Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,15 @@
import java.util.HashMap;
import java.util.List;
import java.util.Map;

import life.mosu.mosuserver.application.oauth.OAuthUserService;
import life.mosu.mosuserver.global.filter.TokenExceptionFilter;
import life.mosu.mosuserver.global.filter.TokenFilter;
import life.mosu.mosuserver.global.handler.AuthLogoutHandler;
import life.mosu.mosuserver.global.handler.AuthLogoutSuccessHandler;
import life.mosu.mosuserver.global.handler.OAuth2LoginFailureHandler;
import life.mosu.mosuserver.global.handler.OAuth2LoginSuccessHandler;
import life.mosu.mosuserver.global.resolver.AuthorizationRequestRedirectResolver;
import lombok.RequiredArgsConstructor;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.http.HttpMethod;
Expand All @@ -31,16 +39,6 @@
import org.springframework.web.cors.CorsConfigurationSource;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;

import life.mosu.mosuserver.application.oauth.OAuthUserService;
import life.mosu.mosuserver.global.filter.TokenExceptionFilter;
import life.mosu.mosuserver.global.filter.TokenFilter;
import life.mosu.mosuserver.global.handler.AuthLogoutHandler;
import life.mosu.mosuserver.global.handler.AuthLogoutSuccessHandler;
import life.mosu.mosuserver.global.handler.OAuth2LoginFailureHandler;
import life.mosu.mosuserver.global.handler.OAuth2LoginSuccessHandler;
import life.mosu.mosuserver.global.resolver.AuthorizationRequestRedirectResolver;
import lombok.RequiredArgsConstructor;

@Configuration
@EnableWebSecurity
@EnableMethodSecurity
Expand Down
Original file line number Diff line number Diff line change
@@ -1,16 +1,14 @@
package life.mosu.mosuserver.global.config;

import java.util.List;

import life.mosu.mosuserver.global.resolver.PhoneNumberArgumentResolver;
import life.mosu.mosuserver.global.resolver.UserIdArgumentResolver;
import lombok.RequiredArgsConstructor;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.method.support.HandlerMethodArgumentResolver;
import org.springframework.web.servlet.config.annotation.CorsRegistry;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;

import life.mosu.mosuserver.global.resolver.PhoneNumberArgumentResolver;
import life.mosu.mosuserver.global.resolver.UserIdArgumentResolver;
import lombok.RequiredArgsConstructor;

@Configuration
@RequiredArgsConstructor
public class WebMvcConfig implements WebMvcConfigurer {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
public enum OAuthErrorType {
CANCELED("CANCELED"),
DUPLICATE("DUPLICATE"),
UNKNOWN("UNKNOWN");
UNKNOWN("UNKNOWN"),
INVALID_TOKEN("INVALID_TOKEN");

private final String message;

Expand All @@ -21,6 +22,8 @@ public static OAuthErrorType from(String text) {
return switch (text) {
case "DUPLICATE" -> DUPLICATE;
case "[access_denied] User denied access" -> CANCELED;
case "[invalid_token_response] An error occurred while attempting to retrieve the OAuth 2.0 Access Token Response: 401 : [no body]" ->
INVALID_TOKEN;
default -> UNKNOWN;
};
Comment on lines 22 to 28

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

오류 메시지 문자열을 직접 비교하는 방식은 Spring Security나 Kakao 측에서 오류 메시지 포맷을 약간만 변경해도 로직이 깨질 수 있어 불안정합니다. 예를 들어, 응답 코드가 401이 아니거나 응답 body 내용이 달라지면 현재 코드는 INVALID_TOKEN으로 인식하지 못하게 됩니다.

startsWith를 사용하여 오류 메시지의 시작 부분만 확인하면 이러한 변경에 더 유연하게 대처할 수 있어 안정성이 높아집니다. switch 표현식과 yield 키워드를 사용하면 기존 구조를 유지하면서도 이러한 로직을 깔끔하게 구현할 수 있습니다.

        return switch (text) {
            case "DUPLICATE" -> DUPLICATE;
            case "[access_denied] User denied access" -> CANCELED;
            default -> {
                if (text.startsWith("[invalid_token_response]")) {
                    yield INVALID_TOKEN;
                }
                yield UNKNOWN;
            }
        };

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ public ResponseEntity<ApiResponseWrapper<Void>> create(
}

@PutMapping
@PreAuthorize("isAuthenticated() and hasRole('USER')")
@PreAuthorize("hasRole('USER')")
public ResponseEntity<ApiResponseWrapper<Void>> update(
@UserId Long userId,
@Valid @RequestBody EditProfileRequest request
Expand All @@ -47,7 +47,7 @@ public ResponseEntity<ApiResponseWrapper<Void>> update(
}

@GetMapping
@PreAuthorize("isAuthenticated() and hasRole('USER')")
@PreAuthorize("hasRole('USER')")
public ResponseEntity<ApiResponseWrapper<ProfileDetailResponse>> getProfile(
@UserId Long userId
) {
Expand Down