我一直在努力用Spring-Security 正确实现Stomp(websocket)身份验证和授权.对于后代,我会回答我自己的问题,提供指导.
Spring WebSocket文档(用于身份验证)看起来不清楚ATM(恕我直言).我无法理解如何正确处理身份验证和授权.
Principal在控制器可用.我正在使用Spring的WebSockets的非常薄的实现.WebSocketSession有方法getPrincipal(),但是如何在HandshakeInterceptor中设置它?
我想把Principal放在的方法是:
public boolean beforeHandshake(final ServerHttpRequest request, final ServerHttpResponse response, final WebSocketHandler wsHandler,
final Map<String, Object> attributes) throws Exception {
Principal = getPrincipal();
// Now where to set the principal so it is available in WebSocketSession?
}
Run Code Online (Sandbox Code Playgroud)