I have an application where I need two different websocket setups:
- one for allowing communication between the application and remote Java-based clients
- uses stateless comms (auth token is included in each request, also in the websocket connect request)
- csrf needs to be disabled
- one for allowing async push notifications from the application to its own web UI.
- uses normal session authentication
- csrf needs to be, or should preferably be, enabled (correct me if I'm wrong?)
Now, in Spring, to disable cross origin checking for websockets one needs to extend AbstractSecurityWebSocketMessageBrokerConfigurer e.g. as follows:
@Configuration
public class WebSocketSecurityConfig extends AbstractSecurityWebSocketMessageBrokerConfigurer {
@Override
protected void configureInbound(final MessageSecurityMetadataSourceRegistry messages) {
messages.anyMessage().authenticated();
}
@Override
protected boolean sameOriginDisabled() {
return true;
}
}
The question is, how can I have it disabled for some websockets and enabled for others?