1001 Commits

Author SHA1 Message Date
Abhinav Raut 071190832b fix agent avatars showing in non-agent automation action dropdowns 2026-08-08 11:04:31 +05:30
Abhinav Raut d435af7d61 Merge pull request #441 from chahat-101/network-status-banner
show connection status banner to agents
2026-08-07 23:58:12 +05:30
Abhinav Raut 2552c8ef53 restyle connection banner as floating pill and fix focus reconnect 2026-08-07 23:57:25 +05:30
Abhinav Raut 64e74300cf Merge pull request #469 from abhinavxd/new-automations
New automations
2026-08-07 23:36:52 +05:30
Abhinav Raut cb96d9f087 pass all previous values when claiming an unassigned conversation 2026-08-07 22:41:19 +05:30
chahat-101 b5f414471c Use warning design tokens for connection banner 2026-08-07 21:17:15 +05:30
chahat-101 d180bfbedc Merge remote-tracking branch 'upstream/main' into network-status-banner 2026-08-07 20:57:38 +05:30
Abhinav Raut cc3f428008 count macro usage for content-only macros
Macros with no actions never hit the apply endpoint, so their usage count
stayed at zero. The frontend now calls apply whenever a macro was picked, and
drafts store the macro id so a macro survives switching conversations.
2026-08-07 19:53:46 +05:30
Abhinav Raut c6961da6aa raise request timeout to 120s for LLM-backed AI endpoints 2026-08-06 15:38:27 +05:30
Abhinav Raut ae0b6ee9f2 rework notify action with subject, message and picked recipients
The notify action only created a fixed in-app notification and recipients
were typed as a raw team:<id> / user:<id> DSL where typos silently notified
nobody. Now:

- recipients are picked by name (assignee, assigned team, any team or agent)
- admin writes the subject and message; both show in the bell notification
  and go out as an email (message plus conversation link, wrapped in the
  default outgoing email template, so nothing is hardcoded in English)
- the action serializes as typed fields {subject, message, recipients}
  instead of a positional value array

Also: previous_* condition fields are hidden for time triggers and populated
on message events (previous = current) so those rules can actually match,
action row widths now follow the RuleBox pattern (fixed type select, value
widgets fill the row), and three new i18n keys merged into existing globals.
2026-08-06 02:38:38 +05:30
Abhinav Raut 89b40f9dac add compact webhooks endpoint and fix previous_* automation values 2026-08-06 00:17:13 +05:30
Abhinav Raut aa0deedd48 fix automation rule feedback loops and scope the starts with operator
An automation rule that listens on an event and then writes the same field
re-fires its own event, so the rule matches again and loops forever. Status
already returned early on a no-op write, but priority and user assignment did
not, so those two could spin a worker doing a DB write per lap. Add the same
unchanged-value guard to both.

Suppression while the engine applies actions was a plain flag in a sync.Map,
so with more than one worker on the same conversation the first one to finish
deleted the key while the other was still applying actions. Make it a refcount
so each worker releases only its own claim.

The starts with operator is only implemented by the automation evaluator, not
the SQL filter builder, so give automation text fields their own operator list
instead of adding it to the shared one.

Also switch the notify action to its own recipients field type, fix the snooze
duration hint since the backend only takes Go duration units, trim and
lowercase notify recipient entries, and treat a missing previous value as no
match rather than an empty string.
2026-08-05 18:01:20 +05:30
Abhinav Raut 2aa4a1a86e Merge branch 'main' into new-automations
# Conflicts:
#	i18n/da-DK.json
#	i18n/de-DE.json
#	i18n/es-ES.json
#	i18n/fa-IR.json
#	i18n/fr-FR.json
#	i18n/it-IT.json
#	i18n/ja-JP.json
#	i18n/mr-IN.json
#	i18n/pt-BR.json
#	internal/conversation/conversation.go
2026-08-05 16:14:06 +05:30
Abhinav Raut 178136cda5 add notify, snooze and trigger webhook automation actions 2026-08-05 16:12:55 +05:30
Abhinav Raut 0efd643146 move improve-draft plain-text fallback to the server 2026-07-31 17:20:05 +05:30
Abhinav Raut fa4305d880 address PR review: stricter HTML detection and fence label punctuation 2026-07-31 17:02:37 +05:30
Abhinav Raut a5a029d894 fix lossy text conversions in AI features 2026-07-31 16:36:04 +05:30
Abhinav Raut 72c3f29830 fix hyperlinks getting lost across AI features
AI grammar fix rewrote the draft as plain text, so links in the reply box were dropped. It now sends the editor HTML and asks the model to keep tags. Conversation transcripts, the AI agent history and copilot context also stripped link URLs when converting HTML to text, so the model never saw them. They now keep links as "text ( url )".
2026-07-31 16:08:19 +05:30
Abhinav Raut c25452a152 remove redundant snippet URL import hint 2026-07-31 03:53:37 +05:30
Abhinav Raut f2edc74e18 hardcode copilot name and tidy up AI admin copy 2026-07-31 03:50:39 +05:30
Abhinav Raut 79da9e8988 Fix live chat image thumbnails 2026-07-31 01:05:32 +05:30
Abhinav Raut 16b99069b9 render the generated reply as html instead of showing raw markdown 2026-07-30 16:52:56 +05:30
Abhinav Raut fb4d665ca7 Merge pull request #421 from abhinavxd/feat/ai-agent
Feat/ai agent
2026-07-30 01:07:34 +05:30
Abhinav Raut 5e972d1dc5 point each AI admin page's docs link at its section anchor 2026-07-30 00:49:48 +05:30
Abhinav Raut bbcc92f2f3 add an aria-label to the channel icon in the conversation list 2026-07-30 00:47:29 +05:30
Abhinav Raut 276f19de0a show enabled state as a status badge and stop making checkbox fields required 2026-07-30 00:25:56 +05:30
Abhinav Raut 82f29f2789 fix Vue onUnmounted warning on the auth pages 2026-07-30 00:02:35 +05:30
dependabot[bot] 349e695fad build(deps-dev): bump postcss from 8.5.10 to 8.5.18 in /frontend
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.18.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/8.5.10...8.5.18)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.18
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-26 21:30:33 +00:00
Abhinav Raut 71fb197826 bump the default completion model off gpt-4o-mini 2026-07-27 02:39:57 +05:30
Abhinav Raut fd21893ebc cache AI assistants in a store instead of refetching on every copilot panel mount 2026-07-26 23:06:54 +05:30
chahat-101 ee45e87d6b show connection status banner to agents 2026-07-26 00:37:52 +05:30
Abhinav Raut b569777cf6 match email quote classes exactly and enforce password length on set password 2026-07-25 21:46:17 +05:30
Abhinav Raut 6b8a0f9521 fix content loss in knowledge base chunking and harden AI agent limits
Final review pass before taking the AI agent branch live.

Knowledge base:
- Text not wrapped in a block tag was never collected, so prose around a
  table or list never reached the index. The assistant answered "no
  relevant information" for questions the snippet covered.
- Blocks over the token limit were truncated and the remainder dropped. They
  are split into several chunks now.
- Trimming an oversized block ran one rune at a time and re-tokenized the
  whole string each step. A large table took minutes. It uses a binary
  search now.
- Overlap text was not escaped, so a sentence containing markup swallowed
  the rest of the chunk.
- SVG and template text no longer reaches the index.

AI agent:
- Verification codes are capped per address and per conversation. The cap
  was per conversation only, so a customer correcting a mistyped email was
  told to check an inbox that never got a code.
- Livechat verification sends synchronously. A queued send returned nil even
  when SMTP failed, so a failure counted as a sent code.
- Queued jobs drain on shutdown and hand off to a human instead of being
  dropped with no reply.
- Deleting an assistant no longer moves resolved and closed conversations
  into the fallback team.
- Image decode is capped at 25 MP. The old bound allowed a 400 MB decode per
  attachment.

Auth and admin:
- A blank OIDC client secret no longer overwrites the stored one. Blank id
  or secret is rejected instead.
- OIDC token exchange uses the SSRF guarded client with a timeout.
- Renaming a tool auth header no longer attaches the secret of whichever row
  now sits at that position.
- Clearing embedding dimensions no longer refills 1536 on the next load,
  which pushed a wrong value to the provider on the next save.
- Copilot conversation lookups filter by access before capping at 10.
2026-07-25 03:52:32 +05:30
Abhinav Raut 9f8f10ae74 drop the unenforced-rules section from the design doc 2026-07-25 00:55:29 +05:30
Abhinav Raut 23938a187a rename the design doc to DESIGN.md and resync it with the code
The surfaces section still described the old gray sidebar and the pre-swap
canvas values. Sidebar background now matches the app background in both
themes, so the tier diagram was wrong.

Also documents what the code already does: the .box, .sidebar-section-label
and .link-style utilities, the badge success variant, the variant prop on
AlertDialogAction, the hover-reveal pattern for table row actions, and the
rule that every non-submit button in a form needs type="button". Trimmed the
prose throughout.
2026-07-25 00:53:43 +05:30
Abhinav Raut d8b73c5877 retheme UI to the green palette and fix form and search bugs
Colors: the brand color moves from indigo to green in both themes, and the
sidebar, tooltip, card and link styles follow it. Three new tokens replace
hardcoded values: foreground-lighter for idle sidebar items, warning-600 for
warning text that needs 4.5:1 contrast on light backgrounds, and link for
anchors inside rendered email content. DESIGN_SYSTEM.md now lists the real
values from main.scss instead of the old indigo ones.

Forms: every button inside a form that is not the submit button now has an
explicit type. Without it the browser treats it as a submit button, so
clicking Cancel on a contact note posted an empty note, "New holiday" saved
the whole business-hours form, and pressing Enter in an SLA field deleted the
first alert row. The login page also highlights an empty password field on a
failed submit, which a broken condition prevented before, and the two
password fields on the set-password page get their own show and hide toggles.

Search: conversation and contact search now drop responses from an older
query, so clearing the box no longer repopulates the list with stale results.

Permissions: /api/v1/ai/summarize now needs messages:write, since it writes a
private note, and the menu item is hidden for agents without it.
2026-07-25 00:49:26 +05:30
Abhinav Raut 712fcbb642 return clear 400 errors for invalid AI tool and snippet input
An invalid custom tool name (bad characters or over 64 chars) used to
skip validation, hit the database check constraint, and return a 500.
The name format and length are now checked up front and return a 400
with the name hint, matching how the reserved-name check already works.
Bad tool URLs and parameter JSON now return their own specific message
instead of a generic "Something went wrong". Snippet create and update
now reject an empty title, like they already do for empty content.
Adds a unit test covering the tool validation cases.
2026-07-23 10:00:19 +05:30
Abhinav Raut 7c2e19b763 style sidebar section headers as labels and add design system doc 2026-07-23 03:52:05 +05:30
Abhinav Raut b8b2b6c9af standardize frontend design system, fix form validation, and skip continuity/CSAT messages in AI context
Design system:
- add semantic success and warning tokens (light + dark) and wire them into Tailwind
- move all hardcoded status colors (green/amber/red) onto tokens across main app and widget; keep file-type icons as identity colors
- give light mode real surface depth: gray chrome sidebars vs white content, deeper canvas gutter, crisper borders, wider gray spread so selected/hover states show
- unify radius (cards rounded-lg, controls rounded-md) and elevation (card shadow-sm, menu shadow-md)
- make reports overview colors uniform: neutral numbers, green met / red breached
- normalize the two page-title heading outliers to text-xl font-semibold

Form fixes:
- require content on AI snippets
- only include non-checkbox prechat fields when they have a value

AI context:
- skip continuity and CSAT messages in AI history, mining, and previous-conversation tools
2026-07-23 03:37:33 +05:30
Abhinav Raut 74813b2e17 reveal admin table row actions on hover and switch to vertical menu, add AI tool enable toggle 2026-07-22 22:04:00 +05:30
Abhinav Raut 40f8284e98 strip quoted reply chains from AI agent message context
When the agent built conversation history and mined FAQs, it used the
raw message text, which included the full quoted reply chain from every
email. That wasted tokens and confused the model with old back-and-forth.

Add emailquote.go to strip quoted blocks. HTML messages get their quote
containers pruned (gmail, yahoo, protonmail, outlook markers, and
blockquotes); plain text gets trailing ">" lines and "On ... wrote:" /
"Original Message" markers trimmed. If stripping leaves nothing (a
quote-only reply or forward), we fall back to the full text so the
message is not dropped. Add the matching protonmail_quote selector to
the frontend hide-quoted-text styles so the two stay in sync.

Also fix knowledge base chunking: plain text with no block structure was
kept as one chunk and could overflow the model limit. It now packs into
size-bound pieces on sentence boundaries, and oversized atomic blocks are
flushed and truncated on their own so they can never sneak through.
2026-07-22 21:22:35 +05:30
Abhinav Raut 6125f5ced0 harden AI agent knowledge base, OTP, and prompt injection defenses
Knowledge base: fold the embedding provider base URL into the snippet
fingerprint so re-pointing the provider triggers a reindex even when the
model name is unchanged. Reject empty knowledge base content. Cap
concurrent background snippet embeds at 4 and tie embedding work to the
app lifecycle context. Reindex when the embedding base URL changes, not
just the model or dimensions.

Prompt injection: neutralize << >> block delimiters in snippets,
transcripts, subjects, and contact fields so untrusted content can't
forge a boundary the model relies on.

OTP: set the verified flag inside the Lua match script so verification
is atomic. Only count codes that were actually emailed toward the resend
cap, and check the cap before sending instead of incrementing up front.

Tools: fetch only the enabled tools among the allowed IDs, and route all
registrations through one helper so custom tools can't shadow built-ins.

Agent queue: hand a dropped response job off to a human instead of
leaving the conversation assigned to the assistant with no reply.

Also let GetAllConversationMessages return every message when limit is
non-positive, populate admin forms without triggering validation, and
default the copilot name to Juno.
2026-07-22 14:56:49 +05:30
Abhinav Raut cf629f34d7 only include checked checkbox fields in prechat form submission 2026-07-22 01:31:37 +05:30
Abhinav Raut 83f9bb5828 show a BETA badge on the AI admin nav item
Adds a badge prop to nav items and renders it next to the collapsible
group title. The AI section now shows BETA in the sidebar.
2026-07-22 01:20:21 +05:30
Abhinav Raut ae44e7f4db expand AI tool context and let contacts correct their email
Custom HTTP tools now get more identity context. Each call sends the
contact id, contact type, conversation UUID, and inbox id as headers,
and the contact email is read live per call instead of snapshotting it
at run start.

set_contact_email is no longer blocked once an email is known. A
customer who gives a different email (for example after their account
could not be found) can now correct it. Changing the email clears the
verification flag and any pending code first, so a failed clear can
never leave the conversation verified against an unproven address. The
prompt and tool descriptions were updated to guide this flow.

Also fixes some widget and admin UI issues: prechat form validation
now handles required numbers, checkboxes, and links correctly; tool
header rows keep stable keys so removing a row does not shuffle inputs;
the verification toggle uses form state directly; and the livechat
inbox form shows the inbox UUID with a copy button.
2026-07-22 00:58:41 +05:30
Abhinav Raut ea03339b0d address CodeRabbit review findings in the AI agent
Drop the deprecated webhook.allowed_hosts fallback from the SSRF setup.
It appended hostnames to allowed_cidrs, which only parses CIDRs, so those
entries were silently dropped anyway. Read the [ssrf] block only.

Link AI assistant messages to the specific assistant. postReply now stamps
the assistant id into the message meta, and the message bubble links to that
assistant's edit page, falling back to the assistants list for older messages
that lack the id.
2026-07-21 11:02:43 +05:30
Abhinav Raut c659e30eca address CodeRabbit review findings in the AI agent
- recover from panics in the AI reply and FAQ-mining workers so one bad run can't crash the process
- guard image decode with a pixel-count cap to block image bombs
- hand off (not silently drop) when the confirmation reply fails to send
- give the model a generic tool-failure message instead of the raw error
- log Redis Expire and assistant-cache refresh failures instead of ignoring them
- drop chunk text from RAG debug logs
- refetch the assistant when the edit route's id changes
2026-07-21 01:05:26 +05:30
dependabot[bot] b4228332ed build(deps): bump axios from 1.16.0 to 1.18.0 in /frontend
Bumps [axios](https://github.com/axios/axios) from 1.16.0 to 1.18.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](https://github.com/axios/axios/compare/v1.16.0...v1.18.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.18.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 18:11:24 +00:00
Abhinav Raut bfc3b6e196 gate AI custom tools behind email OTP verification
Custom tools can now require a verified contact before they run. This gives tools a trustworthy signal about who the customer is without relying on DMARC or the JWT login.

ai_tools gets a requires_verification column, defaulting to true (fail-closed). A flagged tool is blocked in httpTool.Execute until the conversation is verified, and every tool call now carries an X-Libredesk-Contact-Verified header so tool authors can tell an OTP-verified contact from a self-claimed one.

The AI agent gets three native tools: send_email_verification emails a 6-digit code out of band, check_email_verification confirms it, and set_contact_email lets an anonymous visitor add an email to send the code to. Codes and the verified window live in Redis, scoped per conversation, with attempt and resend caps. JWT livechat contacts stay trusted without OTP; email contacts and visitors verify by code.

The tool admin form gets a "require verified contact" toggle (default on) with a confirm dialog when turning it off.
2026-07-20 17:48:41 +05:30
Abhinav Raut 6015859574 scope copilot thinking state per conversation
isThinking was a single global ref, so switching conversations while a copilot
send was still in flight showed the thinking indicator in the wrong conversation
and blocked sending there until the other request settled. Key it by uuid like
the revision and message state already are.
2026-07-19 23:57:01 +05:30