Skip to content

[FLYW-213] 마이페이지 로그아웃 405 오류 해결 - #263

Merged
gaeunnlee merged 6 commits into
devfrom
FLYW-213-마이페이지-로그아웃-405-에러
Apr 26, 2026

Hidden character warning

The head ref may contain hidden characters: "FLYW-213-\ub9c8\uc774\ud398\uc774\uc9c0-\ub85c\uadf8\uc544\uc6c3-405-\uc5d0\ub7ec"
Merged

gaeunnlee merged 6 commits into
devfrom
FLYW-213-마이페이지-로그아웃-405-에러

Conversation

@gaeunnlee

@gaeunnlee gaeunnlee commented Feb 15, 2026 •

Copy link
Copy Markdown
Member

📌 PR 설명

마이페이지 로그아웃 시 405 오류를 해결하고, 로그아웃, CSRF, 에러 처리를 보완하였습니다.

1. 오류 발생 원인
처음 발생하는 오류는 로그아웃 시 CSRF 검증 실패로 인한 403 오류였지만, 403 에러 페이지 포워딩 과정에서 /error가 POST를 처리하지 못해 405 오류가 발생되었습니다.

2. 마이페이지에서만 로그아웃 CSRF 검증 실패가 발생한 이유
메인페이지와 달리 마이페이지는 회원용 API 호출(인증·토큰 갱신 등)로 인해 세션·쿠키 상태가 중간에 변경될 가능성이 높아 CSRF 토큰 정합성이 깨졌고, 이로 인해 마이페이지에서의 로그아웃 POST 요청에서만 403이 발생했습니다. 따라서 로그아웃 요청 시 CSRF 토큰 정합성을 보장하기 위해 form submit 방식 대신 csrfFetch 함수를 사용하여 쿠키 기반 토큰을 헤더에 포함해 전송하도록 수정했습니다.


✅ 완료한 기능 명세

  • 로그아웃 시 세션 무효화 및 인증 정보 제거 (invalidateHttpSession, clearAuthentication)

  • 로그아웃 요청 시 csrfFetch 기반 CSRF 토큰 전송 처리

  • /error 엔드포인트가 GET/POST 모두 처리하도록 수정

  • Origin/Referer 필터에서 localhost 스킴 변형 허용 로직 추가

  • 로그아웃 CSRF 실패/성공 흐름 단위 테스트 추가 (LogoutFlowTest)

  • /error 403 렌더링 테스트 추가 (ErrorControllerTest)


💭 고민과 해결과정

처음에는 로그아웃 URL 매칭과 LogoutFilter이 원인이라고 생각했지만 CsrfFilter에서 차단이 발생하고 있었습니다.

403이 발생했지만, 에러 포워딩으로 인해 /error로 POST가 전달되었고, 기존 /error가 GET만 처리하여 405로 표시된 것이었습니다.

이를 해결하기 위해

  1. 프론트에서 csrfFetch로 토큰을 명확히 전송하도록 수정
  2. /error를 모든 HTTP 메서드에서 처리하도록 변경하여 405 반환 오류 해결
  3. 로그아웃 시 세션/인증/쿠키 정리를 명시적으로 설정하였습니다.

🔗 관련 이슈

Closes #262


Summary by CodeRabbit

  • New Features

    • 로그아웃 시 세션 무효화, 인증 정리 및 JSESSIONID 쿠키 삭제로 로그아웃 정리 강화
    • 클라이언트 측에서 CSRF-aware한 로그아웃 제출 흐름 추가(폼 인터셉트 및 POST 처리)
    • 로컬호스트 환경을 고려한 리퍼러/오리진 검증 로직 개선
  • Behavior

    • 에러 경로가 모든 HTTP 메서드를 처리하도록 확장
  • Tests

    • 로그아웃 플로우 검증 테스트 추가
    • 에러 컨트롤러 동작 테스트 추가
  • Documentation

    • README 대대적 개정 및 내용 재배치 및 서식 정리

@gaeunnlee gaeunnlee self-assigned this Feb 15, 2026
@gaeunnlee gaeunnlee linked an issue Feb 15, 2026 that may be closed by this pull request
6 tasks done
@gaeunnlee gaeunnlee added the FEAT 새로운 기능 추가 또는 기존 기능 확장 label Feb 15, 2026
@coderabbitai

coderabbitai Bot commented Feb 15, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

로그아웃 클라이언트 가로채기 및 csrfFetch 호출이 추가되고, 서버 로그아웃 설정에 세션 무효화·인증 클리어·JSESSIONID 삭제가 포함되었습니다. Referer/Origin 검증이 로컬호스트 크로스스킴을 허용하도록 확장되었고, /error 매핑이 모든 HTTP 메서드를 처리하도록 변경되었습니다.

