Skip to content

Explore application-typed handshake rejection codes - #403

Merged
Mayank808 merged 12 commits into
mainfrom
mayank/typed-handshake-error-codes
Aug 25, 2026
Merged

Explore application-typed handshake rejection codes#403
Mayank808 merged 12 commits into
mainfrom
mayank/typed-handshake-error-codes

Conversation

@Mayank808

@Mayank808 Mayank808 commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Why

Exploration PR, alternative to #401. This sketches application-typed handshake rejection codes: applications declare their codes as a tuple of TypeBox literal schemas, validate may return them, and they travel in the handshake response's code field with compile-time checking on both peers.

The generics are parameterized on the schema tuple itself (ReadonlyArray<TLiteral<string>>), never on bare string unions — the code type is derived from the schemas, so this shape works end to end:

const rejectionCodeSchemas = [
  Type.Literal('ASSET_NOT_FOUND'),
  Type.Literal('TOKEN_EXPIRED'),
] as const;

type ApplicationErrorCode = Static<(typeof rejectionCodeSchemas)[number]>;

Versioning

  • Breaking protocol change
  • Breaking ts/js API change

@Mayank808 Mayank808 added the zergling-authored PRs authored by Zerg label Aug 24, 2026
@Mayank808
Mayank808 marked this pull request as ready for review August 25, 2026 00:09
@Mayank808
Mayank808 requested a review from a team as a code owner August 25, 2026 00:09
@Mayank808
Mayank808 requested review from darshkpatel and removed request for a team August 25, 2026 00:09
@Mayank808
Mayank808 removed the request for review from darshkpatel August 25, 2026 00:24
@Mayank808 Mayank808 removed the zergling-authored PRs authored by Zerg label Aug 25, 2026
@Mayank808
Mayank808 merged commit 5930fbb into main Aug 25, 2026
7 checks passed
@Mayank808
Mayank808 deleted the mayank/typed-handshake-error-codes branch August 25, 2026 21:33
@Mayank808 Mayank808 mentioned this pull request Aug 25, 2026
2 tasks
Mayank808 added a commit that referenced this pull request Aug 25, 2026
## Why

River 0.221.0 includes the new application-typed handshake rejection
code API from #403.

## What changed

Bumps the `@replit/river` package version from 0.220.1 to 0.221.0. This
prepares the package metadata for the next minor npm release.

## Versioning

- [ ] Breaking protocol change
- [ ] Breaking ts/js API change
Armster15 added a commit that referenced this pull request Sep 2, 2026
## Why

River already stores WebSocket upgrade headers in `connection.extras`,
but server handshake validation cannot read them. A downstream gateway
authenticates a session cookie during WebSocket upgrade and needs to
pass the verified identity to `validate`.

## What changed

Server handshake validation now accepts one optional argument:

```ts
validate(metadata, previousMetadata, from, connectionExtras)
```

River passes the extras from the current connection at both validation
sites:

- The initial handshake receives the extras for the new socket.
- A same-socket rehandshake receives the original extras for that
socket.
- A reconnect creates a new socket, so its handshake receives the new
socket extras.

`WebSocketServerTransport` also accepts an optional fourth constructor
argument:

```ts
new WebSocketServerTransport(wss, clientId, options, (ws, req) => extras)
```

The default behavior is unchanged. Without a factory, River stores the
same cleaned upgrade headers that it stores today. The factory is
synchronous because River must install the socket message handler during
the connection event. Applications can finish asynchronous
authentication before this event and let the factory read the verified
result.

Existing three-argument `validate` functions still compile and work.
This PR does not change protocol messages or package versions. The
typing and tests follow the precedent in
#403. The README now documents the
new validator argument, factory, and synchronous constraint.

## Test plan

- `npm run check`
- `npm run test:single` (785 passed, 1 skipped)
- `npm run build`
- `npx prettier README.md --check`

## Versioning

- [ ] Breaking protocol change
- [ ] Breaking ts/js API change

~ written by Zerg 👾
([volatile-queen-8e97](https://zerg.zergrush.dev/chat?id=volatile-queen-8e97))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants