SAMMY works best on screens 1024px wide or larger.
V4.4.1
V4.4.1: Verify that WebSocket over TLS (WSS) is used for all WebSocket connections.

Verify that WebSocket over TLS (WSS) is used for all WebSocket connections.

ASVS Maturity
Description

Verify that WebSocket over TLS (WSS) is used for all WebSocket connections.

V4.4.2
V4.4.2: Verify that, during the initial HTTP WebSocket handshake, the Origin header field is checked against a list of origins allowed for the application.

Verify that, during the initial HTTP WebSocket handshake, the Origin header field is checked against a list of origins allowed for the application.

ASVS Maturity
Description

Verify that, during the initial HTTP WebSocket handshake, the Origin header field is checked against a list of origins allowed for the application.

V4.4.3
V4.4.3: Verify that, if the application's standard session management cannot be used, dedicated tokens are being used for this, which comply with the relevant Session Management security requirements.

Verify that, if the application's standard session management cannot be used, dedicated tokens are being used for this, which comply with the relevant Session Management security requirements.

ASVS Maturity
Description

Verify that, if the application's standard session management cannot be used, dedicated tokens are being used for this, which comply with the relevant Session Management security requirements.

V4.4.4
V4.4.4: Verify that dedicated WebSocket session management tokens are initially obtained or validated through the previously authenticated HTTPS session when transitioning an existing HTTPS session to a WebSocket channel.

Verify that dedicated WebSocket session management tokens are initially obtained or validated through the previously authenticated HTTPS session when transitioning an existing HTTPS session to a WebSocket channel.

ASVS Maturity
Description

Verify that dedicated WebSocket session management tokens are initially obtained or validated through the previously authenticated HTTPS session when transitioning an existing HTTPS session to a WebSocket channel.