runSecureClient A secure replacement for Network.WebSockets.runClient.
let app _connection = return ()runSecureClient "echo.websocket.org" 443 "/" app
:: a typeCtrl KGHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27
Modulewuss-2.0.1.9Haskell2010
Wuss is a library that lets you easily create secure WebSocket clients over the WSS protocol. It is a small addition to the websockets package and is adapted from existing solutions by @jaspervdj, @mpickering, and @elfenlaid.
import Wuss
import Control.Concurrent (forkIO)
import Control.Monad (forever, unless, void)
import Data.Text (Text, pack)
import Network.WebSockets (ClientApp, receiveData, sendClose, sendTextData)
main :: IO ()
main = runSecureClient "echo.websocket.org" 443 "/" ws
ws :: ClientApp ()
ws connection = do
putStrLn "Connected!"
void . forkIO . forever $ do
message <- receiveData connection
print (message :: Text)
let loop = do
line <- getLine
unless (null line) $ do
sendTextData connection (pack line)
loop
loop
sendClose connection (pack "Bye!")Note that it is possible for the connection itself or any message to fail and need to be retried. Fortunately this can be handled by something like the retry package. See this comment for an example.
runSecureClient A secure replacement for Network.WebSockets.runClient.
let app _connection = return ()runSecureClient "echo.websocket.org" 443 "/" app
runSecureClientWith :: (MonadIO m, MonadMask m)=> HostNameHost
-> PortNumberPort
-> StringPath
-> ConnectionOptionsOptions
-> HeadersHeaders
-> ClientApp aApplication
-> m aA secure replacement for Network.WebSockets.runClientWith.
let options = defaultConnectionOptionslet headers = []let app _connection = return ()runSecureClientWith "echo.websocket.org" 443 "/" options headers app
If you want to run a secure client without certificate validation, use
Network.WebSockets.runClientWithStream. For example:
let host = "echo.websocket.org"
let port = 443
let path = "/"
let options = defaultConnectionOptions
let headers = []
let tlsSettings = TLSSettingsSimple
-- This is the important setting.
{ settingDisableCertificateValidation = True
, settingDisableSession = False
, settingUseServerName = False
}
let connectionParams = ConnectionParams
{ connectionHostname = host
, connectionPort = port
, connectionUseSecure = Just tlsSettings
, connectionUseSocks = Nothing
}
context <- initConnectionContext
connection <- connectTo context connectionParams
stream <- makeStream
(fmap Just (connectionGetChunk connection))
(maybe (return ()) (connectionPut connection . toStrict))
runClientWithStream stream host path options headers $ \ connection -> do
-- Do something with the connection.
return ()Configures a secure WebSocket connection.
ConfigconnectionGet :: Connection -> IO ByteStringHow to get bytes from the connection. Typically connectionGetChunk, but could be something else like connectionGetLine.
The default Config value used by runSecureClientWith.
runSecureClientWithConfig :: (MonadIO m, MonadMask m)=> HostNameHost
-> PortNumberPort
-> StringPath
-> ConfigConfig
-> ConnectionOptionsOptions
-> HeadersHeaders
-> ClientApp aApplication
-> m aRuns a secure WebSockets client with the given Config.