Skip to content

Repository files navigation

Paw Bar

The customer-facing chat bar for sites built on Paw OS. A site owner pastes one script tag into their page. That script mounts a sandboxed iframe, and the chat app runs inside it.

Layout

Path What it is
loader/ The small script a site embeds. It creates the iframe, sizes it, and relays host-page signals. The backend serves the built loader.js at /paw-bar/widget.js.
app/ The Vite + Svelte 5 app inside the iframe (pawbar.js / pawbar.css). It has its own package.json and lockfile.
tests/sandbox/ Playwright tests of the iframe sandbox against the built loader, in Chromium, Firefox and WebKit.

Embed

See loader/README.md for the script tag and its attributes.

Development

Loader, from the repo root:

bun install --frozen-lockfile
bun run build:loader      # loader/dist/loader.js
bun run typecheck:loader
bun run test:loader       # jsdom tests against the built loader
bun run size:loader       # size budget
bun run test:sandbox      # needs build:loader first, plus Playwright browsers

App: see app/README.md. To work on its UI with no backend, see Design without a backend.

CI (.github/workflows/ci.yml) runs all of the above, plus a check that no tracked file has CRLF line endings.

Security

  • The loader sandboxes the iframe and only accepts messages from the frame's own origin and window. See loader/README.md.
  • The app renders agent-written markdown as a parsed tree with text bindings, never as an HTML string. See the security note in app/README.md.
  • The server enforces the origin allowlist and rate limits. The client is a renderer, not a security boundary.

License

See LICENSE.

About

Embeddable customer-facing widget for Paw OS pockets — vanilla JS, under 10KB gzipped.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages