Go WebRTC Contract Tests: Five Presence Signals for Realtime Auction Bidders
Short answer: make presence a tested, expiring claim and attach every bidder notification to a versioned authorization envelope. For a live auction dashboard, this gives the server a defensible answer to "may this bidder see this event now?" instead of treating an open WebRTC channel as permission. The useful unit is a decision record, not a socket. It should survive reconnects, replay, and a…
To ensure real-time auctions are conducted fairly, presence must be tested as an expiring claim attached to each bidder. This approach answers the question of which bidder can see a specific event now rather than treating an open WebRTC channel as permission. The core of this contract testing is a decision record, which remains valid even if connections are reestablished, replayed, or disconnected late without altering its meaning.
Before delivery, a realtime bidder contract must prove five signals: authenticated audience, auction membership, session version, expiry, and sequence. The notification body details what happened, while the envelope specifies why this recipient can receive it and where it fits within the stream. To prevent unauthorized access, opaque IDs should be used, with each event assigned an immutable ID for deduplication, along with bidder ID, auction ID, schema version, policy version, session version, and a monotonic sequence in a documented scope.
Both the issue and expiry times clarify freshness. The policy version and session version help answer different questions about which rule allowed the event and which connection lease was current at the time.
The provided Go code defines a `notification` package that implements a contract for dashboard notifications. The `Envelope` struct contains essential information such as the event ID, schema version, policy version, auction ID, bidder ID, session version, sequence, and timestamps indicating when the envelope was issued and expires. The `BidNotice` struct specifies the details of the bid, including its kind, amount in minor currency units, and currency.
In this system, each connection is treated as a renewable lease with a session version. A heartbeat extends the lease, while a disconnect only terminates the connection if its session version still matches the current one. This process guards against outdated closes erasing newer connections. The code includes an `Authorize` function that checks various conditions to ensure the envelope's validity, returning specific errors if any checks fail.
These checks include verifying the authenticity of the bidder, confirming membership in the auction, ensuring the envelope has not expired, matching the current session version, and ensuring the sequence number is not out of order. These checks prevent false online or offline scenarios and ensure deterministic outcomes, even in edge cases.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.