Replaces the chat poll-every-3-seconds compromise with a real
WebSocket pipeline. Server side:
`realtime.mjs`:
- In-memory hub mapping `userId → Set<WebSocket>`. Single-process,
zero external deps; fine for the local demo. A clustered deployment
would swap in Redis pub/sub behind the same surface.
- `attach(userId, socket)` registers a socket and self-detaches on
close/error.
- `broadcast(userIds, event)` JSON-encodes once and dispatches to
every subscriber of every listed user, swallowing per-socket errors.
`server.mjs`:
- Adds a `WebSocketServer({ noServer: true })` that listens on the
HTTP server's `'upgrade'` event for `/api/realtime` paths.
- Authentication mirrors the HTTP path: extract `dating_session` from
the upgrade request's `Cookie` header, pass through `currentSession`
and reject with 401 if it doesn't resolve.
- Rejects upgrades from origins outside the CORS allowlist (the
cookie-based auth is the second line of defence; origin gating is
the first).
- On accept, attaches the socket to the hub and sends a `hello`
envelope so the client can confirm authentication round-trip.
`routes.mjs:messagesPost`:
- After persisting a new message, calls
`broadcast(relationIds(match.users), { type: 'dating.message.created',
message: view })`. Both members (sender and counterpart) get the
push, so multi-device sessions stay in sync.
Adds `ws` (8.20) + `@types/ws` to dependencies.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>