Repository navigation
Conversation
Every socket example now mints a short-lived token server-side (POST /v1/socket/token), connects with an in-memory authEngine or socket.authenticate(token), and refreshes ~60 s before expiry. No API key appears in browser code. Documents authorization rules, the off/log/enforce modes and the self-hosting env vars, adds a migration guide for API customers, an extension-author page on the console socket service, the storefront customer socket-token route and checkout events.
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This was referenced Oct 6, 2026
feat(socket-auth): show channel authorization failures in the sockets viewer
fleetbase/dev-engine#51
Open
…t order Socket authentication is now off until SOCKETCLUSTER_AUTH_ENABLED=true on the API containers and the socket server (fleetbase/core-api#290). System Setup → Socket: env table entry, what the switch gates (token routes, authorize endpoint, signed publishing, socket server mode), enforce requiring the switch on the API, installer defaults (switch off, log), the rollout order, and two troubleshooting entries. Migration guide and Socket Events: the switch and the self-hosted rollout, so self-hosters set it.
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
platform/developer-console/socket-events): rewritten around the authenticated flow. The server mints a token with the API key (POST /v1/socket/token; Express, Node SDK, PHP SDK and cURL tabs). The browser gets only the short-lived token, connects withsocketcluster-clientand an in-memoryauthEngine(orsocket.authenticate(token)before subscribing), refreshes ~60 s before expiry and re-authenticates ondeauthenticate. It subscribes tocompany.{uuid}/api.{key id}/ resource channels and handlessubscribeFail. The page also covers authorization rules (company scope for API-key tokens, anonymous subscriptions rejected in enforce mode, no client publishing) and the off/log/enforce modes.fleetbase/fleetbase-socketimage, the 8000 public and 8001 internal listeners (8001 is never exposed), and the env varsSOCKETCLUSTER_AUTH_KEY(shared by API and socket server),SOCKETCLUSTER_AUTH_MODE,SOCKETCLUSTER_PUBLISH_URL,SOCKETCLUSTER_AUTHORIZE_URL,SOCKETCLUSTER_TOKEN_TTLandSOCKETCLUSTER_INTERNAL_PORT. Also covers modes, the log-then-enforce upgrade path and troubleshooting.platform/developer-console/socket-auth-migration), registered in both platform nav meta files. It covers what changes, step-by-step migration and a checklist. The timeline is generic: the change takes effect when your instance or Fleetbase Cloud enables enforce mode.extension-development/reference/socket-authentication), the ember-core socket service guide moved here from the ember-core repo. Registered in the nav. Thesocketsection ofember-servicesnow says subscriptions are authorized server-side, and the channel list is fixed toapi.{uuid}.POST /storefront/v1/customers/socket-token(authentication and overview pages). Checkoutbeforeresponses gainsocket_token. New Checkout Status Events section with thecheckout.{public_id}payload{checkout, status (paid|completed|failed), order, error}./developers/api(anonymousdriver.driver_xxx) and/platform/developer-consolesamples use the authenticated pattern. The FAQ and the Fleet-Ops order-tracking page mention token-based subscriptions.Why
Realtime channels now require short-lived socket tokens. The previous docs showed anonymous subscriptions and, in one recipe, an API key in browser code.
Test plan
{}/JSX; new pages appear in the sidebar.Related PRs
Part of the authenticated realtime channels rollout (socket auth), one PR per repo:
fleetbase/core-api ^1.6.69)fleetbase/fleetbase-socketserver, compose/helm/installer, console socket test page