OiO.lk Blog java How to renew http session on websocket activity to not timeout active users?
java

How to renew http session on websocket activity to not timeout active users?


I’ve been using this forum for so long and it’s finally time to ask my first question. 🙂

I’m developing a multiplayer game as a personal project (Spring Boot app + React). Most of the user activity in a game happens via websocket, so I need the spring session to be kept alive as long as there is any websocket activity.

I’ve done the configuration described in the documentation:
https://docs.spring.io/spring-session/reference/web-socket.html
and it says that Spring should handle session renewal automatically – exactly what I want, but it just doesn’t work. Websocket messages don’t renew spring session, resulting in a timeout.

Here’s my websocket config class:

package com.myapp.guess_who.configuration;

import lombok.RequiredArgsConstructor;
import org.springframework.context.annotation.Configuration;
import org.springframework.messaging.simp.config.MessageBrokerRegistry;
import org.springframework.session.Session;
import org.springframework.session.web.socket.config.annotation.AbstractSessionWebSocketMessageBrokerConfigurer;
import org.springframework.web.socket.config.annotation.EnableWebSocketMessageBroker;
import org.springframework.web.socket.config.annotation.StompEndpointRegistry;

@RequiredArgsConstructor
@EnableWebSocketMessageBroker
@Configuration
public class WebSocketConfig extends AbstractSessionWebSocketMessageBrokerConfigurer<Session> {


    @Override
    public void configureMessageBroker(MessageBrokerRegistry registry) {
        registry.enableSimpleBroker("/topic", "/queue");
        registry.setApplicationDestinationPrefixes("/app");
    }

    @Override
    protected void configureStompEndpoints(StompEndpointRegistry registry) {
        registry.addEndpoint("/ws").setAllowedOrigins("http://localhost:3000");
    }
}

spring session related settings in application.yaml:

spring:
  session:
    timeout: 15s
    redis:
      repository-type: indexed # needed to be able to listen for redis session events

and a class listening for session created and destroyed events, to print some info and timeout a user:

package com.myapp.guess_who.listener;

import com.myapp.guess_who.room.RoomManager;
import lombok.RequiredArgsConstructor;
import org.springframework.context.event.EventListener;
import org.springframework.messaging.simp.SimpMessagingTemplate;
import org.springframework.session.Session;
import org.springframework.session.events.SessionCreatedEvent;
import org.springframework.session.events.SessionDestroyedEvent;
import org.springframework.stereotype.Component;

import java.time.Instant;
import java.time.ZoneId;
import java.time.temporal.ChronoUnit;
import java.util.UUID;

@RequiredArgsConstructor
@Component
public class RedisSessionListener {

    private final SimpMessagingTemplate messagingTemplate;
    private final RoomManager roomManager;

    @EventListener
    public void sessionCreated(SessionCreatedEvent event) {
        System.out.printf("Session %s created%n", event.getSession().getId());
        System.out.printf("%s - creation time%n%n", event.getSession().getCreationTime().atZone(ZoneId.systemDefault()).toLocalTime());
    }

    @EventListener
    public void sessionDestroyed(SessionDestroyedEvent event) {
        System.out.printf("Session %s destroyed%n", event.getSession().getId());
        System.out.printf("%s - creation time%n", event.getSession().getCreationTime().atZone(ZoneId.systemDefault()).toLocalTime());
        System.out.printf("%s - last accessed time%n", event.getSession().getLastAccessedTime().atZone(ZoneId.systemDefault()).toLocalTime());
        System.out.printf("%s - current time%n%n", Instant.now().truncatedTo(ChronoUnit.MILLIS).atZone(ZoneId.systemDefault()).toLocalTime());

        Session session = event.getSession();
        UUID roomId = session.getAttribute("roomId");
        UUID playerId = session.getAttribute("playerId");

        if (roomId == null || playerId == null || !roomManager.roomExists(roomId)) {
            return;
        }

        roomManager.removePlayer(roomId, playerId);
        messagingTemplate.convertAndSend("/topic/room/%s/player/%s/sessionInvalidate".formatted(roomId, playerId), "timeout");
    }
}

