Websocket and EventSource cannot carry custom header on browser. well then how can i have it carry my token to be authed?
the only other way i can think of is to carry it via url, which is not secure
how to auth websocket or EventSource ?
how to auth websocket or EventSource ?
|
|
Mar 14 2025, 05:18 PM, updated 10 months ago
Show posts by this member only | IPv6 | Post
#1
|
![]() ![]() ![]()
Junior Member
423 posts Joined: Apr 2022 |
Websocket and EventSource cannot carry custom header on browser. well then how can i have it carry my token to be authed?
the only other way i can think of is to carry it via url, which is not secure |
|
|
|
|
|
Mar 14 2025, 05:26 PM
Show posts by this member only | Post
#2
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,354 posts Joined: Apr 2009 |
U dun have to carry ur token on every request, u authenticate it when u establish the socket
https://ably.com/blog/websocket-authentication |
|
|
Mar 14 2025, 05:43 PM
Show posts by this member only | IPv6 | Post
#3
|
![]() ![]() ![]()
Junior Member
423 posts Joined: Apr 2022 |
QUOTE(ragk @ Mar 14 2025, 05:26 PM) U dun have to carry ur token on every request, u authenticate it when u establish the socket but if someone figure out the endpoint for socket they can try to connect to the socket directly?https://ably.com/blog/websocket-authentication edit: oh ok i realise what u meant u cant add custom header during the handshake as well right? This post has been edited by 15cm: Mar 14 2025, 05:47 PM |
|
|
Mar 14 2025, 05:51 PM
Show posts by this member only | Post
#4
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,354 posts Joined: Apr 2009 |
QUOTE(15cm @ Mar 14 2025, 05:43 PM) but if someone figure out the endpoint for socket they can try to connect to the socket directly? The link got the example of submitting token during handshake too edit: oh ok i realise what u meant u cant add custom header during the handshake as well right? QUOTE const ws = new WebSocket( "wss://example.com/path", ["Authorization", "your_token_here"] ) |
|
|
Mar 14 2025, 05:53 PM
Show posts by this member only | IPv6 | Post
#5
|
![]() ![]() ![]()
Junior Member
423 posts Joined: Apr 2022 |
|
|
|
Mar 14 2025, 05:54 PM
Show posts by this member only | Post
#6
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,354 posts Joined: Apr 2009 |
|
| Change to: | 0.0132sec
0.73
5 queries
GZIP Disabled
Time is now: 24th December 2025 - 08:26 AM |