인증과 권한 부여
핸드셰이크 과정에서 인증 메커니즘(예: JWT)을 통합하고 WebSocket 메시지에 대한 사용자 권한을 관리합니다.
인증과 권한 부여은(는) CoddyKit의 무료 WebSockets & Realtime Systems Programming 강의입니다. 이것은 4개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 WebSockets & Realtime Systems Programming 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. WebSockets & Realtime Systems Programming 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
Securing WebSocket Interactions
WebSockets enable powerful real-time communication. But just like any web interaction, we need to know who is connecting and what they are allowed to do.
This is where authentication and authorization come in. They are crucial for building secure and reliable applications.
Auth Challenges for WebSockets
Unlike traditional HTTP requests, which are stateless and often carry authentication headers with each request, WebSockets establish a persistent, stateful connection.
This means we authenticate once during the initial connection handshake, and then the server must remember the client's identity for the duration of the connection.
Authentication During Handshake
The perfect moment to authenticate a client is during the WebSocket handshake. This is the initial HTTP request that upgrades to a WebSocket connection.
- The client sends an HTTP GET request with a
Upgrade: websocketheader. - The server can inspect this request for authentication credentials before deciding to upgrade.
- If credentials are valid, the connection is established; otherwise, it's rejected.
Passing Credentials: Query Params
One way to pass credentials is via query parameters in the WebSocket URL. For example: ws://server.com/chat?token=your_jwt.
- Pros: Simple to implement.
- Cons: Can expose sensitive tokens in server logs or browser history. Generally less secure and not recommended for production.
Passing Credentials: HTTP Headers
A more secure and recommended approach is to pass authentication tokens within HTTP headers during the handshake.
While the standard WebSocket API doesn't directly support custom headers, some libraries or proxy configurations allow this. Often, custom headers like Authorization: Bearer your_jwt are used, or tokens are embedded in the Sec-WebSocket-Protocol header.
What is a JSON Web Token (JWT)?
A JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. It's often used for authentication.
- It's digitally signed, ensuring its authenticity.
- It contains user information (like user ID, roles) in a payload.
- The server verifies the JWT signature to confirm the user's identity.
Server-Side JWT Handshake (Node.js)
Here's a simplified Node.js example using the ws library showing how a server might verify a JWT from a query parameter during the handshake. In a real app, you'd use a robust JWT library.
const WebSocket = require('ws');
const url = require('url');
const wss = new WebSocket.Server({ noServer: true });
wss.on('connection', function connection(ws, request) {
const userId = request.userId; // Set during handshake verification
console.log(`Client ${userId} connected`);
ws.on('message', function incoming(message) {
console.log(`Received from ${userId}: ${message}`);
});
ws.on('close', () => console.log(`Client ${userId} disconnected`));
});
// This is where you would integrate with an HTTP server
// For simplicity, we'll simulate the handshake here.
// Simulate an HTTP server upgrade listener
// In a real app, this would be an http.Server.on('upgrade')
function handleUpgrade(request, socket, head) {
const pathname = url.parse(request.url).pathname;
if (pathname === '/ws') {
const token = new URLSearchParams(url.parse(request.url).query).get('token');
// --- Simulate JWT verification ---
if (token === 'valid_jwt_123') {
request.userId = 'user_1'; // Attach user info to request
wss.handleUpgrade(request, socket, head, function done(ws) {
wss.emit('connection', ws, request);
});
} else {
console.log('Invalid JWT. Connection rejected.');
socket.destroy();
}
} else {
socket.destroy();
}
}
// Example usage (not a full http server, just for demonstration)
const mockRequest = {
url: '/ws?token=valid_jwt_123',
headers: { 'upgrade': 'websocket', 'connection': 'upgrade' }
};
const mockSocket = {
destroy: () => console.log('Socket destroyed (connection rejected)')
};
const mockHead = Buffer.alloc(0);
console.log('Attempting connection with valid token...');
handleUpgrade(mockRequest, mockSocket, mockHead);
// Attempt connection with invalid token
const mockInvalidRequest = {
url: '/ws?token=invalid_jwt',
headers: { 'upgrade': 'websocket', 'connection': 'upgrade' }
};
const mockInvalidSocket = {
destroy: () => console.log('Socket destroyed (connection rejected)')
};
console.log('\nAttempting connection with invalid token...');
handleUpgrade(mockInvalidRequest, mockInvalidSocket, mockHead);Authorization: Who Can Do What?
