Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - iadvize/boxed-tag · GitHub
Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - iadvize/boxed-tag · GitHub
Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - iadvize/boxed-tag · GitHub
Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - iadvize/boxed-tag · GitHub
Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - iadvize/boxed-tag · GitHub
Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - iadvize/boxed-tag · GitHub
Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - iadvize/boxed-tag · GitHub
Skip to content

Repository files navigation

Boxed tag

The “iAdvize Boxed Tag” is a way to include the iAdvize Tag in the most secure way, without it having access to the client’s website.

With this solution, the iAdvize tag can be loaded in an isolated box (a sandboxed iframe). This way, the main page context cannot be accessed by the iAdvize tag: the main page only sends controlled, relevant data to the boxed tag.

Simple installation

This is the simplest way too add the iAdvize Boxed Tag to a website with the default configuration.

1 - Serve this HTML file

Serve a HTML file. We will use the name iadvize-boxed-iframe.html, but any name can be chosen. This file needs to be served on the same top domain as the page it will be included in. Replace <your-sid> with your own sid.

Ex :

<!DOCTYPE html><html><body><scriptsrc="https://static.iadvize.com/boxed-tag/1.4.4/index.js" integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==" crossorigin="anonymous"></script><script>window.iAdvizeBoxedTag.initIAdvizeIframe(<your-sid>, "halc");
</script></body></html>

2 - Add the following script

Add the following script (in your frontend code, or in your tag manager), replacing https://static.brand-domain.com/iadvize-boxed-iframe.html with the actual URL of the iframe :

// Change this URL with the actual URL of the iframeconstiAdvizeIframeUrl="https://static.brand-domain.com/iadvize-boxed-iframe.html";conststyle=document.createElement("style");style.innerHTML=` #iAdvizeSandboxedIframe { border: none; position: fixed; bottom: 0; right: 0; width: 100vw; height: 100vh; pointer-events: none; z-index: 2147483647; }`;document.body.append(style);constboxedTagScript=document.createElement("script");boxedTagScript.src="https://static.iadvize.com/boxed-tag/1.4.4/index.js";boxedTagScript.integrity="sha512-NS7M2FyNHaefJ42ilas6W+t/qJleeGTWIyhM2pj2Pn+t7PgWRH/HarBqV8HT+RFDi6JVS1ReAeF2Afz5dwpBjQ==";boxedTagScript.crossOrigin="anonymous";constiAdvizeSandboxedIframe=document.createElement("iframe");iAdvizeSandboxedIframe.sandbox="allow-scripts allow-same-origin allow-popups allow-forms";iAdvizeSandboxedIframe.allow="camera;microphone;autoplay";iAdvizeSandboxedIframe.src=iAdvizeIframeUrl;iAdvizeSandboxedIframe.id="iAdvizeSandboxedIframe";document.body.append(iAdvizeSandboxedIframe);boxedTagScript.onload=function(){window.iAdvizeBoxedTag.initIAdvizeHost("iAdvizeSandboxedIframe");};document.body.append(boxedTagScript);

Advanced installation

This is a more advanced installation, allowing :

Install the lib on your project

npm install @iadvize-oss/boxed-tag

Create the iframe script

Create a js file that will import the iframe script. Then call initIAdvizeIframe to listen the host messages. The initIAdvizeIframe comes with 2 arguments :

  • sid : your iAdvize sid.
  • iAdvizePlatform : the iadvize platform (default: ha).
import{initIAdvizeIframe}from'@iadvize-oss/boxed-tag';initIAdvizeIframe(<sid>, <iAdvizePlatform>);

Add a boxed iframe

Add a boxed iframe on your site's main page.

