Question
Vaadin Push endpoint origin validation configuration for multi‑tenant deployments
Rahul Nea
0 reputation · 25 Jan 2022, 12:52 UTC
23.4K views0
Goal
Enable per‑session origin whitelisting for Vaadin Push WebSocket connections so that a single server can safely serve Push to multiple hostnames in a multi‑tenant environment.
Vaadin Push currently relies on the browser same‑origin policy and validates the TLS certificate only against the server hostname; there is no documented API or server‑side configuration to inject custom origin checks per UI session.
- Is there a way to register a custom WebSocket handshake interceptor or filter in Vaadin that can inspect the Origin header and reject or allow connections based on a per‑session list?
- Can the Push endpoint be bound to a specific network interface or IP address to limit exposure while still allowing different DNS names to resolve to that address?
- If neither of the above is possible, what alternative deployment patterns (e.g., separate Push servers, reverse‑proxy based origin validation) are recommended to achieve the required isolation?