Skip to content

feat(socket-auth): add socket->token() to mint realtime socket tokens - #28

Open
roncodes wants to merge 2 commits into
mainfrom
feature/socket-auth
Open

roncodes wants to merge 2 commits into
mainfrom
feature/socket-auth

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

What

  • New Fleetbase\Sdk\Services\SocketService, exposed as $fleetbase->socket / $fleetbase->socket() / service('socket').
  • $fleetbase->socket->token(array $options = []) sends POST socket/token and returns the decoded { token, expires_in, expires_at }. A server without realtime auth configured answers 404, raised as NotFoundException.
  • The service is hand-written: the route is not yet in the locked Postman contract, so it is outside the generated endpoint services and docs/api-coverage.md. When the Postman collection gains the route it can move into the generated set.
  • README section on server-side minting and the browser socket.authenticate(token) flow; CHANGELOG [Unreleased] entry. No version bump.

Why

Realtime channels are moving to authenticated subscriptions. PHP backends need a supported way to exchange their secret key for a short-lived token so that browsers never hold the API key.

Test plan

  • tests/Fleetbase/SocketTest.php: request method/path and decoded payload; 404 maps to NotFoundException.
  • FleetbaseTest service list includes socket.
  • Verified by CI (not run locally).

Related PRs

Part of the authenticated realtime channels rollout (socket auth), one PR per repo:

Hand-written SocketService (not generated from the Postman contract):
POST socket/token returns { token, expires_in, expires_at } for a
server-side exchange; the browser presents only the token.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant