What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
In a servlet-based Spring Boot application, add Spring’s HttpSessionHandshakeInterceptor to the WebSocket handler mapping, then read the copied HTTP session ID from WebSocketSession.getAttributes(). The HTTP session ID and WebSocketSession.getId() identify different sessions; use the interceptor’s HTTP_SESSION_ID_ATTR_NAME key to retrieve the former.
Capture the HTTP session ID in a servlet-based Spring Boot application
Spring’s HttpSessionHandshakeInterceptor bridges servlet HTTP-session information into the WebSocket handshake attributes. Its API describes the interceptor as copying information from the HTTP session into a map available through WebSocketSession.getAttributes(). The HTTP session ID is copied under HTTP_SESSION_ID_ATTR_NAME when copyHttpSessionId is enabled; that option defaults to true. See the HttpSessionHandshakeInterceptor API.
1. Register the interceptor on the WebSocket endpoint
For the Spring MVC/servlet stack, add the interceptor to the same handler mapping that registers your WebSocket endpoint:
@Configuration
@EnableWebSocket
class WebSocketConfig implements WebSocketConfigurer {
private final WebSocketHandler handler;
WebSocketConfig(WebSocketHandler handler) {
this.handler = handler;
}
@Override
public void registerWebSocketHandlers(WebSocketHandlerRegistry registry) {
registry.addHandler(handler, "/ws")
.addInterceptors(new HttpSessionHandshakeInterceptor());
}
}
2. Read the copied value in the handler
After the connection is established, retrieve the attribute using Spring’s constant rather than a manually typed key:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
@Override
public void afterConnectionEstablished(WebSocketSession session) {
Object httpSessionId = session.getAttributes().get(
HttpSessionHandshakeInterceptor.HTTP_SESSION_ID_ATTR_NAME);
// Use the value for correlation or an appropriate lookup.
}
The result is an object because the attributes map stores values as objects. Check for null if your application must handle handshakes without an available HTTP session.
Why the WebSocket ID is not the HTTP session ID
WebSocketSession.getId() returns an identifier for the WebSocket session, not the servlet container’s HTTP session. Spring’s WebSocket API distinguishes that identifier from the handshake attributes available through getAttributes(). Use getId() to identify the WebSocket connection; use the copied HTTP_SESSION_ID_ATTR_NAME attribute when you specifically need the HTTP session ID. See the WebSocketSession API.
Rank #2
Session creation, cookies, and authentication continuity
HttpSessionHandshakeInterceptor.setCreateSession(boolean) controls whether accessing the HTTP session may create one. The documented default is false. Choose whether session creation is permitted according to your application’s session policy; do not enable it merely to make an attribute appear.
The client also needs to retain and send the cookie identifying the HTTP session on the HTTP upgrade request. Spring’s STOMP security reference explains that every STOMP-over-WebSocket session begins with an HTTP request and that a cookie-based HTTP session can carry authentication into a WebSocket or SockJS session. This describes the HTTP-to-WebSocket handshake; it does not make a WebSocket ID interchangeable with an HTTP session ID. See Spring’s STOMP authentication reference.
Rank #3
Treat the copied ID as a correlation or lookup value, not as proof of authorization. Make authorization decisions using the application’s established security context and rules, rather than trusting possession of an identifier alone.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Servlet MVC and WebFlux use different mechanisms
The interceptor above is the bridge for Spring’s servlet-based WebSocket configuration. Reactive Spring WebFlux uses HandshakeWebSocketService and its sessionAttributePredicate to select attributes from a WebSession and insert them into WebSocket session attributes. It is therefore not configured by registering the servlet HttpSessionHandshakeInterceptor. See the HandshakeWebSocketService API.
Quick Recap
Best Value
Rank #4
Troubleshoot a missing HTTP session ID
- Confirm the application stack. Use the interceptor for servlet-based Spring MVC; use the WebFlux handshake service mechanism for a reactive application.
- Check the exact endpoint mapping. The interceptor must be registered on the handler mapping that serves the requested WebSocket endpoint.
- Check the handshake cookie. Confirm the browser or client sends the cookie identifying the HTTP session with the upgrade request.
- Check session availability and interceptor settings. A session may not exist, and the interceptor may have
copyHttpSessionIddisabled. Also review whethersetCreateSessionis configured as intended. - Read from the attributes map with Spring’s constant. The ID is stored under
HttpSessionHandshakeInterceptor.HTTP_SESSION_ID_ATTR_NAME, not returned byWebSocketSession.getId().
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

