When your site has accounts, the chat can know who asked: the Stats and the History then show the visitor’s email instead of Anonymous.
On the pages of a visitor who is signed in to your site, add the email and its signature to the script tag of the chat:
<script src="/opensolr-chat/widget.js" data-ident="visitor@example.com" data-ident-sig="SIGNATURE" defer></script>
For a visitor who is not signed in, leave both attributes out: the tag stays as it was.
The package writes both attributes for you, already escaped, and nothing for a visitor who is not signed in. $email is the email of the signed-in visitor, or an empty string:
<script src="/opensolr-chat/widget.js"<?= \Opensolr\ChatBot\Identity::attributes('/opt/opensolr-chat', $email) ?> defer></script>The first argument is the data_dir of your front controller. The Add to your pages tab of the admin shows this line with your own data folder, ready to copy.
The signature is HMAC-SHA256 of the email in lower case, with the identity key shown in the Add to your pages tab, written in hex. For example, in Python:
import hmac, hashlib signature = hmac.new(IDENTITY_KEY.encode(), email.strip().lower().encode(), hashlib.sha256).hexdigest()
Keep the identity key on your server, in your configuration, never in a page.
- A visitor counts as signed in only when the signature is right for that email. No signature, or a wrong one, is an anonymous visitor: nobody can make the chat believe they are somebody else.
- The email is kept in lower case, so
Ana@Example.comandana@example.comare the same visitor. - A conversation that starts anonymous and goes on after the visitor signs in takes the email.
The chat on this site does exactly this: signed-in users of the Opensolr control panel are shown by their email in its History.