Skip to content

feat(ws): opt-in allowed origins and observer key - #170

Merged
MrAlders0n merged 1 commit into
devfrom
feat/ws-embed-options
Sep 27, 2026
Merged

MrAlders0n merged 1 commit into
devfrom
feat/ws-embed-options

Conversation

@MrAlders0n

Copy link
Copy Markdown
Member

Two opt-in WebSocket additions so another site can embed the live feed. Both are off by default, so existing installs and clients see no change.

  • websocket.allowed_origins lets listed sites open /ws from the browser. Entries must be exact scheme://host[:port]; wildcards, paths and non-http(s) schemes stop startup. Same-host connections work as before, and anything unlisted still gets 403.
  • configure {includeObserverKey: true} adds observation.observerPublicKey to that connection's packetObservation events. Clients that don't ask get byte-identical events, and ingest only builds the extra payloads while someone has opted in.

The configured reply now echoes includeObserverKey alongside resolvePath. It's additive, and v stays 1.

Example:

websocket:
  allowed_origins:
    - https://example.com

Tests cover origin matching, config validation, the hub's payload selection and opt-in count, and the ingest variants. No swagger change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant