WebSockets & Real-Time Systems with Spring · Lekcja

Zarządzanie sesjami użytkowników

Proszę zaimplementować zaawansowane zarządzanie sesjami użytkowników WebSocket, łącząc sesje HTTP z sesjami WebSocket.

Lekcja 3 z 411 kroki

Zarządzanie sesjami użytkowników to bezpłatna lekcja WebSockets & Real-Time Systems with Spring na CoddyKit. To lekcja 3 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej WebSockets & Real-Time Systems with Spring, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs WebSockets & Real-Time Systems with Spring zawiera 4 lekcji w sumie.

Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.

Understanding User Sessions

In web applications, a "session" helps a server remember a user across multiple requests. It's like a temporary memory for each user.

For traditional HTTP, sessions are often managed with cookies. They allow you to store user-specific data, like login status or cart items, between page loads.

WebSockets: Session Challenges

Unlike HTTP, WebSockets establish a persistent, full-duplex connection. This connection doesn't inherently carry the same session context as an HTTP request.

This means if a user logs in via HTTP and then opens a WebSocket, the WebSocket connection won't automatically know who the user is without specific setup.

  • HTTP Session: Short-lived, request-response.
  • WebSocket Session: Long-lived, persistent connection.

Bridging HTTP & WebSocket Sessions

To build rich real-time applications, you often need the WebSocket connection to know about the user's HTTP session context.

For example, you might need to know if a user is authenticated, their user ID, or other profile details that were established during their initial HTTP login.

Spring provides mechanisms to "bridge" this gap during the WebSocket handshake.

The Handshake Interceptor

Spring's primary tool for linking HTTP and WebSocket sessions is the HttpSessionHandshakeInterceptor.

This interceptor runs during the WebSocket handshake, which is the initial HTTP request that upgrades to a WebSocket connection. It can copy attributes from the current HTTP session to the WebSocket session.

  • What it does: Copies HTTP session attributes.
  • When it runs: During the WebSocket handshake.

Configuring Session Interceptor

To use the HttpSessionHandshakeInterceptor, you need to register it within your WebSocket configuration. This tells Spring to apply the interceptor when a WebSocket connection is being established.

It's typically added in your WebSocketMessageBrokerConfigurer implementation:

public class WebSocketConfig extends AbstractWebSocketMessageBrokerConfigurer {
  @Override
  public void registerStompEndpoints(StompEndpointRegistry registry) {
    registry.addEndpoint("/ws")
            .addInterceptors(new HttpSessionHandshakeInterceptor())
            .withSockJS();
  }
}

Accessing Linked Session Data

Once the HttpSessionHandshakeInterceptor has done its job, you can access the copied HTTP session attributes within your WebSocket message handlers.

Commonly, you'll want to access the Principal (representing the authenticated user) or other custom attributes you've stored in the HTTP session.

@Controller
public class MyWebSocketController {
  @MessageMapping("/hello")
  public void handleMessage(@Payload String message, Principal principal) {
    String username = principal.getName();
    System.out.println("Message from " + username + ": " + message);
    // ... use username for user-specific logic
  }
}

WebSocket-Specific Data

Besides copying HTTP session data, you can also store information directly within the WebSocketSession itself. This data is specific to that particular WebSocket connection.

This is useful for managing connection-specific states, like a user's current chat room, notification preferences for this connection, or other transient data.

@EventListener
public void handleSessionConnect(SessionConnectedEvent event) {
  StompHeaderAccessor accessor = StompHeaderAccessor.wrap(event.getMessage());
  WebSocketSession session = (WebSocketSession) accessor.getSessionAttributes().get("webSocketSession");
  if (session != null) {
    session.getAttributes().put("customKey", "customValue");
  }
  System.out.println("User connected: " + accessor.getUser().getName());
}

Managing Session Lifecycle

Spring allows you to listen to WebSocket session lifecycle events. This is crucial for cleaning up resources or updating user status when connections are established or closed.

You can use @EventListener with SessionConnectedEvent and SessionDisconnectEvent to react to these changes.

  • SessionConnectedEvent: Fired when a new STOMP session is established.
  • SessionDisconnectEvent: Fired when a STOMP session is closed.