Once a user is authenticated (we know who they are), authorization determines what actions they are permitted to perform.
This often involves checking user roles or permissions associated with their authenticated identity. For example, a 'guest' user might only be able to read messages, while an 'admin' can also delete them.
Message-Level Authorization (Node.js)
After a WebSocket connection is established and the user is authenticated, the server can enforce authorization rules on incoming messages. This example shows a simple check based on a user's role.
const WebSocket = require('ws');
// Simulate a WebSocket server for demonstration
const wss = new WebSocket.Server({ port: 8080 });
// In a real application, user info (like roles) would be
// stored in the ws object after successful authentication.
const connectedClients = new Map(); // Map ws -> { userId, role }
wss.on('connection', function connection(ws) {
// Simulate authenticated user and their role
const userId = `user_${Math.floor(Math.random() * 100)}`;
const role = (userId === 'user_10') ? 'admin' : 'member';
connectedClients.set(ws, { userId, role });
console.log(`Client ${userId} (${role}) connected.`);
ws.send(`Welcome, ${userId}! Your role is ${role}.`);
ws.on('message', function incoming(message) {
const clientInfo = connectedClients.get(ws);
const msg = message.toString();
console.log(`Received from ${clientInfo.userId}: ${msg}`);
// --- Authorization Check ---
if (msg.startsWith('/delete') && clientInfo.role !== 'admin') {
ws.send('Error: You are not authorized to delete messages.');
console.log(`${clientInfo.userId} (member) tried to delete.`);
} else if (msg.startsWith('/delete') && clientInfo.role === 'admin') {
ws.send('Message deleted successfully!');
console.log(`${clientInfo.userId} (admin) deleted a message.`);
// In a real app, delete logic would go here
} else {
// Broadcast message to others or process normally
wss.clients.forEach(function each(client) {
if (client !== ws && client.readyState === WebSocket.OPEN) {
client.send(`${clientInfo.userId}: ${msg}`);
}
});
ws.send(`You said: ${msg}`);
}
});
ws.on('close', () => {
const clientInfo = connectedClients.get(ws);
console.log(`Client ${clientInfo.userId} disconnected.`);
connectedClients.delete(ws);
});
});
console.log('WebSocket server started on port 8080. Try connecting with a WebSocket client!');
console.log('Simulated user_10 is an admin, others are members.');Auth & Auth Quick Check
When is the most appropriate and secure time to authenticate a client in a WebSocket connection?
Recap: Secure Connections
We've explored how to secure WebSocket connections by implementing authentication and authorization.
- Authentication happens primarily during the handshake, often using JWTs passed in headers.
- Authorization determines user permissions, controlling what actions they can take over the established connection.
- These mechanisms are vital for protecting your real-time applications from unauthorized access and actions.
자주 묻는 질문
“인증과 권한 부여” 강의는 무료인가요?
네 — “인증과 권한 부여” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 WebSockets & Realtime Systems Programming 강의 전체를 잠금 해제할 수 있습니다. WebSockets & Realtime Systems Programming 강의에는 총 4개의 강의가 포함되어 있습니다.
“인증과 권한 부여”에서 뭘 배우나요?
핸드셰이크 과정에서 인증 메커니즘(예: JWT)을 통합하고 WebSocket 메시지에 대한 사용자 권한을 관리합니다. 브라우저에서 직접 실행하는 실습 코드로 WebSockets & Realtime Systems Programming을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
WebSockets & Realtime Systems Programming을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 WebSockets & Realtime Systems Programming은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 2번째 강의입니다.
“인증과 권한 부여” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 WebSockets & Realtime Systems Programming 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 WebSockets & Realtime Systems Programming 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.