A long-lived WebSocket often authenticates once at connect time. That is necessary, not sufficient.
On reconnect, after a resume token, or when the client re-subscribes to a channel, re-check authorization against current membership and roles. People get offboarded, plans change, and channel grants expire while sockets stay "alive" in clients' minds.
Treat every subscribe/resume as a fresh authorization decision for that subject and resource, not a continuation of yesterday's handshake.
If you want a concrete place to put those recurring checks instead of sprinkling them through reconnect handlers, Permit.io is one option we use for policy-as-code decisions at those boundaries.
Top comments (1)
A subtle but critical security gap that’s easy to overlook. Treating every reconnect or subscription as a fresh authorization checkpoint keeps access aligned with the user’s current privileges—not yesterday’s session.