Skip to content

feat(socket-auth): add customer.socketToken() for realtime channels - #22

Open
roncodes wants to merge 2 commits into
mainfrom
feature/socket-auth
Open

roncodes wants to merge 2 commits into
mainfrom
feature/socket-auth

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

What

  • Customer#socketToken(params?, options?) calls POST customers/socket-token with the customer's Customer-Token header (request-scoped, via performAuthorizedRequest) and resolves to { token, expires_in, expires_at }.
  • New exported type SocketTokenResponse.
  • Declarations in types/ updated to match; public API snapshot gains Customer.socketToken.
  • README: Realtime order updates section (in-memory authEngine, socket.authenticate() refresh ~60 s before expiry, subscribing to order.{id}, the checkout socket_token); docs/api-contract.md lists the route.
  • No version bump.

Why

Realtime channels are moving to authenticated subscriptions. Storefront customers need a token scoped to their own channels instead of subscribing anonymously.

Test plan

  • tests/actions.test.js covers the endpoint, method, response and the Customer-Token header (existing loop asserts it on every authorized call); public API snapshot updated.
  • dist/ is generated output. It was not rebuilt locally; a follow-up commit on this branch regenerates it, otherwise the Require reproducible generated artifacts step will flag it.
  • Verified by CI.

Related PRs

Part of the authenticated realtime channels rollout (socket auth), one PR per repo:

POST customers/socket-token with the customer's Customer-Token header,
resolving to { token, expires_in, expires_at } (SocketTokenResponse).
Declarations under types/ updated by hand; dist/ needs regenerating.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant