Skip to content

🔒️(yprovider) readOnly connections awareness propagation - #2544

Open
AntoLC wants to merge 2 commits into
mainfrom
secu/block-awareness-when-reader
Open

🔒️(yprovider) readOnly connections awareness propagation#2544
AntoLC wants to merge 2 commits into
mainfrom
secu/block-awareness-when-reader

Conversation

@AntoLC

@AntoLC AntoLC commented Jul 29, 2026

Copy link
Copy Markdown
Collaborator

Purpose

We noticed that a read-only connection was still able to propagate awareness updates (cursor/selection presence) to other clients, even though connectionConfig.readOnly already blocked document sync updates.

Override MessageReceiver.apply to no-op for any read-only connection instead of delegating to the original implementation, so neither document updates nor awareness updates ever propagate from it.
The connection itself is left open; only the message is dropped.

@AntoLC AntoLC self-assigned this Jul 29, 2026
@AntoLC
AntoLC force-pushed the secu/block-awareness-when-reader branch 2 times, most recently from d13c89a to 487411f Compare July 29, 2026 12:45
@AntoLC
AntoLC requested a review from lunika July 29, 2026 14:06
@AntoLC
AntoLC requested a review from dmonad August 6, 2026 08:15
@dmonad

dmonad commented Aug 6, 2026

Copy link
Copy Markdown
Collaborator

Looks good! I will add an option to ignore awareness messages in yhub as well.

The one thing to look out for is whether the connection resets regularly. y-websocket-server, for example, will disconnect the user if it did not receive an update from that user.

AntoLC added 2 commits August 11, 2026 15:54
We noticed that a read-only connection was still able
to propagate awareness updates (cursor/selection presence)
to other clients, even though connectionConfig.readOnly
already blocked document sync updates.

Override MessageReceiver.apply to no-op for any read-only
connection instead of delegating to the original
implementation, so document awareness updates never propagate
from it.
The connection itself is left open; only the
awareness is dropped.
@AntoLC
AntoLC force-pushed the secu/block-awareness-when-reader branch from 487411f to a035fea Compare August 11, 2026 14:32
@AntoLC

AntoLC commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator Author

Looks good! I will add an option to ignore awareness messages in yhub as well.

The one thing to look out for is whether the connection resets regularly. y-websocket-server, for example, will disconnect the user if it did not receive an update from that user.

@dmonad - Thank you for the review - Yes you were right, the ping pong to keep the connection alive was based on awareness , at least in Hocuspocus v3.4.4, I think they change this mechanism in their last version (>v4).

I did a fixup commit - when we get a awareness message from readOnly connection, we still intercept it, but send our own awareness message to keep this ping pong mechanism.

Wdyt ?

@dmonad

dmonad commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

Please investigate if that fixes the issue. y-websocket doesn't disconnect, it is the server that disconnects after a timeout. Returning the awareness message to the client might not help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants