SSE and WebSocket handlers often authorize once when the connection opens, then push events for minutes or hours. That first check is not a standing grant. While the stream is open, membership can be revoked, a role narrowed, or the resource moved out of the subject's scope. If you only gate the handshake, later events can leak data the subject is... Weiterlesen: A long-lived stream is not a standing permission grant
Intelligence View
⚡ tsecurity.de Intelligence
A long-lived stream is not a standing permission grant
SSE and WebSocket handlers often authorize once when the connection opens, then push events for minutes or hours. That first check is not a standing grant.…