Channel security
For Admins

Channel security

How SupportHub hides channel passwords and tokens, checks incoming webhooks and limits where the widget can be used from.

Passwords and tokens in settings

  • Channel fields holding passwords, secrets and tokens (the bot token, IMAP and SMTP passwords and others) reach the interface masked as “••••••••”. The owner and admins see the mask; regular operators don't get these fields at all.
  • Saving a channel with the mask or an empty field keeps the stored value. To change a password or token, type the new one.

Checking incoming webhooks

  • Telegram: when you connect a bot, SupportHub generates a random secret and hands it to Telegram. Telegram sends it back in the X-Telegram-Bot-Api-Secret-Token header, and requests without the right secret are ignored. Nothing to set up.
  • VK: the channel takes the Confirmation string from the community's Callback API settings and a Secret key — any string, which you also enter in VK. With a key set, requests carrying a different key are ignored, so don't leave it empty.
  • BILLmanager: the module and the API connection use their own keys — see the BILLmanager integration.

Widget

  • Allowed domains in the widget builder (the Privacy section) — one domain per line, without http(s):// or a port; *.example.com allows subdomains. Once the list is filled in, messages from other sites are refused. An empty list lets the widget work on any site.
  • To stop a visitor from posing as another customer, pass a signed visitor token to the widget — see HMAC visitor token.
  • Request rates are capped per visitor: sending messages at 10 a minute, file uploads and identification at 20 each, ticket replies at 30.

Outgoing requests

  • Notification webhooks are signed with HMAC-SHA256 in the X-SupportHub-Signature header — see the notification system. API webhooks have their own signature — see Webhooks.
  • Requests to Telegram, VK, mail servers and BILLmanager can go through a proxy.
Never share channel tokens and passwords. If a token may have leaked, issue a new one where it was created (BotFather for Telegram, the VK community settings, your mail server for IMAP and SMTP) and save it in the channel.
Was this page helpful?