Packages
phoenix
1.8.0-rc.0
1.8.9
1.8.8
1.8.7
1.8.6
1.8.5
1.8.4
1.8.3
1.8.2
1.8.1
1.8.0
1.8.0-rc.4
1.8.0-rc.3
1.8.0-rc.2
1.8.0-rc.1
1.8.0-rc.0
1.7.24
1.7.23
1.7.22
1.7.21
1.7.20
1.7.19
1.7.18
1.7.17
1.7.16
1.7.15
1.7.14
1.7.13
1.7.12
1.7.11
1.7.10
1.7.9
1.7.8
1.7.7
1.7.6
1.7.5
1.7.4
1.7.3
1.7.2
1.7.1
1.7.0
1.7.0-rc.3
1.7.0-rc.2
1.7.0-rc.1
1.7.0-rc.0
1.6.17
1.6.16
1.6.15
1.6.14
1.6.13
1.6.12
1.6.11
1.6.10
1.6.9
1.6.8
1.6.7
1.6.6
1.6.5
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.6.0-rc.1
1.6.0-rc.0
1.5.15
1.5.14
1.5.13
1.5.12
1.5.11
1.5.10
1.5.9
1.5.8
1.5.7
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.5.0-rc.0
1.4.18
1.4.17
1.4.16
1.4.15
1.4.14
1.4.13
1.4.12
1.4.11
1.4.10
1.4.9
1.4.8
1.4.7
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.4.0-rc.3
1.4.0-rc.2
1.4.0-rc.1
1.4.0-rc.0
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.3.0-rc.3
1.3.0-rc.2
1.3.0-rc.1
1.3.0-rc.0
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.2.0-rc.1
1.2.0-rc.0
1.1.9
1.1.8
1.1.7
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
0.17.1
0.17.0
0.16.1
0.16.0
0.15.0
0.14.0
0.13.1
0.13.0
0.12.0
0.11.0
0.10.0
0.9.0
0.8.0
0.7.2
0.7.1
0.7.0
0.6.2
0.6.1
0.6.0
0.5.0
0.4.1
0.4.0
0.3.1
0.3.0
0.2.11
0.2.10
0.2.9
0.2.8
0.2.7
0.2.6
0.2.5
0.2.4
0.2.3
0.2.2
0.2.1
0.2.0
0.1.0
Productive. Reliable. Fast. A productive web framework that does not compromise speed or maintainability.
Security advisory:
This version has known vulnerabilities.
View advisories
Current section
Files
Jump to
Current section
Files
lib/phoenix/transports/websocket.ex
defmodule Phoenix.Transports.WebSocket do
@moduledoc false
#
# How WebSockets Work In Phoenix
#
# WebSocket support in Phoenix is implemented on top of the `WebSockAdapter` library. Upgrade
# requests from clients originate as regular HTTP requests that get routed to this module via
# Plug. These requests are then upgraded to WebSocket connections via
# `WebSockAdapter.upgrade/4`, which takes as an argument the handler for a given socket endpoint
# as configured in the application's Endpoint. This handler module must implement the
# transport-agnostic `Phoenix.Socket.Transport` behaviour (this same behaviour is also used for
# other transports such as long polling). Because this behaviour is a superset of the `WebSock`
# behaviour, the `WebSock` library is able to use the callbacks in the `WebSock` behaviour to
# call this handler module directly for the rest of the WebSocket connection's lifetime.
#
@behaviour Plug
@connect_info_opts [:check_csrf]
@auth_token_prefix "base64url.bearer.phx."
import Plug.Conn
alias Phoenix.Socket.{V1, V2, Transport}
def default_config() do
[
path: "/websocket",
serializer: [{V1.JSONSerializer, "~> 1.0.0"}, {V2.JSONSerializer, "~> 2.0.0"}],
error_handler: {__MODULE__, :handle_error, []},
timeout: 60_000,
transport_log: false,
compress: false
]
end
def init(opts), do: opts
def call(%{method: "GET"} = conn, {endpoint, handler, opts}) do
subprotocols =
if opts[:auth_token] do
# when using Sec-WebSocket-Protocol for passing an auth token
# the server must reply with one of the subprotocols in the request;
# therefore we include "phoenix" as allowed subprotocol and include it on the client
["phoenix" | Keyword.get(opts, :subprotocols, [])]
else
opts[:subprotocols]
end
conn
|> fetch_query_params()
|> Transport.code_reload(endpoint, opts)
|> Transport.transport_log(opts[:transport_log])
|> Transport.check_origin(handler, endpoint, opts)
|> maybe_auth_token_from_header(opts[:auth_token])
|> Transport.check_subprotocols(subprotocols)
|> case do
%{halted: true} = conn ->
conn
%{params: params} = conn ->
keys = Keyword.get(opts, :connect_info, [])
connect_info =
Transport.connect_info(conn, endpoint, keys, Keyword.take(opts, @connect_info_opts))
config = %{
endpoint: endpoint,
transport: :websocket,
options: opts,
params: params,
connect_info: connect_info
}
case handler.connect(config) do
{:ok, arg} ->
try do
conn
|> WebSockAdapter.upgrade(handler, arg, opts)
|> halt()
rescue
e in WebSockAdapter.UpgradeError -> send_resp(conn, 400, e.message)
end
:error ->
send_resp(conn, 403, "")
{:error, reason} ->
{m, f, args} = opts[:error_handler]
apply(m, f, [conn, reason | args])
end
end
end
def call(conn, _), do: send_resp(conn, 400, "")
def handle_error(conn, _reason), do: send_resp(conn, 403, "")
defp maybe_auth_token_from_header(conn, true) do
case get_req_header(conn, "sec-websocket-protocol") do
[] ->
conn
[subprotocols_header | _] ->
request_subprotocols =
subprotocols_header
|> Plug.Conn.Utils.list()
|> Enum.split_with(&String.starts_with?(&1, @auth_token_prefix))
case request_subprotocols do
{[@auth_token_prefix <> encoded_token], actual_subprotocols} ->
token = Base.decode64!(encoded_token, padding: false)
conn
|> put_private(:phoenix_transport_auth_token, token)
|> set_actual_subprotocols(actual_subprotocols)
_ ->
conn
end
end
end
defp maybe_auth_token_from_header(conn, _), do: conn
defp set_actual_subprotocols(conn, []), do: delete_req_header(conn, "sec-websocket-protocol")
defp set_actual_subprotocols(conn, subprotocols),
do: put_req_header(conn, "sec-websocket-protocol", Enum.join(subprotocols, ", "))
end