Close public collaboration sockets after the frame limit #270

Open
opened 2026-09-27 21:10:09 +00:00 by kayg · 1 comment
Owner

Evidence

In the local adversarial run on 2026-09-27, the public-edit WebSocket probe sent 301 empty binary frames from one guest and IP in a minute. The probe expected the socket to close after the 300-frame limit. It remained open for the probe's 10 second close check.

The server stayed alive. Other API work was slow during this mixed-load run, so please first confirm this on a less loaded local server. Then ensure an over-limit frame is rejected and the socket closes or is otherwise terminated promptly, with guest presence cleaned up.

## Evidence In the local adversarial run on 2026-09-27, the public-edit WebSocket probe sent 301 empty binary frames from one guest and IP in a minute. The probe expected the socket to close after the 300-frame limit. It remained open for the probe's 10 second close check. The server stayed alive. Other API work was slow during this mixed-load run, so please first confirm this on a less loaded local server. Then ensure an over-limit frame is rejected and the socket closes or is otherwise terminated promptly, with guest presence cleaned up.
Author
Owner

Duplicate of #223: both report the public-edit WebSocket staying open after 301 empty binary frames, with the 300-frame per-link/IP limit and a 10-second close check. This issue adds the expected guest-presence cleanup. Recommend keeping #270 as the tracking issue and linking #223 as repeated evidence.

Duplicate of #223: both report the public-edit WebSocket staying open after 301 empty binary frames, with the 300-frame per-link/IP limit and a 10-second close check. This issue adds the expected guest-presence cleanup. Recommend keeping #270 as the tracking issue and linking #223 as repeated evidence.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#270
No description provided.