The admin

One page on your own site, behind a password, with every setting of the chat in seven tabs.

The admin is a page of the chat itself, on your own site: https://your-site/opensolr-chat/admin. Every setting of the chat is there, and nothing about it lives anywhere else.

01 · Before the first sign-in

Until an admin password is set, the admin does not open. It shows the command to run instead:

php vendor/bin/opensolr-chat-bot password <data_dir>

<data_dir> is the data_dir of your front controller. Run it in your project folder as the user PHP runs as, as on Installing, then reload the page.

02 · The captcha before the admin

Once both reCAPTCHA keys are saved on the Captcha tab, the admin asks you to confirm that you are a person before any of its pages opens, and the sign-in form asks again. A solved captcha is remembered in that browser for the hours set on the same tab, 240 by default.

Before the keys are saved, the sign-in form has no captcha.

03 · Signing in and out
  • The password is the one you set with the command. Spaces before or after a pasted password are ignored.
  • Wrong passwords. After five wrong passwords from the same IP address within 15 minutes, signing in is refused until those 15 minutes have passed: Too many failed sign-ins. Please try again in 15 minutes.
  • A session lasts until you click Sign out, or until it has gone unused for two hours. Signing in from another browser does not sign the first one out.
  • An expired form. The form expired. Please try again. means the page was loaded before you last signed in, or the browser dropped the admin’s cookies. Reload the page and try again.
04 · The tabs
TabWhat you set there
AccountYour Opensolr email and API key, Test connection, and the index the chat answers from
AssistantYour own instructions for the assistant, and its time zone
Chat windowThe title, the text of the chat button, the greeting, the placeholder, your logo and the accent colour
LimitsCharacters per message and per text to translate, questions per visitor, questions per conversation
CaptchaThe reCAPTCHA v2 keys, and how many hours a solved captcha lasts
LanguageThe language of the admin
Add to your pagesThe script tag to paste into your pages

All the tabs are one form: Save settings at the bottom saves every tab at once, and you stay on the tab you were on. The button is not shown on Add to your pages, which has nothing to save. When something cannot be saved, the admin lists what is wrong at the top and keeps what you typed, except the two secret keys.

05 · Changing the admin password

Run the same command again, with the same data folder:

cd /var/www/your-site
sudo -u www-data php vendor/bin/opensolr-chat-bot password /opt/opensolr-chat

The new password replaces the old one, and every admin session, in every browser, is signed out. There is no password field in the admin and no reset by email: the admin password can only be set on the server, by someone who can run commands as the user PHP runs as.

06 · What else protects it
  • Your API key and your reCAPTCHA secret key are never shown back once saved: their field shows dots and, for a long key, its last four characters. Leave the field empty to keep the saved one.
  • Every form of the admin carries a token of your session, and a form sent from another site is refused.
  • The admin cannot be shown inside a frame of another site, and asks search engines not to index it.

The Opensolr Chat Bot Client is open source and MIT licensed. Questions about your Opensolr account, index or plan go to opensolr.com/contact; questions about the client itself belong on GitHub.

Opensolr Chat Bot Documentation