SSE and WebSocket handlers often authorize once when the connection opens, then push events for minutes or hours. That first check is not a standing grant.
While the stream is open, membership can be revoked, a role narrowed, or the resource moved out of the subject's scope. If you only gate the handshake, later events can leak data the subject is no longer allowed to see.
Re-authorize before sensitive payloads leave the server—on a short interval, on each privileged event type, or when the subject's session/membership version changes. Close the stream when the check fails.
A connection lifetime is not a permission lifetime. Authorization still belongs at the moment of access.
Top comments (0)