ba0c7bfa9b
The ?token= fallback leaked JWTs in server logs and was never used by the client, which always sends the token via WebSocket subprotocol header.