This page demonstrates embedding the remote chat widget served by your Next.js application.
The widget script performs a trusted-domain check based on the referer header.
Ensure this page's host is listed in trusted-domains.json on the server.
pnpm devtrusted-domains.json includes localhost (already provided).file:// the referer may be missing and the widget could be disabled.Set window.__CHAT_WIDGET_ORIGIN BEFORE the embed script tag if the API lives on a different origin.
The widget injects minimal scoped CSS. Override with stronger selectors or use :root { --chat-widget-accent: #9333ea; }.
The server validates the referer/origin host against the trusted domains list before serving an active widget.
POST /api/chat with JSON { message: string } returns { reply: string }. Adjust logic server-side as needed.