Channels & presence
Private channel
A private channel requires backend authorization before a client can subscribe, allowing an application to restrict realtime events to permitted users.
Also found under: Restricted channel
How it works
The backend authenticates the requester, checks permission for the requested resource and returns a signed subscription response. Signing any requested channel merely because a user is logged in defeats the restriction. Private access also does not automatically mean end-to-end encrypted message content.
In a Pubb integration
Pubb private channel names start with private-. The authorization flow binds a signature to the requesting socket ID and channel name, with the app secret kept on the server.
Understand channel accessA practical example
Before signing a subscription to private-user-42, verify that the current session belongs to user 42 or has an explicit permission to receive those events.