syntaqxA page opened with an access token keeps its live sockets connected: just before it opens the feed, a conversation or an artifact's room, it asks GET /-/live/ticket with the token for a socket ticket and adds it to the socket's address, because a browser cannot put the Authorization header on a WebSocket. A ticket seals the token and its owner with a key derived from USERCONTENT_KEY, lasts 60 seconds, opens only the socket path it was made for, is read only by a WebSocket upgrade and never by a page, data request, form post or the API, and the token is checked again when the socket opens, so one deleted, expired, revoked or without Use the website as you opens nothing. Sessions open their sockets as before, with no ticket, and the authentication guide and the rate limits notes say how it works.d6356d9History
- notify
- repo
- settings
- workspace
- auth-github-callback.tsx
- auth-github-username.tsx
- auth-github.ts
- confirm-email.tsx
- device.tsx
- downloads-runner.ts
- explore.tsx
- forgot.tsx
- github-install.ts
- github-setup.tsx
- home.tsx
- hovercard-user.ts
- inbox-json.ts
- inbox.tsx
- invitations.tsx
- invite.tsx
- login-two-factor.tsx
- login.tsx
- logout.tsx
- new-github.tsx
- new.tsx
- not-found.tsx
- oauth-authorize.tsx
- people-json.ts
- policies.tsx
- policy.tsx
- pricing.tsx
- register.tsx
- reset.tsx
- robots-txt.ts
- search-json.ts
- search.tsx
- security-txt.ts
- security.tsx
- settings-menu-json.ts
- sitemap-xml.ts
- status-json.ts
- status.tsx
- support.tsx
- user.tsx
- verify.tsx