stop polling approval requests for anonymous visitors - #70
Open
OsamaHaikal wants to merge 1 commit into
Open
OsamaHaikal wants to merge 1 commit into
OsamaHaikal wants to merge 1 commit into
Conversation
The widget polled the approvals endpoint every 1.5s for every visitor and was refused each time unless the user was signed in with connection access.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ElicitationFormpolledGET /widget/v5/connections/elicitation/:sessionevery 1.5 s for every active chat. The backend refuses anyone without a signed-in token carrying connection access, so anonymous embeds produced a steady stream of 401s (seen on the docs site on prod today).Poll only when
config.user.tokenis set; the explicitcapabilities.connections: falseopt-out still applies.🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎🦎
Greptile Summary
This PR prevents
ElicitationFormfrom polling connection approval requests unless the widget has a signed-in user token, while preserving the explicit connections capability opt-out.Confidence Score: 5/5
Risk level: Low; the PR appears safe to merge because it only suppresses unauthorized anonymous polling and preserves signed-in polling.
The authentication guard matches the stated backend access contract, sign-in transitions remain reactive, token renewal continues using current credentials, and the focused tests cover the changed decision branches.
Reviews (1): Last reviewed commit: "stop polling approval requests for anony..." | Re-trigger Greptile