Well, to come back to Georg's point of not deprecating BOSH until we have a solution, it seems that XEP-0397 would need to be included in the compliance suite, at least for this particular use-case (maintaining anonymous logins
over websocket).

Well, as I already said, the issue with anonymous logins and XEP-0198 resumption already exists for "normal" TCP/TLS c2s connections. It's unrelated to websockets.

