Browsers set the "Origin" header for ws:// calls, and the websocket servers are expected to check that. Without the check, it'd be possible to issue blind writes (CSRF) from random webpages to the ws:// endpoints. If you're using main site authentication with a separate websocket domain and auth'd requests, all garden variety security scanners will flag the separate websocket domain as a problem, and only the robust ones actually try to validate the server side configuration.
Disclosure: I have triaged and responded to a few of such reports.
> Browsers set the "Origin" header for ws:// calls, and the websocket servers are expected to check that.
I know that, but as always insecure by default protocols are terrible, and are guaranteed to be exploited beyond recognition... The question is why not be secure by default and force servers to whitelist origins they expect to talk to?
That's probably because websockets require asynchronous servers optimizing for number of active connections, while normal sites are best served by servers optimized for response time.
Of course, you can have both handled by the same origin, but it's not the blatantly obvious way.
index.html:
<html>
<head></head>
<body>
<div id="message"></div>
<script>
let ws = new WebSocket("ws://localhost:5000/");
ws.onopen = () => ws.send("hello server!");
ws.onmessage = ev => {
const $message = document.getElementById("message");
$message.textContent = `ws://localhost:5000/ response: ${ev.data}`;
};
</script>
</body>
</html>
server.js: const express = require("express");
const http = require("http");
const WebSocket = require("ws");
const app = express();
const server = http.createServer(app);
const wss = new WebSocket.Server({ server });
wss.on("connection", ws => {
ws.on("message", message => {
console.log(`received: ${message}`);
ws.send("hello client");
});
});
server.listen(5000, () => console.log("ws server listening on localhost:5000"));
Server runs on localhost:5000. Now serve index.html from any other origin and see it talk to the server without any problem.