spring-projects / spring-projects/spring-security
SEC-3006: Allow programmatically login using STOMP messaging
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Alex (Migrated from SEC-3006) said:
Currently it's not possible to authenticate a user inside a @MessageMapping method.
I suppose the problem is that if in the body of the method we manually call SimpMessageHeaderAccessor.setUser(...) then the user destination changes and he stops receiving messages sent to the queues it was subscribed to.
If there are no workaround for this, a clean solution would be welcome.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing authentication inside @MessageMapping methods and reviewing how SimpMessageHeaderAccessor.setUser(...) affects user destinations and existing queue subscriptions. The work is done when a user can authenticate programmatically through STOMP without losing messages from queues they subscribed to.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100