||||
instagram_ids_from_entry(entry.with_indifferent_access).flat_map do |instagram_id|
|
|
||||||
[
|
|
||||||
Channel::Instagram.find_by(instagram_id: instagram_id),
|
|
||||||
Channel::FacebookPage.find_by(instagram_id: instagram_id)
|
|
||||||
]
|
|
||||||
end
|
|
||||||
end.compact.uniq
|
|
||||||
end
|
|
||||||
|
|
||||||
def instagram_ids_from_entry(entry)
|
|
||||||
messages = entry[:messaging].presence || entry[:standby] || []
|
|
||||||
messages.filter_map { |messaging| instagram_id_from_messaging(messaging.with_indifferent_access) }
|
|
||||||
end
|
|
||||||
|
|
||||||
def instagram_id_from_messaging(messaging)
|
|
||||||
return messaging.dig(:sender, :id) if messaging.dig(:message, :is_echo).present?
|
|
||||||
|
|
||||||
messaging.dig(:recipient, :id)
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,35 +0,0 @@
|
|||||||
class Webhooks::ShopifyController < ActionController::API
|
|
||||||
before_action :verify_hmac!
|
|
||||||
|
|
||||||
def events
|
|
||||||
case request.headers['X-Shopify-Topic']
|
|
||||||
when 'shop/redact'
|
|
||||||
handle_shop_redact
|
|
||||||
end
|
|
||||||
|
|
||||||
head :ok
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
|
||||||
|
|
||||||
def verify_hmac!
|
|
||||||
secret = GlobalConfigService.load('SHOPIFY_CLIENT_SECRET', nil)
|
|
||||||
return head :unauthorized if secret.blank?
|
|
||||||
|
|
||||||
data = request.body.read
|
|
||||||
request.body.rewind
|
|
||||||
|
|
||||||
hmac_header = request.headers['X-Shopify-Hmac-SHA256']
|
|
||||||
return head :unauthorized if hmac_header.blank?
|
|
||||||
|
|
||||||
computed = Base64.strict_encode64(OpenSSL::HMAC.digest('SHA256', secret, data))
|
|
||||||
return head :unauthorized unless ActiveSupport::SecurityUtils.secure_compare(computed, hmac_header)
|
|
||||||
end
|
|
||||||
|
|
||||||
def handle_shop_redact
|
|
||||||
shop_domain = params[:shop_domain]
|
|
||||||
return if shop_domain.blank?
|
|
||||||
|
|
||||||
Integrations::Hook.where(app_id: 'shopify', reference_id: shop_domain).destroy_all
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -1,8 +1,6 @@
|
|||||||
class Webhooks::WhatsappController < ActionController::API
|
class Webhooks::WhatsappController < ActionController::API
|
||||||
include MetaTokenVerifyConcern
|
include MetaTokenVerifyConcern
|
||||||
|
|
||||||
before_action :verify_meta_signature!, only: :process_payload
|
|
||||||
|
|
||||||
def process_payload
|
def process_payload
|
||||||
if inactive_whatsapp_number?
|
if inactive_whatsapp_number?
|
||||||
Rails.logger.warn("Rejected webhook for inactive WhatsApp number: #{params[:phone_number]}")
|
Rails.logger.warn("Rejected webhook for inactive WhatsApp number: #{params[:phone_number]}")
|
||||||
@@ -22,45 +20,6 @@ class Webhooks::WhatsappController < ActionController::API
|
|||||||
token == whatsapp_webhook_verify_token if whatsapp_webhook_verify_token.present?
|
token == whatsapp_webhook_verify_token if whatsapp_webhook_verify_token.present?
|
||||||
end
|
end
|
||||||
|
|
||||||
def meta_app_secrets
|
|
||||||
[
|
|
||||||
*channel_meta_app_secrets(whatsapp_channel),
|
|
||||||
GlobalConfigService.load('WHATSAPP_APP_SECRET', nil)
|
|
||||||
]
|
|
||||||
end
|
|
||||||
|
|
||||||
def whatsapp_channel
|
|
||||||
@whatsapp_channel ||= whatsapp_business_payload_channel || Channel::Whatsapp.find_by(phone_number: params[:phone_number])
|
|
||||||
end
|
|
||||||
|
|
||||||
def meta_signature_verification_required?
