feat: require app key header on API requests - #184
Merged
Merged
Conversation
Check x-app-key against APP_KEY on every /api request, accepting a comma separated list so keys can be rotated, and skip the check for admin authenticated requests. An empty APP_KEY turns the check off.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
✏️ 작업 개요
모든
/api요청에x-app-key헤더 검사를 추가했습니다. 공식 앱이 아닌 클라이언트(토큰만 확보한 스크립트 등)가 API를 직접 호출하는 것을 막기 위함이고, 키 값은APP_KEY환경변수로 주입합니다.로그인·회원가입처럼 토큰 없이 열려 있는 엔드포인트까지 포함해
/api/**전체가 대상입니다. 다만 어드민 대시보드는 브라우저에서 동작해 키를 들고 있을 수 없으므로, ADMIN으로 인증된 요청은 검사에서 면제됩니다.🔨 작업 상세 내용
앱키 검사 필터 추가 (
AppKeyAuthenticationFilter)/api/**. 헤더가 없거나 값이 다르면 **403G403**으로 차단합니다MessageDigest.isEqual로 상수 시간 비교하고, 키가 여러 개여도 단축평가 없이 전부 비교해서 어느 키에 걸렸는지가 응답 시간으로 새지 않게 했습니다/admin/**,/actuator/**,/docs, 정적 리소스는 검사 대상이 아닙니다어드민 면제 방식
/api/training/**,/api/puzzle/cache/**를 직접 호출합니다. 페이지 HTML에 키를 심는 방법도 있었지만, 키가 브라우저에 노출되지 않도록 ADMIN 인증 요청을 면제하는 쪽을 택했습니다/api/**요청입니다키 로테이션 / 비활성화
APP_KEY는 콤마 구분 목록을 받습니다.새키,구키로 배포 → 앱 업데이트 확산 대기 →새키만 남기기 순서로 무중단 교체가 가능합니다환경변수 / 배포 설정
application.yml에app.key: ${APP_KEY:}추가,.env.example갱신ci.yml,cd-prod.yml,cd-test.yml의 빌드 env와 서버용.env생성 단계에APP_KEY추가문서 / 테스트
x-app-keyapiKey 스킴을 추가해/docs에서 키를 넣고 호출할 수 있게 했습니다 (겸사겸사SwaggerConfig→OpenApiConfig로 이름 변경)APP_KEY공백 → 검사 비활성화. 전체 테스트 275건 통과💡 생각해볼 문제
APP_KEYGitHub Secret 등록이 필요합니다. 지금은 시크릿이 없어서, 이대로 배포하면 빈 값이 들어가 검사가 꺼진 채로 나갑니다