Skip to content

Conversation

@kdkd
Copy link

@kdkd kdkd commented Nov 29, 2025

Commit from kdkd fork 5adfcf8

Websocket reliability changes

In WsWriteTimeout, ConcurrentSkipListSet ordering collapses endpoints that
share the same timeoutExpiry (comparator returns 0 on equal timestamps).
Any concurrent async writes that pick the same millisecond expiry will drop
all but one endpoint from the timeout set, so those writes never time out
and can hang indefinitely.

Origin checking in server/DefaultServerEndpointConfigurator.java no longer
throws when the Origin header is missing; with cross-origin policy enabled
it rejects missing origins cleanly and logs the reason.

The connection ID stored in WebSocketConnection is a random string, but the
on-close fallback lookup uses the container session ID. When the session
user properties can’t be read (the scenario the fallback is meant for), the
lookup always fails and the connection stays registered in the
scope/manager, leaking resources and skipping disconnect notifications.


In WsWriteTimeout, ConcurrentSkipListSet ordering collapses endpoints that
share the same timeoutExpiry (comparator returns 0 on equal timestamps).
Any concurrent async writes that pick the same millisecond expiry will drop
all but one endpoint from the timeout set, so those writes never time out
and can hang indefinitely.

Origin checking in server/DefaultServerEndpointConfigurator.java no longer
throws when the Origin header is missing; with cross-origin policy enabled
it rejects missing origins cleanly and logs the reason.

The connection ID stored in WebSocketConnection is a random string, but the
on-close fallback lookup uses the container session ID.  When the session
user properties can’t be read (the scenario the fallback is meant for), the
lookup always fails and the connection stays registered in the
scope/manager, leaking resources and skipping disconnect notifications.
// the websocket session id will be used for hash code comparison, its the only usable value currently
//wsSessionId = session.getId();
wsSessionId = RandomStringUtils.insecure().nextAlphabetic(11); // random 11 char string
// use the websocket session id for comparisons and lookups
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We moved away from this because its guessable due to its being monotonic. 0, 1, 2... vs random 11 char string

@mondain
Copy link
Member

mondain commented Jan 2, 2026

Closed as the accepted adjustments are added to another branch

@mondain mondain closed this Jan 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants