Vert.x WebSocket + JWTAuthHandler: enforcing least-privilege after a token expires mid-connection
We are integrating vertx-auth-jwt with a Vert.x 4.x HTTP server that upgrades some routes to long-lived WebSocket connections. Initial authentication works: JWTAuthHandler validates the signature and standard claims, and per-route AuthorizationHandler instances enforce PermissionBasedAuthorization so each endpoint only requires the one permission it needs. T