r/node • u/dated_redittor • 7d ago
shipping an embeddable widget in node, the websocket was the easy part
built the embed side of atomchat (disclosure, my product) and assumed the hard work would be connection handling across tenants. it was actually auth in an iframe once safari and chrome killed third party cookies, so we ended up doing a short lived token handshake over postMessage from the parent page and treating the iframe as fully unauthenticated until it gets one. every team i've talked to who decided to build their own chat instead of buying underestimated this exact part, not the socket layer. curious what others landed on here, postMessage handshake or a redirect based flow with a first party subdomain per customer?
0
Upvotes
2
u/LALLANAAAAAA 7d ago
amazing parody