<iframetitle="iAdvize chat notification frame"
sandbox="allow-scripts allow-same-origin allow-popups allow-forms"
allow="camera;microphone;autoplay"
src="https://my-iframe-script-url"
id="myIframeId"
></iframe>

The iframe is set with the following sandbox parameters:

sandbox paramdescription
allow-scriptsAllows the page to run iAdvize tag script.
allow-same-originAllows the iAdvize tag to access the host cookies and storages
allow-popupsAllows the iAdvize tag to open links sent by the agent
allow-formsAllows the iAdvize tag to submit the visitor email if needed

And the following allow parameters:

allow paramdescription
cameraAllows the boxed tag to ask the camera permission (for video calls)
microphoneAllows the boxed tag to ask the microphone permission (for video calls)
autoplayAllows the boxed tag to launch the video stream automatically

Add the host script on your site's main page

Create a js file with the host lib import, then call initIAdvizeHost to listen to the iframe messages.

import{initIAdvizeHost}from'@iadvize-oss/boxed-tag';initIAdvizeHost('myIframeId');

Communication

The only way to start a communication between the host and the sandboxed iframe is the window.postMessage method provided by the navigators (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage).

warning The postMessage data is serialized, so functions cannot be sent (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#parameters).

Then, the target of the postMessage calls can listen to the events using window.addEventListener('message').

warning The source of the event should be checked to avoid conflicts and security concerns (see https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage#security_concerns).

Call iAdvize WebSDK methods from host

WebSDK methods cannot be called from the host context because the iAdvize tag is isolated in the iframe : we need to communicate to the iframe what we want to call.

After having called initIAdvizeHost, a iAdvizeBoxedInterface object is available in the host window context.
This object sends the method name and args to the iframe, that will call the webSDK. The activate, get and on methods can return a value to the host :
to retrieve it, add a window.addEventListener("message") and check the e.data.method property to recognize the method called.

Navigate

// WebSDK navigatewindow.iAdvizeBoxedInterface.push({method: 'navigate',args: [window.location.href],});

Activate

The host can listen to the result of the activate call.

For an anonymous authentication:

// WebSDK activate anonymouswindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'ANONYMOUS'},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{if(method==='activate'){console.log(activation);// activation return object : success or failure}});

For a secured authentication, the JWE token should be generated on the host side and sent to the iframe :

  • the host should listen a get-activate-auth-token message initiated by the iframe.
  • the backend api then gets the JWE token,
  • the token is then sent to the iframe inside a set-activate-auth-token message.

The get-activate-auth-token listener allows the iframe to ask for a token refresh if needed.

Example of secured authentication implementation:

// WebSDK activate secured authconstgetJweToken=Promise.resolve('myJWEToken');// your backend logic to generate a JWEwindow.iAdvizeBoxedInterface.push({method: 'activate',args: {authenticationOption: {type: 'SECURED_AUTHENTICATION',},},});// Listen to activate resultwindow.addEventListener('message',({data: { method, activation }})=>{// Handle authentication tokenif(method==='get-activate-auth-token'){getJweToken().then((token)=>window.iAdvizeBoxedInterface.push({method: 'set-activate-auth-token',args: `${token}`,}),);}if(method==='activate'){console.log(activation);// activation return object : success or failure}});

Logout

The host can listen to the result of the logout call.

Example of implementation:

// WebSDK logoutwindow.iAdvizeBoxedInterface.push({method: 'logout',});// Listen to logoutwindow.addEventListener('message',({data: { method }})=>{if(method==='logout'){// Do something after logout}});

On

The host can listen to the result of the on call.

Example of implementation:

// WebSDK onwindow.iAdvizeBoxedInterface.push({method: 'on',args: ['visitor:cookiesConsentChanged'],});// Listen to cookiesConsentChanged resultwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='on'&&args.includes('visitor:cookiesConsentChanged')){console.log(value);// cookiesConsentChanged value}});

Off

// WebSDK offwindow.iAdvizeBoxedInterface.push({method: 'off',args: ['visitor:cookiesConsentChanged'],});

Set

// WebSDK setwindow.iAdvizeBoxedInterface.push({method: 'set',args: ['visitor:GDPRConsent',true],});

Get

The host can listen to the result of the get call.

Example of implementation:

// WebSDK getwindow.iAdvizeBoxedInterface.push({method: 'get',args: ['visitor:cookiesConsent'],});// Listen to cookiesConsent getwindow.addEventListener('message',({data: { method, args, value }})=>{if(method==='get'&&args.includes('visitor:cookiesConsent')){console.log(value);// cookiesConsent value}});

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

10 watching

Forks

Releases

Packages

Used by

Contributors

Languages