Repository navigation
fix(serverdb): re-acquire the bearer token when a reconnect gets 401 (#39) - #113
Merged
Merged
Conversation
…39) WebSocketClient::Connect handed the JWT to ixwebsocket once, through setExtraHeaders. ixwebsocket 11.4.6 reconnects by calling WebSocket::connect() again, which copies the stored _extraHeaders (IXWebSocket.cpp:210). So every automatic reconnect presented the token that was valid at the first Connect. Nakama rejects an expired JWT at the upgrade with 401 (parseToken, jwt.WithExpirationRequired), and in server mode nothing else refreshes the token (TokenAuth::Init returns early on is_server). A ServerDB reconnect after the ~1h TTL could therefore never succeed. Now an Error message carrying HTTP 401 calls a token refresher, and the next attempt presents the new header. The refresher is AcquireServerDbToken, factored out of RequestRegistration unchanged: refresh-token exchange first, then password auth. Only 401 triggers it, so a network failure or a 5xx does not call the auth endpoint. The header is written on ixwebsocket's own thread, the only thread that emits Error and the one whose connect() reads the headers without a lock. Each step logs: the rejection, a failed re-acquisition, and the replacement with refresh_count. test_websocket_client_auth drives the real client against a scripted loopback upgrade server and records each handshake's Authorization header. It pins the stale-header behaviour without a refresher, the 401 path that mints a new token, the 503 path that does not, and a failed mint. Two mutants were checked: no hook turns two tests red, and refreshing on any error turns the 503 test red. The target is added to test-auth-unit. Co-Authored-By: nevr-runtime <agents@sprock.io>
thesprockee
added a commit
that referenced
this pull request
Oct 6, 2026
…erdb-uri Resolve justfile test-target list conflict from #113 landing on main: keep both test_serverdb_uri (this branch) and test_websocket_client_auth (main) in both test-auth-unit lists. Co-Authored-By: nevr-runtime <agents@sprock.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Test plan
Not done
Found, not fixed here
🤖 Generated with Claude Code