Repository navigation
Conversation
…et tokens The socket service now hands the SocketCluster client an in-memory auth engine that mints a short-lived socket token from the console session (POST int/v1/socket/token) for every handshake, so subscriptions queued before the handshake go out authenticated and existing callers need no change. Without a session, or when the server cannot mint tokens (404), the client connects anonymously as before. Tokens never touch localStorage or the URL. - refresh 60s before expiry via socket.authenticate() - on deauthenticate, or a kickOut/subscribeFail with a token reason, mint a fresh token, authenticate, and resubscribe the lost channels by name (restores delivery to raw instance().subscribe loops); retries are once per channel per token and capped per minute - re-key on login, session restore and organization switch; on logout clear the token, stop timers and disconnect - send query client=console/<version> - extension-author notes live in the PR (docs moved to fleetbase.io)
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #97 +/- ##
==========================================
Coverage 100.00% 100.00%
==========================================
Files 168 168
Lines 5027 5229 +202
Branches 1362 1395 +33
==========================================
+ Hits 5027 5229 +202
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
This was referenced Oct 6, 2026
feat(socket-auth): show channel authorization failures in the sockets viewer
fleetbase/dev-engine#51
Open
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The console's realtime socket now authenticates with short-lived socket tokens minted from the console session. The
socketservice gives the SocketCluster client its own in-memory auth engine.loadToken()runs on every connect and reconnect. While the session is authenticated it callsPOST int/v1/socket/tokenand gets{ token, expires_in, expires_at }. A cached token is reused while it has more than 60 s left, and concurrent loads share one request.saveTokenandremoveTokenkeep the token in memory only. It is never written tolocalStorageor put in the URL. Subscriptions queued before the handshake go out authenticated, so existing callers (listen(),instance().subscribe()) need no change.loadTokenresolvesnulland the client connects anonymously as it does today.settled()waiting) fires atexpires_in - 60 s(minimum 5 s). It mints a new token and callssocket.authenticate(). While disconnected, the token waits for the next handshake.deauthenticate, akickOutwith a token reason, or asubscribeFailwith anAuthErrorwhose reason isno_token,token_expired,token_changed,deauthenticatedoridentity_changed.for awaitloops on rawinstance().subscribe()channels start receiving again.deauthenticatecaused by the service's ownauthenticatecall is ignored. A token the server rejects is dropped.subscribeFailhandling.session.authenticated(login) anduser.organization_switchedre-key the socket with a new token.user.loadedauthenticates a socket that connected anonymously before the session was restored. An anonymousconnectwhile signed in does the same.user.deauthenticated(logout) clears the token, stops timers and retries, and disconnects. The next login reconnects.client=console/<app version>. It is not a secret; the server uses it to label its logs.Why
Today any client can subscribe to any channel name. This is the console's part of the socket-auth work: the socket server can now check each subscription against the user's session (see the contract in the related PRs). This PR does not change channel names.
Notes for extension authors
The
docs/guides moved to fleetbase.io, so these notes are here for now:authenticateyourself.user.*andcompany.*channels.channel.listener('subscribeFail'):error.name === 'AuthError', anderror.reasonis a short snake_case code. Show or log the refusal instead of waiting.Tests
tests/unit/services/socket-auth-test.jscovers:tests/helpers/stub-socketcluster.jsgainsinertClientMethods(),createEventStream()andcreateRecordingClient(). The suite-wide stub,socket-test.jsandsocket-listen-test.jsnow provide the client methods the service calls.Test plan
Verified by CI (lint, full suite, 100% coverage gate). No local builds or test runs.
Related PRs
Part of the authenticated realtime channels rollout (socket auth), one PR per repo:
fleetbase/core-api ^1.6.69)fleetbase/fleetbase-socketserver, compose/helm/installer, console socket test page