# WSS Authentication failure

**URL:** <https://forums.suse.com/t/wss-authentication-failure/3874>\
**Category:** Rancher 1.x\
**Created:** [September 1, 2016, 2:02pm UTC](https://forums.suse.com/t/wss-authentication-failure/3874 "2016-09-01T14:02:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![olds463](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/olds463/32/7318_2.png) [@olds463](https://forums.suse.com/u/olds463)\
**Post date:** [September 1, 2016, 2:02pm UTC](https://forums.suse.com/t/wss-authentication-failure/3874/1 "2016-09-01T14:02:21Z")

</div>

Howdy,

I have an nginx proxy infront of my rancher instance serving HTTPS which is setup per the rancher documentation. I am trying to authenticate to a WSS socket at myhost/v1/projects/1a39/subscribe?eventNames=resource.change.

Using HTML5 websockets my connection string is like so:

```
var ws = new WebSocket("wss://apikey:secretkey@myhost/v1/projects/1a39/subscribe?eventNames=resource.change");

```

However, in javascript console I receive the following error:

> failed: HTTP Authentication failed; no valid credentials available

I am basing this off of [this gist](https://gist.github.com/vincent99/491afed2306ba448dd89)

What am I doing wrong here?

---

<div class="post-metadata">

**Author:** ![olds463](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/olds463/32/7318_2.png) [@olds463](https://forums.suse.com/u/olds463)\
**Post date:** [September 1, 2016, 3:22pm UTC](https://forums.suse.com/t/wss-authentication-failure/3874/2 "2016-09-01T15:22:27Z")

</div>

so it turns out most browsers dont support the authorization header for Websockets, which is this issue. One way I can determine is to pass a JWT token into the URL, but how does this work with the API? Posting to /v1/token requires a local user?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [September 1, 2016, 3:42pm UTC](https://forums.suse.com/t/wss-authentication-failure/3874/3 "2016-09-01T15:42:54Z")

</div>

Token takes a `code`, which has a meaning that depends on the auth provider configured, but it is not possible to generate a token from an API key.

The straightforward solution is to proxy the request and add the authorization header there; here’s the proxy that’s in the UI for development: [https://github.com/rancher/ui/blob/master/server/proxies/api.js#L18-L25](https://github.com/rancher/ui/blob/master/server/proxies/api.js#L18-L25)

---

<div class="post-metadata">

**Author:** ![olds463](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/olds463/32/7318_2.png) [@olds463](https://forums.suse.com/u/olds463)\
**Post date:** [September 1, 2016, 3:51pm UTC](https://forums.suse.com/t/wss-authentication-failure/3874/4 "2016-09-01T15:51:49Z")

</div>

Thanks @vincent. Kind of the solution I thought of when fetching lunch. Wasn’t sure if their was a more native approach or not.

Regards
