80000Coding / 80000Coding-Backend

MIT License
2 stars 0 forks source link

๐Ÿ”ง WebSecurity to MethodSecurity #55

Closed psychology50 closed 9 months ago

psychology50 commented 10 months ago

์ˆ˜์ •ํ•  ๊ธฐ๋Šฅ

ํ•  ์ผ ๋ชฉ๋ก

  1. API ์ „๋ถ€ ๋‚˜์—ด(๋…ธ์…˜)
  2. API ๋ณ„๋กœ ํ•„์š”ํ•œ ์ ‘๊ทผ ์ œํ•œ ์ข…๋ฅ˜ ์ •๋ฆฌ
    1์ฐจ 
    - PermitAll, Anonymous, Authenticate ํŒ๋‹จ
    2์ฐจ (Authenticate)์ธ ๊ฒฝ์šฐ
    - resource_id์— ๋Œ€ํ•œ ์š”์ฒญ ์ œ์–ด ํ•„์š” ์—ฌ๋ถ€ ํŒ๋‹จ => ์ ‘๊ทผ ์ œ์–ด ๋งค๋‹ˆ์ € ํ•„์š”
    3์ฐจ (PermitAll)์ธ ๊ฒฝ์šฐ
    - ๋กœ๊ทธ์ธ, ๋น„๋กœ๊ทธ์ธ ์œ ์ € ๊ตฌ๋ถ„ ํ•„์š”ํ•œ ์ง€ ํŒ๋‹จ
    - ํ•„์š”ํ•˜๋ฉด AccessTokenInfo๋กœ Controller ํ•˜์œ„ ๊ณ„์ธต์—์„œ ์ฒ˜๋ฆฌ
  3. 1์ฐจ ๊ฒ€ํ† 
  4. @PreAuthorize ๊ตฌ๋ฌธ์œผ๋กœ ํ‘œํ˜„ํ•ด์„œ Notion์— ์ •๋ฆฌ
  5. 2์ฐจ ๊ฒ€ํ† 
  6. ๋ฐ˜์˜

์„ค๋ช…

WebSecurity ๋ฐฉ์‹์œผ๋กœ ์ธํ•œ url ๋ฌธ์ž์—ด ์˜์กด์„ฑ๊ณผ controller ๊ตฌ์กฐ ์˜์กด์„ฑ ์ด์Šˆ ๋ฐœ์ƒ.
Legacy code๋กœ ์ธํ•œ Authorization ์–ด๋ ค์›€.
๋”ฐ๋ผ์„œ, MethodSecurity ๋ฐฉ์‹์œผ๋กœ Controller ๋‹จ์—์„œ Authorize๋ฅผ ์ˆ˜ํ–‰ํ•˜๊ณ , blacklist ๋ฐฉ์‹์—์„œ whitelist ๋ฐฉ์‹์œผ๋กœ ๊ต์ฒด