Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: DocGrid/docgrid/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔍️ 작업 내용
✨ 상세 설명
기존 목적지 interceptor는
/topic/dashboard와 정확히 같은 문자열만 ADMIN 권한을 확인하고, 나머지 구독과 client 발행은 통과시켰습니다. 그러나 Spring SimpleBroker는 구독 목적지를 pattern으로 해석하므로 일반 사용자가/topic/**또는/queue/*를 구독해 관리자 dashboard event와 다른 사용자의 RAG 완료 신호를 받을 수 있었습니다./topic/dashboard,/user/queue/rag-answer두 주소로 제한했습니다.ROLE_ADMIN, RAG 개인 알림은 인증된 사용자에게만 허용했습니다./queue, 알 수 없는 목적지, 목적지 없는 구독은 기본 거부합니다.SimpMessageType.MESSAGE에서 차단해 일반SEND뿐 아니라 rawMESSAGEcommand 우회도 막았습니다.StompDestinationAuthorizationInterceptor로 옮겨 dashboard와 RAG를 함께 다루는 책임을 이름과 package에 반영했습니다.docs/design,docs/test-results에 기록했습니다.서버의
SimpMessagingTemplatepush는clientInboundChannel을 거치지 않으므로 이 차단의 영향을 받지 않습니다.검증
./backend/gradlew -p backend build: 통과🛠️ 추후 리팩토링 및 고도화 계획
📸 스크린샷 (선택)
💬 리뷰 요구사항
SimpMessageType.MESSAGE차단이 clientSEND와 rawMESSAGE를 함께 막으면서 서버 push는 유지하는지 확인 부탁드립니다.