The reason why this is not allowed is due to poor browser security. WebSockets are cross-domain, which means that, if you authenticate into a WebSocket with cookie/auth headers, an attacker on a completely different website can use the same credentials to open up and control a WebSocket with your credentials on any website.
Even if you plan to use WebSockets outside of the browser, in my humble opinion, just use the x-headers, as otherwise it is not worth introducing such a big hole in your app. If you want to risk it anyway, latest Plug (v1.14+) and Phoenix (v1.7+) allows you to upgrade any connection to a WebSocket, so that could be used instead. Here is an example: GitHub - elixir-plug/plug: Compose web applications with functions · GitHub


















