Operations / Security boundary
Chat UI Web Server Configuration
Manage authentication, embedding, and operational settings for the chat. Sign in once (SSO or admin token) - the session applies across every admin page for 30 minutes.
Resolution Explainer
Which surface this admin request (this browser, right now) resolved to, and why. The same algorithm gates every chat turn - reload this page from a different host/origin to see it change.
- Resolved surface
- -
- Resolved via
- -
- Auth mode
- -
- Reason (if unresolved)
- -
Identity Bypass - master switch
Kill-switch for every surface's bypass at once. Turn OFF here to instantly stop all impersonation, regardless of what any individual surface tab has configured.
Master enable (all surfaces)
When OFF, no surface's identity bypass can be active even if individually enabled. Independent of the per-environment hard guard (bypass is always refused in prod).
Surface Fallback
What to resolve to when a request's Host doesn't match any surface's hosts[] and no Origin was sent. Refused in production regardless of this setting.
Enable fallback surface
Effective CORS allow-list (read-only)
Union of every enabled surface's allowedOrigins plus the legacy flat list below - this is what the CORS middleware actually honours. Edit origins per-surface in the surface tabs.
Allowed Parent Origins (legacy)
Which Salesforce hosts (LWC / Experience Cloud) are allowed to embed this chat in an iframe and post identity tokens to it. Predates per-surface origins - still unioned into the effective CORS allow-list above, but new origins should be added on the Salesforce tab instead.
https://host.example.com - no path, no query, no trailing slash. Wildcards are rejected because *.my.site.com would match any Salesforce org.
Admin Console Access
Who can sign into /admin pages and how. The legacy admin token always works as a fallback; enabling SSO below lets internal employees sign in through the same ConnectWise STS used by the partner-facing widgets, gated by the allow-list.
Enable SSO sign-in
Shows a "Sign in with ConnectWise" button on the admin login gate. Requires the STS app registration fields below to be filled in.
ADMIN_AUTH_CLIENT_SECRET secret, same convention as cwHomeAuth/platformAuth.
Identity Bypass
Lets a browser open the chat without a real Salesforce identity token, by accepting the built-in sentinel string local-dev at POST /api/session/exchange. Local dev uses this permanently. Production uses it only for short, tracked smoke tests before the Salesforce LWC integration is wired up.
Enable identity bypass
What this enables - share with developers
// The browser sends this automatically. No user action, no token to type in.
POST /api/session/exchange
Content-Type: application/json
{ "token": "local-dev" }
// Server responds with the Simulated Identity below while the bypass is ON and unexpired:
200 OK
{
"identity": { "first_name": "Local", "last_name": "Dev", "email": "local-dev@example.com", "partner_id": "local-dev-partner" },
"entity": { "isBypassSession": true, "type": null, "id": null }
}
// Any other token, or bypass OFF/expired, gets refused:
501 Not Implemented
{ "error": "Token validation not implemented yet" }
app_config_audit with the admin user and request id on every change.
/api/session/exchange returns while the bypass is active. Partner ID becomes the AgentCore actorId once the partner-context cookie is implemented - keep it stable so local memory/history stays consistent across restarts.
The synthetic identity looks real to every downstream system (chat DB, AgentCore memory, MCP tools). Bypass chats are flagged with is_bypass_session = true and can be deleted after the test with DELETE FROM support_ai.chat WHERE is_bypass_session = true;. Keep production bypass windows in the minutes-to-hours range, never days.
Salesforce JWT Verification
Real (non-bypass) login path for POST /api/session/exchange. Verifies the Apex-signed identity token from the Salesforce community page and maps its claims to the same identity shape the bypass path returns.
Enable Salesforce token verification
Master kill-switch. Leave OFF until the algorithm, key, and issuer below are confirmed correct for this environment.
.env locally or AWS Secrets Manager per environment, never in this database row.
aud yet.
Verification key reference, so you can test signed tokens without editing .env. Ignored whenever identity bypass is OFF (i.e. never used in a real environment).
Every field in the decoded token (partner_id, email, account_id, etc.) is passed straight to the chat session. Only enable this once the verification key and issuer are confirmed correct - a misconfigured key here would accept forged tokens.
Partner Context Cookie
Config for the signed, stateless cookie that will carry partner identity (actorId) across chat turns after the initial Salesforce handoff. Not wired to any code path yet - these values are already read from the config store, but no signing/verification code exists in server.js until that work ships.
Enable partner-context cookie
Master kill-switch. Leave OFF until the cookie-signing/verification code is implemented and verified for this environment.
/api/session/exchange.
.env locally or AWS Secrets Manager per environment, never in this database row.
Log Storage
Upload completed rotated log files to a private S3 prefix. The ECS task role must have s3:PutObject permission for this destination.
Enable S3 log storage
Applies outside local mode. Files are uploaded after rotation, under a category subfolder.