0Pricing
WebSockets & Real-Time Systems with Spring · Lesson

WebSocket Interceptors

Utilize WebSocket interceptors to perform pre-processing and post-processing of messages and connection events.

WebSocket Interceptors is a free WebSockets & Real-Time Systems with Spring lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the WebSockets & Real-Time Systems with Spring learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Welcome to Interceptors!

In Spring WebSockets, Interceptors act like gatekeepers or event listeners that can observe and modify the WebSocket lifecycle.

They allow you to perform actions like logging, authentication, or modifying data at specific points during a connection or message exchange.

Lifecycle Hooks

Think of the WebSocket process:

  • Handshake: Initial HTTP request to upgrade to WebSocket.
  • Connection: WebSocket link is established.
  • Message Exchange: Data flows between client and server.
  • Disconnection: WebSocket link closes.

Interceptors let you "hook" into these stages.

Intercepting the Handshake

The HandshakeInterceptor is crucial for the very first step: the WebSocket handshake.

It lets you:

  • Inspect the HTTP request before the WebSocket connection is established.
  • Perform authentication or authorization checks.
  • Add attributes to the WebSocket session.

You can decide whether to allow the handshake to proceed.

Coding a Handshake Interceptor

Let's create a simple HandshakeInterceptor that logs when a connection attempt begins and ends. This is useful for monitoring or debugging.

Notice the beforeHandshake and afterHandshake methods.

import org.springframework.http.server.ServerHttpRequest;
import org.springframework.http.server.ServerHttpResponse;
import org.springframework.web.socket.WebSocketHandler;
import org.springframework.web.socket.server.HandshakeInterceptor;
import java.util.Map;

public class MyHandshakeInterceptor implements HandshakeInterceptor {

  @Override
  public boolean beforeHandshake(ServerHttpRequest request, ServerHttpResponse response,
                                 WebSocketHandler wsHandler, Map<String, Object> attributes) throws Exception {
    System.out.println(">>> Handshake starting for: " + request.getURI());
    // 'attributes' map can be used to pass data to WebSocket session
    return true; // Allow handshake to proceed
  }

  @Override
  public void afterHandshake(ServerHttpRequest request, ServerHttpResponse response,
                             WebSocketHandler wsHandler, Exception exception) {
    System.out.println("<<< Handshake completed for: " + request.getURI());
    if (exception != null) {
      System.err.println("Handshake failed: " + exception.getMessage());
    }
  }
}

Integrating Handshake Interceptors

To make our MyHandshakeInterceptor active, we need to register it within our Spring Boot application's WebSocket configuration.

Run this code and try connecting to ws://localhost:8080/ws from a browser's developer console (e.g., new WebSocket('ws://localhost:8080/ws')) to see the logs!

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.socket.config.annotation.*;
import org.springframework.web.socket.handler.TextWebSocketHandler;
import org.springframework.http.server.ServerHttpRequest;
import org.springframework.http.server.ServerHttpResponse;
import org.springframework.web.socket.server.HandshakeInterceptor;
import java.util.Map;

@SpringBootApplication
public class Main {
  public static void main(String[] args) {
    SpringApplication.run(Main.class, args);
  }
}

// MyHandshakeInterceptor.java (nested for brevity)
class MyHandshakeInterceptor implements HandshakeInterceptor {
  @Override
  public boolean beforeHandshake(ServerHttpRequest req, ServerHttpResponse res,
                                 org.springframework.web.socket.WebSocketHandler h, Map<String, Object> a) {
    System.out.println(">>> Handshake: " + req.getURI());
    return true;
  }
  @Override
  public void afterHandshake(ServerHttpRequest req, ServerHttpResponse res,
                             org.springframework.web.socket.WebSocketHandler h, Exception e) {
    System.out.println("<<< Handshake done: " + req.getURI());
  }
}

// WebSocketConfig.java (nested for brevity)
@Configuration
@EnableWebSocket
class WebSocketConfig implements WebSocketConfigurer {
  @Override
  public void registerWebSocketHandlers(WebSocketHandlerRegistry r) {
    r.addHandler(new TextWebSocketHandler(), "/ws")
     .addInterceptors(new MyHandshakeInterceptor())
     .setAllowedOrigins("*");
  }
}

Intercepting STOMP Messages

While HandshakeInterceptor handles initial connections, ChannelInterceptor focuses on STOMP messages flowing through Spring's message broker.

These interceptors operate on the messaging channels, allowing you to inspect or modify messages before they reach their destination or after they are sent.

Coding a Channel Interceptor

A ChannelInterceptor provides methods like preSend, postSend, and afterSendCompletion.

The preSend method is commonly used to inspect or modify a message before it is sent to its destination (e.g., a STOMP topic or user queue).

import org.springframework.messaging.Message;
import org.springframework.messaging.MessageChannel;
import org.springframework.messaging.support.ChannelInterceptor;

public class MyChannelInterceptor implements ChannelInterceptor {

  @Override
  public Message<?> preSend(Message<?> message, MessageChannel channel) {
    // Log the message or perform security checks
    System.out.println("Intercepted STOMP message: " + message.getHeaders());
    // You can modify the message here
    return message; // Return the message to proceed
  }

  // Other methods like postSend, afterSendCompletion...
}

Integrating Channel Interceptors

To register a ChannelInterceptor, you typically use a configuration class that extends WebSocketMessageBrokerConfigurer.

  • Use clientInboundChannel() to intercept messages coming from clients.
  • Use clientOutboundChannel() to intercept messages going to clients.

This allows fine-grained control over message flow.

Common Use Cases

Interceptors are powerful for many scenarios:

  • Authentication & Authorization: Validate users before connection or message delivery.
  • Logging: Track connection events and message traffic.
  • Session Management: Attach user-specific data to WebSocket sessions.
  • Message Modification: Add headers, filter content, or transform payloads.
  • Rate Limiting: Prevent abuse by limiting message frequency.

Interceptor Knowledge Check

You've learned about two main types of WebSocket interceptors in Spring. Let's see if you can distinguish their primary use cases.

Interceptors: Your WebSocket Control

Today, you learned about Spring's WebSocket Interceptors, powerful tools for controlling and observing your real-time communication.

  • Handshake Interceptors: For pre-connection logic.
  • Channel Interceptors: For STOMP message flow.

They are essential for building secure, robust, and observable WebSocket applications. Next, we'll explore message converter customization!

Frequently asked questions

Is the “WebSocket Interceptors” lesson free?

Yes — the full text of “WebSocket Interceptors” is free to read here on the web, and the WebSockets & Real-Time Systems with Spring course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the WebSockets & Real-Time Systems with Spring course, upgrade to CoddyKit PRO.

What will I learn in “WebSocket Interceptors”?

Utilize WebSocket interceptors to perform pre-processing and post-processing of messages and connection events. You practise WebSockets & Real-Time Systems with Spring with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start WebSockets & Real-Time Systems with Spring?

No prior experience is required. WebSockets & Real-Time Systems with Spring on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “WebSocket Interceptors” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this WebSockets & Real-Time Systems with Spring lesson?

Yes. Every WebSockets & Real-Time Systems with Spring lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. WebSocket Interceptors
  2. Message Converters Customization
  3. User Session Management
  4. Targeted Messaging to Specific Users
← Back to WebSockets & Real-Time Systems with Spring