- tls-config: allow production HTTP when TERMINATE_TLS_AT_EDGE=1 (matches CT 7800) - websocket: disable perMessageDeflate on graphql-ws server (RSV1 / proxy compatibility) - server: remove unused @fastify/websocket (standalone ws + graphql-ws only) - package: drop @fastify/websocket dependency; refresh lockfile - .env.example: document HOST and TERMINATE_TLS_AT_EDGE for nginx-terminated TLS Made-with: Cursor
64 lines
1.5 KiB
TypeScript
64 lines
1.5 KiB
TypeScript
/**
|
|
* WebSocket server for GraphQL subscriptions
|
|
*/
|
|
|
|
import { WebSocketServer } from 'ws'
|
|
import { useServer } from 'graphql-ws/lib/use/ws'
|
|
import { schema } from '../schema'
|
|
import { createContext } from '../context'
|
|
import { FastifyRequest } from 'fastify'
|
|
import { logger } from '../lib/logger'
|
|
|
|
export function createWebSocketServer(httpServer: any, path: string) {
|
|
const wss = new WebSocketServer({
|
|
server: httpServer,
|
|
path,
|
|
perMessageDeflate: false,
|
|
})
|
|
|
|
const serverCleanup = useServer(
|
|
{
|
|
schema,
|
|
context: async (ctx) => {
|
|
// Create a mock request for context
|
|
const request = {
|
|
headers: ctx.connectionParams?.authorization
|
|
? { authorization: ctx.connectionParams.authorization as string }
|
|
: {},
|
|
} as FastifyRequest
|
|
|
|
return createContext(request)
|
|
},
|
|
onConnect: async (ctx) => {
|
|
// Validate connection - check authentication if needed
|
|
// For now, allow all connections
|
|
return true
|
|
},
|
|
onDisconnect: (ctx, code, reason) => {
|
|
// Handle disconnection
|
|
logger.info('WebSocket client disconnected', { code, reason })
|
|
},
|
|
onError: (ctx, msg, errors) => {
|
|
logger.error('WebSocket error', { message: msg, errors })
|
|
},
|
|
},
|
|
wss
|
|
)
|
|
|
|
// Graceful shutdown
|
|
const shutdown = () => {
|
|
serverCleanup.dispose()
|
|
wss.close()
|
|
}
|
|
|
|
process.on('SIGTERM', shutdown)
|
|
process.on('SIGINT', shutdown)
|
|
|
|
return {
|
|
wss,
|
|
serverCleanup,
|
|
shutdown,
|
|
}
|
|
}
|
|
|