Skip to content

Fix/js sdk jwt refresh - #49

Open
6bda68f0-ctrl wants to merge 1 commit into
appsinacup:mainfrom
6bda68f0-ctrl:fix/js-sdk-jwt-refresh
Open

6bda68f0-ctrl wants to merge 1 commit into
appsinacup:mainfrom
6bda68f0-ctrl:fix/js-sdk-jwt-refresh

Conversation

@6bda68f0-ctrl

Copy link
Copy Markdown

No description provided.

@6bda68f0-ctrl
6bda68f0-ctrl force-pushed the fix/js-sdk-jwt-refresh branch from 35240ec to 76e4ba6 Compare October 1, 2026 12:08
GameRealtime stored the access token in Phoenix.Socket connect params at
construction time and never updated it. When the 15-minute token expired and
the socket reconnected, it sent the stale JWT, causing a 403 handshake
rejection and an infinite reconnect loop.

Adds an optional tokenProvider function as the fourth constructor argument.
When supplied, socket and channel params are stored as functions that Phoenix
JS evaluates fresh on every transportConnect() (socket reconnect) and channel
rejoin, picking up the current (refreshed) token without rebuilding the
instance. Omitting tokenProvider preserves the original static-token
behaviour.

The Godot client already uses this pattern via its _token_provider Callable.
Fixes appsinacup#47.
@6bda68f0-ctrl
6bda68f0-ctrl force-pushed the fix/js-sdk-jwt-refresh branch from 76e4ba6 to 7820aaf Compare October 1, 2026 12:11
@6bda68f0-ctrl
6bda68f0-ctrl marked this pull request as ready for review October 1, 2026 12:15
@Ughuuu

Ughuuu commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

The fix is real, but I'm not a fan of the change. I feel like the API wasn't great and now the constructor adds to that and keeps both old and new case behavior. I would rather break compatibility and keep the constructor lean than try to design for both cases.

@Ughuuu

Ughuuu commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

If you want to continue, take a look at this, it's a draft branch with WIP stuff, you can continue on it if you want. The idea is that we would need a higher level concept that ideally manages the low level operations for us (eg. a session class). We kind of have this already for other sdks.
https://github.com/appsinacup/gamend/tree/fix/js-sdk-jwt-refresh

@6bda68f0-ctrl

Copy link
Copy Markdown
Author

The fix addresses my immediate problem with the JS SDK. I don't really have the big picture to make changes that affect the other SDKs because I have no idea how they are used and what could break.

This fix should have no effect on existing implementations so it would be safe to merge.

I have the fix locally so feel free to close and make the bigger changes

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants