fix(browser): sign the live-view stream socket, not just the auth socket - #1190
Merged
philmerrell merged 2 commits intoSep 19, 2026
Merged
Conversation
`connect` reads `httpExtraSearchParams` ONLY from `observers`. We passed it at the top level, where it is silently ignored — so the stream socket opened with no query string at all, unsigned, and the service refused it. Measured by running the shipped 1.13.2 bundle against a stubbed WebSocket: top-level -> wss://.../live-view/ws (UNSIGNED) observers -> wss://.../live-view/ws?X-Amz-Algorithm= (signed) That is exactly what the browser console showed: repeated failures to `/live-view/ws` carrying no parameters. `authenticate` is the opposite — it reads the callback from the top level — which is what made the top-level form look right. The two entry points genuinely differ. `firstFrame`/`disconnect` move into `observers` with it, because the SDK honours observers or callbacks and not both. This is also what AWS's own BrowserLiveView component does; its config was read from the published package rather than guessed. Mutation-checked: restoring the top-level form fails the new assertion. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
`.connprobe.mjs` was a throwaway jsdom harness used to capture the DCV SDK's WebSocket URL. Its cleanup `rm` sat in the same command line as a node process that never exited, so `git add -A` swept it into the branch. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This was referenced Sep 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
connectreadshttpExtraSearchParamsonly fromobservers. We passed it at the top level, where it is silently ignored — so the stream socket opened with no query string at all, unsigned, and the service refused it.Measured
Running the shipped DCV 1.13.2 bundle against a stubbed
WebSocket:wss://…/live-view/ws— UNSIGNEDobservers(AWS's)wss://…/live-view/ws?X-Amz-Algorithm=…— signedThis is exactly what the browser console showed all along: repeated failures to
/live-view/wscarrying no parameters. I had read those as fallout from the earlier auth failure; they were a second, independent bug.authenticateis the opposite — it reads the callback from the top level — which is precisely what made the top-level form look correct for both. The two entry points genuinely differ, and nothing in the surface hints at it.firstFrame/disconnectmove intoobserverswith it, since the SDK honours observers or callbacks and not both.Cross-checked against AWS's own
BrowserLiveView, read from the published package rather than guessed: it usesobservers: { httpExtraSearchParams }too.Correction to #1189
#1189 claimed the doubled-SigV4-parameter theory was the cause. Running the real SDK disproves it: it produces exactly one
X-Amz-Signaturewhether or not the URL still carries its query, because it replaces the query rather than appending. #1189 is behaviourally neutral, not a fix. The 403-on-doubled-params probe was real, but we were never sending that form.Tests
Asserts the connect config shape:
httpExtraSearchParamspresent inobservers, absent at top level, and nocallbacksalongside. Mutation-checked — restoring the top-level form fails it. Suite 873 pass,tsc --noEmitclean.Still open
authenticateintermittently fails with code 10 before connect is reached. One hypothesis worth testing after this lands: the unsigned/wsretry loop leaves the SDK's network monitor wedged ("No transition available") and poisons subsequent attempts. Not yet proven.🤖 Generated with Claude Code