المصادقة والتفويض
نفّذوا مصادقة مستخدمي WebSocket وتفويض الوصول استنادًا إلى الأدوار والأذونات.
المصادقة والتفويض درس مجاني في WebSockets & Real-Time Systems with Spring على CoddyKit. هذا هو الدرس 3 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في WebSockets & Real-Time Systems with Spring، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة WebSockets & Real-Time Systems with Spring 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
Securing Your Real-Time Interactions
Welcome to the final lesson in securing your WebSocket endpoints! Today, we'll dive into how to authenticate users and authorize their actions.
Authentication is about verifying who a user is (e.g., logging in). Authorization is about determining what an authenticated user is allowed to do (e.g., access admin features).
Both are vital for preventing unauthorized access and ensuring data integrity in your real-time applications.
Bridging HTTP Authentication
When using Spring Security, it cleverly bridges your existing HTTP session authentication to your WebSocket sessions. This means if a user is already logged in via your web application, they are automatically authenticated for WebSocket communication as well.
Spring associates the authenticated user's Principal (representing the user) with their WebSocket session, making it easy to identify who is sending or receiving messages.
Knowing Your WebSocket User
Once a user is authenticated, you can access their Principal object directly within your STOMP message-handling methods. This allows you to personalize responses or log user-specific actions.
Try running this simple Java example to understand the concept of a Principal:
import java.security.Principal;
public class Main {
public static void main(String[] args) {
// In a Spring @MessageMapping method,
// you'd get Principal directly from the framework.
// This simulates an authenticated user for demonstration.
Principal currentUser = () -> "alice@example.com";
System.out.println("Current user: " + currentUser.getName());
}
}Path-Based Access Control
Spring Security provides a powerful way to authorize access to WebSocket destinations (topics or queues) using a MessageMatcherRegistry. This allows you to define rules based on the STOMP destination path.
You typically configure these rules in your WebSocketSecurityConfigurer or WebSocketMessageBrokerConfigurer, granting or denying access based on roles or authentication status.
Securing Specific Destinations
Here's an example of how to use MessageMatcherRegistry to secure WebSocket destinations. Notice how different paths require different roles or simply authentication.
This code snippet is part of a Spring configuration and is not runnable as a standalone Java program.
// Inside a WebSocketSecurityConfigurer or similar class
protected void configureInbound(MessageSecurityMetadataSourceRegistry messages) {
messages
.simpDestMatchers("/topic/public").permitAll() // Anyone can subscribe
.simpDestMatchers("/topic/admin").hasRole("ADMIN") // Only admins
.simpDestMatchers("/app/**").authenticated() // All app messages need auth
.anyMessage().denyAll(); // Deny everything else by default
}Fine-Grained Method Security
For even more granular control, you can apply Spring Security's @PreAuthorize annotations directly to your @MessageMapping methods. This allows you to define authorization rules that are evaluated before the method even executes.
This approach is excellent for complex logic, like checking specific permissions or validating message content against the authenticated user.
Restricting Message Sending
Let's look at an example using @PreAuthorize. This ensures that only users with the 'MODERATOR' role can send messages to an administrative broadcast channel, while regular users can send standard chat messages.
This code snippet is part of a Spring controller and is not runnable as a standalone Java program.
// Inside a @Controller or @MessageMapping class
@MessageMapping("/chat.sendMessage")
@PreAuthorize("hasRole('USER')")
public ChatMessage sendMessage(@Payload ChatMessage chatMessage, Principal principal) {
System.out.println("User " + principal.getName() + " sent: " + chatMessage.getContent());
// ... further processing ...
return chatMessage;
}
@MessageMapping("/admin.broadcast")
@PreAuthorize("hasRole('MODERATOR')")
public void broadcastAdminMessage(@Payload String message) {
System.out.println("Admin broadcast: " + message);
// ... send admin message to all admins ...
}Secure Private Messages
One of the great features of STOMP with Spring is its built-in support for user-specific destinations, typically prefixed with /user/.
When a client subscribes to, for example, /user/queue/notifications, Spring ensures that messages sent to this destination are routed only to the authenticated user associated with that session. This provides inherent privacy and authorization for one-on-one communication.
Custom Authentication Flow
While Spring Security's integration often covers many cases, you might encounter scenarios requiring custom authentication (e.g., using JWT tokens in WebSocket headers, independent of HTTP sessions).
For these advanced cases, you can implement a ChannelInterceptor. This allows you to inspect and modify incoming STOMP messages, extract authentication tokens, and manually set the Principal in the message header before it reaches your controllers.
Test Your Knowledge
Which of the following are valid and effective ways to implement authorization for WebSocket messages in Spring?
Recap: Securing Real-Time
You've learned how to implement authentication and authorization for your Spring WebSocket applications! Key takeaways:
- Spring Security seamlessly integrates HTTP session authentication with WebSockets.
- Access the authenticated user via the
Principalobject. - Use
MessageMatcherRegistryfor path-based authorization on STOMP destinations. - Apply
@PreAuthorizefor granular, method-level authorization. - Leverage the
/userdestination for inherently secure private messaging. - For advanced needs,
ChannelInterceptorallows custom authentication flows.
By implementing these strategies, you can build robust and secure real-time features!
الأسئلة الشائعة
هل درس «المصادقة والتفويض» مجاني؟
نعم — نص درس «المصادقة والتفويض» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة WebSockets & Real-Time Systems with Spring، انتقل إلى CoddyKit PRO. تتضمن دورة WebSockets & Real-Time Systems with Spring 4 دروس في المجموع.
ماذا ستتعلم في «المصادقة والتفويض»؟
نفّذوا مصادقة مستخدمي WebSocket وتفويض الوصول استنادًا إلى الأدوار والأذونات. تتمرن على WebSockets & Real-Time Systems with Spring مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ WebSockets & Real-Time Systems with Spring؟
لا تُشترط خبرة سابقة. WebSockets & Real-Time Systems with Spring على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 3 من أصل 4.
كم من الوقت يستغرق درس «المصادقة والتفويض»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس WebSockets & Real-Time Systems with Spring هذا؟
نعم. كل درس في WebSockets & Real-Time Systems with Spring يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.