Skip to content

feat(socket-auth): show channel authorization failures in the sockets viewer - #51

Open
roncodes wants to merge 1 commit into
mainfrom
feature/socket-auth
Open

roncodes wants to merge 1 commit into
mainfrom
feature/socket-auth

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

What

The Developers → Sockets viewer now shows when a channel subscription is refused. Before, it showed "Awaiting events..." forever. The same view handles channels opened from the Listen on custom channel modal, so that path is covered too.

  • subscribeFail on the channel is logged in red:
    • An authorization refusal from the socket server (AuthError) reads "Not authorized to subscribe to channel {name} ({reason})". The reason is the server's short snake_case code, for example forbidden.
    • Any other failure reads "Could not subscribe to channel {name}: {message}".
    • After a refusal the "Awaiting events..." indicator is hidden.
  • kickOut is logged as "Removed from channel {name} ({reason})". When the channel was lost for a token reason, the socket service in ember-core resubscribes it. The view then logs "Socket subscribed to channel..." again and clears the failure state.
  • Output lines are built through a logEvent() helper, which reassigns the tracked array instead of calling pushObject.
  • Event content is now rendered as escaped text with whitespace-pre-wrap, not through html-safe. The lines carry server-provided strings (refusal reasons, published payloads), so they should not be read as HTML. Pretty-printed JSON now keeps its line breaks.
  • New strings are added to all 11 locales.

Why

This is the dev-engine part of the socket-auth work. Once the socket server enforces channel authorization, a channel the user may not see is refused. The viewer should say so rather than look broken.

Test plan

Verified by CI. tests/unit/controllers/sockets/view-test.js replaces the placeholder test with tests for:

  • how refusals are described
  • the refusal, kick-out and resubscribe sequence and the awaiting indicator
  • JSON data output
  • cleanup when leaving the page

Related PRs

Part of the authenticated realtime channels rollout (socket auth), one PR per repo:

… viewer

The sockets viewer (including channels opened from the custom-channel
modal, which lands on the same view) now logs a refused subscription
instead of showing "Awaiting events..." forever. Authorization refusals
from the socket server (AuthError) show their reason; other failures
show their message. Kick-outs are logged too, and a later resubscribe
(the socket service retries channels lost for token reasons) clears the
failure state.

Event content is now rendered as escaped text with preserved whitespace
instead of through html-safe, since it carries server-provided strings
and published payloads.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant