Signed-in Visitors
When your site has accounts, the Stats and the History can show the email of a signed-in visitor instead of Anonymous.
- On the pages of a signed-in visitor, your site adds two attributes to the embed line: the visitor's email and its signature.
- The signature is HMAC-SHA256 of the email in lower case, made with the identity key shown on the Signed-in visitors tab, written in hex.
- The tab also shows the signature expected for visitor@example.com, to check your code.
<script src="https://opensolr.com/chatbot/YOUR_CHAT_ID/widget.js" data-ident="EMAIL" data-ident-sig="SIGNATURE" defer></script>
Make the signature on your server and keep the key there, never in a page. Without a valid signature the visitor is anonymous, so nobody can pass for somebody else. Code in several languages: Signed-in visitors.