40 Commits

Author SHA1 Message Date
Abhinav Raut 6b8a0f9521 fix content loss in knowledge base chunking and harden AI agent limits
Final review pass before taking the AI agent branch live.

Knowledge base:
- Text not wrapped in a block tag was never collected, so prose around a
  table or list never reached the index. The assistant answered "no
  relevant information" for questions the snippet covered.
- Blocks over the token limit were truncated and the remainder dropped. They
  are split into several chunks now.
- Trimming an oversized block ran one rune at a time and re-tokenized the
  whole string each step. A large table took minutes. It uses a binary
  search now.
- Overlap text was not escaped, so a sentence containing markup swallowed
  the rest of the chunk.
- SVG and template text no longer reaches the index.

AI agent:
- Verification codes are capped per address and per conversation. The cap
  was per conversation only, so a customer correcting a mistyped email was
  told to check an inbox that never got a code.
- Livechat verification sends synchronously. A queued send returned nil even
  when SMTP failed, so a failure counted as a sent code.
- Queued jobs drain on shutdown and hand off to a human instead of being
  dropped with no reply.
- Deleting an assistant no longer moves resolved and closed conversations
  into the fallback team.
- Image decode is capped at 25 MP. The old bound allowed a 400 MB decode per
  attachment.

Auth and admin:
- A blank OIDC client secret no longer overwrites the stored one. Blank id
  or secret is rejected instead.
- OIDC token exchange uses the SSRF guarded client with a timeout.
- Renaming a tool auth header no longer attaches the secret of whichever row
  now sits at that position.
- Clearing embedding dimensions no longer refills 1536 on the next load,
  which pushed a wrong value to the provider on the next save.
- Copilot conversation lookups filter by access before capping at 10.
2026-07-25 03:52:32 +05:30
Abhinav Raut c7f55e2394 guard reply-box AI prompt race and share the SSRF-safe http transport
handleAiPromptSelected now captures the conversation uuid and bails if it changed while the completion was in flight, and uses convertTextToHtml with a null guard, matching handleGenerateReply. This stops a generated prompt from landing in the wrong conversation's draft or crashing on an empty response.

Add ssrf.NewTransport that clones http.DefaultTransport (keeping proxy and connection-pool defaults) and applies the dial guard, then use it for the OIDC, AI, OpenAI, and webhook clients. The bare transports were dropping HTTP_PROXY handling and pool defaults.
2026-07-18 11:20:16 +05:30
Abhinav Raut 758a01ab74 guard knowledge base URL import against SSRF and fix OIDC transport defaults
The earlier SSRF work covered the provider, custom-tool, webhook, and OIDC
outbound calls but missed the knowledge base URL import path, which still used
http.DefaultClient. An admin importing a URL could reach loopback, link-local,
or RFC1918 hosts. Renamed the Manager's toolClient to httpClient (it is a
general SSRF-guarded outbound client now) and pointed fetchURL at it. The guard
sits on the dialer's Control, so it also runs on redirect targets, not just the
first hop.

