Skip to content

๐Ÿ› Fix: ์†Œ์…œ ๋กœ๊ทธ์ธ ์ด๋ฉ”์ผ ์ค‘๋ณต ์ฒดํฌ ๋กœ์ง ์ถ”๊ฐ€ - #166

Open
jihwankim128 wants to merge 2 commits into
devfrom
fix/duplication-eamil
Open

๐Ÿ› Fix: ์†Œ์…œ ๋กœ๊ทธ์ธ ์ด๋ฉ”์ผ ์ค‘๋ณต ์ฒดํฌ ๋กœ์ง ์ถ”๊ฐ€#166
jihwankim128 wants to merge 2 commits into
devfrom
fix/duplication-eamil

Conversation

@jihwankim128

@jihwankim128 jihwankim128 commented Aug 19, 2025

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • ๋ฒ„๊ทธ ์ˆ˜์ •
    • ๊ตฌ๊ธ€/์นด์นด์˜ค/๋„ค์ด๋ฒ„ ์†Œ์…œ ๋กœ๊ทธ์ธ์—์„œ ๋™์ผ ์ด๋ฉ”์ผ๋กœ ์ด๋ฏธ ๊ฐ€์ž…๋œ ๊ณ„์ •์ด ์žˆ์„ ๊ฒฝ์šฐ ์‚ฌ์ „ ๊ฒ€์ฆํ•ด ์ค‘๋ณต ๊ฐ€์ž… ๋ฐ ์˜ˆ๊ธฐ์น˜ ์•Š์€ ๋กœ๊ทธ์ธ ์‹คํŒจ๋ฅผ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • ๊ฐœ์„ 
    • ์ค‘๋ณต ์ด๋ฉ”์ผ ๊ด€๋ จ ์•ˆ๋‚ด ๋ฌธ๊ตฌ๋ฅผ ๋ณด๋‹ค ๋ช…ํ™•ํ•œ ํ‘œํ˜„์œผ๋กœ ๋ณ€๊ฒฝํ•ด ์‚ฌ์šฉ์ž๊ฐ€ ์ƒํ™ฉ์„ ์‰ฝ๊ฒŒ ์ดํ•ดํ•  ์ˆ˜ ์žˆ๋„๋ก ํ–ˆ์Šต๋‹ˆ๋‹ค.

@coderabbitai

coderabbitai Bot commented Aug 19, 2025

Copy link
Copy Markdown

Walkthrough

Google/Kakao/Naver ์†Œ์…œ ๋กœ๊ทธ์ธ ์ „๋žต์— UserValidator ์˜์กด์„ฑ ๋ฐ ์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์ฆ์„ ์ถ”๊ฐ€ํ–ˆ๊ณ , AuthService์—๋Š” import ์ •๋ฆฌ์™€ TODO ์ฃผ์„์„ ์ถ”๊ฐ€ํ–ˆ์œผ๋ฉฐ UserValidator์— ์ธ๋ผ์ธ ์ฃผ์„์„ ๋ณด๊ฐ•ํ•˜๊ณ  UserErrorCode์˜ USER_DUPLICATE_EMAIL ๋ฉ”์‹œ์ง€๋ฅผ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.

Changes

Cohort / File(s) Summary
์†Œ์…œ ๋กœ๊ทธ์ธ ์ „๋žต ๊ฒ€์ฆ ์ถ”๊ฐ€
insty-api/src/main/java/insty/domain/auth/strategy/GoogleStrategy.java, insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java, insty-api/src/main/java/insty/domain/auth/strategy/NaverStrategy.java
๊ฐ Strategy์— UserValidator ํ•„๋“œ(์ƒ์„ฑ์ž ์ฃผ์ž…) ์ถ”๊ฐ€ ๋ฐ loginBySocial ํ๋ฆ„ ์ค‘ ์ด๋ฉ”์ผ์— ๋Œ€ํ•ด validateDuplicateEmail ํ˜ธ์ถœ ์ถ”๊ฐ€(์‹ ๊ทœ ์‚ฌ์šฉ์ž ์ƒ์„ฑ ๊ฒฝ๋กœ ํฌํ•จ). ๊ธฐ์กด ๋กœ๊ทธ์ธ ํ๋ฆ„ ๋ฐ ์‹œ๊ทธ๋‹ˆ์ฒ˜๋Š” Lombok ์ƒ์„ฑ์ž ๋ณ€๊ฒฝ์œผ๋กœ ์˜์กด์„ฑ ํ™•์žฅ๋จ.
Auth ์„œ๋น„์Šค ๋น„๊ธฐ๋Šฅ ๋ณ€๊ฒฝ
insty-api/src/main/java/insty/domain/auth/service/AuthService.java
import ์ˆœ์„œ ์กฐ์ • ๋ฐ ์†Œ์…œ ๋กœ๊ทธ์ธ ๊ด€๋ จ TODO ์ฃผ์„ 2๊ฐœ ์ถ”๊ฐ€. ๋™์ž‘ ๋ณ€๊ฒฝ ์—†์Œ.
์œ ํšจ์„ฑ ๊ฒ€์ฆ ์ฃผ์„ ๋ณด๊ฐ•
insty-api/src/main/java/insty/domain/user/implement/UserValidator.java
validateDuplicateEmail ๋‚ด๋ถ€์— ์ธ๋ผ์ธ ์ฃผ์„ ์ถ”๊ฐ€. ๋กœ์ง๊ณผ ์˜ˆ์™ธ ์ฒ˜๋ฆฌ ๋ถˆ๋ณ€.
์—๋Ÿฌ ๋ฉ”์‹œ์ง€ ๋ณ€๊ฒฝ
insty-common/src/main/java/insty/error/UserErrorCode.java
USER_DUPLICATE_EMAIL ๋ฉ”์‹œ์ง€๋ฅผ "ํ•ด๋‹น ์ด๋ฉ”์ผ ์ •๋ณด๋กœ ๊ฐ€์ž…๋œ ๊ณ„์ •์ด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค."๋กœ ๋ณ€๊ฒฝ(์ฝ”๋“œ ๋ฐ HTTP ์ƒํƒœ๋Š” ๋™์ผ).

Estimated code review effort

๐ŸŽฏ 3 (Moderate) | โฑ๏ธ ~25 minutes

Tip

๐Ÿ”Œ Remote MCP (Model Context Protocol) integration is now available!

Pro plan users can now connect to remote MCP servers from the Integrations page. Connect with popular remote MCPs such as Notion and Linear to add more context to your reviews and chats.

โœจ Finishing Touches
  • ๐Ÿ“ Generate Docstrings
๐Ÿงช Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/duplication-eamil

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

โค๏ธ Share
๐Ÿชง Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

CodeRabbit Commands (Invoked using PR/Issue comments)

Type @coderabbitai help to get the list of available commands.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Status, Documentation and Community

  • Visit our Status Page to check the current availability of CodeRabbit.
  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and canโ€™t be posted inline due to platform limitations.

โš ๏ธ Outside diff range comments (1)
insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (1)

57-67: ์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์ฆ ์œ„์น˜๊ฐ€ ์ž˜๋ชป๋˜์–ด ๊ธฐ์กด ํšŒ์› ๋กœ๊ทธ์ธ ์‹คํŒจ ๊ฐ€๋Šฅ โ€” ๊ฐ€์ž… ์ผ€์ด์Šค์—์„œ๋งŒ ๊ฒ€์ฆํ•˜๋„๋ก ์ด๋™ ํ•„์š”

ํ˜„์žฌ๋Š” ๋กœ๊ทธ์ธ ํ๋ฆ„ ์ดˆ๋ฐ˜์— validateDuplicateEmail(email)์„ ํ•ญ์ƒ ํ˜ธ์ถœํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฏธ ๊ฐ€์ž…๋œ ์นด์นด์˜ค ์‚ฌ์šฉ์ž๊ฐ€ ์žฌ๋กœ๊ทธ์ธํ•˜๋Š” ๊ฒฝ์šฐ์—๋„ ์ด๋ฉ”์ผ์ด DB์— ์กด์žฌํ•˜๋ฏ€๋กœ ์ค‘๋ณต ์˜ˆ์™ธ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ค‘๋ณต ๊ฒ€์‚ฌ๋Š” โ€œ์‹ ๊ทœ ํšŒ์› ์ƒ์„ฑโ€ ๋ถ„๊ธฐ(ํšŒ์›๊ฐ€์ž…)์—์„œ๋งŒ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋‹‰๋„ค์ž„ ์ƒ์„ฑ๋„ ๋™์ผํ•˜๊ฒŒ ๊ฐ€์ž… ์‹œ์—๋งŒ ์ˆ˜ํ–‰ํ•˜์„ธ์š”.

์•„๋ž˜์™€ ๊ฐ™์ด ์ˆ˜์ • ์ œ์•ˆ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

@@ public User loginBySocial(String code, UserType userType) {
-        String nickname = NicknameGenerator.generateNickname();
-
-        userValidator.validateDuplicateEmail(email);
+        // ์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์‚ฌ๋Š” ์‹ ๊ทœ ๊ฐ€์ž… ์ผ€์ด์Šค์—์„œ๋งŒ ์ˆ˜ํ–‰

         log.info("์นด์นด์˜ค ๋กœ๊ทธ์ธ : ์‚ฌ์šฉ์ž ์ •๋ณด ์กฐํšŒ ์™„๋ฃŒ , ์†Œ์…œ ID : {}", socialId);

         return userRepository.findBySocialIdAndSocialType(String.valueOf(socialId), SocialType.KAKAO)
                 .orElseGet(() -> {                      // ์กด์žฌ X โ†’ ํšŒ์›๊ฐ€์ž…
-                    User newUser = User.createBySocial(String.valueOf(socialId), SocialType.KAKAO, email, nickname, userType);
+                    if (email != null && !email.isBlank()) {
+                        userValidator.validateDuplicateEmail(email);
+                    }
+                    String nickname = NicknameGenerator.generateNickname();
+                    User newUser = User.createBySocial(String.valueOf(socialId), SocialType.KAKAO, email, nickname, userType);
                     return userRepository.save(newUser);
                 });
๐Ÿงน Nitpick comments (7)
insty-api/src/main/java/insty/domain/user/implement/UserValidator.java (1)

28-32: [์†Œ์…œ ๊ฐ€์ž… ์ „์šฉ] ์ค‘๋ณต ์ฒดํฌ ์˜๋„๋ฅผ ๋ฉ”์„œ๋“œ ์‹œ๊ทธ๋‹ˆ์ฒ˜/๋„ค์ด๋ฐ์œผ๋กœ ๋ช…ํ™•ํžˆ

ํ˜„์žฌ validateDuplicateEmail์€ โ€œ์กด์žฌํ•˜๋ฉด ์˜ˆ์™ธโ€๋งŒ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์†Œ์…œ ๋กœ๊ทธ์ธ ํ๋ฆ„์—์„œ โ€œ๊ธฐ์กด ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธโ€ ๋‹จ๊ณ„์—์„œ ์ด ๋ฉ”์„œ๋“œ๋ฅผ ํ˜ธ์ถœํ•˜๋ฉด ์ •์ƒ ์‚ฌ์šฉ์ž๋„ ๋ง‰ํžˆ๋Š” ์˜ค์šฉ ๋ฆฌ์Šคํฌ๊ฐ€ ํฝ๋‹ˆ๋‹ค(์ „๋žต ํŒŒ์ผ ์ฝ”๋ฉ˜ํŠธ ์ฐธ๊ณ ). ์•„๋ž˜์ฒ˜๋Ÿผ โ€œ์‹ ๊ทœ ์ƒ์„ฑ ์‹œ์—๋งŒโ€ ํ˜ธ์ถœํ•˜๋„๋ก ์˜๋„๋ฅผ ๋“œ๋Ÿฌ๋‚ด๋Š” ๋ฉ”์„œ๋“œ๋กœ ๋ถ„๋ฆฌ/๋„ค์ด๋ฐํ•˜๋ฉด ์˜ค์šฉ์„ ์ค„์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์˜ˆ:

  • validateDuplicateEmailForCreate(String email)
  • validateDuplicateEmailExcluding(String email, Long excludeUserId) // ์ƒํ™ฉ์— ๋”ฐ๋ผ

ํ•„์š”ํ•˜์‹œ๋‹ค๋ฉด ๋ณ€๊ฒฝ ํŒจ์น˜ ์ œ์•ˆ ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.

insty-api/src/main/java/insty/domain/auth/service/AuthService.java (1)

127-128: ์†Œ์…œ ๋กœ๊ทธ์ธ ์ฒ˜๋ฆฌ ์ˆœ์„œ ์žฌ์ •๋ ฌ ์ œ์•ˆ: โ€œ์กฐํšŒ โ†’ ์žˆ์œผ๋ฉด ๋กœ๊ทธ์ธ โ†’ ์—†์œผ๋ฉด ์ค‘๋ณต๊ฒ€์‚ฌ ํ›„ ์ƒ์„ฑโ€

ํ˜„์žฌ ์ „๋žต ๋‚ด๋ถ€์—์„œ โ€œ์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์‚ฌโ€๋ฅผ ๋จผ์ € ์ˆ˜ํ–‰ํ•˜๋ฉด ๊ธฐ์กด ์†Œ์…œ ์‚ฌ์šฉ์ž์˜ ์ •์ƒ ๋กœ๊ทธ์ธ๊นŒ์ง€ ์ฐจ๋‹จ๋˜๋Š” ๋ฌธ์ œ๊ฐ€ ์ƒ๊น๋‹ˆ๋‹ค. ๊ถŒ์žฅ ํ”Œ๋กœ์šฐ:

  1. ์†Œ์…œ ํ† ํฐ/ํ”„๋กœํ•„ ์กฐํšŒ
  2. socialId+provider๋กœ ์‚ฌ์šฉ์ž ์กฐํšŒ
  3. ์กด์žฌํ•˜๋ฉด ๊ทธ๋Œ€๋กœ ๋กœ๊ทธ์ธ
  4. ์กด์žฌํ•˜์ง€ ์•Š์œผ๋ฉด โ€œ์‹ ๊ทœ ์ƒ์„ฑโ€ ์ง์ „์— ์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์‚ฌ โ†’ ์ค‘๋ณต ์‹œ 409 ๋ฐ˜ํ™˜ or ๊ณ„์ • ์—ฐ๊ฒฐ(migration) ํ”Œ๋กœ์šฐ ์œ ๋„

๋˜ํ•œ 4)์—์„œ DB Unique ์ œ์•ฝ(์ด๋ฉ”์ผ)์— ์˜์กดํ•ด ๋™์‹œ์„ฑ(TOCTOU) ๋ฐฉ์–ดํ•˜๊ณ , ์œ„๋ฐ˜ ์‹œ DataIntegrityViolationException์„ ์žก์•„ ๋™์ผ ์—๋Ÿฌ์ฝ”๋“œ๋กœ ๋งคํ•‘ํ•˜๋Š” ๊ฒƒ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (5)

5-5: NicknameGenerator import ์ถ”๊ฐ€ OK

์•„๋ž˜ ์ œ์•ˆ๋Œ€๋กœ ๋‹‰๋„ค์ž„ ์ƒ์„ฑ์€ โ€œ๊ฐ€์ž… ์‹œโ€์—๋งŒ ์ˆ˜ํ–‰ํ•˜๋ฉด ๋” ๊น”๋”ํ•ด์ง‘๋‹ˆ๋‹ค.


55-56: ์ด๋ฉ”์ผ null ๊ฐ€๋Šฅ์„ฑ ๋ฐฉ์–ด ์ฝ”๋“œ ์ถ”๊ฐ€ ๊ถŒ์žฅ

์นด์นด์˜ค ๊ณ„์ •์€ ์•ฝ๊ด€ ๋™์˜ ์—ฌ๋ถ€์— ๋”ฐ๋ผ ์ด๋ฉ”์ผ์ด ์ œ๊ณต๋˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. NPE ๋ฐฉ์ง€๋ฅผ ์œ„ํ•ด null-safe ํ• ๋‹น์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค(๊ฒ€์ฆ ๋กœ์ง์€ ์ด๋ฏธ null ์ฒดํฌ ํ›„ ํ˜ธ์ถœ๋กœ ๋ณด์™„ ์˜ˆ์ •).

-        String email = userProfile.kakaoAccount().email();      // ์ด๋ฉ”์ผ
+        String email = userProfile.kakaoAccount() != null ? userProfile.kakaoAccount().email() : null; // ์ด๋ฉ”์ผ(๋ฏธ์ œ๊ณต ๊ฐ€๋Šฅ์„ฑ ๊ณ ๋ ค)

์ด๋ฉ”์ผ ๋ฏธ์ œ๊ณต ์‹œ์˜ ์ •์ฑ…(๊ฐ€์ž… ํ—ˆ์šฉ/์ฐจ๋‹จ, ๋Œ€์ฒด ์‹๋ณ„์ž ์‚ฌ์šฉ ๋“ฑ)์ด ์ •ํ•ด์ ธ ์žˆ๋‹ค๋ฉด ๊ณต์œ  ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค. ์ •์ฑ…์— ๋งž์ถฐ ์˜ˆ์™ธ ์ฒ˜๋ฆฌ๋‚˜ ๋ถ„๊ธฐ ๋กœ์ง๊นŒ์ง€ ๋ฐ˜์˜ํ•ด๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.


61-61: PII(์†Œ์…œ ID) ๋กœ๊ทธ ๋…ธ์ถœ ์ตœ์†Œํ™” ๊ถŒ์žฅ

INFO ๋ ˆ๋ฒจ์— ์†Œ์…œ ์‹๋ณ„์ž๋ฅผ ๊ทธ๋Œ€๋กœ ๊ธฐ๋กํ•˜๋Š” ๊ฒƒ์€ ๊ณผ๋„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋””๋ฒ„๊ทธ๋กœ ๋‚ด๋ฆฌ๊ฑฐ๋‚˜ ๋งˆ์Šคํ‚น์„ ๊ณ ๋ คํ•ด์ฃผ์„ธ์š”.

-        log.info("์นด์นด์˜ค ๋กœ๊ทธ์ธ : ์‚ฌ์šฉ์ž ์ •๋ณด ์กฐํšŒ ์™„๋ฃŒ , ์†Œ์…œ ID : {}", socialId);
+        log.debug("์นด์นด์˜ค ๋กœ๊ทธ์ธ : ์‚ฌ์šฉ์ž ์ •๋ณด ์กฐํšŒ ์™„๋ฃŒ , ์†Œ์…œ ID : {}", socialId);

46-54: ํŠธ๋žœ์žญ์…˜ ๊ฒฝ๊ณ„ ์ตœ์†Œํ™” ๊ณ ๋ ค

์™ธ๋ถ€ API ํ˜ธ์ถœ(ํ† ํฐ/ํ”„๋กœํ•„ ์กฐํšŒ)์„ ํŠธ๋žœ์žญ์…˜ ๋ฐ”๊นฅ์—์„œ ์ˆ˜ํ–‰ํ•˜๊ณ , DB I/O๊ฐ€ ํ•„์š”ํ•œ ๊ตฌ๊ฐ„๋งŒ ํŠธ๋žœ์žญ์…˜์œผ๋กœ ๊ฐ์‹ธ๋Š” ํŽธ์ด ํšจ์œจ์ ์ž…๋‹ˆ๋‹ค. ํ˜„์žฌ ์˜ํ–ฅ์€ ํฌ์ง€ ์•Š์ง€๋งŒ, ์ž ์žฌ์ ์ธ ์ปค๋„ฅ์…˜ ์ ์œ  ์‹œ๊ฐ„์„ ์ค„์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํŠธ๋žœ์žญ์…˜ ์„ค์ • ์ „์ฒด ์ •์ฑ…์— ๋”ฐ๋ผ ์œ ์ง€๊ฐ€ ํ•„์š”ํ•˜๋‹ค๋ฉด ๊ทธ๋Œ€๋กœ ๊ฐ€์…”๋„ ๋ฉ๋‹ˆ๋‹ค. ํ™•์ธ๋งŒ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค.


57-67: ๊ฒฝํ•ฉ ์ƒํ™ฉ์—์„œ์˜ ์ตœ์ข… ์ผ๊ด€์„ฑ ํ™•๋ณด(๊ณ ์œ  ์ธ๋ฑ์Šค/์˜ˆ์™ธ ์ „ํ™˜) ์ œ์•ˆ

์ค‘๋ณต ๊ฒ€์‚ฌ โ†’ ์ €์žฅ ์‚ฌ์ด์— ๋‹ค๋ฅธ ํŠธ๋žœ์žญ์…˜์ด ๋™์ผ ์ด๋ฉ”์ผ๋กœ ๊ฐ€์ž…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฉ”์ผ ์ปฌ๋Ÿผ์— ์œ ๋‹ˆํฌ ์ธ๋ฑ์Šค๊ฐ€ ์žˆ๋‹ค๋ฉด DB๊ฐ€ ์ตœ์ข… ๋ฐฉ์–ด๋ฅผ ํ•ด์ฃผ๊ณ , ์ด๋•Œ DataIntegrityViolationException์„ ์žก์•„ ๋„๋ฉ”์ธ ์˜ˆ์™ธ๋กœ ์ „ํ™˜ํ•˜๋Š” ๊ฒƒ์ด ์•ˆ์ „ํ•ฉ๋‹ˆ๋‹ค. ์Šคํ‚ค๋งˆ๊ฐ€ ์ด๋ฏธ ๋ณด์žฅํ•œ๋‹ค๋ฉด ๋ฌด์‹œํ•˜์…”๋„ ๋ฉ๋‹ˆ๋‹ค.

์Šคํ‚ค๋งˆ์— ์ด๋ฉ”์ผ ์œ ๋‹ˆํฌ ์ œ์•ฝ์ด ์žˆ๋Š”์ง€ ํ™•์ธ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค. ํ•„์š” ์‹œ ์˜ˆ์™ธ ์ „ํ™˜ ๋กœ์ง ์ถ”๊ฐ€๋„ ๋„์™€๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.

๐Ÿ“œ Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

๐Ÿ’ก Knowledge Base configuration:

  • MCP integration is disabled by default for public repositories
  • Jira integration is disabled by default for public repositories
  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

๐Ÿ“ฅ Commits

Reviewing files that changed from the base of the PR and between d7e8da8 and b167d0c.

๐Ÿ“’ Files selected for processing (6)
  • insty-api/src/main/java/insty/domain/auth/service/AuthService.java (2 hunks)
  • insty-api/src/main/java/insty/domain/auth/strategy/GoogleStrategy.java (3 hunks)
  • insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (3 hunks)
  • insty-api/src/main/java/insty/domain/auth/strategy/NaverStrategy.java (3 hunks)
  • insty-api/src/main/java/insty/domain/user/implement/UserValidator.java (1 hunks)
  • insty-common/src/main/java/insty/error/UserErrorCode.java (1 hunks)
๐Ÿงฐ Additional context used
๐Ÿงฌ Code Graph Analysis (1)
insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (1)
insty-common/src/main/java/insty/generator/NicknameGenerator.java (1)
  • NicknameGenerator (5-48)
๐Ÿ”‡ Additional comments (6)
insty-common/src/main/java/insty/error/UserErrorCode.java (1)

8-8: ๋ฉ”์‹œ์ง€ ๋ณ€๊ฒฝ OK. ๋‹ค๋งŒ ํด๋ผ์ด์–ธํŠธ(์›น/์•ฑ) ๋ฌธ์ž์—ด ์˜์กด ์—ฌ๋ถ€ ์ ๊ฒ€ ๊ถŒ์žฅ

๋ฌธ์ž์—ด์ด ๋ฐ”๋€Œ๋ฉด E2E/FE ๋‹จ์—์„œ ๋ฌธ์ž์—ด ๋งค์นญ/์Šค๋ƒ…์ƒท ํ…Œ์ŠคํŠธ๊ฐ€ ๊นจ์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ฐ€๋Šฅํ•˜๋ฉด FE๋Š” code(=USER_005)์—๋งŒ ์˜์กดํ•˜๋„๋ก ์ ๊ฒ€ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

insty-api/src/main/java/insty/domain/auth/service/AuthService.java (1)

3-4: ๋น„๊ธฐ๋Šฅ ๋ณ€๊ฒฝ(import ์ •๋ฆฌ) โ€” ๋ฌธ์ œ ์—†์Œ

insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (4)

23-23: UserValidator ์ƒ์„ฑ์ž ์ฃผ์ž… ์ถ”๊ฐ€ ์ ์ ˆ

์ „๋žต ๋ ˆ๋ฒจ์—์„œ ๊ฐ€์ž… ์ „ ๊ฒ€์ฆ ์ฑ…์ž„์„ ๋ถ€์—ฌํ•˜๋Š” ๋ฐฉํ–ฅ์ด ์ผ๊ด€๋˜๊ณ  ์ข‹์Šต๋‹ˆ๋‹ค.


3-3: UserValidator import ์ถ”๊ฐ€ OK

์˜์กด์„ฑ ์ฃผ์ž…๊ณผ ์ผ์น˜ํ•ฉ๋‹ˆ๋‹ค.


9-11: ์นด์นด์˜ค ์–ด๋Œ‘ํ„ฐ/DTO import ์ •๋ฆฌ ์ด์ƒ ์—†์Œ

์˜์กด์„ฑ ์‚ฌ์šฉ๊ณผ ์ผ์น˜ํ•ฉ๋‹ˆ๋‹ค.


23-23: ์ˆ˜๋™ ์ธ์Šคํ„ด์Šคํ™” ๋ฐ ๊ฒ€์ฆ ์œ„์น˜ ์ •์ƒ ํ™•์ธ๋จ
ํ”„๋กœ์ ํŠธ ๋‚ด new KakaoStrategy(...) ํ˜ธ์ถœ์€ ์—†์—ˆ๊ณ , Google/Naver ์ „๋žต์—์„œ๋„ validateDuplicateEmail๊ฐ€ ํšŒ์›๊ฐ€์ž… ์‹œ์ (orElseGet ์ง์ „)์— ํ˜ธ์ถœ๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

Comment on lines +58 to +59
userValidator.validateDuplicateEmail(email);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

๐Ÿ’ก Verification agent

๐Ÿงฉ Analysis chain

์ค‘๋Œ€ํ•œ ๋ฒ„๊ทธ: ๊ธฐ์กด ์†Œ์…œ ์‚ฌ์šฉ์ž์˜ ์ •์ƒ ๋กœ๊ทธ์ธ๊นŒ์ง€ 409(USER_DUPLICATE_EMAIL)๋กœ ์ฐจ๋‹จ๋ฉ๋‹ˆ๋‹ค

์ด ์ค„์—์„œ ์ด๋ฉ”์ผ ์ค‘๋ณต์„ ๋จผ์ € ๊ฒ€์ฆํ•˜๋ฉด, ์ด๋ฏธ ๋“ฑ๋ก๋œ ๊ตฌ๊ธ€ ์‚ฌ์šฉ์ž(๋™์ผ email)๋„ ๋กœ๊ทธ์ธ ๋‹จ๊ณ„์—์„œ ์˜ˆ์™ธ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ์˜ฌ๋ฐ”๋ฅธ ์œ„์น˜๋Š” โ€œํ•ด๋‹น socialId/provider๋กœ ์‚ฌ์šฉ์ž๊ฐ€ ์—†์–ด์„œ ์ƒˆ๋กœ ๋งŒ๋“ค๋ ค๋Š” ์‹œ์ โ€์ž…๋‹ˆ๋‹ค.

์ ์šฉ ์ œ์•ˆ:

  1. ์‚ฌ์ „ ์ค‘๋ณต๊ฒ€์‚ฌ ํ˜ธ์ถœ ์ œ๊ฑฐ
-        userValidator.validateDuplicateEmail(email);
  1. ์‹ ๊ทœ ์ƒ์„ฑ ๋ถ„๊ธฐ ๋‚ด์—์„œ๋งŒ ์ค‘๋ณต ๊ฒ€์‚ฌ ์ˆ˜ํ–‰(์˜ˆ์‹œ ์ฝ”๋“œ)
return userRepository.findBySocialIdAndSocialType(socialId, SocialType.GOOGLE)
        .orElseGet(() -> {
            // ์‹ ๊ทœ ์ƒ์„ฑ ์ „์—๋งŒ ์ด๋ฉ”์ผ ์ค‘๋ณต ์ฒดํฌ
            userValidator.validateDuplicateEmail(email);
            User newUser = User.createBySocial(socialId, SocialType.GOOGLE, email, nickname, userType);
            return userRepository.save(newUser);
        });

์ถ”๊ฐ€ ๊ถŒ์žฅ:

  • ์ด๋ฉ”์ผ์— Unique ์ธ๋ฑ์Šค๊ฐ€ ์žˆ์–ด์•ผ ๋™์‹œ ๊ฐ€์ž… ๊ฒฝํ•ฉ ์‹œ ๋ฌด๊ฒฐ์„ฑ์ด ๋ณด์žฅ๋ฉ๋‹ˆ๋‹ค. ์œ„๋ฐ˜ ์˜ˆ์™ธ๋ฅผ ์žก์•„ USER_DUPLICATE_EMAIL๋กœ ๋งคํ•‘ํ•ด์ฃผ์„ธ์š”.

๊ฒ€์ฆ ์Šคํฌ๋ฆฝํŠธ(๋‹ค๋ฅธ ์ „๋žต์—์„œ๋„ ๋™์ผ ๋ฌธ์ œ ์—ฌ๋ถ€ ํ™•์ธ):


๐Ÿ Script executed:

#!/bin/bash
# ์ „๋žต๋“ค์—์„œ validateDuplicateEmail ํ˜ธ์ถœ ์œ„์น˜ ํ™•์ธ
rg -n -C3 --type=java '\bvalidateDuplicateEmail\s*\(' insty-api/src/main/java/insty/domain/auth/strategy

Length of output: 2422


์ค‘๋Œ€ํ•œ ๋ฒ„๊ทธ: ์†Œ์…œ ๋กœ๊ทธ์ธ ํ๋ฆ„์—์„œ ์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์‚ฌ ์œ„์น˜ ์˜ค๋ฅ˜๋กœ ๊ธฐ์กด ์‚ฌ์šฉ์ž 409 ์ฐจ๋‹จ

ํ˜„์žฌ Naver/Google/Kakao ์ „๋žต ๋ชจ๋‘ ๋กœ๊ทธ์ธ ์ดˆ๊ธฐ์— userValidator.validateDuplicateEmail(email);์„ ํ˜ธ์ถœํ•˜๊ณ  ์žˆ์–ด, ์ด๋ฏธ ๊ฐ€์ž…๋œ ์†Œ์…œ ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธํ•  ๋•Œ๋„ 409(USER_DUPLICATE_EMAIL) ์˜ˆ์™ธ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.
ํ•ด๊ฒฐ์„ ์œ„ํ•ด ์•„๋ž˜ ์ž‘์—…์„ ๋ฐ˜๋“œ์‹œ ์ ์šฉํ•ด์ฃผ์„ธ์š”.

โ€ข ์˜ํ–ฅ ํŒŒ์ผ ๋ฐ ์œ„์น˜

  • insty-api/src/main/java/insty/domain/auth/strategy/NaverStrategy.java:57
  • insty-api/src/main/java/insty/domain/auth/strategy/GoogleStrategy.java:58
  • insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java:59

โ€ข 1) ๋กœ๊ทธ์ธ ์ „์ค‘๋ณต๊ฒ€์‚ฌ ํ˜ธ์ถœ ์ œ๊ฑฐ

-        userValidator.validateDuplicateEmail(email);

โ€ข 2) ์‹ ๊ทœ ์‚ฌ์šฉ์ž ์ƒ์„ฑ ๋ถ„๊ธฐ ๋‚ด์—์„œ๋งŒ ์ค‘๋ณต๊ฒ€์‚ฌ ์ˆ˜ํ–‰

return userRepository.findBySocialIdAndSocialType(socialId, SocialType.GOOGLE)
        .orElseGet(() -> {
            // ์‹ ๊ทœ ์ƒ์„ฑ ์ „์—๋งŒ ์ด๋ฉ”์ผ ์ค‘๋ณต ์ฒดํฌ
            userValidator.validateDuplicateEmail(email);
            User newUser = User.createBySocial(socialId, SocialType.GOOGLE, email, nickname, userType);
            return userRepository.save(newUser);
        });

(๊ฐ ์ „๋žต์—์„œ findBySocialIdAndSocialType ํ˜ธ์ถœ๋ถ€๋ฅผ ์œ„ ํ˜•ํƒœ๋กœ ์ˆ˜์ •)

โ€ข 3) ์ด๋ฉ”์ผ ์ปฌ๋Ÿผ์— Unique ์ธ๋ฑ์Šค ์ถ”๊ฐ€
๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์ด๋ฉ”์ผ ๊ณ ์œ  ์ œ์•ฝ์กฐ๊ฑด์„ ๊ฑธ๊ณ , ConstraintViolation(DataIntegrityViolationException ๋“ฑ)๋ฅผ ์žก์•„ USER_DUPLICATE_EMAIL๋กœ ๋งคํ•‘ํ•ด ์ฃผ์„ธ์š”.

์œ„ ์„ธ ๊ฐ€์ง€๋ฅผ ๋ฐ˜์˜ํ•˜๋ฉด ๊ธฐ์กด ์†Œ์…œ ์‚ฌ์šฉ์ž์˜ ์ •์ƒ ๋กœ๊ทธ์ธ์ด 409๋กœ ์ฐจ๋‹จ๋˜๋Š” ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿค– Prompt for AI Agents
insty-api/src/main/java/insty/domain/auth/strategy/GoogleStrategy.java around
lines 58-59: currently calling userValidator.validateDuplicateEmail(email)
before checking for existing social user causes already-registered social users
to be blocked with 409; remove that pre-login duplicate-email check, change the
user lookup to use findBySocialIdAndSocialType(...).orElseGet(() -> {
userValidator.validateDuplicateEmail(email); create new User via
User.createBySocial(...); save and return it; }) so the email uniqueness check
runs only when creating a new user, and additionally add a UNIQUE
constraint/index on the email column in the DB and catch
constraint-violation/DataIntegrityViolationException to map it to
USER_DUPLICATE_EMAIL.

Comment on lines +57 to +58
userValidator.validateDuplicateEmail(email);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

โš ๏ธ Potential issue

์ค‘๋Œ€ํ•œ ๋ฒ„๊ทธ: ๊ธฐ์กด ๋„ค์ด๋ฒ„ ์†Œ์…œ ์‚ฌ์šฉ์ž์˜ ์ •์ƒ ๋กœ๊ทธ์ธ๊นŒ์ง€ 409(USER_DUPLICATE_EMAIL)๋กœ ์ฐจ๋‹จ๋ฉ๋‹ˆ๋‹ค

์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์‚ฌ๋Š” โ€œ์‹ ๊ทœ ์‚ฌ์šฉ์ž ์ƒ์„ฑโ€ ๊ฒฝ๋กœ์—์„œ๋งŒ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ˜„์žฌ ์œ„์น˜์—์„  ์ด๋ฏธ ๋“ฑ๋ก๋œ ์‚ฌ์šฉ์ž๋„ ์˜ˆ์™ธ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

์ ์šฉ ์ œ์•ˆ:

  1. ์‚ฌ์ „ ์ค‘๋ณต๊ฒ€์‚ฌ ํ˜ธ์ถœ ์ œ๊ฑฐ
-        userValidator.validateDuplicateEmail(email);
  1. ์‹ ๊ทœ ์ƒ์„ฑ ๋ถ„๊ธฐ ๋‚ด๋กœ ์ด๋™(์˜ˆ์‹œ ์ฝ”๋“œ)
return userRepository.findBySocialIdAndSocialType(socialId, SocialType.NAVER)
        .orElseGet(() -> {
            userValidator.validateDuplicateEmail(email); // ์‹ ๊ทœ ์ƒ์„ฑ ์ง์ „
            User newUser = User.createBySocial(socialId, SocialType.NAVER, email, nickname, userType);
            return userRepository.save(newUser);
        });

์ถ”๊ฐ€ ๊ถŒ์žฅ:

  • ์ด๋ฉ”์ผ Unique ์ œ์•ฝ + ์œ„๋ฐ˜ ์˜ˆ์™ธ๋ฅผ USER_DUPLICATE_EMAIL๋กœ ๋ณ€ํ™˜ํ•˜์—ฌ ๊ฒฝํ•ฉ/์žฌ์‹œ๋„ ์ƒํ™ฉ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ฒ˜๋ฆฌํ•˜์„ธ์š”.
๐Ÿค– Prompt for AI Agents
In insty-api/src/main/java/insty/domain/auth/strategy/NaverStrategy.java around
lines 57-58, the call to userValidator.validateDuplicateEmail(email) is
currently executed for all lookups causing existing Naver social users to be
blocked with 409; remove that pre-check and instead invoke
validateDuplicateEmail(email) only immediately before creating a new User inside
the orElseGet (or equivalent "create new" branch). Ensure the code finds by
socialId+SocialType, orElseGet does the duplicate-email validation then creates
and saves the new User; additionally add/ensure mapping from DB unique
constraint violations on email to the USER_DUPLICATE_EMAIL error to handle race
conditions safely.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and canโ€™t be posted inline due to platform limitations.

โš ๏ธ Outside diff range comments (1)
insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (1)

55-67: ์ด๋ฉ”์ผ ์ค‘๋ณต ๊ฒ€์ฆ์˜ ์ค‘๋ณต ํ˜ธ์ถœ๋กœ ๊ธฐ์กด ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ ์ฐจ๋‹จ ์œ„ํ—˜

  • Line 59์—์„œ ์„ (ๅ…ˆ) ์ค‘๋ณต ๊ฒ€์ฆ์„ ์ˆ˜ํ–‰ํ•˜๊ณ , Line 65์—์„œ๋„ ํšŒ์›๊ฐ€์ž… ๊ฒฝ๋กœ์—์„œ ๋™์ผ ๊ฒ€์ฆ์„ ๋‹ค์‹œ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  • ๋งŒ์•ฝ validateDuplicateEmail์ด โ€œํ•ด๋‹น ์ด๋ฉ”์ผ์ด ํ•˜๋‚˜๋ผ๋„ ์กด์žฌํ•˜๋ฉด ์˜ˆ์™ธโ€๋กœ ๋™์ž‘ํ•œ๋‹ค๋ฉด, ์ด๋ฏธ ๊ฐ€์ž…๋œ ๋™์ผ ์‚ฌ์šฉ์ž์˜ ์ผ๋ฐ˜ ๋กœ๊ทธ์ธ(= ๊ธฐ์กด ์†Œ์…œ ID ๋งค์นญ)๋„ Line 59์—์„œ ๋ถˆํ•„์š”ํ•˜๊ฒŒ ์ฐจ๋‹จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ์ค‘๋ณต ๊ฒ€์ฆ์€ โ€œ์‹ ๊ทœ ์‚ฌ์šฉ์ž ์ƒ์„ฑ ๊ฒฝ๋กœ(orElseGet ๋‚ด๋ถ€)โ€์—์„œ๋งŒ ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฒƒ์ด ์•ˆ์ „ํ•ฉ๋‹ˆ๋‹ค. ๋˜ํ•œ ๋‹‰๋„ค์ž„ ์ƒ์„ฑ๋„ ์‹ ๊ทœ ๊ฐ€์ž… ๊ฒฝ๋กœ์—์„œ๋งŒ ์ˆ˜ํ–‰ํ•˜๋ฉด ๋ถˆํ•„์š”ํ•œ ์—ฐ์‚ฐ์„ ์ค„์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ œ์•ˆ ์ˆ˜์ •์•ˆ:

         Long socialId = userProfile.id();       // ์†Œ์…œ ํšŒ์› ID
         String email = userProfile.kakaoAccount().email();      // ์ด๋ฉ”์ผ
-        String nickname = NicknameGenerator.generateNickname();
-
-        userValidator.validateDuplicateEmail(email);
+        // ์ด๋ฉ”์ผ/๋‹‰๋„ค์ž„ ๊ฒ€์‚ฌ๋Š” ์‹ ๊ทœ ํšŒ์›๊ฐ€์ž… ๊ฒฝ๋กœ์—์„œ๋งŒ ์ˆ˜ํ–‰

         log.info("์นด์นด์˜ค ๋กœ๊ทธ์ธ : ์‚ฌ์šฉ์ž ์ •๋ณด ์กฐํšŒ ์™„๋ฃŒ , ์†Œ์…œ ID : {}", socialId);

         return userRepository.findBySocialIdAndSocialType(String.valueOf(socialId), SocialType.KAKAO)
                 .orElseGet(() -> {                      // ์กด์žฌ X โ†’ ํšŒ์›๊ฐ€์ž…
                     userValidator.validateDuplicateEmail(email);
-                    User newUser = User.createBySocial(String.valueOf(socialId), SocialType.KAKAO, email, nickname, userType);
+                    String nickname = NicknameGenerator.generateNickname();
+                    User newUser = User.createBySocial(String.valueOf(socialId), SocialType.KAKAO, email, nickname, userType);
                     return userRepository.save(newUser);
                 });
๐Ÿงน Nitpick comments (2)
insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (2)

46-54: ์™ธ๋ถ€ HTTP ํ˜ธ์ถœ์„ ํŠธ๋žœ์žญ์…˜ ๋ฒ”์œ„ ๋ฐ–์œผ๋กœ ์ด๋™ ๊ณ ๋ ค

@Transactional ๋ฉ”์„œ๋“œ ์‹œ์ž‘ ์งํ›„ ์™ธ๋ถ€ API ํ˜ธ์ถœ(kakao ํ† ํฐ/ํ”„๋กœํ•„ ์กฐํšŒ)์ด ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋ถˆํ•„์š”ํ•˜๊ฒŒ ํŠธ๋žœ์žญ์…˜์ด ๊ธธ์–ด์งˆ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ:

  • ์™ธ๋ถ€ ํ˜ธ์ถœ์€ ํŠธ๋žœ์žญ์…˜ ๋ฐ–์—์„œ ์ˆ˜ํ–‰ํ•˜๊ณ ,
  • DB ์“ฐ๊ธฐ๊ฐ€ ํ•„์š”ํ•œ ๊ตฌ๊ฐ„(์‹ ๊ทœ ์œ ์ € ์ƒ์„ฑ/์ €์žฅ)๋งŒ ํŠธ๋žœ์žญ์…˜์œผ๋กœ ๊ฐ์‹ธ๋Š” ๊ตฌ์กฐ(๋ณ„๋„ ๋ฉ”์„œ๋“œ ๋ถ„๋ฆฌ ๋“ฑ)๋ฅผ ๊ณ ๋ คํ•ด ์ฃผ์„ธ์š”.

61-61: ๋กœ๊ทธ ๋ฏผ๊ฐ๋„ ์ ๊ฒ€ (์†Œ์…œ ID ์ถœ๋ ฅ)

์†Œ์…œ ID๋Š” ์™ธ๋ถ€ ์‹๋ณ„์ž๋ผ ๊ฐœ์ธ ์‹๋ณ„ ์ •๋ณด๋กœ ๊ฐ„์ฃผ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์šด์˜ ํ™˜๊ฒฝ์—์„œ๋Š” debug ๋ ˆ๋ฒจ๋กœ ๋‚ฎ์ถ”๊ฑฐ๋‚˜ ๋งˆ์Šคํ‚น/ํ•ด์‹ฑ์„ ๊ณ ๋ คํ•ด ์ฃผ์„ธ์š”.

๐Ÿ“œ Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

๐Ÿ’ก Knowledge Base configuration:

  • MCP integration is disabled by default for public repositories
  • Jira integration is disabled by default for public repositories
  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

๐Ÿ“ฅ Commits

Reviewing files that changed from the base of the PR and between b167d0c and 21a4327.

๐Ÿ“’ Files selected for processing (3)
  • insty-api/src/main/java/insty/domain/auth/strategy/GoogleStrategy.java (3 hunks)
  • insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (3 hunks)
  • insty-api/src/main/java/insty/domain/auth/strategy/NaverStrategy.java (3 hunks)
๐Ÿšง Files skipped from review as they are similar to previous changes (2)
  • insty-api/src/main/java/insty/domain/auth/strategy/NaverStrategy.java
  • insty-api/src/main/java/insty/domain/auth/strategy/GoogleStrategy.java
๐Ÿงฐ Additional context used
๐Ÿงฌ Code Graph Analysis (1)
insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (1)
insty-common/src/main/java/insty/generator/NicknameGenerator.java (1)
  • NicknameGenerator (5-48)
๐Ÿ”‡ Additional comments (2)
insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java (2)

23-23: UserValidator ์˜์กด์„ฑ ์ฃผ์ž… ๐Ÿ‘

์†Œ์…œ ๋กœ๊ทธ์ธ ์‹œ ์ด๋ฉ”์ผ ์œ ํšจ์„ฑ ๊ณตํ†ต ๊ฒ€์ฆ์„ ์œ„ํ•ด Validator๋ฅผ ์ฃผ์ž…ํ•œ ๋ฐฉํ–ฅ์„ฑ ์ข‹์Šต๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ์ „๋žต๋“ค๊ณผ์˜ ์ผ๊ด€์„ฑ๋„ ํ™•๋ณด๋  ๋“ฏํ•ฉ๋‹ˆ๋‹ค.


56-56: Kakao ํ”„๋กœํ•„์—์„œ ์ด๋ฉ”์ผ์ด null/๋ฏธ๋™์˜์ผ ์ˆ˜ ์žˆ์Œ โ€” NPE/๊ฒ€์ฆ ํ๋ฆ„ ํ™•์ธ ํ•„์š”

Kakao๋Š” ๊ณ„์ • ์„ค์ •/๋™์˜์— ๋”ฐ๋ผ kakaoAccount() ํ˜น์€ email()์ด null์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ:

  • validateDuplicateEmail(email) ๋‚ด๋ถ€์—์„œ NPE๊ฐ€ ๋ฐœ์ƒํ•˜๊ฑฐ๋‚˜,
  • createBySocial(..., email, ...) ์ €์žฅ ์‹œ ์ œ์•ฝ ์กฐ๊ฑด ์œ„๋ฐ˜์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ˜„์žฌ UserValidator.validateDuplicateEmail์ด null/blank๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ์ฒ˜๋ฆฌํ•˜๋Š”์ง€, ๋˜๋Š” ์—ฌ๊ธฐ์„œ ์„ ํ–‰ ๊ฐ€๋“œ๋ฅผ ๋‘์–ด์•ผ ํ•˜๋Š”์ง€ ํ™•์ธ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค. ํ•„์š” ์‹œ ๋‹ค์Œ ์ค‘ ํ•˜๋‚˜๋ฅผ ๊ณ ๋ คํ•ด ์ฃผ์„ธ์š”:

  • ์ด๋ฉ”์ผ ๋ฏธ์ œ๊ณต ์‹œ ๋ช…ํ™•ํ•œ ์—๋Ÿฌ ์ฝ”๋“œ๋กœ ๊ฑฐ์ ˆ ์ฒ˜๋ฆฌ
  • ์ด๋ฉ”์ผ ์—†๋Š” ์†Œ์…œ ๊ฐ€์ž…์„ ํ—ˆ์šฉํ•˜๋Š” ์ •์ฑ…์ด๋ผ๋ฉด, ํ•ด๋‹น ์ผ€์ด์Šค๋Š” ์ค‘๋ณต ๊ฒ€์‚ฌ ์Šคํ‚ต ๋ฐ DB ์ œ์•ฝ๊ณผ์˜ ์ผ๊ด€์„ฑ ํ™•๋ณด

Comment on lines 63 to 68
return userRepository.findBySocialIdAndSocialType(String.valueOf(socialId), SocialType.KAKAO)
.orElseGet(() -> { // ์กด์žฌ X โ†’ ํšŒ์›๊ฐ€์ž…
userValidator.validateDuplicateEmail(email);
User newUser = User.createBySocial(String.valueOf(socialId), SocialType.KAKAO, email, nickname, userType);
return userRepository.save(newUser);
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

๐Ÿ’ก Verification agent

๐Ÿงฉ Analysis chain

TOCTOU ๊ฒฝ์Ÿ ์กฐ๊ฑด ๊ฐ€๋Šฅ์„ฑ โ€” DB ์œ ๋‹ˆํฌ ์ œ์•ฝ/์˜ˆ์™ธ ์ฒ˜๋ฆฌ ํ™•์ธ ๊ถŒ์žฅ

์ค‘๋ณต ์ด๋ฉ”์ผ ๊ฒ€์‚ฌ ํ›„ ์ €์žฅ ์‚ฌ์ด์— ๊ฒฝ์Ÿ ์กฐ๊ฑด์ด ๋ฐœ์ƒํ•˜๋ฉด(๋™์‹œ ๊ฐ€์ž…), ๋™์ผ ์ด๋ฉ”์ผ์˜ ๊ณ„์ •์ด ์ค‘๋ณต ์ƒ์„ฑ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‹ค์งˆ์ ์ธ ์•ˆ์ „์žฅ์น˜๋Š” DB์˜ ์œ ๋‹ˆํฌ ์ œ์•ฝ์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ์„ ํ™•์ธํ•ด ์ฃผ์„ธ์š”:

  • user.email์— ์œ ๋‹ˆํฌ ์ธ๋ฑ์Šค ์กด์žฌ ์—ฌ๋ถ€
  • (์„ ํƒ) social_id + social_type ์กฐํ•ฉ์— ๋Œ€ํ•œ ์œ ๋‹ˆํฌ ์ œ์•ฝ ์กด์žฌ ์—ฌ๋ถ€
  • ์œ„๋ฐ˜ ์‹œ DataIntegrityViolationException ๋“ฑ์„ ์บ์น˜ํ•˜์—ฌ ๋„๋ฉ”์ธ ์˜ค๋ฅ˜๋กœ ๋ณ€ํ™˜ํ•˜๋Š” ์ฒ˜๋ฆฌ

์•„๋ž˜ ์Šคํฌ๋ฆฝํŠธ๋กœ ์—”ํ‹ฐํ‹ฐ/๋งˆ์ด๊ทธ๋ ˆ์ด์…˜์—์„œ ์œ ๋‹ˆํฌ ์ œ์•ฝ์„ ๋น ๋ฅด๊ฒŒ ์ ๊ฒ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


๐Ÿ Script executed:

#!/bin/bash
set -euo pipefail

echo "== JPA ์—”ํ‹ฐํ‹ฐ์—์„œ ์œ ๋‹ˆํฌ ์ œ์•ฝ ์–ด๋…ธํ…Œ์ด์…˜ ๊ฒ€์ƒ‰ =="
rg -n -C2 -P '(?i)@Table\([^)]*uniqueConstraints|@Column\([^)]*unique\s*=\s*true' --type=java

echo
echo "== User ์—”ํ‹ฐํ‹ฐ ๋‚ด email ํ•„๋“œ/์ œ์•ฝ ๊ด€๋ จ ๋‹จ์„œ ๊ฒ€์ƒ‰ =="
rg -n -C3 -P '(?i)class\s+User\b|@Column|email' --type=java

echo
echo "== SQL/๋งˆ์ด๊ทธ๋ ˆ์ด์…˜์—์„œ ์œ ๋‹ˆํฌ ์ œ์•ฝ ๊ฒ€์ƒ‰ =="
rg -n -C2 -P '(?i)create\s+table|unique\s+index|unique\s*\(|constraint' --type=sql

Length of output: 211263


DB ์œ ๋‹ˆํฌ ์ œ์•ฝ ๋ˆ„๋ฝ ๋ฐ TOCTOU ๋ฐฉ์ง€ ๋ณด๊ฐ• ํ•„์š”

ํ˜„์žฌ users.email์— ๋Œ€ํ•œ DBยทJPA ๋ ˆ๋ฒจ ์œ ๋‹ˆํฌ ์ œ์•ฝ์ด ์—†์–ด ๋™์‹œ ๊ฐ€์ž… ์‹œ ์ค‘๋ณต ๊ณ„์ •์ด ์ƒ์„ฑ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜๋ฅผ ๋ฐ˜๋“œ์‹œ ์ ์šฉํ•ด์ฃผ์„ธ์š”:

โ€ข insty-domain/src/main/java/insty/model/user/User.java
โ€“ @Column(nullable = false, length = 100) โ†’ @Column(nullable = false, length = 100, unique = true) ์ถ”๊ฐ€

โ€ข ์‹ค์šด์˜ DB ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜(๋˜๋Š” schema.sql)
โ€“ users.email์— UNIQUE INDEX ์ƒ์„ฑ
โ€“ (์„ ํƒ) (social_id, social_type) ๋ณตํ•ฉ ์œ ๋‹ˆํฌ ์ œ์•ฝ ์ถ”๊ฐ€

โ€ข ์˜ˆ์™ธ ์ฒ˜๋ฆฌ ๋ณด๊ฐ•
โ€“ ํšŒ์›๊ฐ€์ž… ๋กœ์ง(์˜ˆ: KakaoStrategy)์—์„œ userRepository.save(...) ํ˜ธ์ถœ์„ try { โ€ฆ } catch (DataIntegrityViolationException e)๋กœ ๊ฐ์‹ธ๊ณ 
UserErrorCode.USER_DUPLICATE_EMAIL(409) ๋“ฑ์œผ๋กœ ๋ณ€ํ™˜ํ•˜๋Š” ํ•ธ๋“ค๋Ÿฌ ์ถ”๊ฐ€

๐Ÿค– Prompt for AI Agents
In insty-api/src/main/java/insty/domain/auth/strategy/KakaoStrategy.java around
lines 63 to 68, the current signup flow can create duplicate users under
concurrent requests because there's no DB/JPA UNIQUE constraint on users.email
and the save() is not handling integrity violations; add a DB/JPA unique
constraint and catch integrity exceptions: 1) update
insty-domain/src/main/java/insty/model/user/User.java to change @Column(nullable
= false, length = 100) to @Column(nullable = false, length = 100, unique =
true); 2) add a DB migration (or update schema.sql) to create a UNIQUE INDEX on
users.email (and optionally a composite UNIQUE on (social_id, social_type)); 3)
wrap userRepository.save(...) in KakaoStrategy with try { ... } catch
(DataIntegrityViolationException e) and translate it into your application error
(e.g., throw a UserErrorCode.USER_DUPLICATE_EMAIL mapped to 409) so TOCTOU race
conditions result in a controlled, meaningful error.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant