I am developing a Spring Boot web application which uses WebSockets via the spring-boot-starter-websocket package and is deployed to AWS Elastic Beanstalk. When I go the the http version of the page everything works perfectly, but when I try to connect with https I can't establish a WebSocket connection. Specifically, the sockjs client I have in my frontend continually retries with wss, xhr, and other fallback protocols. The wss requests have no response, and the other requests get either 403 or 404 status codes. I haven't been able to find anyone with a similar issue, so I don't have any idea what the problem might be.
Here are the configuration files that might be relevant:
@Configuration
@EnableWebSocketMessageBroker
public class WebSocketConfig implements WebSocketMessageBrokerConfigurer {
@Override
public void configureMessageBroker(MessageBrokerRegistry config) {
config.enableSimpleBroker("/topic");
config.setApplicationDestinationPrefixes("/api/socket");
}
@Override
public void registerStompEndpoints(StompEndpointRegistry registry) {
registry.addEndpoint("/api/websocket").withSockJS();
}
}
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
@Autowired
private ExternalAuthenticationProvider externalAuth;
@Autowired
private InMemoryAuthenticationProvider internalAuth;
@Override
protected AuthenticationManager authenticationManager() throws Exception {
return new ProviderManager(List.of(externalAuth, internalAuth));
}
@Override
protected void configure(HttpSecurity http) throws Exception {
http.httpBasic()
.and().csrf()
.ignoringAntMatchers("/api/websocket/**")
.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse())
.and().authorizeRequests()
.antMatchers("/api/websocket/**").permitAll()
.antMatchers("/api/activity/host/**").authenticated()
.antMatchers("/api/activity/**").permitAll()
.antMatchers("/api/users").hasRole("ADMIN")
.antMatchers("/api/users/*").hasRole("ADMIN")
.antMatchers("/api/**").authenticated()
.anyRequest().permitAll()
.and().logout()
.logoutUrl("/api/auth/logout")
.invalidateHttpSession(true)
.permitAll();
}
}
This is the endpoint I am trying to hit while debugging:
@Controller
public class SocketController {
@MessageMapping("/test")
@SendTo("/topic/test")
public String testConnection() {
return "CONNECTED";
}
}
If there is any other details that might be helpful to diagnose my issue, please let me know. I have been messing around with this for weeks and can't figure it out.