Advice regarding using Sub Resource Integrity (SRI) checking

Dear Community

Has anyone implemented SRI checking for their webchat implementation and any advice on how the implementation was done please?

Particularly is there advice on how versioning of the Web Chat API can be managed i.e. does / can the SRI be broken because their has been a change in the API?

Thanks and regards
Blair Wilkinson

Unfortunately, the jsapi file isn't semantically versioned, so SRI checking on the file won't provide a reliable result. You can request improvements to the versioning scheme at https://purecloud.ideas.aha.io/ideas.

Hello Tim, thank you for the response. We have a customer who would like to use Web Chat in a scenario where there may be sensitive information included such as account and credit card details. Are there any security features or recommendations for Web Chat that we can investigate further please? For example, any method to hash out sensitive data from being stored or techniques to secure the chat etc? Thanks and regards, Blair Wilkinson.

PS. Please can I also confirm that all recorded interactions including voice, chat, email, messages and social are encrypted at rest?

There isn't currently a feature to mask PHI in chats, though some basic functionality is planned for a future release. You can make the request and share your use case on the Ideas Lab linked above.

For security concerns relating to PureCloud, please open a case with PureCloud Care.

This topic was automatically closed 31 days after the last reply. New replies are no longer allowed.