|
|
||||||
return true if whatsapp_channel.blank?
|
|
||||||
return false unless whatsapp_channel.provider == 'whatsapp_cloud'
|
|
||||||
return true if channel_meta_app_secrets(whatsapp_channel).present?
|
|
||||||
|
|
||||||
whatsapp_channel.provider_config['source'] == 'embedded_signup'
|
|
||||||
end
|
|
||||||
|
|
||||||
def whatsapp_business_payload_channel
|
|
||||||
return unless params[:object] == 'whatsapp_business_account'
|
|
||||||
|
|
||||||
metadata = params.dig(:entry, 0, :changes, 0, :value, :metadata)
|
|
||||||
return if metadata.blank?
|
|
||||||
|
|
||||||
phone_number = normalized_phone_number(metadata[:display_phone_number])
|
|
||||||
phone_number_id = metadata[:phone_number_id]
|
|
||||||
channel = Channel::Whatsapp.find_by(phone_number: phone_number)
|
|
||||||
|
|
||||||
return channel if channel && channel.provider_config['phone_number_id'] == phone_number_id
|
|
||||||
end
|
|
||||||
|
|
||||||
def normalized_phone_number(phone_number)
|
|
||||||
return if phone_number.blank?
|
|
||||||
|
|
||||||
phone_number = phone_number.to_s
|
|
||||||
phone_number.start_with?('+') ? phone_number : "+#{phone_number}"
|
|
||||||
end
|
|
||||||
|
|
||||||
def inactive_whatsapp_number?
|
def inactive_whatsapp_number?
|
||||||
phone_number = params[:phone_number]
|
phone_number = params[:phone_number]
|
||||||
return false if phone_number.blank?
|
return false if phone_number.blank?
|
||||||
|
|||||||
@@ -77,23 +77,13 @@ class WidgetsController < ActionController::Base
|
|||||||
end
|
end
|
||||||
|
|
||||||
def allow_iframe_requests
|
def allow_iframe_requests
|
||||||
if @web_widget.allowed_domains.blank? || embedded_from_non_web_origin?
|
if @web_widget.allowed_domains.blank?
|
||||||
response.headers.delete('X-Frame-Options')
|
response.headers.delete('X-Frame-Options')
|
||||||
else
|
else
|
||||||
domains = @web_widget.allowed_domains.split(',').map(&:strip).join(' ')
|
domains = @web_widget.allowed_domains.split(',').map(&:strip).join(' ')
|
||||||
response.headers['Content-Security-Policy'] = "frame-ancestors #{domains}"
|
response.headers['Content-Security-Policy'] = "frame-ancestors #{domains}"
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
# Mobile WebViews (iOS/Android) load content from file:// or null origins,
|
|
||||||
# which cannot match any domain in frame-ancestors. When the per-inbox flag
|
|
||||||
# is enabled, skip frame-ancestors for these requests.
|
|
||||||
def embedded_from_non_web_origin?
|
|
||||||
return false unless @web_widget.allow_mobile_webview?
|
|
||||||
|
|
||||||
origin = request.headers['Origin']
|
|
||||||
origin.blank? || origin == 'null' || origin&.start_with?('file://')
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
|
||||||
WidgetsController.prepend_mod_with('WidgetsController')
|
WidgetsController.prepend_mod_with('WidgetsController')
|
||||||
|
|||||||
@@ -1,20 +0,0 @@
|
|||||||
require 'administrate/base_dashboard'
|
|
||||||
|
|
||||||
class PlatformBannerDashboard < Administrate::BaseDashboard
|
|
||||||
ATTRIBUTE_TYPES = {
|
|
||||||
id: Field::Number,
|
|
||||||
banner_message: Field::Text.with_options(truncate: 200),
|
|
||||||
banner_type: Field::Select.with_options(collection: %w[info warning error]),
|
|
||||||
active: Field::Boolean,
|
|
||||||
created_at: Field::DateTime,
|
|
||||||
updated_at: Field::DateTime
|
|
||||||
}.freeze
|
|
||||||
|
|
||||||
COLLECTION_ATTRIBUTES = %i[id banner_message banner_type active created_at].freeze
|
|
||||||
SHOW_PAGE_ATTRIBUTES = %i[id banner_message banner_type active created_at updated_at].freeze
|
|
||||||
FORM_ATTRIBUTES = %i[banner_message banner_type active].freeze
|
|
||||||
|
|
||||||
def display_resource(platform_banner)
|
|
||||||
"Banner ##{platform_banner.id} (#{platform_banner.banner_type})"
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -25,7 +25,7 @@ class UserDashboard < Administrate::BaseDashboard
|
|||||||
current_sign_in_ip: Field::String,
|
current_sign_in_ip: Field::String,
|
||||||
last_sign_in_ip: Field::String,
|
last_sign_in_ip: Field::String,
|
||||||
confirmation_token: Field::String,
|
confirmation_token: Field::String,
|
||||||
confirmed_at: ConfirmedAtField,
|
confirmed_at: Field::DateTime,
|
||||||
confirmation_sent_at: Field::DateTime,
|
confirmation_sent_at: Field::DateTime,
|
||||||
unconfirmed_email: Field::String,
|
unconfirmed_email: Field::String,
|
||||||
name: Field::String.with_options(searchable: true),
|
name: Field::String.with_options(searchable: true),
|
||||||
|
|||||||
@@ -17,7 +17,6 @@ class AsyncDispatcher < BaseDispatcher
|
|||||||
InstallationWebhookListener.instance,
|
InstallationWebhookListener.instance,
|
||||||
NotificationListener.instance,
|
NotificationListener.instance,
|
||||||
ParticipationListener.instance,
|
ParticipationListener.instance,
|
||||||
Conversations::UnreadCounts::Listener.instance,
|
|
||||||
ReportingEventListener.instance,
|
ReportingEventListener.instance,
|
||||||
WebhookListener.instance
|
WebhookListener.instance
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -7,15 +7,11 @@ class UserDrop < BaseDrop
|
|||||||
@obj.try(:available_name)
|
@obj.try(:available_name)
|
||||||
end
|
end
|
||||||
|
|
||||||
def email
|
|
||||||
@obj.try(:email)
|
|
||||||
end
|
|
||||||
|
|
||||||
def first_name
|
def first_name
|
||||||
@obj.try(:name).try(:split).try(:first).try(:capitalize) if @obj.try(:name).try(:split).try(:size).to_i > 1
|
@obj.try(:name).try(:split).try(:first).try(:capitalize) if @obj.try(:name).try(:split).try(:size) > 1
|
||||||
end
|
end
|
||||||
|
|
||||||
def last_name
|
def last_name
|
||||||
@obj.try(:name).try(:split).try(:last).try(:capitalize) if @obj.try(:name).try(:split).try(:size).to_i > 1
|
@obj.try(:name).try(:split).try(:last).try(:capitalize) if @obj.try(:name).try(:split).try(:size) > 1
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
require 'administrate/field/base'
|
|
||||||
|
|
||||||
class ConfirmedAtField < Administrate::Field::DateTime
|
|
||||||
end
|
|
||||||
@@ -11,7 +11,6 @@ class ConversationFinder
|
|||||||
'priority_desc' => %w[sort_on_priority desc],
|
'priority_desc' => %w[sort_on_priority desc],
|
||||||
'waiting_since_asc' => %w[sort_on_waiting_since asc],
|
'waiting_since_asc' => %w[sort_on_waiting_since asc],
|
||||||
'waiting_since_desc' => %w[sort_on_waiting_since desc],
|
'waiting_since_desc' => %w[sort_on_waiting_since desc],
|
||||||
'priority_desc_created_at_asc' => %w[sort_on_priority_created_at desc],
|
|
||||||
|
|
||||||
# To be removed in v3.5.0
|
# To be removed in v3.5.0
|
||||||
'latest' => %w[sort_on_last_activity_at desc],
|
'latest' => %w[sort_on_last_activity_at desc],
|
||||||
@@ -56,22 +55,6 @@ class ConversationFinder
|
|||||||
}
|
}
|
||||||
end
|
end
|
||||||
|
|
||||||
def perform_meta_only
|
|
||||||
set_up
|
|
||||||
|
|
||||||
mine_count, unassigned_count, all_count, = set_count_for_all_conversations
|
|
||||||
assigned_count = all_count - unassigned_count
|
|
||||||
|
|
||||||
{
|
|
||||||
count: {
|
|
||||||
mine_count: mine_count,
|
|
||||||
assigned_count: assigned_count,
|
|
||||||
unassigned_count: unassigned_count,
|
|
||||||
all_count: all_count
|
|
||||||
}
|
|
||||||
}
|
|
||||||
end
|
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def set_up
|
def set_up
|
||||||
|
|||||||
@@ -48,5 +48,3 @@ class MessageFinder
|
|||||||
messages.reorder('created_at desc').limit(20).reverse
|
messages.reorder('created_at desc').limit(20).reverse
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
MessageFinder.prepend_mod_with('MessageFinder')
|
|
||||||
|
|||||||
@@ -17,12 +17,15 @@ module Api::V1::InboxesHelper
|
|||||||
def validate_imap(channel_data)
|
def validate_imap(channel_data)
|
||||||
return unless channel_data.key?('imap_enabled') && channel_data[:imap_enabled]
|
return unless channel_data.key?('imap_enabled') && channel_data[:imap_enabled]
|
||||||
|
|
||||||
# Validate the user-selected auth mechanism before opening the connection.
|
Mail.defaults do
|
||||||
authentication = Imap::Authentication.validate_user_configurable!(channel_data[:imap_authentication])
|
retriever_method :imap, { address: channel_data[:imap_address],
|
||||||
|
port: channel_data[:imap_port],
|
||||||
|
user_name: channel_data[:imap_login],
|
||||||
|
password: channel_data[:imap_password],
|
||||||
|
enable_ssl: channel_data[:imap_enable_ssl] }
|
||||||
|
end
|
||||||
|
|
||||||
# Use the same auth adapter as the fetch service so LOGIN uses the IMAP LOGIN command,
|
check_imap_connection(channel_data)
|
||||||
# not SASL AUTH=LOGIN.
|
|
||||||
check_imap_connection(channel_data, authentication)
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def validate_smtp(channel_data)
|
def validate_smtp(channel_data)
|
||||||
@@ -34,8 +37,8 @@ module Api::V1::InboxesHelper
|
|||||||
check_smtp_connection(channel_data, smtp)
|
check_smtp_connection(channel_data, smtp)
|
||||||
end
|
end
|
||||||
|
|
||||||
def check_imap_connection(channel_data, authentication)
|
def check_imap_connection(channel_data)
|
||||||
imap = open_imap_connection(channel_data, authentication)
|
Mail.connection {} # rubocop:disable:block
|
||||||
rescue SocketError => e
|
rescue SocketError => e
|
||||||
raise StandardError, I18n.t('errors.inboxes.imap.socket_error')
|
raise StandardError, I18n.t('errors.inboxes.imap.socket_error')
|
||||||
rescue Net::IMAP::NoResponseError => e
|
rescue Net::IMAP::NoResponseError => e
|
||||||
@@ -50,50 +53,43 @@ module Api::V1::InboxesHelper
|
|||||||
rescue StandardError => e
|
rescue StandardError => e
|
||||||
raise StandardError, e.message
|
raise StandardError, e.message
|
||||||
ensure
|
ensure
|
||||||
imap.disconnect if imap.present? && !imap.disconnected?
|
|
||||||
Rails.logger.error "[Api::V1::InboxesHelper] check_imap_connection failed with #{e.message}" if e.present?
|
Rails.logger.error "[Api::V1::InboxesHelper] check_imap_connection failed with #{e.message}" if e.present?
