Skip to content

docs(socket-auth): authenticated realtime channels and migration guide - #120

Open
roncodes wants to merge 3 commits into
mainfrom
feature/socket-auth
Open

roncodes wants to merge 3 commits into
mainfrom
feature/socket-auth

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

What

  • Socket Events (platform/developer-console/socket-events): rewritten around the authenticated flow. The server mints a token with the API key (POST /v1/socket/token; Express, Node SDK, PHP SDK and cURL tabs). The browser gets only the short-lived token, connects with socketcluster-client and an in-memory authEngine (or socket.authenticate(token) before subscribing), refreshes ~60 s before expiry and re-authenticates on deauthenticate. It subscribes to company.{uuid} / api.{key id} / resource channels and handles subscribeFail. The page also covers authorization rules (company scope for API-key tokens, anonymous subscriptions rejected in enforce mode, no client publishing) and the off/log/enforce modes.
  • Set Up Real-Time Tracking recipe: same pattern. The old browser-side API-key fetch for active drivers is replaced by a server proxy endpoint.
  • System Setup → Socket: the fleetbase/fleetbase-socket image, the 8000 public and 8001 internal listeners (8001 is never exposed), and the env vars SOCKETCLUSTER_AUTH_KEY (shared by API and socket server), SOCKETCLUSTER_AUTH_MODE, SOCKETCLUSTER_PUBLISH_URL, SOCKETCLUSTER_AUTHORIZE_URL, SOCKETCLUSTER_TOKEN_TTL and SOCKETCLUSTER_INTERNAL_PORT. Also covers modes, the log-then-enforce upgrade path and troubleshooting.
  • New: Migrating to Authenticated Socket Channels (platform/developer-console/socket-auth-migration), registered in both platform nav meta files. It covers what changes, step-by-step migration and a checklist. The timeline is generic: the change takes effect when your instance or Fleetbase Cloud enables enforce mode.
  • New: Extension development → Socket Authentication (extension-development/reference/socket-authentication), the ember-core socket service guide moved here from the ember-core repo. Registered in the nav. The socket section of ember-services now says subscriptions are authorized server-side, and the channel list is fixed to api.{uuid}.
  • Storefront: POST /storefront/v1/customers/socket-token (authentication and overview pages). Checkout before responses gain socket_token. New Checkout Status Events section with the checkout.{public_id} payload {checkout, status (paid|completed|failed), order, error}.
  • Marketing pages: /developers/api (anonymous driver.driver_xxx) and /platform/developer-console samples use the authenticated pattern. The FAQ and the Fleet-Ops order-tracking page mention token-based subscriptions.

Why

Realtime channels now require short-lived socket tokens. The previous docs showed anonymous subscriptions and, in one recipe, an API key in browser code.

Test plan

  • Verified by CI (site build). Not built locally.
  • Manual review: MDX prose was checked for stray {}/JSX; new pages appear in the sidebar.

Related PRs

Part of the authenticated realtime channels rollout (socket auth), one PR per repo:

Every socket example now mints a short-lived token server-side
(POST /v1/socket/token), connects with an in-memory authEngine or
socket.authenticate(token), and refreshes ~60 s before expiry. No API
key appears in browser code. Documents authorization rules, the
off/log/enforce modes and the self-hosting env vars, adds a migration
guide for API customers, an extension-author page on the console socket
service, the storefront customer socket-token route and checkout events.
@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
fleetbase-io Error Error Oct 7, 2026 6:35am UTC

Request Review

…t order

Socket authentication is now off until SOCKETCLUSTER_AUTH_ENABLED=true on the
API containers and the socket server (fleetbase/core-api#290). System Setup →
Socket: env table entry, what the switch gates (token routes, authorize
endpoint, signed publishing, socket server mode), enforce requiring the switch
on the API, installer defaults (switch off, log), the rollout order, and two
troubleshooting entries. Migration guide and Socket Events: the switch and the
self-hosted rollout, so self-hosters set it.

This branch had an error being deployed

1 failed deployment
Preview — 54060d12 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant