Skip to main content

Module push

Module push 

Source
Expand description

Web push notifications: messages a browser shows even when the app’s page is closed (the Push API, with the service worker of ocre g pwa).

The browser subscribes with the app’s public VAPID key and hands the app a Subscription: an endpoint at its push service (Google’s for Chrome, Apple’s for Safari, Mozilla’s for Firefox) and the keys to encrypt for it. send encrypts the message (aes128gcm, RFC 8291), signs the request with the app’s private VAPID key (RFC 8292) and posts it to the endpoint: one subrequest per subscription. A subscription the push service answers 404 or 410 to is gone (Sent::Gone): delete it.

Settings: VAPID_PUBLIC_KEY and VAPID_SUBJECT (mailto: or https: contact, required by push services) are variables, VAPID_PRIVATE_KEY a secret; VapidKeys::generate (or ocre g push) makes a pair.

CPU: each message takes three P-256 operations in WebAssembly (an ephemeral key, the key agreement, the VAPID signature), the costliest part of sending (not yet measured on Workers): send to many subscribers from a job, a batch per run, rather than in a request.

Structs§

Subscription
What a browser’s PushSubscription.toJSON() gives: where and how to push to it.
SubscriptionKeys
The browser’s public key and authentication secret, URL-safe base64.
VapidKeys
A VAPID key pair, URL-safe base64 without padding.

Enums§

Sent
What the push service did with a message.

Constants§

MAX_PAYLOAD
Largest message, in bytes: one 4,096-byte record less the encryption’s overhead.
VAPID_PRIVATE_KEY
Worker secret holding the private VAPID key (URL-safe base64, 32 bytes).
VAPID_PUBLIC_KEY
Worker variable holding the public VAPID key (URL-safe base64), which browsers subscribe with.
VAPID_SUBJECT
Worker variable holding the contact push services may write to: mailto:you@example.com or an https: URL.

Functions§

encrypt
Encrypts payload for a subscription (aes128gcm content coding, RFC 8291), with a new key and salt.
message
The message the service worker of ocre g pwa shows: {"title", "options": {"body", "data": {"path"}}}; clicking the notification opens path.
send
Encrypts message (JSON, e.g. message) for subscription and posts it to its push service, signed with the app’s VAPID keys. The push service keeps it up to ttl seconds while the browser is offline. One subrequest.
vapid_authorization
The Authorization header of a push to endpoint (VAPID, RFC 8292): vapid t=<JWT signed with ES256>, k=<public key>, valid 12 hours.