Status: unreleased experimental prototype. Not available for merchant or public use.
This repository contains an incomplete plugin implementation. The version in
package.json is a development version, not a claim of release readiness.
private: true prevents accidental npm publication while the plugin is incomplete.
There is no supported installation or embed snippet yet.
The built-in widget supplied by some Escalated backends is a separate feature. Its availability and security guarantees must be checked for the selected backend.
frontend/index.jspoints to a JavaScript module that is not shipped.- The advertised
widget.jsbundle andWebWidgetConfiguratorcomponent are absent. allowed_originsis read from settings but is not enforced. It provides no CORS protection in this prototype.- The public endpoint, raw request/response and ticket-creation contracts need integration with the plugin bridge. Declared handlers are not working public APIs.
- The current rate limiter uses non-atomic storage and untrusted forwarded IP headers. A public embed key does not authenticate a recipient.
- Tenant routing, verified recipient access and end-to-end browser tests are missing.
The branding, custom fields, endpoints and configurator declared in source describe work in progress. They are not supported features.
Before removing the unreleased status:
- Ship and test the packed frontend, configurator and embeddable script.
- Enforce an explicit Origin allowlist and preflight policy at the public boundary.
- Add trusted, atomic rate limiting and server-side validation of every submission.
- Create tickets through the authorized, tenant-aware backend service and verify recipient identity before granting access to correspondence.
- Exercise the published artifact from a different browser origin, including denied origins, expired access, retries and disabled-widget behavior.
- Document the supported backend and SDK/runtime versions, then publish a release.
MIT - Copyright (c) Escalated.dev. See LICENSE.