Theia API Documentation v1.74.0
    Preparing search index...

    Validates WebSocket and HTTP requests using a cookie-based connection token.

    In browser deployments, the server generates a random token at startup and sets it as a SameSite=Strict; HttpOnly cookie on the first page load. Cross-origin pages cannot obtain or send this cookie, so their requests are rejected.

    The cookie is bootstrapped for every HTTP request (via expressMiddleware) so that browsers always receive it, but HTTP requests are only rejected on routes that opt in to enforcement via validateRequest (see HttpConnectionValidator). WebSocket upgrades are always validated (see allowWsUpgrade).

    This complements the origin validator: non-browser callers that omit the Origin header (e.g. Node.js scripts) still cannot reach the backend without the cookie.

    Skipped in Electron deployments (which use their own ElectronSecurityToken).

    Implements

    Index

    Constructors

    Properties

    browserConnectionToken: BrowserConnectionToken
    earlyMiddleware: EarlyExpressMiddleware

    Methods