12 September 2026 — V1.9.0
- New:
- WhatsApp website widget: the embed script is now also served at an extensionless URL (/widgets/whatsapp/{key}), so it keeps working on hosts whose web server treats every
.js path as a static file and never passes it to the app (nginx “location ~ \.js$” rules, some CDN/cache layers). The .js URL remains the canonical one.
– The widget embed snippet is now generated on the server, so installs served from a sub-directory (e.g.
https://example.com/public/) get a script URL that carries the right base path — the copy button, card preview and “direct JS link” all use it.
– Widget greeting card supports multi-line messages and closes on Escape or a click outside; the script can now be placed in <head> with async — it waits for the document to be ready before touching the page.
- Improvements & Fixes:
– Fixed Instagram and Messenger inbound messages silently going missing for some contacts. Meta’s signed CDN profile-picture URLs run 600–900+ characters while the contact avatar column was capped at 512, so the webhook failed with “Data too long for column ‘avatar’” before the message was stored — the contact appeared, the conversation never did. The column is now TEXT (migration included — run php artisan migrate after updating).
– Widget script hardened: every value that comes from the database (greeting, agent name, colours, allowed domains) is JSON-encoded and HTML-escaped, so quotes, newlines, </script> or emoji can no longer break the script or inject markup into your customer’s page, and the output is pure ASCII.
– Widget phone number is normalised to digits for wa.me (a ”+”, spaces or dashes used to produce a dead link), the pre-filled text is only appended when set, allowed domains are matched on the bare host (scheme,
www., port and path are stripped), colour values are validated, the agent-name initial is multibyte-safe, and script errors are caught and logged instead of breaking the host page.
– New feature tests for the WhatsApp widget embed (both URLs, sub-directory base path, JavaScript validity, domain whitelist) and for Instagram inbound messages with long avatar URLs.
– Performance and stability improvements.
Decryption Key: