Skip to content

fix(ws): proper websocket handle types - #846

Merged
kettanaito merged 1 commit into
mainfrom
fix/websocket-handle-types
Sep 25, 2026
Merged

kettanaito merged 1 commit into
mainfrom
fix/websocket-handle-types

Conversation

@kettanaito

Copy link
Copy Markdown
Member

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: f68c1fc1-ff6b-4b66-ac6b-6f5c9424369f

📥 Commits

Reviewing files that changed from the base of the PR and between 1c93e05 and fe08adb.

📒 Files selected for processing (3)
  • src/events/websocket.ts
  • src/interceptors/WebSocket/index.ts
  • src/interceptors/WebSocket/web-socket-extension.ts

Included review availability: Your plan provides up to 4 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

WebSocket event data and extension APIs now use client and server handle types. Intercepted connection events retain local connection types, and the interceptor module re-exports the intercepted connection type.

Changes

WebSocket connection typing

Layer / File(s) Summary
Event data and intercepted connection types
src/events/websocket.ts
WebSocketConnectionEventData now types its client and server as handles. WebSocketInterceptedConnection narrows them to local connection classes, and WebSocketConnectionEvent uses that type.
Handle types in extension APIs
src/interceptors/WebSocket/web-socket-extension.ts, src/interceptors/WebSocket/index.ts
Extension contexts and the apply method now accept handles. The interceptor module re-exports WebSocketInterceptedConnection and uses it for the connection setup context.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to fe08a

No actionable issue is established for the WebSocket typing change; it is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to fe08a

The public types now accept WebSocket handles, but the reviewed interception path still creates and emits its own concrete connections. No new security exposure was established. Compatibility with extensions outside the repository remains uncertain.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated effect is on WebSocket consumer types, not on an additional service, credential, or connection-creation path. An extension still receives control of the interceptor-created connection pair when selected.

Trust Boundaries and Controls

  • inferred — No new attacker-to-extension authority transition is established in the reviewed path: extension matching and application still precede event emission and operate on the same interceptor-owned connections. This conclusion does not cover arbitrary external handle implementations.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: correcting WebSocket handle types.
Description check ✅ Passed The description identifies related Cloudflare and MSW work, which is relevant to the WebSocket type changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 3…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Sep 25, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/mswjs/interceptors/@mswjs/interceptors@846

commit: fe08adb

@kettanaito
kettanaito merged commit 417bbfc into main Sep 25, 2026
8 checks passed
@kettanaito
kettanaito deleted the fix/websocket-handle-types branch September 25, 2026 13:14
@kettanaito

Copy link
Copy Markdown
Member Author

Released: v0.45.3 🎉

This has been released in v0.45.3.

Get these changes by running the following command:

npm i @mswjs/interceptors@latest

Predictable release automation by Release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant