Repository navigation
feat(socket-auth): fleetops channel resolvers, driver socket tokens, per-customer tracking channel - #358
Merged
Conversation
…per-customer tracking channel - Register who may subscribe to every FleetOps channel prefix with the core SocketChannelRegistry: company match for console users and API credentials; narrow rules for drivers (own record, current vehicle and its devices and positions, assigned orders incl. via payload entities) and customers (own orders, driver and vehicle of their active orders). tracking.* is denied by the registry (reachable only through a scoped tracking token). - Claim Sanctum users who drive for the current company as driver socket principals on v1/socket/token. - positions/replay validates channel_id with the ChannelAuthorizer when socket authentication is on. - Public tracking channel: TrackingScope (one customer of one order), TrackingChannel (name/opaque id/token via core-api), TrackingUpdate (sanitized per-customer payload) and TrackingPublisher (gated, throttled, queued) publishing on order, stop and position changes. - Require fleetbase/core-api ^1.6.69.
…s only its own
The scheduler subscribed to company.{id}.orders, which nothing publishes to,
and its teardown closed every socket channel, chat included. It now opens
the per-driver channels only and on teardown closes just those (sweeping
once more for subscriptions still pending).
This was referenced Oct 6, 2026
feat(socket-auth): show channel authorization failures in the sockets viewer
fleetbase/dev-engine#51
Open
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
FleetOps part of realtime socket authentication.
SocketChannelRegistry:order,driver,driverAssigned,vehicle,trailer,device,waypoint,entity,place,contact,fleet,zone,service_area,service_rate,service_quote,purchase_rate,tracking_status,tracking_number,payload(generic model resolver),customer,vendor,facilitator(morph prefixes),position(uuid only; positions have no public id) andtracking(always denied).v1/socket/token. The resultingdriverprincipal hassub= driver uuid andids= driver uuid and public id plus user uuid and public id.positions/replayonly accepts achannel_idthat the requesting user could subscribe to (checked throughChannelAuthorizer). Any other channel gets a 403. When socket auth is off, the endpoint behaves exactly as before.TrackingScopecovers one customer of one order. A stop belongs to the waypoint's customer, else to the order's customer.TrackingChannelgivestracking.{opaque}and the scoped token, both through core-apiSocketToken::trackingId()andSocketToken::forTracking().TrackingUpdatebuilds the sanitized payload. It holds only the viewer's stops (status, ETA, timeline status/code/time with no free-text details) and whole-route counts. For the driver it holds the first name, the vehicle label and the online flag, with no photo or phone. The vehicle position is rounded to 4 decimals and comes with heading and seen_at. Driver and position are included only while the order is en route and the viewer still has an incomplete stop.TrackingPublisherand thePublishTrackingUpdatejob publish when order status, assignment or ETA changes, on waypoint/entity activity, and on driver or vehicle positions. The hooks do nothing while socket auth is off. Position lookups are throttled to once per 5 s per driver/vehicle and per order, and ETAs are refreshed at most once a minute.company.{id}.orderschannel. Its teardown closes only the driver channels it opened; before, it closed every channel, chat included.Why
Without these resolvers, enabling socket authentication would deny every FleetOps channel. With them, drivers and customers only see their own data.
Dependency
Requires
fleetbase/core-api^1.6.69(raised incomposer.json). CI on this PR needs that core-api release, socomposer installfails until it is tagged.Test plan
Verified by CI. New Pest tests cover:
There is also an Ember unit test for the scheduler teardown.
Related PRs
Part of the authenticated realtime channels rollout (socket auth), one PR per repo:
fleetbase/core-api ^1.6.69)fleetbase/fleetbase-socketserver, compose/helm/installer, console socket test page