Also fixed the OIDC discovery client. Its hand-built transport dropped two
defaults that http.DefaultTransport sets. Added Proxy: http.ProxyFromEnvironment
so it honors HTTP_PROXY/HTTPS_PROXY (SSO discovery now works behind an egress
proxy) and ForceAttemptHTTP2 so HTTP/2 is negotiated.
2026-07-17 19:24:31 +05:30
Abhinav Raut 9566dcbf4d apply SSRF guard to all admin-configured outbound URLs
Move the webhook SSRF guard into a shared internal/ssrf package and wire it
into every place the server fetches an admin-set URL: webhooks, OIDC discovery,
the AI provider base URL, and custom AI tool calls. Add a global [ssrf] config
block, off by default with an allowed_cidrs bypass, so single-tenant self-hosters
keep reaching internal hosts while multi-tenant or hosted deploys can turn it on.
The old [webhook] allowed_hosts key is still read for backward compat and folds
into the guard.
2026-07-16 12:58:12 +05:30
Abhinav Raut 15021bf22b Make session lifetime configurable 2026-04-21 20:27:40 +05:30
Abhinav Raut d7d58bebdb Lock agent WS to same-origin and set SameSite=Lax on session cookie 2026-04-16 03:13:09 +05:30
Abhinav Raut 81847c7f4e i18n: fix localization issues (#231)
Not backported to main due to extensive i18n refactoring changes in this branch.
2026-02-22 15:12:00 +05:30
Abhinav Raut 4409bd84e8 fix: set session store TTL to 9 hours.
Fixes #228
2026-01-19 23:46:12 +05:30
Abhinav Raut 0de712762c fix: auth initialization with i18n 2025-04-03 01:21:12 +05:30
Abhinav Raut 6b6549cb03 standardize i18n keys for consistency rename keys
fix: avatar url `null` console warnings.
2025-04-03 01:21:12 +05:30
Abhinav Raut 4361250c73 feat: backend api response translations 2025-04-03 01:21:12 +05:30
Jonathan Leroy 36077b1837 Update Config struct description 2025-03-30 19:56:15 +02:00
Jonathan Leroy a5a9d1304c Allow to disable cookies secure flag when needed 2025-03-24 12:24:50 +01:00
Abhinav Raut 03c68afc4c fix: max age not working for cookies
Switch from expires to max age for setting cookie expiry
Set default max age to 9 hours
2025-03-02 16:28:26 +05:30
Abhinav Raut 5361bcb24f feat: dockerize libredesk
- feat: new flag for idempotent installation `--idempotent-install`
- feat: new flag to skip yes/no prompt `--yes`
- feat: new flag for upgrades `--upgrade`
- refactor: update doc strings and sample toml file.
- chore: update .gitignore.
2025-02-22 23:33:18 +05:30
Abhinav Raut 62e38814c7 feat: API to discover OIDC provider
- fix: discover oidc provider first before attempting to create one.
2025-02-21 20:34:15 +05:30
Abhinav Raut 356a206110 fix: new incoming messages having 0 attachments in API responses, upload attachments first before sending out websocket updates.
- refactor: stringutils package remove unncessary `string` in function names.
- minor refactors.
2025-02-08 18:04:02 +05:30
Abhinav Raut c8ee82e3e5 set 48 hr expirty to login cookie. 2025-02-04 00:47:06 +05:30
Abhinav Raut 7ff2a7ea7d doc: adds doc string for auth structs. 2025-02-02 16:59:57 +05:30
Abhinav Raut b15c07c5a6 fix: return user friendly error messages on initializing new oidc provider. 2025-02-02 14:13:49 +05:30
Abhinav Raut 1549e87370 fix: OIDC login. 2025-02-01 04:23:26 +05:30
Abhinav Raut 966707191d fix: oidc hide secrets in json marshal
- adds new public handler that returns available providers.
2025-01-30 01:43:44 +05:30
Abhinav Raut 0c54abbbad refactor: rename modules and imports to reflect project name 2025-01-11 21:46:29 +05:30
Abhinav Raut caf8e7d34d WIP: MVP with shadcn sidebar
- csat
- SLA
- email notification templates
2025-01-06 02:39:44 +05:30
Abhinav Raut 48e89dc4b9 feat: hot reload package configs on change, no binary restart needed
- feat: soft deletion for users, inboxes, teams, and tags
- Rename tables and queries.
2024-11-13 01:47:16 +05:30
Abhinav Raut 2b25ce32b6 feat: adds nonce check for oidc token exchange
- feat: adds filters support on conversations list
- refactor middlewares.go
- Adds new paginate.go for generating filtered paginated SQL queries this removes sql generation code from the conversations package.
- rename some components
- removes hardcoded `/uploads/`
2024-10-17 04:21:22 +05:30
Abhinav Raut 98df9efd63 feat: adds dropdown to automation form fields
- feat: adds csrf token check
- feat: adds conversation sub and unsub for WS updates.
- Clean up and remove unncessary code
- refactor and simplify auth middlewares
- fix: automation rules
- Update schema.sql
2024-10-14 01:50:08 +05:30
Abhinav Raut 844dbf1e9d fix: auth
- fix: null attachments in get message api.
2024-10-09 04:42:15 +05:30
Abhinav Raut 671b2371b5 feat: attachment download / view button on preview
- adds /compact apis for fetching teams and users
- adds form field to allow admin to set user password.
- fix: inline images for incoming email.
- save content id & disposition for each media.
- Update to schema.sql
2024-10-09 03:50:53 +05:30
Abhinav Raut 4f9118d675 feat: new install & set-system-user-password flags for setting up DB schema and setting system user password
- fixes issues in auth redirect to login, by making simple session cookie auto create = true.
- fixes issues with conversation tab filters WS subscription.
- fixes nulls returned for empty team list in handlers
- fixes logout btn not working.
- fixes charts error when there's no data returned from the API.
- Updates schema.sql
2024-10-07 04:26:10 +05:30
Abhinav Raut f42824aceb feat: set menu card max-w .
- fix: program crashing when OIDC provider request fails.
2024-08-26 03:30:09 +05:30
Abhinav Raut ce30055223 PUSH COMMITS 2024-08-13 03:32:31 +05:30
Abhinav Raut 06db29f7f3 refactor. 2024-08-11 03:52:05 +05:30
Abhinav Raut 704c485b6a refactor 2024-08-09 03:55:20 +05:30
Abhinav Raut 4c52af8f62 feat: dashboard. 2024-08-02 04:50:47 +05:30
Abhinav Raut ead54665fb wip: oidc 2024-07-31 04:02:34 +05:30
Abhinav Raut 8b763fb167 refactor. 2024-07-24 03:00:54 +05:30
Abhinav Raut 5e00558e9b feat: updates to admin page.
- role page.
2024-07-22 03:05:30 +05:30
Abhinav Raut f86077f944 refactor. 2024-07-15 02:55:27 +05:30
Abhinav Raut d7fb9be211 some more commits? 2024-07-01 03:08:45 +05:30