Runnable: Handshake Interceptor

This Spring Boot example configures a WebSocket endpoint with HttpSessionHandshakeInterceptor. When a client connects, the interceptor helps link the HTTP session (if any) to the WebSocket session.

We demonstrate a simple message handler that could access the authenticated user's Principal. If Spring Security were enabled, principal.getName() would return the logged-in username.

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.context.annotation.Configuration;
import org.springframework.messaging.handler.annotation.MessageMapping;
import org.springframework.messaging.simp.config.MessageBrokerRegistry;
import org.springframework.stereotype.Controller;
import org.springframework.web.socket.config.annotation.EnableWebSocketMessageBroker;
import org.springframework.web.socket.config.annotation.StompEndpointRegistry;
import org.springframework.web.socket.config.annotation.WebSocketMessageBrokerConfigurer;
import org.springframework.web.socket.server.support.HttpSessionHandshakeInterceptor;
import java.security.Principal;

@SpringBootApplication
@EnableWebSocketMessageBroker
public class WebSocketSessionApp {
  public static void main(String[] args) {
    SpringApplication.run(WebSocketSessionApp.class, args);
  }

  @Configuration
  public static class WebSocketConfig implements WebSocketMessageBrokerConfigurer {
    @Override
    public void configureMessageBroker(MessageBrokerRegistry config) {
      config.enableSimpleBroker("/topic");
      config.setApplicationDestinationPrefixes("/app");
    }

    @Override
    public void registerStompEndpoints(StompEndpointRegistry registry) {
      registry.addEndpoint("/ws")
              .addInterceptors(new HttpSessionHandshakeInterceptor())
              .withSockJS();
    }
  }

  @Controller
  public static class WebSocketGreetingController {
    @MessageMapping("/hello")
    public void greeting(Principal principal) {
      if (principal != null) {
        System.out.println("Message from authenticated user: " + principal.getName());
      } else {
        System.out.println("Message from unauthenticated user (Principal is null).");
      }
    }
  }
}

Quick Check: Handshake Interceptor

Test your understanding of the HttpSessionHandshakeInterceptor.

Recap: Session Management

We've explored how to manage user sessions in Spring WebSocket applications, particularly how to link HTTP session context to WebSocket sessions.

  • The HttpSessionHandshakeInterceptor is key for copying HTTP session attributes during the handshake.
  • You can access authenticated user information (Principal) in WebSocket handlers.
  • @EventListener helps manage connection and disconnection events.

Proper session management ensures your real-time features are personalized and secure for each user.

Bezpłatny start

Ucz się WebSockets & Real-Time Systems with Spring dzięki korepetycjom AI — za darmo

Pisz i uruchamiaj kod w przeglądarce, otrzymuj natychmiastową pomoc od korepetytora AI dostępnego 24/7 i kontynuuj naukę w sieci lub w aplikacji.

Kursy
12
Lekcje
48

Często zadawane pytania

Czy lekcja „Zarządzanie sesjami użytkowników” jest bezpłatna?

Tak — pełny tekst „Zarządzanie sesjami użytkowników” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu WebSockets & Real-Time Systems with Spring, przejdź na CoddyKit PRO. Kurs WebSockets & Real-Time Systems with Spring zawiera 4 lekcji w sumie.

Co nauczysz się w „Zarządzanie sesjami użytkowników”?

Proszę zaimplementować zaawansowane zarządzanie sesjami użytkowników WebSocket, łącząc sesje HTTP z sesjami WebSocket. Ćwiczysz WebSockets & Real-Time Systems with Spring z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.

Czy potrzebuję doświadczenia, aby zacząć WebSockets & Real-Time Systems with Spring?

Nie wymagamy żadnego doświadczenia. WebSockets & Real-Time Systems with Spring w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 3 z 4.

Ile czasu zajmuje lekcja „Zarządzanie sesjami użytkowników”?

Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.

Czy mogę pisać i uruchamiać kod w tej lekcji WebSockets & Real-Time Systems with Spring?

Tak. Każda lekcja WebSockets & Real-Time Systems with Spring zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.

Wszystkie lekcje w tym kursie

  1. Interceptory WebSocket
  2. Dostosowywanie konwerterów wiadomości
  3. Zarządzanie sesjami użytkowników
  4. Kierowane wiadomości do konkretnych użytkowników
← Powrót do WebSockets & Real-Time Systems with Spring