We recently had a pen test done and the report came back with a high issue for Cross-Site WebSocket Hijacking. The issue reported relates to once scenario where we use the o:s