In case it’s useful, here’s the code for changing the team (I cut out rest of the class methods – not needed for my explanation):

package com.myapp.guess_who.player;

import com.myapp.guess_who.room.RoomManager;
import com.myapp.guess_who.team.Team;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import org.springframework.messaging.handler.annotation.DestinationVariable;
import org.springframework.messaging.handler.annotation.MessageMapping;
import org.springframework.messaging.handler.annotation.Payload;
import org.springframework.messaging.handler.annotation.SendTo;
import org.springframework.stereotype.Controller;

import java.time.Instant;
import java.time.ZoneId;
import java.time.temporal.ChronoUnit;
import java.util.Map;
import java.util.UUID;

@Slf4j
@RequiredArgsConstructor
@Controller
public class PlayerController {

    private final RoomManager roomManager;
    private final PlayerService playerService;

    @MessageMapping("/room/{roomId}/player/{playerId}/changeTeam")
    @SendTo("/topic/room/{roomId}/players")
    public Map<UUID, Player> changePlayerTeam(
        @DestinationVariable("roomId") UUID roomId,
        @DestinationVariable("playerId") UUID playerId,
        @Payload Team newTeam
    ) {
        Map<UUID, Player> players = roomManager.getRoom(roomId).getPlayers();
        System.out.printf(
            "%s - changePlayerTeam called%n%n",
            Instant.now().truncatedTo(ChronoUnit.MILLIS).atZone(ZoneId.systemDefault()).toLocalTime()
        );
        playerService.changePlayerTeam(players, playerId, newTeam);
        return players;
    }
}

Application works fine, the timeout after 15 seconds works fine. Session is obviously extended with each http request, BUT not with websocket message.
Constantly changing the team, while waiting in the room, doesn’t renew the session and results in a timeout after 15 seconds. Here’s the console output:

Session 428df918-f84a-4203-b9c6-c9fc63e9eed9 created
17:15:05.029 - creation time

17:15:14.978 - changePlayerTeam called

17:15:17.884 - changePlayerTeam called

Session 428df918-f84a-4203-b9c6-c9fc63e9eed9 destroyed
17:15:05.029 - creation time
17:15:05.549 - last accessed time
17:15:20.605 - current time

I didn’t deploy the application yet, so it all happens in my local environment, which means that server is running on Tomcat.

I tried renewing spring session manually in my custom interceptor:

package com.myapp.guess_who.interceptor;

import jakarta.servlet.http.HttpSession;
import org.springframework.lang.NonNull;
import org.springframework.messaging.Message;
import org.springframework.messaging.MessageChannel;
import org.springframework.messaging.simp.SimpMessageHeaderAccessor;
import org.springframework.messaging.support.ChannelInterceptor;
import org.springframework.stereotype.Component;

import java.util.Objects;

@Component
public class WebSocketSessionInterceptor implements ChannelInterceptor {

    @Override
    public Message<?> preSend(@NonNull Message<?> message, @NonNull MessageChannel channel) {
        SimpMessageHeaderAccessor headerAccessor = SimpMessageHeaderAccessor.wrap(message);
        System.out.println(headerAccessor.getSessionAttributes());
        // Access HttpSession from the message headers
        HttpSession httpSession = (HttpSession) Objects.requireNonNull(headerAccessor.getSessionAttributes()).get("HTTP_SESSION");

        if (httpSession != null) {
            // Manually update the session to renew it
            httpSession.setAttribute("lastAccessedTime", System.currentTimeMillis());
        }

        return message;
    }
}

that I registered in WebSocketConfig class:

@Override
    public void configureClientInboundChannel(ChannelRegistration registration) {
        registration.interceptors(webSocketSessionInterceptor);
    }

but the line:
System.out.println(headerAccessor.getSessionAttributes());
prints empty map:
{}

It seems that spring autoconfiguration doesn’t correctly map http session to websocket session.
I was looking for the solution on the forums and in the documentation for 2 days now, but I can’t seem to find any that would work. Did I miss something?
I know I could implement this manually but I would really like to know how to make it work with spring boot autoconfig mechanism and avoid unnecessary code.



You need to sign in to view this answers

Exit mobile version