Hacker News new | ask | show | jobs
by syspec 1619 days ago
Yeah this is the technique I've also used.

The first websocket message is the original request, which will have the users cookies / headers where your session information / bearer token should live.