Is the URL itself encrypted as well when using wss://? For example, say you have a simple Sinatra web application that accepts web socket connections:
class App < Sinatra::Base
get "/ws/:api_key/room/:id" do |api_key, id|
user = User.find_by(api_key: api_key)
room = Room.find(id)
if RoomAuthenticator.new(room).authorized?(user)
request.websocket do |ws|
ws.onopen { publish(room, "#{user.name} connected.") }
end
else
401
end
end
end
Then from the client/browser, in JavaScript:
new WebSocket("wss://" + window.location.host + "/ws/" + user.api_key + "/room/" + room.id);
Is the user.api_key in the URL encrypted or is it susceptible to attacks?