Callus.js script needs hosting by 3CX

Status
Not open for further replies.

ochapple

New User
Basic Certified
Joined
Dec 19, 2019
Messages
48
Reaction score
10
Dear 3CX team,
Quite a few Website companies like Webdadi, use Google Tag Manager to install 3rd party code snippets - embed javascripts for plugins like yours to integrate smoothly and also run so that core libraries and code like your callus.js file are all called asynchronously, so that they don't either slow down the page load times, and consequent PageSpeed stats, and secondly by using Google Tag Manager the web company and customer can do beta and user acceptance testing, not only but also we don't have to worry about a customer uploading JS files to a server that could potentially break the website. Examples of a company who's CSS script does break Websites include Calendly as their CSS file can break websites, fortunately, you can avoid this as their script will install via GTM.

The 3CX messenger JS Main script callus.js, not the embed snippet, is too large to install via Google Tag Manager and normally these scripts would be pulled asynchronously from a CDN not from our server or the customer's server. For instance, the Landbot Chatbot is pulled via their site <script src="https://static.landbot.io/landbot-3/landbot-3.0.0.js"></script> This is what we need for your callus.js script.

Would you consider hosting your callus.js script either at 3cx.com or via a direct CDN and enable all the config to work via your code snippet that's fine as is, and that can all be installed via GTM? Until this is done we won't be able to add you to our Plugin Store.

Kind regards,
Oliver @ Webdadi
 
I use the Live Chat plugin, and it does not slow my site down at all, you just have to know how to load scripts and use caching

Screenshot 2020-12-03 115804.jpg
 
  • Like
Reactions: N_G and Evolute IT
Hi @ochapple ,

Frameworks or large scripts such as the callus file shouldn't be embedded in the GTM but loaded externally instead.

To avoid having the script affect the load time of your site, you should add the defer (or async) attribute in the script tag. This will allow the script to be downloaded asynchronously and the HTML/DOM to be parsed and rendered before executing it.
 
HI guys,
I'm not saying the file is slowing down the Websites, if you refer to my post I'm actually saying I can and would run it as an async to prevent that happening. What I am saying is that we install 3rd party scripts all the time and do it via GTM. The point of my post is that the callus script is obviously too large to be inside a GTM tag, and you are quite right you don't want to load a script as big as callus into a tag.

Instead what I'd like is the callus script itself hosted by 3CX or some other CDN so we can load it via GTM and using an async script tag. We use GTM for many reasons not least that it's the most secure way for our customers to upload scripts and test them before running publishing them Live,but also because GTM prevents xss (cross-site scripting) attacks and here is the best part - You don't need a developer to do it who is expensive and where there can be a delay in scheduling it; using GTM entirely bypasses the development team and that cost.

For this reason we recommend that the callus script is hosted and NOT 'uploaded' onto customer servers, so that the script can be easily installed, and efficiently, via an async or defer script tag call, once the DOM has loaded which can all be done smartly and securely via a GTM on DOM loaded Trigger. We won't enable any third-party script that cannot be installed via GTM.

The point of is, if it really is that simple a plugin to install, then it should be installable through GTM by a marketeer and not a techie, and if it can't be, then it's not that simple, nor can it be done immediately by SME's without a dev department.
 
Last edited:
Hi @ochapple ,
Instead what I'd like is the callus script itself hosted by 3CX or some other CDN so we can load it via GTM and using an async script tag.

I understand what you are saying however I am not sure what is preventing you from using GTM for asynchronously loading files hosted on your customer's server :) CDN has its benefits of course but its not mandatory having one to do this.

Regarding security, unless you are using CSP with a very very strict configuration (which nowadays is almost impossible to have), then you are exposed to various vulnerabilities (including XSS) either you are using GTM or not.
 
  • Love
Reactions: StefanW
Hi Stefan, we categorically won't let customers upload js files to our servers. Not least as js scripts and css scripts can conflict. Like many providers, the servers are shared not dedicated, and one reckless file upload, and I'm not saying your script is, could so easily bring down not just a Website but potentially the entire Web server pool. GTM avoids that possibility for us by being both a buffer and a testing harness and something that can be operated by marketeers without fear of breaking the Website in the process.

Ultimately this is simply about not being able to upload a js file to a server, as our Websites are provided on a WaaS basis. Whilst in theory we could manually upload the script to our own CDN if i asked a developer to do it for us, but we don't work that way as everything on the CDN is content managed to ensure the logistical management and integrity of our Websites and associated files, and the storage thereof; this is not 'our' content to curate, or that we should curate and manage on behalf of any third-party.

Essentially we do not create shared server storage space for customers like on a WordPress webserver, as it's our WaaS proprietary IP that's sitting there, instead we are providing a WaaS solution with deliberate walls, more akin to Wix and Squarespace than WordPress, where there are deliberate CMS limitations to prevent both preventable Website breakage and unnecessary reactive support.
 
  • Like
Reactions: JLSeagull
Status
Not open for further replies.

Forum statistics

Threads
112,149
Messages
590,964
Members
165,170
Latest member
SupportRock