DEV Community

Auth By Example
Auth By Example

Posted on

A WebSocket reconnect is not a free pass

A long-lived WebSocket often authenticates once at connect time. That is necessary, not sufficient.

On reconnect, after a resume token, or when the client re-subscribes to a channel, re-check authorization against current membership and roles. People get offboarded, plans change, and channel grants expire while sockets stay "alive" in clients' minds.

Treat every subscribe/resume as a fresh authorization decision for that subject and resource, not a continuation of yesterday's handshake.

If you want a concrete place to put those recurring checks instead of sprinkling them through reconnect handlers, Permit.io is one option we use for policy-as-code decisions at those boundaries.

Top comments (1)

Collapse
 
nullandvoid_ profile image
Jyanthi •

A subtle but critical security gap that’s easy to overlook. Treating every reconnect or subscription as a fresh authorization checkpoint keeps access aligned with the user’s current privileges—not yesterday’s session.