I've been struggling a lot to properly implement Stomp (websocket) Authentication and Authorization with Spring-Security. For posterity i'll answer my own question to provide a guide.
The Problem
Spring WebSocket documentation (for Authentication) looks unclear ATM (IMHO). And i couldn't understand how to properly handle Authentication and Authorization.
What i want
- Authenticate users with login/password.
- Prevent anonymous users to CONNECT though WebSocket.
- Add authorization layer (user, admin, ...).
- Having
Principalavailable in controllers.
What i don't want
- Authenticate on HTTP negotiation endpoints (since most of JavaScript libraries don't sends authentication headers along with the HTTP negotiation call).