Splitting HTTP auth and history from WebSocket broadcast makes the architecture easy to follow. The next scaling challenge would be moving room membership out of a single process. Are you planning Redis pub/sub or sticky sessions first?
Nice. Redis pub/sub is a natural next step. I would keep room state behind a small adapter so you can compare in-memory and Redis implementations without changing the WebSocket handlers. That should make the scaling path easier to test.
Julian Neagu
500+ AI tools shipped solo. Founder of VisionVix.
the part about state clicked for me too. building the room map makes the whole websocket flow much easier to reason about