Skip to content

[deploy] 배포 - #132

Merged
You-Hyuk merged 16 commits into
mainfrom
develop
Sep 27, 2026
Merged

You-Hyuk merged 16 commits into
mainfrom
develop

Conversation

@You-Hyuk

Copy link
Copy Markdown
Contributor

배포 내용

[chore] 행동 원칙 전역 이관 및 Claude Code 설정 정비 (#128, PR #129)

  • CLAUDE.md 행동 원칙을 전역 설정으로 이관, 패키지 구조·기술 스택 현행화
  • security-reviewer 에이전트 추가
  • 프로젝트 훅 개편: 시크릿 파일 Read/Write/Edit/Grep/Bash 접근 차단, 커밋된 Flyway 마이그레이션 수정 차단
  • README 현행화 및 ERD 이미지 추가

[feat] 다중 기기 세션 관리 및 토큰 폐기 강화 (#130, PR #131)

  • Refresh Token에 세션 식별자(jti) 추가, RT:{userId}:{sessionId} 세션 단위 저장 (사용자당 최대 5개)
  • Lua 스크립트 기반 원자적 RT 회전, 로그아웃 시 현재 세션만 삭제 / 탈퇴 시 전체 세션 삭제
  • 토큰 종류(typ) 구분으로 RT의 API 인증 사용 차단, RT 재사용 감지 시 해당 세션 폐기
  • RT 쿠키 재발급·삭제 시 secure 설정값 사용

⚠️ 기존 RT:{userId} 키는 마이그레이션하지 않으므로, 배포 후 기존 로그인 사용자는 1회 재로그인이 필요합니다.

You-Hyuk and others added 16 commits September 26, 2026 11:06
행동 원칙 섹션은 전역 ~/.claude/CLAUDE.md로 승격되어 모든 레포에 적용되므로,
중복·드리프트 방지를 위해 Backend CLAUDE.md에는 참조 한 줄만 남긴다.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
범용 /security-review 대신 Coming 인증 정책(JWT·OAuth2·Redis 블랙리스트) 체크리스트를
가진 읽기 전용 security-reviewer 에이전트를 추가하고, CLAUDE.md 커밋 전 체크리스트에 반영한다.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
하나의 json 블록에 주석(//)과 두 개의 객체가 함께 있어 JSON 문법 오류가 발생하던 문제를
에러·페이지네이션 블록으로 분리해 해결한다.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rating/post/report/notice/policy 도메인 추가, Spring Batch·Mail 기술 스택 반영,
도메인 수(13개)·마이그레이션 수(40개)·신고 Discord 알림을 코드 기준으로 갱신한다.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Data 레포 양식에 맞춰 흐름·에이전트 역할 분리·코드 리뷰·훅 구조로 재구성하고,
security-reviewer 에이전트 도입과 도메인 전문가 에이전트·review-feature 스킬 제거를 반영한다.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rating/post/report/notice/policy 도메인과 user 역할 설명을 코드 기준으로 반영하고,
Spring Batch·Mail 기술 스택을 추가한다.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- 시크릿 차단을 파일명 기준으로 변경하고 Read까지 확장 (.env.example 허용)
- git에 올라간 application-prod.yaml(환경변수 자리표시만 존재)은 차단 대상에서 제외
- 커밋된 Flyway 마이그레이션 수정 차단 (checksum 불일치 방지)
- Stop 훅은 미커밋 Java 변경이 있을 때만 systemMessage로 워크플로우 안내
- CLAUDE.md 알려진 제약·README 훅 표 현행화

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- matcher에 Grep·Bash 추가 — 기존에는 Bash(cat/sed 등)·Grep 경유 접근이 훅을 거치지 않음
- Bash는 명령을 토큰으로 나눠 파일명 검사, 따옴표 문장·heredoc 본문은 제외
- CLAUDE.md·README 훅 설명 현행화

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- guard_files: Grep glob 검사 추가, 디렉터리에 공백이 든 따옴표 경로 검사
- guard_files: 마이그레이션 커밋 여부를 index 대신 HEAD 기준으로 판정 (staged 신규 파일 편집 허용)
- security-reviewer: merge-base 대비 diff + untracked 파일까지 검토, SQL Injection 기준 명확화

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
[chore] 행동 원칙 전역 이관 및 Claude Code 설정 정비
- 새 로그인마다 UUID jti를 발급하고, 회전 시 같은 jti로 재발급하는 오버로드 추가
- getSessionId로 jti 조회 (jti 도입 이전 토큰은 null)
- 같은 초에 발급된 Refresh Token 값이 동일해지던 문제 해소

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- TokenRepository: RT:{userId}:{sessionId} + 세션 목록 ZSET(RT_SESSIONS:{userId})으로 변경, 사용자당 최대 5세션(초과 시 가장 오래된 세션 제거)
- 회전은 Lua 스크립트로 저장값 비교 후 교체해 동시 refresh 중 1건만 성공, 세션 목록 TTL도 함께 연장
- 로그인(OAuth2·Dev)마다 새 세션 저장 — 다른 기기의 Refresh Token을 덮어쓰지 않음
- refresh: 해당 세션만 검증·교체, jti 없는 기존 토큰은 REFRESH_TOKEN_INVALID(재로그인)
- logout: Refresh Token 쿠키로 현재 기기 세션만 삭제 (쿠키 없거나 무효·타 사용자 토큰이면 삭제 생략, 200 유지)
- withdraw: 모든 기기 세션 삭제

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- AT에 typ=access, RT에 typ=refresh claim 추가, 인증 필터는 typ=access만 인증
  (로그아웃·세션 제거 후에도 서명이 유효한 RT가 Bearer로 통과하던 문제 차단)
- JwtProvider.parseRefreshToken: typ·jti를 검증해 userId·sessionId 반환 (getSessionId·getUserId 대체)
- 회전 Lua 스크립트: 저장값 불일치 시 이미 회전된 RT의 재사용으로 보고 해당 세션만 원자적으로 폐기
- AuthService: 재사용 감지 시 WARN 로그 후 REFRESH_TOKEN_INVALID

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AuthController가 secure(true)를 하드코딩해 로컬(http)에서 refresh 후 쿠키가 Secure로
재발급되던 문제를 OAuth2SuccessHandler와 같이 app.cookie.secure 설정을 따르도록 수정

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
[feat] 다중 기기 세션 관리 및 토큰 폐기 강화
@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 19ff208e-7f9b-42ac-8fbd-5b9c6a060644

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@You-Hyuk
You-Hyuk merged commit e476999 into main Sep 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant