spring-projects / spring-projects/spring-security
SEC-3119: Allow extending SecurityContextChannelInterceptor
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Allar Saarnak (Migrated from SEC-3119) said:
Currently it's not possible to extend SecurityContextChannelInterceptor, because it's final.
Extending SecurityContextChannelInterceptor would be useful for authenticating from custom headers, like custom token.
Useful when overriding method: org.springframework.security.config.annotation.web.socket.AbstractSecurityWebSocketMessageBrokerConfigurer#securityContextChannelInterceptor
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with SecurityContextChannelInterceptor and the securityContextChannelInterceptor override point in AbstractSecurityWebSocketMessageBrokerConfigurer. Check how the interceptor is declared and how WebSocket message security configures it; done means custom subclasses can support custom-header authentication without breaking existing behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100