|
||||||
end
|
end
|
||||||
|
|
||||||
def open_imap_connection(channel_data, authentication)
|
|
||||||
imap = build_imap_connection(channel_data)
|
|
||||||
Imap::Authentication.authenticate!(imap, authentication, channel_data[:imap_login], channel_data[:imap_password])
|
|
||||||
imap
|
|
||||||
end
|
|
||||||
|
|
||||||
def build_imap_connection(channel_data)
|
|
||||||
Net::IMAP.new(channel_data[:imap_address], port: channel_data[:imap_port], ssl: channel_data[:imap_enable_ssl])
|
|
||||||
end
|
|
||||||
|
|
||||||
def check_smtp_connection(channel_data, smtp)
|
def check_smtp_connection(channel_data, smtp)
|
||||||
smtp.open_timeout = 10
|
|
||||||
smtp.start(channel_data[:smtp_domain], channel_data[:smtp_login], channel_data[:smtp_password],
|
smtp.start(channel_data[:smtp_domain], channel_data[:smtp_login], channel_data[:smtp_password],
|
||||||
channel_data[:smtp_authentication]&.to_sym || :login)
|
channel_data[:smtp_authentication]&.to_sym || :login)
|
||||||
smtp.finish
|
smtp.finish
|
||||||
rescue Net::SMTPAuthenticationError
|
|
||||||
raise StandardError, I18n.t('errors.inboxes.smtp.authentication_error')
|
|
||||||
rescue SocketError, Errno::ECONNREFUSED, Errno::EHOSTUNREACH, Errno::ENETUNREACH, Net::OpenTimeout
|
|
||||||
raise StandardError, I18n.t('errors.inboxes.smtp.connection_error')
|
|
||||||
rescue OpenSSL::SSL::SSLError
|
|
||||||
raise StandardError, I18n.t('errors.inboxes.smtp.ssl_error')
|
|
||||||
rescue Net::SMTPServerBusy, Net::SMTPSyntaxError, Net::SMTPFatalError
|
|
||||||
raise StandardError, I18n.t('errors.inboxes.smtp.smtp_error')
|
|
||||||
rescue StandardError => e
|
|
||||||
raise StandardError, e.message
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def set_smtp_encryption(channel_data, smtp)
|
def set_smtp_encryption(channel_data, smtp)
|
||||||
if channel_data[:smtp_enable_ssl_tls]
|
if channel_data[:smtp_enable_ssl_tls]
|
||||||
set_smtp_ssl_method(smtp, :enable_tls, channel_data[:smtp_openssl_verify_mode])
|
set_enable_tls(channel_data, smtp)
|
||||||
elsif channel_data[:smtp_enable_starttls_auto]
|
elsif channel_data[:smtp_enable_starttls_auto]
|
||||||
set_smtp_ssl_method(smtp, :enable_starttls_auto, channel_data[:smtp_openssl_verify_mode])
|
set_enable_starttls_auto(channel_data, smtp)
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def set_smtp_ssl_method(smtp, method, openssl_verify_mode)
|
def set_enable_starttls_auto(channel_data, smtp)
|
||||||
return unless smtp.respond_to?(method)
|
return unless smtp.respond_to?(:enable_starttls_auto)
|
||||||
|
|
||||||
context = enable_openssl_mode(openssl_verify_mode) if openssl_verify_mode
|
if channel_data[:smtp_openssl_verify_mode]
|
||||||
context ? smtp.send(method, context) : smtp.send(method)
|
context = enable_openssl_mode(channel_data[:smtp_openssl_verify_mode])
|
||||||
|
smtp.enable_starttls_auto(context)
|
||||||
|
else
|
||||||
|
smtp.enable_starttls_auto
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
def set_enable_tls(channel_data, smtp)
|
||||||
|
return unless smtp.respond_to?(:enable_tls)
|
||||||
|
|
||||||
|
if channel_data[:smtp_openssl_verify_mode]
|
||||||
|
context = enable_openssl_mode(channel_data[:smtp_openssl_verify_mode])
|
||||||
|
smtp.enable_tls(context)
|
||||||
|
else
|
||||||
|
smtp.enable_tls
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def enable_openssl_mode(smtp_openssl_verify_mode)
|
def enable_openssl_mode(smtp_openssl_verify_mode)
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ module EmailHelper
|
|||||||
def render_email_html(content)
|
def render_email_html(content)
|
||||||
return '' if content.blank?
|
return '' if content.blank?
|
||||||
|
|
||||||
ChatwootMarkdownRenderer.new(content).render_message(hardbreaks: true).to_s
|
ChatwootMarkdownRenderer.new(content).render_message.to_s
|
||||||
end
|
end
|
||||||
|
|
||||||
# Raise a standard error if any email address is invalid
|
# Raise a standard error if any email address is invalid
|
||||||
|
|||||||
@@ -17,7 +17,6 @@ module FileTypeHelper
|
|||||||
def image_file?(content_type)
|
def image_file?(content_type)
|
||||||
[
|
[
|
||||||
'image/jpeg',
|
'image/jpeg',
|
||||||
'image/jpg',
|
|
||||||
'image/png',
|
'image/png',
|
||||||
'image/gif',
|
'image/gif',
|
||||||
'image/bmp',
|
'image/bmp',
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user