Hacker News new | past | comments | ask | show | jobs | submit login

Supposedly websockets (the protocol) support authorization headers, but often there are no APIs for that in websocket libraries, so people just abuse the subprotocols header in the handshake.





I don't think the problem is libraries. Browsers don't support this.

Sure, I didn't mean to distinguish browsers and the JS websocket API and websocket libraries in other languages.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: