Skip to content

Maintenance: Document the FQDN requirement for the real-time channel. - #933

Merged
ralf401 merged 1 commit into
pre-releasefrom
rsc/maintenance/fqdn-realtime-origin
Oct 8, 2026
Merged

ralf401 merged 1 commit into
pre-releasefrom
rsc/maintenance/fqdn-realtime-origin

Conversation

@ralf401

@ralf401 ralf401 commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

The legacy WebSocket authenticates from the session cookie of its handshake and only trusts it when the Origin header matches <http_type>:// (lib/sessions/event/login.rb in zammad/zammad; see also the BREAKING_CHANGES.md entry "The legacy WebSocket login is authenticated from the session cookie and signshow no longer returns session_id").

An instance opened with an IP address or with a host name that differs from the FQDN setting therefore has no authenticated real-time channel, which shows up as ticket changes that cannot be saved. The webserver configuration page now states the requirement for server_name and ServerName, and the troubleshooting section names the symptom.

The legacy WebSocket authenticates from the session cookie of its handshake and only trusts it when the Origin header matches <http_type>://<fqdn> (lib/sessions/event/login.rb in zammad/zammad; see also the BREAKING_CHANGES.md entry "The legacy WebSocket login is authenticated from the session cookie and signshow no longer returns session_id").

An instance opened with an IP address or with a host name that differs from the FQDN setting therefore has no authenticated real-time channel, which shows up as ticket changes that cannot be saved. The webserver configuration page now states the requirement for server_name and ServerName, and the troubleshooting section names the symptom.
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Artifacts

Produced during runtime

📦 html-896761b

@ralf401
ralf401 merged commit b83ac00 into pre-release Oct 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant