Appearance
WordPress
The chat is one script tag in the site's footer. Pick whichever way you already add code to your site.
A header and footer plugin
If you use a plugin for code snippets (most sites have one), add this to the footer for the whole site:
html
<script src="https://chat.example.com/widget.js" data-bot="pk_your_bot_id" async></script>Without a plugin
Add this to your (child) theme's functions.php:
php
add_action('wp_footer', function () {
echo '<script src="https://chat.example.com/widget.js" data-bot="pk_your_bot_id" async></script>';
});Signed-in users
To pass the signed-in WordPress user with identity verification, define the bot's identity secret in wp-config.php (define('WIREFACE_IDENTITY_SECRET', 'wfs_...');) and print the settings with the hash:
php
add_action('wp_footer', function () {
$settings = ['bot' => 'pk_your_bot_id'];
if (is_user_logged_in()) {
$user = wp_get_current_user();
$id = (string) $user->ID;
$settings['user'] = [
'id' => $id,
'hash' => hash_hmac('sha256', $id, WIREFACE_IDENTITY_SECRET),
'name' => $user->display_name,
'email' => $user->user_email,
];
}
echo '<script>window.wirefaceChatSettings = ' . wp_json_encode($settings, JSON_HEX_TAG | JSON_HEX_AMP) . ';</script>';
echo '<script src="https://chat.example.com/widget.js" async></script>';
});JSON_HEX_TAG keeps a name like </script> from breaking out of the tag.
Notes
- Add your site's address (and any staging address) to the bot's allowed origins.
- A page cache that served signed-in pages would hand one user's identity to another. Caching plugins normally skip signed-in users; make sure yours does.
- Security plugins that send a Content-Security-Policy need the chat host added: see Content-Security-Policy.
- On sign-out, WordPress reloads the page; the server then starts a fresh visitor for the anonymous page, so the next person doesn't see the previous user's chat.