3.72v Security update and other changes

Last modification: 2021-06-15 11:52:35

Hi,

This update includes fix for possible XSS vulnerability. I advise everyone to update. My clients whom I look after already were updates.

  • Security fix for https://huntr.dev/bounties/1-LiveHelperChat/livehelperchat/
  • You can change sound option per invitation now. (Play sound or not)
  • Fixes for webhooks conditions being parsed incorrectly.
  • Now you can change order of start chat fields including custom fields you define in start chat form.
  • You can set titles for standard fields in widget theme now.
  • Now you can trigger offline form manually from website https://doc.livehelperchat.com/docs/javascript-arguments#open-offline-form-while-keeping-option-to-start-a-chat-normally
  • You can set default sound setting in widget theme. (Play sound for new messages or not)
  • Offline message will support BBCode now.
  • Rest API call will support now also x-www-form-urlencoded request type.
  • !block command did not worked.
  • Chat lists has direct option to filter abandoned chats https://doc.livehelperchat.com/docs/chat/statistic/#performance
  • Send message did not set nick if previous chat was not found. (Empty nick scenario)
  • Now you can login to back office using e-mail also.
  • If operator is not looking at online visitors widget we will not load it's content. Performance improvement.
  • New widget dropdown was missing click action support.
  • Users dropdown filter is now AJAX based and will filter directly.
  • NodeJS extension now support option to track online visitors live status or not.
  • Setting subject in the chat will sort subjects by their names.
  • Bot Execute JS will support replaceable variables also.
  • foreach cycle support in bot response https://doc.livehelperchat.com/docs/bot/bot-text/#foreach-cycle
  • Bot buttons will support translations also.
  • If visitor has closed chat there will be button invite support in chat messages.
  • Different color for a system message if visitor has left a chat.

For update just follow standard update procedure There is no database update this time.