Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneesstack72

Relationships

#2614 Dashboard live audit stream fails in auth mode none when a token is left in sessionStorage

Opened by stack72 · 9/28/2026· Shipped 9/28/2026

Problem

useAuditStream opens its own WebSocket and presents the stored dashboard token as a bearer subprotocol whenever one exists (packages/dashboard/src/client/useAuditStream.ts, around line 111), regardless of serve's auth mode. In auth mode none serve upgrades without echoing a subprotocol, and Chrome rejects a handshake that requested one but got none back. So with a token left in sessionStorage (for example after serve switched from token mode to none, or a tab that signed in earlier), the live audit stream never connects while the main dashboard socket works.

Reproduction

  1. swamp serve --dashboard --auth-mode token, sign in to the dashboard.
  2. Restart serve with --auth-mode none; the dashboard reconnects without a token (swamp-club#2609).
  3. The audit stream socket is still opened with the bearer subprotocol and fails its handshake, so live audit events stop.

Expected

useAuditStream presents the token only when authMode is not none, matching SwampProvider. Alternatively SwampProvider exposes the protocols it connected with and the hook reuses them.

Found while verifying swamp-club#2609; not introduced by it.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 3 MOREREVIEW+ 7 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/28/2026, 9:38:36 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
stack72 assigned stack729/28/2026, 9:03:35 PM

Sign in to post a ripple.