Spring Security 통합
Spring Security를 통합하여 WebSocket 연결과 메시지 흐름을 보호합니다.
Spring Security 통합은(는) CoddyKit의 무료 WebSockets & Real-Time Systems with Spring 강의입니다. 이것은 4개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 WebSockets & Real-Time Systems with Spring 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. WebSockets & Real-Time Systems with Spring 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
Secure Your Real-Time Apps
Integrating real-time features like WebSockets into your applications is exciting, but security is paramount. Just like traditional HTTP endpoints, your WebSocket connections and message flows need protection.
- Data Integrity: Prevent unauthorized tampering with messages.
- Confidentiality: Ensure only authorized users can read sensitive data.
- Access Control: Control who can connect, send messages, or subscribe to topics.
Spring Security offers a powerful framework to secure your WebSocket endpoints effectively.
Essential Security Dependencies
To begin securing your Spring WebSocket application, you'll need to add the necessary Spring Security dependencies to your project. If you're using Spring Boot, these are typically straightforward.
You'll primarily need:
spring-boot-starter-security: Provides core Spring Security features.spring-security-messaging: Specifically for securing Spring's messaging infrastructure, including WebSockets and STOMP.
If you used Spring Initializr, ensure these are included in your pom.xml (Maven) or build.gradle (Gradle).
HTTP Security Foundation
WebSocket connections typically start with an HTTP handshake. This means that your existing HTTP security configuration in Spring Security forms the foundation for WebSocket security.
Before messages flow over WebSockets, the user is usually authenticated via a standard HTTP login process. Spring Security then leverages this authenticated session to secure subsequent WebSocket interactions. A minimal HTTP security setup might look like this:
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(auth -> auth.anyRequest().authenticated())
.formLogin(withDefaults());
return http.build();
}This ensures all HTTP requests require authentication, which is crucial for the WebSocket handshake.
Activate WebSocket Security
Once you have your basic HTTP security in place, you need to tell Spring Security to secure your WebSocket messages. This is done by adding the @EnableWebSocketSecurity annotation.
You'll typically place this annotation on a configuration class that extends WebSocketMessageBrokerConfigurer. This allows you to customize both the WebSocket message broker and its security rules within a single configuration.
The @EnableWebSocketSecurity annotation enables Spring Security's message-based authorization for STOMP messages, allowing you to define fine-grained access control.
Guarding STOMP Destinations
Spring Security integrates with the STOMP protocol, allowing you to secure specific message destinations. You achieve this by overriding the configureInbound() method in your WebSocketMessageBrokerConfigurer.
Inside this method, you use a MessageSecurityMetadataSourceRegistry to define rules based on destination patterns:
.simpDestMatchers("/app/private-chat").authenticated(): Only authenticated users can send messages to this destination..simpDestMatchers("/topic/admin-updates").hasRole("ADMIN"): Only users with the 'ADMIN' role can subscribe to this topic.
This provides powerful, URL-like security for your real-time messages.
User Identity in WebSockets
A key benefit of integrating Spring Security is how it handles user authentication. When a user connects to a WebSocket endpoint after authenticating via HTTP, Spring Security automatically associates their Principal (user identity) with the WebSocket session.
This means that any security rules you define for WebSocket messages can leverage the same authentication and authorization context as your regular HTTP requests. You don't need to re-authenticate users separately for WebSockets.
The Principal object will be available in the WebSocket session, allowing you to make authorization decisions based on the authenticated user's roles or details.
Control Message Sending
You can define authorization rules for messages that clients send to the server (e.g., publishing to an /app destination). This is done using .simpMessageSending() in the MessageSecurityMetadataSourceRegistry.
For example, to allow only authenticated users to send messages:
messages.simpMessageSending().authenticated();Or, to restrict sending to a specific role:
messages.simpMessageSending().hasRole("USER");This ensures that only authorized clients can publish messages to your application's internal handlers.
Restrict Subscriptions
Controlling who can subscribe to a particular topic is equally important. You can use .simpSubscribe() within the MessageSecurityMetadataRegistry to apply authorization rules for subscription requests.
For instance, to allow anyone to subscribe to a public topic, but only admins to a private one:
messages
.simpSubscribeDestMatchers("/topic/public").permitAll()
.simpSubscribeDestMatchers("/topic/private-admin").hasRole("ADMIN");This prevents unauthorized users from receiving messages meant for specific groups or roles.
Example: Securing Destinations
Let's see a minimal Spring Boot application that integrates Spring Security to protect WebSocket STOMP destinations. This example defines different access rules for public, admin, and authenticated-only channels.
When this application starts, it enables WebSocket security and configures rules for sending and subscribing to specific paths. For a real application, you'd also need an HTTP security config (as mentioned in Scene 3) and a user service for authentication.
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.messaging.MessageSecurityMetadataSourceRegistry;
import org.springframework.security.config.annotation.web.socket.EnableWebSocketSecurity;
import org.springframework.web.socket.config.annotation.EnableWebSocketMessageBroker;
import org.springframework.web.socket.config.annotation.WebSocketMessageBrokerConfigurer;
import org.springframework.web.socket.config.annotation.StompEndpointRegistry;
import org.springframework.messaging.simp.config.MessageBrokerRegistry;
@SpringBootApplication
@EnableWebSocketMessageBroker // Enables STOMP over WebSockets
@EnableWebSocketSecurity // Enables Spring Security for WebSocket messages
@Configuration
public class Main implements WebSocketMessageBrokerConfigurer {
public static void main(String[] args) {
SpringApplication.run(Main.class, args);
System.out.println("WebSocket Security Demo Started!");
System.out.println("Access at ws://localhost:8080/ws");
}
// Configure STOMP endpoints (e.g., /ws)
@Override
public void registerStompEndpoints(StompEndpointRegistry registry) {
registry.addEndpoint("/ws").withSockJS();
}
// Configure message broker (e.g., /topic, /app)
@Override
public void configureMessageBroker(MessageBrokerRegistry registry) {
registry.enableSimpleBroker("/topic", "/queue");
registry.setApplicationDestinationPrefixes("/app");
}
// Configure message security rules for inbound messages
@Override
protected void configureInbound(MessageSecurityMetadataSourceRegistry messages) {
messages
// Allow anyone to subscribe to /topic/public
.simpSubscribeDestMatchers("/topic/public").permitAll()
// Only ADMIN role can subscribe to /topic/admin
.simpSubscribeDestMatchers("/topic/admin").hasRole("ADMIN")
// Authenticated users can send messages to /app/private
.simpDestMatchers("/app/private").authenticated()
// Deny all other message types/destinations by default
.anyMessage().denyAll();
}
}Configure Access
Imagine you're building a real-time application with chat rooms. You need to set up the following security rules for your STOMP messages:
- Clients can send messages to
/app/general-chatonly if they are authenticated. - Only users with the
MODERATORrole can subscribe to/topic/moderator-alerts. - All other message types or destinations not explicitly allowed should be denied by default.
Which Spring Security rules would you apply from the options below?
Recap: Secure Your Real-Time Apps
You've learned how to integrate Spring Security with your WebSocket applications to protect real-time communication. Here's a quick summary:
- Add
spring-boot-starter-securityandspring-security-messagingdependencies. - Ensure a basic HTTP security configuration exists, as WebSocket security builds on it.
- Use
@EnableWebSocketSecurityto activate message-level security. - Override
configureInbound()inWebSocketMessageBrokerConfigurerto define rules. - Utilize
MessageSecurityMetadataSourceRegistrywith.simpDestMatchers(),.simpMessageSending(), and.simpSubscribeDestMatchers()to apply authorization. - Leverage
.authenticated(),.hasRole(), and.permitAll(), along with.anyMessage().denyAll()for a robust security posture.
By following these steps, you can ensure your real-time applications are secure and reliable!
자주 묻는 질문
“Spring Security 통합” 강의는 무료인가요?
네 — “Spring Security 통합” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 WebSockets & Real-Time Systems with Spring 강의 전체를 잠금 해제할 수 있습니다. WebSockets & Real-Time Systems with Spring 강의에는 총 4개의 강의가 포함되어 있습니다.
“Spring Security 통합”에서 뭘 배우나요?
Spring Security를 통합하여 WebSocket 연결과 메시지 흐름을 보호합니다. 브라우저에서 직접 실행하는 실습 코드로 WebSockets & Real-Time Systems with Spring을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
WebSockets & Real-Time Systems with Spring을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 WebSockets & Real-Time Systems with Spring은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 2번째 강의입니다.
“Spring Security 통합” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 WebSockets & Real-Time Systems with Spring 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 WebSockets & Real-Time Systems with Spring 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- WebSocket 보안 고려 사항
- Spring Security 통합
- 인증 및 권한 부여
- TLS 및 wss://를 활용한 트래픽 암호화