변경사항

Cohort / File(s) Summary
로그아웃 보안 설정
src/main/java/com/flyway/security/config/SecurityConfigWeb.java
로그아웃 설정에 invalidateHttpSession(true), clearAuthentication(true), deleteCookies("JSESSIONID") 체이닝 추가.
클라이언트 로그아웃 흐름 (UI/JS)
src/main/webapp/WEB-INF/views/common/header.jsp, src/main/webapp/resources/common/js/csrfFetch.js
헤더에서 로그아웃 폼 제출을 가로채고 csrfFetch로 POST /auth/logout 요청 수행(버튼 비활성화·성공시 /login 리다이렉트). csrfFetch.js는 문서 주석 제거(로직 불변).
Origin/Referer 검증
src/main/java/com/flyway/security/filter/OriginRefererCheckFilter.java
extractOrigin, OriginParts, isLocalhostHost, isLocalhostSchemeVariant 헬퍼 추가로 localhost 간 http↔https 포트 매칭을 허용하는 검증 로직 확장.
에러 처리 경로 변경
src/main/java/com/flyway/template/controller/ErrorController.java
@GetMapping → @RequestMapping으로 변경해 /error 엔드포인트가 모든 HTTP 메서드 처리 가능하도록 확장.
테스트 추가: 로그아웃 흐름
src/test/java/com/flyway/security/filter/LogoutFlowTest.java
CSRF 보호 하의 로그아웃 흐름 검증 테스트 추가(토큰 없으면 403, 유효 토큰 시 리다이렉트·세션 무효화·쿠키 삭제 등).
테스트 추가: 에러 컨트롤러
src/test/java/com/flyway/template/controller/ErrorControllerTest.java
GET/POST /error 요청에 대해 403 상황에서 올바른 뷰 렌더링을 검증하는 테스트 추가.
경미한 정리
src/main/java/com/flyway/security/config/SecurityConfigApi.java
주석 한 줄 제거(로직 불변).
문서 변경
README.md
문서 포맷·섹션 재배치 및 텍스트 정리, 이미지 순서 일부 변경(내용 설명성 변경에 한정).

시퀀스 다이어그램

sequenceDiagram
    actor User
    participant Browser as "브라우저"
    participant HeaderJS as "헤더 JS"
    participant Server as "애플리케이션 서버\n(Spring Security)"
    participant CSRF as "CsrfFilter"
    participant Session as "세션 스토어"

    User->>Browser: 로그아웃 클릭
    Browser->>HeaderJS: 폼 제출 가로채기
    HeaderJS->>Browser: csrfFetch POST /auth/logout (X-CSRF-Token 포함)
    Browser->>Server: POST /auth/logout (쿠키 포함)
    Server->>CSRF: CSRF 토큰 검증
    alt 토큰 유효
        CSRF-->>Server: 유효
        Server->>Session: 세션 무효화
        Server->>Server: 인증 정보 제거
        Server->>Browser: Set-Cookie: JSESSIONID 삭제
        Server-->>Browser: 3xx 리다이렉트 -> /login
    else 토큰 없음/유효X
        CSRF-->>Server: 유효하지 않음
        Server-->>Browser: 403 Forbidden
    end
Loading

예상 코드 리뷰 노력

🎯 3 (Moderate) | ⏱️ ~25 분

Possibly related PRs

제안 레이블

FIX, ready-for-review

제안 리뷰어

  • hjh79gw
  • ochanhyeok
  • minseokim0113

시 🐰

로그아웃 버튼 톡, 토끼가 달려와
토큰 챙기고 쿠키는 싹 지워요 🥕
로컬호스트도 반갑게 맞아주고
필터는 깐깐히, 테스트는 반짝 빛나네 ✨

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning README.md 변경 사항이 로그아웃 오류 해결과 무관하며 문서 포맷팅과 구조 재편성만 다룹니다. 이는 405 오류 해결의 범위 밖입니다. README.md 문서 포맷팅 변경은 별도 PR로 분리하여 로그아웃 오류 수정과 관련된 변경에 집중할 것을 권장합니다.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목 'FLYW-213 마이페이지 로그아웃 405 오류 해결'은 PR의 주요 변경 사항을 명확하게 요약하고 있습니다. 마이페이지 로그아웃 405 오류 해결이라는 핵심 목표를 직접적으로 나타냅니다.
Linked Issues check ✅ Passed PR의 모든 주요 구현 사항이 연결된 이슈 #262의 요구 사항을 충족합니다. 프론트엔드 logout 변경(csrfFetch), 세션 무효화, /error 엔드포인트 수정, CSRF 필터 테스트, 에러 핸들링 테스트 등이 모두 포함됩니다.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch FLYW-213-마이페이지-로그아웃-405-에러

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@README.md`:
- Around line 149-153: The README contains <img> tags missing alt attributes
(e.g., the two <img src="https://github.com/user-attachments/..."> instances
shown), causing accessibility issues; update each <img> element in README.md
(including the other instances between lines 192-221) to include meaningful alt
text that describes the image content (e.g., "screenshot of X", "architecture
diagram showing Y") so screen readers and static analysis no longer flag them.
- Line 470: Fix the markdown header typo in the README by removing the stray
"/>" from the header text "### 2) 좌석 동시성 제어 (HOLD → PAYING → CONFIRMED)/>" so it
becomes "### 2) 좌석 동시성 제어 (HOLD → PAYING → CONFIRMED)" (or otherwise properly
escape/format the arrow characters) to restore correct Markdown rendering.

