According to documentation:
The SecurityContextHolder is populated with the user within the simpUser header attribute for any inbound request.
Once set on CONNECT request, the user (simpUser) will be stored in the websocket session and no more authentication will be required on further messages.
Where is the simpUser header taken from?