Skip to content

WordPress ​

The chat is one script tag in the site's footer. Pick whichever way you already add code to your site.

A header and footer plugin ​

If you use a plugin for code snippets (most sites have one), add this to the footer for the whole site:

html
<script src="https://chat.example.com/widget.js" data-bot="pk_your_bot_id" async></script>

Without a plugin ​

Add this to your (child) theme's functions.php:

php
add_action('wp_footer', function () {
    echo '<script src="https://chat.example.com/widget.js" data-bot="pk_your_bot_id" async></script>';
});

Signed-in users ​

To pass the signed-in WordPress user with identity verification, define the bot's identity secret in wp-config.php (define('WIREFACE_IDENTITY_SECRET', 'wfs_...');) and print the settings with the hash:

php
add_action('wp_footer', function () {
    $settings = ['bot' => 'pk_your_bot_id'];
    if (is_user_logged_in()) {
        $user = wp_get_current_user();
        $id = (string) $user->ID;
        $settings['user'] = [
            'id' => $id,
            'hash' => hash_hmac('sha256', $id, WIREFACE_IDENTITY_SECRET),
            'name' => $user->display_name,
            'email' => $user->user_email,
        ];
    }
    echo '<script>window.wirefaceChatSettings = ' . wp_json_encode($settings, JSON_HEX_TAG | JSON_HEX_AMP) . ';</script>';
    echo '<script src="https://chat.example.com/widget.js" async></script>';
});

JSON_HEX_TAG keeps a name like </script> from breaking out of the tag.

Notes ​

  • Add your site's address (and any staging address) to the bot's allowed origins.
  • A page cache that served signed-in pages would hand one user's identity to another. Caching plugins normally skip signed-in users; make sure yours does.
  • Security plugins that send a Content-Security-Policy need the chat host added: see Content-Security-Policy.
  • On sign-out, WordPress reloads the page; the server then starts a fresh visitor for the anonymous page, so the next person doesn't see the previous user's chat.

Wireface Chat 0.1.0. These docs are served by your own server.