Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: DocGrid/docgrid/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔍️ 작업 내용
CONNECT와STOMP명령을 모두 같은 연결 인증 경계로 처리합니다.jti가 없는 JWT의 신규 WebSocket 연결을 거부합니다.✨ 상세 설명
기존 interceptor는 원본 명령을
StompCommand.CONNECT와 직접 비교했습니다. 같은 연결 의미를 갖는STOMP명령은 인증 분기에 들어가지 않아 token 없이 익명 session을 만들 수 있었습니다. 또한WebSocket 인증은 JWT 서명과 만료만 확인해, HTTP 로그아웃으로 Redis blacklist에 등록된 token도
만료 전까지 새 session을 만들 수 있었습니다.
연결 판정을 Spring의 의미 단위인
SimpMessageType.CONNECT로 변경하고, JWT 검증 뒤jti와TokenBlacklistService를 확인한 다음에만 현재 권한을 조회해 Principal을 등록하도록 순서를고정했습니다. 정상 경로와 거부 경로는 SockJS native WebSocket endpoint에 raw STOMP frame을 보내는
통합 테스트로 검증했습니다.
설계와 실행 결과는 다음 문서에 기록했습니다.
docs/design/gimin-#356-stomp-connect-authentication.mddocs/test-results/gimin-#356-stomp-connect-authentication-test.md✅ 검증
./backend/gradlew -p backend build통과🛠️ 추후 리팩토링 및 고도화 계획
연결 시점 인증만 보강했습니다. 로그아웃·token 만료 후 이미 열린 session의 강제 종료와 dashboard
destination의 pattern·wildcard subscription 권한 규칙은 별도 범위입니다.
📸 스크린샷 (선택)
해당 없음
💬 리뷰 요구사항
fail-closed로 둔 장애 정책이 적절한지 확인 부탁드립니다.
SimpMessageType.CONNECT하나로 판정하는 경계와 raw WebSocket 검증 범위를확인 부탁드립니다.