-
Notifications
You must be signed in to change notification settings - Fork 38.8k
Closed
Labels
in: webIssues in web modules (web, webmvc, webflux, websocket)Issues in web modules (web, webmvc, webflux, websocket)type: taskA general taskA general task
Milestone
Description
Rob Winch opened SPR-12226 and commented
It is best practice to verify the origin of a WebSocket connection. It would be nice if Spring WebSocket support provided a convenient way to whitelist a set of origins.
NOTE: If interested, I am willing to provide a PR for this.
Affects: 4.1 GA
Reference URL: http://docs.oracle.com/middleware/1213/wls/WLPRG/websockets.htm#BABEDBBB
This issue is a sub-task of #16921
Issue Links:
- SEC-2667 Consider Oracle Guidelines ("is depended on by")
- AbstractSockJsService.checkAndAddCorsHeaders fails for same origin requests when setAllowedOrigins is set [SPR-12660] #17260 AbstractSockJsService.checkAndAddCorsHeaders fails for same origin requests when setAllowedOrigins is set
Referenced from: commits 743356f
0 votes, 6 watchers
Metadata
Metadata
Assignees
Labels
in: webIssues in web modules (web, webmvc, webflux, websocket)Issues in web modules (web, webmvc, webflux, websocket)type: taskA general taskA general task