CARVIEW |
Select Language
HTTP/2 200
date: Tue, 22 Jul 2025 08:20:14 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"7f1a6fd5a7fd7cfd86fe81c071de5002"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=xxCRdk5nBX3c3GCFB9CY93t6S2NnIyLVu3Ab45nfcFJ0CSUeLHSLbCrBiwi54tJ%2FMNFCh86x%2Foezzg9Hvbi8TBqNnRjD1NtXIlSmdmVctH3q%2BgBr9Gk2U0THXwOOPuaAGe1JDDT2NloBcBK%2FrTwfvijW%2Bx%2B7j9tZYoqS4H7rpBMFgyAMAiqERNrtsf6pH%2FO16dah3YP8SmQGpjSXHd7M3fwTayicHHqJbekEmO6axo4giWaqHln2D2gNa0RCw7Au%2FPm210vx0N5N8OjiIPPbjA%3D%3D--AVrswmr%2BAxfEtzxq--8NYRWaJ8EzMZPiqsh6q44w%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.1785196531.1753172414; Path=/; Domain=github.com; Expires=Wed, 22 Jul 2026 08:20:14 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Wed, 22 Jul 2026 08:20:14 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: 9AA4:180C8D:356ECF:3BA330:687F49BE
Tags · LiveHelperChat/livehelperchat · GitHub
Toggle 4.65v's commit message
Toggle 4.61v's commit message
Toggle 4.59v's commit message
Skip to content
Navigation Menu
{{ message }}
-
-
Notifications
You must be signed in to change notification settings - Fork 716
Tags: LiveHelperChat/livehelperchat
Tags
4.65v
4.65v (#2251) 1. Department statistic modal window will show department online status. Useful for investigations. 2. Case insensitive will be a global in additional chat variables. 3. Sometimes while logging as other operator did not work and operator was logged out instantly. 4. `vars_encrypted` option should be respected in popup. 5. `If` condition support in bot individualization. https://doc.livehelperchat.com/docs/bot/multiple-languages#setting-translations-for-messages execute doc/update_db/update_333.sql for update
4.61v
Master routing (#2228) 4.61v Security Fixes Multiple XSS vulnerabilities were fixed (all required operator login to exploit) These were minor security issues that couldn't be exploited by anonymous visitors Reported by: * Name: Manojkumar Jaganathan (TheWhiteEvil) * LinkedIn: https://www.linkedin.com/in/manojkumar-j-7ba35b202/ * HackerOne Profile: https://hackerone.com/the-white-evil?type=user * Company: HackerBro Technologies * Their website https://www.hackerbro.net Specific fixes included: 1. Properly escaping operator names in the dropdown filtering box 2. Escaping bot usernames in the Telegram module 3. Escaping operator names in the change owner window 4. Escaping "Alias nick" field in department assignment modals 5. Escaping Facebook page "Name" fields 6. Escaping canned message content in chat window flows New Features 1. Added logging capability for chat priority rules application 2. Added support for passing chat_id and chat_hash parameters 3. Improved UI to show which siteaccess is being used for translated text in widget themes execute doc/update_db/update_329.sql for update
4.59v
Merge pull request #2222 from LiveHelperChat/master-459 1. Fixed an issue where the assigned operator's statistics were not updated if the chat was auto-assigned but handled by another operator. 2. Optimized database indexing for the online operators widget, improving data fetching speed by 40–50%. 3. Browser notifications now display unread messages instead of just indicating the assigned chat. 4. Improved clarity of explanations in mobile settings. 5. Added support for canned messages in the mobile app. 6. Implemented a workaround for a Chrome bug: Chromium issue 414284085. 7. Added the option to display a custom message for connection issues. 8. Fixed an issue where the widget, when set to embed mode with a popup-on-click action, failed to render. This now properly handles misconfigurations. 9. The foreach loop in REST API calls now supports a {skip_empty_msg} option to ignore empty messages. 10. The dropdown search component now aborts previous API calls when a new one is made. 11. Migrated browser confirm dialogs to modal-based dialogs to resolve a Safari issue where confirm and submit actions were not handled correctly. 12. Improved user experience when scrolling to previous messages. 13. Fixed an issue causing double replacements in bot trigger texts. 14. Added an option to crop visitor-uploaded images to a square in file upload settings. 15. Option in chat list search by chat close time. 16. `lh_transfer` table was not cleaned up in some scenarios. 17. Various minor improvements throughout the system. execute doc/update_db/update_327.sql for update
PreviousNext
You can’t perform that action at this time.