=== GetSupportX ===
Contributors: getsupportx
Tags: live chat, help desk, customer support, sso, single sign-on
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.3.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Live chat and one-click customer portal sign-in for GetSupportX. Click Connect — there is nothing to copy or paste.

== Description ==

**GetSupportX** is the official WordPress companion to your [GetSupportX](https://getsupportx.com) support workspace.

Click **Connect**, approve it in GetSupportX, and you're done:

* **Live chat on every page** — your chat bubble, with the colours, greeting and office hours you set in GetSupportX. Survives theme changes and updates.
* **No second password** — customers already logged into WordPress open their tickets in your help portal without signing in again.
* **Know who you're talking to** — when a logged-in customer starts a chat, your agents see their verified name and email instead of "Visitor".
* **WooCommerce details** (optional) — phone, company, lifetime spend and order count, shown to agents next to every conversation.

Settings → GetSupportX shows a live **Status** check, so you can see at a glance that chat and sign-in are working — and exactly what to do if they aren't.

= What this plugin does NOT do =

By design, to keep it small and reliable:

* No Gutenberg blocks — a shortcode and an optional menu link cover it.
* No ticket UI inside wp-admin — agents work in GetSupportX.
* No proxying of GetSupportX APIs.
* No multisite network-admin UI — per-site settings only.

= External service =

This plugin connects your site to GetSupportX (https://getsupportx.com), a hosted customer-support service. It contacts GetSupportX only:

* when an admin clicks **Connect** (to receive this site's configuration),
* when an admin clicks **Disconnect** (to tell GetSupportX this site is no longer connected),
* when an admin opens the settings screen or clicks **Check again** (the status check),
* when a logged-in customer follows the support link (their browser is sent to your GetSupportX portal with a signed, 5-minute sign-in link),
* and through the chat widget script loaded from GetSupportX on your site's pages.

Terms: https://getsupportx.com/legal/terms — Privacy: https://getsupportx.com/legal/privacy

= Updates =

Plugin updates come from TheDevGarden's update server (https://push.thedevgarden.dev). The plugin registers the site there on the first wp-admin visit and checks for updates daily and hourly, sending the site's address and name, its language, active theme, WooCommerce version, web server, PHP memory limit, whether it is a multisite, the plugin, WordPress and PHP versions, and whether auto-updates are on — never users, emails, contacts or content. Update packages are verified against a signed manifest before WordPress installs them. When a new version is pushed, the server may notify the site through its REST API so the update appears (or, if auto-updates are on for GetSupportX, installs) straight away.

== Installation ==

1. Install and activate the plugin. You'll land on **Settings → GetSupportX**.
2. Click **Connect to GetSupportX**.
3. Sign in to GetSupportX if asked, choose your workspace, and click **Connect**.
4. You're sent back to WordPress with everything switched on. The **Status** card confirms it.

Optional: under **Customer portal sign-in**, choose a menu to add a "Support" link to, or use the `[gsx_support_link]` shortcode.

Can't use Connect (for example, your host blocks outgoing requests)? Open **Set up manually instead** and paste the values from GetSupportX.

== Frequently Asked Questions ==

= Do I need to copy anything from GetSupportX? =

No. Connect fetches the widget key, sign-in address and secrets for you, turns portal sign-in on in GetSupportX, and points your portal's "Sign in" button at this site.

= How do customers get to the portal? =

Any of: the menu link (choose a menu in the plugin settings), the `[gsx_support_link text="Support"]` shortcode, or the direct link shown in the settings (`https://your-site.com/?gsx_support=1`). Logged-out visitors are asked to log in to WordPress first, then continue.

= My theme has no menu option in the plugin settings =

Block themes build menus in the Site Editor. Go to Appearance → Editor → Navigation, add a Custom Link, and paste the direct link from the plugin settings.

= Is the secret safe? =

The secrets never reach the front end — not in a script tag, an inline variable, a data attribute or a log. They're used only on your server to sign short-lived (5-minute) links. During Connect they travel server-to-server; your browser only ever sees a single-use code.

= What happens if a secret leaks? =

Regenerate it in GetSupportX → Settings → Portal sign-in, then click **Reconnect** in this plugin. The old secret stops working immediately.

= Will a broken setup lock customers out? =

No. An invalid or expired sign-in link sends the customer to the normal portal login screen, where they can still sign in with email.

= Does this work without WooCommerce? =

Yes. WooCommerce is optional and auto-detected; every WooCommerce call is guarded.

= How do I disconnect? =

Settings → GetSupportX → Disconnect. Chat and portal sign-in stop on this site, and GetSupportX is told to stop sending customers here. If it couldn't be told, the plugin says so — then regenerate the sign-in secret in GetSupportX to be sure.

== Screenshots ==

1. Connect — one click, nothing to paste.
2. Connected — live status check and one switch per feature.

== Changelog ==

= 0.3.3 =
Security release.
* Fix: two WordPress sites connected to the same GetSupportX workspace no longer share customers. Each customer's sign-in is now tied to the site it came from, so user #7 on one site can never open user #7's tickets from another.
* Fix: the chat widget now recognises a logged-in customer by the same site-scoped ID as the portal sign-in, so one customer is never split into two contacts.
* Fix: portal sign-in links can no longer be replayed — every link now carries a one-time ID and this site's address, so GetSupportX can refuse a link it has already seen or one meant for another site.
* Fix: Connect is now protected against a stolen approval code (PKCE). The code in the address bar is useless without a secret that never leaves your server.
* Fix: Disconnect now tells GetSupportX, so your portal stops sending customers to this site. If GetSupportX can't be reached, you're told to rotate the sign-in secret by hand.
* Fix: a cloned or staging copy of your site (a different address, same database) can no longer sign customers in or vouch for them in chat. You'll see a "This site's address changed — reconnect GetSupportX" notice until you reconnect.
* Fix: deleting the plugin now also removes everything on every site of a multisite network, plus the update client's leftover settings and scheduled tasks.
* Fix: the secrets row is kept out of WordPress's autoloaded options.
* Fix: Reconnect keeps your chat, identity and sign-in switches as you left them instead of turning everything back on.
* Fix: the "Support" link now explains when sign-in isn't available instead of silently going to the home page, and the sign-in redirect is never cached.
* Fix: the "Check connection" requests refuse private and internal addresses (except local development hosts).
* Improved: the chat widget loads through WordPress's script API (async), skips the Customizer preview, and can be switched off per page with the `gsx_widget_enabled` filter.
* Improved: clearer connection errors — DNS failure, timeout, secure-connection problem, a GetSupportX outage and an unexpected reply are told apart, and the message names the server actually contacted.

= 0.3.2 =
* Improved: sends basic site details (name, language, theme, WooCommerce and server versions) to the update server, so support can see your setup at a glance — never users, emails or content.

= 0.3.1 =
* New: Updates card in Settings → GetSupportX — see the installed and latest version, check for updates, update in one click, and turn automatic updates on or off.

= 0.3.0 =
* New: automatic updates, signed and verified before install. New versions reach your site at once — and install themselves if auto-updates are on for GetSupportX.

= 0.2.1 =
* Redesigned settings screen in the GetSupportX look: brand logo and typeface, a live product preview, status tiles for chat, sign-in and identity, and an unsaved-changes bar.
* Plain-language connection errors instead of raw server messages.
* Typeface bundled with the plugin (no external font requests).

= 0.2.0 =
* New: one-click **Connect to GetSupportX** — no more pasting keys, URLs or secrets.
* New: recognise logged-in users in chat (verified name and email for agents).
* New: live **Status** check on the settings screen, run automatically.
* New: pick which menu gets the "Support" link (was hard-coded to a menu named "primary", which most themes don't have). Block themes get Site Editor instructions.
* Fix: a browser-saved password can no longer be saved as the sign-in secret — secrets are validated.
* Fix: the connection test no longer creates a "gsx-test" customer in GetSupportX.
* Redesigned settings screen.

= 0.1.0 =
Initial build. Chat widget embed, portal SSO handoff with HMAC-SHA256 signing, Test connection, shortcode + optional nav-menu link, WooCommerce-aware profile data.

== Upgrade Notice ==

= 0.3.3 =
Security release: customers are now tied to the site they signed in from, sign-in links can't be replayed, Connect uses PKCE, Disconnect tells GetSupportX, and a cloned site can't sign customers in. Update recommended.

= 0.3.2 =
Improved: sends basic site details (name, language, theme, WooCommerce and server versions) to the update server, so support can see your setup at a glance — never users, emails or content.

= 0.3.1 =
New: Updates card in Settings → GetSupportX — see the installed and latest version, check for updates, update in one click, and turn automatic updates on or off.

= 0.3.0 =
Adds automatic, verified updates. Install this version once by hand; later versions arrive on their own.

= 0.2.1 =
New GetSupportX-styled settings screen. No setup changes needed.

= 0.2.0 =
Adds one-click Connect. Existing manual setups keep working; click Connect to switch.