Comment thread README.md
Comment thread README.md Outdated
@gaeunnlee
gaeunnlee force-pushed the FLYW-213-마이페이지-로그아웃-405-에러 branch from 8844b2b to 089fcb7 Compare February 15, 2026 19:40
@gaeunnlee gaeunnlee changed the title [FLYW-2123] 마이페이지 로그아웃 405 오류 해결 [FLYW-213] 마이페이지 로그아웃 405 오류 해결 Feb 15, 2026
@gaeunnlee
gaeunnlee merged commit a05defa into dev Apr 26, 2026
1 check was pending

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
README.md (1)

149-152: ⚠️ Potential issue | 🟡 Minor

이미지 alt 속성 누락이 남아 있습니다.

Line 149, Line 152, Line 193, Line 196, Line 199, Line 202, Line 215, Line 218, Line 221의 <img> 태그에 alt가 없어 접근성/문서 품질 경고(MD045)가 계속 발생합니다.

🔧 예시 수정안
-      <img src="https://github.com/user-attachments/assets/e57143dc-6340-4c6a-9ca9-7af8b65c56c3" width="700"/>
+      <img src="https://github.com/user-attachments/assets/e57143dc-6340-4c6a-9ca9-7af8b65c56c3" width="700" alt="회원 기능 화면 모음"/>

-      <img src="https://github.com/user-attachments/assets/eb38c38e-5483-4eb4-8d68-fd7d9218f8fc" width="700"/>
+      <img src="https://github.com/user-attachments/assets/eb38c38e-5483-4eb4-8d68-fd7d9218f8fc" width="700" alt="관리자 기능 화면 모음"/>

-      <img src="https://github.com/user-attachments/assets/57ce3a42-ecc1-43d8-a3bc-a97c9b42ef74" width="320"/>
+      <img src="https://github.com/user-attachments/assets/57ce3a42-ecc1-43d8-a3bc-a97c9b42ef74" width="320" alt="ERD 항공편 테이블"/>

Also applies to: 193-203, 215-221

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@README.md` around lines 149 - 152, Several <img> tags in README.md (e.g., the
images with src values containing e57143dc-6340-4c6a-9ca9-7af8b65c56c3 and
eb38c38e-5483-4eb4-8d68-fd7d9218f8fc, plus the other images around the same
blocks) are missing alt attributes and trigger MD045; add an appropriate alt
attribute to each <img> tag (use concise descriptive text for meaningful images
or alt="" for purely decorative images) so every <img> in the affected sections
(the groups around the shown src URLs and the other occurrences ~lines 193–203
and 215–221) includes an alt value.
🧹 Nitpick comments (1)
README.md (1)

176-176: alt="Image"/alt="image"는 의미가 너무 약합니다.

접근성 품질을 위해 Line 176, Line 244, Line 247, Line 251의 alt 텍스트를 이미지 내용 중심으로 구체화하는 것을 권장합니다.

Also applies to: 244-247, 251-251

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@README.md` at line 176, The README contains <img> elements with generic alt
attributes (alt="Image" / "image") which are not descriptive; update each <img>
tag at the reported locations to replace the generic alt text with a concise,
content-focused description of the image (e.g., describe the scene, purpose, or
data shown) so that the alt attribute conveys the image meaning for assistive
technologies; ensure you edit the alt attribute on the relevant <img> elements
(use the existing <img ... src="..."> tags to locate them) and keep descriptions
short, specific, and non-redundant with surrounding text.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Duplicate comments:
In `@README.md`:
- Around line 149-152: Several <img> tags in README.md (e.g., the images with
src values containing e57143dc-6340-4c6a-9ca9-7af8b65c56c3 and
eb38c38e-5483-4eb4-8d68-fd7d9218f8fc, plus the other images around the same
blocks) are missing alt attributes and trigger MD045; add an appropriate alt
attribute to each <img> tag (use concise descriptive text for meaningful images
or alt="" for purely decorative images) so every <img> in the affected sections
(the groups around the shown src URLs and the other occurrences ~lines 193–203
and 215–221) includes an alt value.

---

Nitpick comments:
In `@README.md`:
- Line 176: The README contains <img> elements with generic alt attributes
(alt="Image" / "image") which are not descriptive; update each <img> tag at the
reported locations to replace the generic alt text with a concise,
content-focused description of the image (e.g., describe the scene, purpose, or
data shown) so that the alt attribute conveys the image meaning for assistive
technologies; ensure you edit the alt attribute on the relevant <img> elements
(use the existing <img ... src="..."> tags to locate them) and keep descriptions
short, specific, and non-redundant with surrounding text.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 78993b03-82f1-43ff-9521-fec35ad0f8b3

📥 Commits

Reviewing files that changed from the base of the PR and between 089fcb7 and 5644943.

📒 Files selected for processing (1)
  • README.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

FEAT 새로운 기능 추가 또는 기존 기능 확장

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FLYW-213] 마이페이지 로그아웃 405 에러

1 participant