Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecuritySchutz vor DDoS-Angriffen beim Zocken - WindowsPower.de(29.09.2026 um 17:36 Uhr)
••
Unix & Linux ServerLinux May Soon Work on Snapdragon X2-Based PCs(29.09.2026 um 20:49 Uhr)
•
Sicherheitslücken (CVE)USN-8847-1: OpenSSL vulnerabilities(29.09.2026 um 20:19 Uhr)
•
Sichere ProgrammierungRepository custom runner settings for Dependabot(29.09.2026 um 21:10 Uhr)
•
Sichere ProgrammierungRead the papers behind it: 7 free resources(29.09.2026 um 21:11 Uhr)
•
Sichere ProgrammierungHelp a kid start coding: 13 free resources(29.09.2026 um 21:11 Uhr)
•
AI & KI NachrichtenGet good with a specific AI model: 19 free resources(29.09.2026 um 21:12 Uhr)
•
Sichere ProgrammierungI couldn't find a good Google Trends MCP. So I just built one(29.09.2026 um 21:12 Uhr)
•
Sichere ProgrammierungSynchronous & Event Driven(29.09.2026 um 21:13 Uhr)
•
Windows Tipps & SecuritySchutz vor DDoS-Angriffen beim Zocken - WindowsPower.de(29.09.2026 um 17:36 Uhr)
••
Unix & Linux ServerLinux May Soon Work on Snapdragon X2-Based PCs(29.09.2026 um 20:49 Uhr)
•
Sicherheitslücken (CVE)USN-8847-1: OpenSSL vulnerabilities(29.09.2026 um 20:19 Uhr)
•
Sichere ProgrammierungRepository custom runner settings for Dependabot(29.09.2026 um 21:10 Uhr)
•
Sichere ProgrammierungRead the papers behind it: 7 free resources(29.09.2026 um 21:11 Uhr)
•
Sichere ProgrammierungHelp a kid start coding: 13 free resources(29.09.2026 um 21:11 Uhr)
•
AI & KI NachrichtenGet good with a specific AI model: 19 free resources(29.09.2026 um 21:12 Uhr)
•
Sichere ProgrammierungI couldn't find a good Google Trends MCP. So I just built one(29.09.2026 um 21:12 Uhr)
•
Sichere ProgrammierungSynchronous & Event Driven(29.09.2026 um 21:13 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

When your Phoenix socket has no identity at all (and why that was the right call)

Most Phoenix Channel tutorials assume the socket carries an authenticated identity — a user token, a session cookie, something that connect/3 validates. That's the path of least resistance and it works for 95% of apps. I ended up writing o…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Most Phoenix Channel tutorials assume the socket carries an authenticated identity — a user token, a session cookie, something that connect/3 validates. That's the path of least resistance and it works for 95% of apps.



I ended up writing one where it was actively wrong.






The setup



I was building a zero-knowledge messaging app — two people share a secret and talk through a web channel, and the entire threat model hinges on the server not knowing who is talking to whom. If the socket had any durable identity, it would become a correlatable identifier. That identifier would exist in logs, in crash dumps, in whatever the BEAM's Process.info returns during a hot debug session.



I needed a socket the server literally could not identify.






The code



It turns out this is shorter than the normal path:




defmodule MyAppWeb.AnonSocket do
use Phoenix.Socket
channel "anon_room:*", MyAppWeb.AnonRoomChannel

@impl true
def connect(_params, socket, _connect_info), do: {:ok, socket}

@impl true
def id(_socket), do: nil
end






That's it. connect/3 accepts everyone. id/1 returns nil, which tells Phoenix.Socket there is no identifier to use for per-user broadcasts. The socket is equally anonymous to Phoenix and to anyone reading the code.






Where auth actually lives



All access control moves into Channel.join/3:




def join("anon_room:" <> room_hash, params, socket) do
%{"access_hash" => access_hash, "sender_hash" => sender_hash} = params

with :ok <- validate_hex(room_hash),
:ok <- validate_hex(access_hash),
:ok <- validate_hex(sender_hash),
{:ok, room} <- Rooms.get_active_room(room_hash),
:ok <- Rooms.verify_access(room_hash, access_hash) do
{:ok, assign(socket, room: room, sender_hash: sender_hash)}
else
_ -> {:error, %{reason: "unauthorized"}}
end
end






The three hashes are all SHA-256 hex strings computed client-side from a shared secret. The server verifies them against its database but never sees the secret itself.






What you give up



Phoenix's per-user utilities stop working because there is no "user":





  • Phoenix.PubSub keyed by socket.id — doesn't apply; there's nothing to key on.


  • Presence tracking by user ID — works only at the topic level (who is in anon_room:<hash>), not across topics for the same user.


  • Server-side rate limiting by identity — you have to fall back to IP-based rate limiting at the endpoint/plug layer, since the channel has no identity to throttle.






What you keep




  • The channel itself still works normally — push, broadcast-to-topic, handle_in, all of it.

  • You can still store assigns per-socket (assign(socket, room: room)). You just can't share identity across sockets for the same user.

  • A smaller attack surface: a socket that never authenticates cannot leak authentication state.






The useful mental model



Normal Phoenix sockets are like a long-lived session: you log in once, then every channel inherits that identity. The sessionless variant is more like a capability-URL system — each channel join carries its own bearer credentials, and the socket is just a pipe.



For most apps this is unnecessary complication. For apps where the socket mustn't correlate activity across channels, it's the simpler mental model.






If you've got a use case where this pattern fits, I'd love to hear about it — I've only seen it come up a couple of times. (The app that drove this design: sTELgano, AGPL-3.0.)

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten When your Phoenix socket has no identity at all (and why that was the right call)

Thematisch verwandte Begriffe: When, your, Phoenix, socket · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-102714 | `_nx_icmpv6_validate_options()` scans the option area with `while (leng…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag