boostorg / boostorg/beast

Better websocket handshake workflow for the server

Open
#1,442 1 comment 0 reactions 0 assignees View on GitHub
Design
Dominant language
C++
Stars
4.8k
Forks
694
Avg merge
12h 48m
Merged PRs (30d)
1

Description

Currently servers that want full control over accepting a websocket upgrade have to:

1. read the upgrade request themselves using `http::read`
2. use `websocket::is_upgrade` to determine if the message contains a valid websocket upgrade
3. decide if they want to attempt the upgrade
- if not, composed an HTTP error response and send it
- if yes:
4. call `websocket::stream::accept` with the request
5. optionally provide a decorator to modify the 101 switching protocols response before it is sent

In this workflow there is no way for the server to determine first if the upgrade would fail at the stream level. For example by requesting invalid permessage-deflate settings. There is no way to identify defective upgrade requests and send back a rationale 400 Bad Request.

It should be possible to present the HTTP request to the stream to preflight it for validity, and if invalid then fill out a suitable default 400 Bad Request response which the caller can further customize before sending.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.