authorize or
onAttach (or webSocket
itself) and the default webSocket serves the agent socket protocol for you, no
AgentSocketServer wiring
required — overriding
onConnect alone does
not activate it. The default authorize admits every connection as a
read-only watcher — remote @rpc()
calls require an explicit authorize override that validates the credential and
grants "rpc" deliberately.