The admin is a page of the chat itself, on your own site: https://your-site/opensolr-chat/admin. Every setting of the chat is there, and nothing about it lives anywhere else.
Until an admin password is set, the admin does not open. It shows the command to run instead:
php vendor/bin/opensolr-chat-bot password <data_dir>
<data_dir> is the data_dir of your front controller. Run it in your project folder as the user PHP runs as, as on Installing, then reload the page.
Once both reCAPTCHA keys are saved on the Captcha tab, the admin asks you to confirm that you are a person before any of its pages opens, and the sign-in form asks again. A solved captcha is remembered in that browser for the hours set on the same tab, 240 by default.
Before the keys are saved, the sign-in form has no captcha.
- The password is the one you set with the command. Spaces before or after a pasted password are ignored.
- Wrong passwords. After five wrong passwords from the same IP address within 15 minutes, signing in is refused until those 15 minutes have passed: Too many failed sign-ins. Please try again in 15 minutes.
- A session lasts until you click Sign out, or until it has gone unused for two hours. Signing in from another browser does not sign the first one out.
- An expired form. The form expired. Please try again. means the page was loaded before you last signed in, or the browser dropped the admin’s cookies. Reload the page and try again.
| Tab | What you set there |
|---|---|
| Account | Your Opensolr email and API key, Test connection, and the index the chat answers from |
| Assistant | Your own instructions for the assistant, and its time zone |
| Chat window | The title, the text of the chat button, the greeting, the placeholder, your logo and the accent colour |
| Limits | Characters per message and per text to translate, questions per visitor, questions per conversation |
| Captcha | The reCAPTCHA v2 keys, and how many hours a solved captcha lasts |
| Language | The language of the admin |
| Add to your pages | The script tag to paste into your pages |
All the tabs are one form: Save settings at the bottom saves every tab at once, and you stay on the tab you were on. The button is not shown on Add to your pages, which has nothing to save. When something cannot be saved, the admin lists what is wrong at the top and keeps what you typed, except the two secret keys.
Run the same command again, with the same data folder:
cd /var/www/your-site sudo -u www-data php vendor/bin/opensolr-chat-bot password /opt/opensolr-chat
The new password replaces the old one, and every admin session, in every browser, is signed out. There is no password field in the admin and no reset by email: the admin password can only be set on the server, by someone who can run commands as the user PHP runs as.
- Your API key and your reCAPTCHA secret key are never shown back once saved: their field shows dots and, for a long key, its last four characters. Leave the field empty to keep the saved one.
- Every form of the admin carries a token of your session, and a form sent from another site is refused.
- The admin cannot be shown inside a frame of another site, and asks search engines not to index it.