Conversation
행동 원칙 섹션은 전역 ~/.claude/CLAUDE.md로 승격되어 모든 레포에 적용되므로, 중복·드리프트 방지를 위해 Backend CLAUDE.md에는 참조 한 줄만 남긴다. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
범용 /security-review 대신 Coming 인증 정책(JWT·OAuth2·Redis 블랙리스트) 체크리스트를 가진 읽기 전용 security-reviewer 에이전트를 추가하고, CLAUDE.md 커밋 전 체크리스트에 반영한다. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
하나의 json 블록에 주석(//)과 두 개의 객체가 함께 있어 JSON 문법 오류가 발생하던 문제를 에러·페이지네이션 블록으로 분리해 해결한다. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rating/post/report/notice/policy 도메인 추가, Spring Batch·Mail 기술 스택 반영, 도메인 수(13개)·마이그레이션 수(40개)·신고 Discord 알림을 코드 기준으로 갱신한다. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Data 레포 양식에 맞춰 흐름·에이전트 역할 분리·코드 리뷰·훅 구조로 재구성하고, security-reviewer 에이전트 도입과 도메인 전문가 에이전트·review-feature 스킬 제거를 반영한다. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rating/post/report/notice/policy 도메인과 user 역할 설명을 코드 기준으로 반영하고, Spring Batch·Mail 기술 스택을 추가한다. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- 시크릿 차단을 파일명 기준으로 변경하고 Read까지 확장 (.env.example 허용) - git에 올라간 application-prod.yaml(환경변수 자리표시만 존재)은 차단 대상에서 제외 - 커밋된 Flyway 마이그레이션 수정 차단 (checksum 불일치 방지) - Stop 훅은 미커밋 Java 변경이 있을 때만 systemMessage로 워크플로우 안내 - CLAUDE.md 알려진 제약·README 훅 표 현행화 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- matcher에 Grep·Bash 추가 — 기존에는 Bash(cat/sed 등)·Grep 경유 접근이 훅을 거치지 않음 - Bash는 명령을 토큰으로 나눠 파일명 검사, 따옴표 문장·heredoc 본문은 제외 - CLAUDE.md·README 훅 설명 현행화 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- guard_files: Grep glob 검사 추가, 디렉터리에 공백이 든 따옴표 경로 검사 - guard_files: 마이그레이션 커밋 여부를 index 대신 HEAD 기준으로 판정 (staged 신규 파일 편집 허용) - security-reviewer: merge-base 대비 diff + untracked 파일까지 검토, SQL Injection 기준 명확화 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- 새 로그인마다 UUID jti를 발급하고, 회전 시 같은 jti로 재발급하는 오버로드 추가 - getSessionId로 jti 조회 (jti 도입 이전 토큰은 null) - 같은 초에 발급된 Refresh Token 값이 동일해지던 문제 해소 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- TokenRepository: RT:{userId}:{sessionId} + 세션 목록 ZSET(RT_SESSIONS:{userId})으로 변경, 사용자당 최대 5세션(초과 시 가장 오래된 세션 제거)
- 회전은 Lua 스크립트로 저장값 비교 후 교체해 동시 refresh 중 1건만 성공, 세션 목록 TTL도 함께 연장
- 로그인(OAuth2·Dev)마다 새 세션 저장 — 다른 기기의 Refresh Token을 덮어쓰지 않음
- refresh: 해당 세션만 검증·교체, jti 없는 기존 토큰은 REFRESH_TOKEN_INVALID(재로그인)
- logout: Refresh Token 쿠키로 현재 기기 세션만 삭제 (쿠키 없거나 무효·타 사용자 토큰이면 삭제 생략, 200 유지)
- withdraw: 모든 기기 세션 삭제
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- AT에 typ=access, RT에 typ=refresh claim 추가, 인증 필터는 typ=access만 인증 (로그아웃·세션 제거 후에도 서명이 유효한 RT가 Bearer로 통과하던 문제 차단) - JwtProvider.parseRefreshToken: typ·jti를 검증해 userId·sessionId 반환 (getSessionId·getUserId 대체) - 회전 Lua 스크립트: 저장값 불일치 시 이미 회전된 RT의 재사용으로 보고 해당 세션만 원자적으로 폐기 - AuthService: 재사용 감지 시 WARN 로그 후 REFRESH_TOKEN_INVALID Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AuthController가 secure(true)를 하드코딩해 로컬(http)에서 refresh 후 쿠키가 Secure로 재발급되던 문제를 OAuth2SuccessHandler와 같이 app.cookie.secure 설정을 따르도록 수정 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
[feat] 다중 기기 세션 관리 및 토큰 폐기 강화
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
배포 내용
[chore] 행동 원칙 전역 이관 및 Claude Code 설정 정비 (#128, PR #129)
security-reviewer에이전트 추가[feat] 다중 기기 세션 관리 및 토큰 폐기 강화 (#130, PR #131)
jti) 추가,RT:{userId}:{sessionId}세션 단위 저장 (사용자당 최대 5개)typ) 구분으로 RT의 API 인증 사용 차단, RT 재사용 감지 시 해당 세션 폐기secure설정값 사용