aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/revocation.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/revocation.py3
1 files changed, 2 insertions, 1 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
index 5a33d77..2499374 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/revocation.py
@@ -438,7 +438,8 @@ async def _authorize_node_ws(token: str, claimed_id: str, claimed_groups) -> tup
@router.websocket("/v1/nodes/ws")
async def node_websocket(ws: WebSocket):
"""
- Persistent WebSocket connection for nodes.
+ Persistent WebSocket connection for nodes, authenticated by the node's token in the
+ first message.
Finding C2: this used to take `node_id` and `group_ids` straight from the
client's first message, with no check that the authenticated user owned that