AEROSIM-TS-22
Implement the authenticated Socket.IO gateway
Singularity accepts authorized typed Socket.IO connections, rejects invalid identities and events, and preserves declared event ordering.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-44
- Component
- API Service — Socket.IO gateway
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Attach Socket.IO to the Fastify HTTP server, authenticate the handshake bearer token, validate flight:command, reject non-increasing sequence numbers per connection, return CommandAck, emit flight:state in accepted order, and clear connection state on disconnect. Primary files: applications/api/src/realtime/socket-gateway.ts, applications/api/src/realtime/authenticate-socket.ts, applications/api/src/realtime/flight-command-handler.ts, applications/api/tests/realtime/socket-gateway.test.ts.
Implementation contract
Implementation artifacts
- applications/api/src/realtime/socket-gateway.ts
- applications/api/src/realtime/authenticate-socket.ts
- applications/api/src/realtime/flight-command-handler.ts
- applications/api/tests/realtime/socket-gateway.test.ts
Inputs
- Socket.IO handshake auth {token} resolving to AuthenticatedSubject
- FlightCommand messages defined by @aerosim/realtime-contract
Outputs
- CommandAck {commandId,accepted,sequence,error?}
- Ordered flight:state emissions and released per-socket sequence state after disconnect
Failure boundaries
- Reject the handshake with AUTH_REQUIRED or TOKEN_INVALID before joining a namespace.
- A malformed command receives INVALID_PAYLOAD; a repeated or decreasing sequence receives OUT_OF_ORDER and is not forwarded.
Excluded scope
- The gateway transports commands and state but does not calculate aerodynamics, own authoritative flight state, or persist event history.
Verification steps
- pnpm --filter @aerosim/api test -- socket-gateway.test.ts
- Connect with invalid token, malformed axes, and sequences 2,1,2; assert rejection codes, one accepted forward, and cleanup after disconnect.
Traceability
Dependencies
- AEROSIM-TS-21Canonical ID: TASK-0021
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #32 reviewed head db2f0ece14edaf6606c6099cb6eb58ab6c1bb01f, exact-head validation task 1847 succeeded, merged as fe25ca085e5cd90f41081259dd95c0ef3a0bc3e9; Wave 5 integrated application head e6212bf637045138da191634fe113285156426b3 passed publish task 1856 and validate task 1857. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.