Repository navigation
[FLYW-140] CSRF 설정 분리 (JSP Web 활성화 / API Origin 검증 적용) #261
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
ochanhyeok
merged 18 commits into
dev
from
FLYW-140-CSRF-설정-분리-(JSP-Web-활성화-%2F-API-Origin-검증-적용)
Feb 13, 2026
The head ref may contain hidden characters: "FLYW-140-CSRF-\uC124\uC815-\uBD84\uB9AC-(JSP-Web-\uD65C\uC131\uD654-%2F-API-Origin-\uAC80\uC99D-\uC801\uC6A9)"
Merged
Changes from all commits
Commits
Show all changes
18 commits
Select commit
Hold shift + click to select a range
a8dc54a
FLYW-140 feat: refreshToken 불일치 시 강제 로그아웃 및 WEB 세션 동기화 필터 추가 (#100)
gaeunnlee 366cc1b
FLYW-140 fix: JwtApiAuthFilter에 JWT 인증 마커 추가 및 중복 인증 방지 (#100)
gaeunnlee 4a11841
FLYW-140 feat: 로그인 페이지 returnUrl 파라미터 연동 (#100)
gaeunnlee ff042c6
FLYW-140 feat: 로그인 성공 시 returnUrl 기반 리다이렉트 추가 (#100)
gaeunnlee a085a02
FLYW-140 feat: 웹 인증 실패 시 login redirect entrypoint 적용 (#100)
gaeunnlee b5c109e
FLYW-140 fix: JWT/refresh 인증 실패 시 returnUrl 기반 redirect 처리 (#100)
gaeunnlee 8acb044
FLYW-140 feat: SecurityConfigWeb CSRF 활성화 및 form 태그 csrfInput 추가 (#100)
gaeunnlee e7ec217
FLYW-140 feat: SecurityConfigApi CSRF 활성화 및 csrfFetch 유틸 추가 (#100)
gaeunnlee 12310cb
FLYW-140 feat: 항공권 목록 조회 POST 변경 및 CSRF 유틸 적용 (#100)
gaeunnlee 98b9998
FLYW-140 feat: SecurityConfigWeb csrf 활성화 (#100)
gaeunnlee 7fabc30
FLYW-140 feat: fetch 요청 csrfFetch 일괄 변경 (#100)
gaeunnlee 8a0d02f
FLYW-140 feat: OriginRefererCheckFilter 구현 및 적용 (#100)
gaeunnlee 0ae6e58
FLYW-140 test: CSRF 토큰 검증 테스트 (#100)
gaeunnlee 41105e2
FLYW-140 fix: csrfFetch 초기화 레이스 방지 및 보안 필터 정규화 (#100)
gaeunnlee e80f0ea
FLYW-140 feat: 허용 Origin URI 환경별 설정 (#100)
gaeunnlee 3dd952c
FLYW-140 feat: refresh token 재사용 시 revoke 트랜잭션 분리 (#100)
gaeunnlee 842ebf5
FLYW-140 feat: Origin/Referer allowlist 대소문자 정규화 (#100)
gaeunnlee 13f4a2b
FLYW-140 test: 회원가입 테스트에 phoneNumber 필드 추가 및 SMS 인증 mock 처리 (#100)
gaeunnlee File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
21 changes: 21 additions & 0 deletions
21
src/main/java/com/flyway/auth/service/RefreshTokenRevocationService.java
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,21 @@ | ||
| package com.flyway.auth.service; | ||
|
|
||
| import com.flyway.auth.repository.RefreshTokenRepository; | ||
| import lombok.RequiredArgsConstructor; | ||
| import org.springframework.stereotype.Service; | ||
| import org.springframework.transaction.annotation.Propagation; | ||
| import org.springframework.transaction.annotation.Transactional; | ||
|
|
||
| import java.time.LocalDateTime; | ||
|
|
||
| @Service | ||
| @RequiredArgsConstructor | ||
| public class RefreshTokenRevocationService { | ||
|
|
||
| private final RefreshTokenRepository refreshTokenRepository; | ||
|
|
||
| @Transactional(propagation = Propagation.REQUIRES_NEW) | ||
| public void revokeAllByUserTokens(String userId, LocalDateTime now) { | ||
| refreshTokenRepository.revokeAllByUserId(userId, now); | ||
| } | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.