If someone ends up actually doing this in a production system, remember to not to log the accessToken if you're logging full paths/URIs somewhere, as query params usually is a part of that type of logging.
Matt, Ably co-founder
Best solution might be to generate a short-lived one-time-use ticket and pass it in the querystring.
However, websockets are not subject to the same-origin policy, so this exposes you to CSRF [1]. To protect against that, you should check the Origin header on the server side.
[1] https://christian-schneider.net/CrossSiteWebSocketHijacking....
I'm sure there are repercussions to this on the client-side, but I haven't gotten to that point yet. I'm still writing the server and testing it using automated integration tests.
The first websocket message is the original request, which will have the users cookies / headers where your session information / bearer token should live.