|
|
|
|
|
by capableweb
1618 days ago
|
|
> so it's typical instead to have credentials supplied via a query param (such as "accessToken" for a bearer token) in the wss request. If someone ends up actually doing this in a production system, remember to not to log the accessToken if you're logging full paths/URIs somewhere, as query params usually is a part of that type of logging. |
|
Matt, Ably co-founder