Expand description
WebSocket accept + authorization handshake.
Upgrades an accepted TCP stream to a WebSocket, gating on the
x-claude-code-ide-authorization header. A mismatched token is
rejected during the handshake with HTTP 401 — the connection never
reaches the MCP loop. Loopback bind + this token are the security
boundary (design §4).
Functions§
- accept
- Accept a WebSocket connection on
stream, requiring thex-claude-code-ide-authorizationheader to matchexpected_token(constant-time). Rejects with HTTP 401 otherwise — the returned future resolves to an error and the connection is dropped.