[FLYW-213] 마이페이지 로그아웃 405 오류 해결 - #263
Hidden character warning
Conversation
📝 WalkthroughWalkthrough로그아웃 클라이언트 가로채기 및 csrfFetch 호출이 추가되고, 서버 로그아웃 설정에 세션 무효화·인증 클리어·JSESSIONID 삭제가 포함되었습니다. Referer/Origin 검증이 로컬호스트 크로스스킴을 허용하도록 확장되었고, 변경사항
시퀀스 다이어그램sequenceDiagram
actor User
participant Browser as "브라우저"
participant HeaderJS as "헤더 JS"
participant Server as "애플리케이션 서버\n(Spring Security)"
participant CSRF as "CsrfFilter"
participant Session as "세션 스토어"
User->>Browser: 로그아웃 클릭
Browser->>HeaderJS: 폼 제출 가로채기
HeaderJS->>Browser: csrfFetch POST /auth/logout (X-CSRF-Token 포함)
Browser->>Server: POST /auth/logout (쿠키 포함)
Server->>CSRF: CSRF 토큰 검증
alt 토큰 유효
CSRF-->>Server: 유효
Server->>Session: 세션 무효화
Server->>Server: 인증 정보 제거
Server->>Browser: Set-Cookie: JSESSIONID 삭제
Server-->>Browser: 3xx 리다이렉트 -> /login
else 토큰 없음/유효X
CSRF-->>Server: 유효하지 않음
Server-->>Browser: 403 Forbidden
end
예상 코드 리뷰 노력🎯 3 (Moderate) | ⏱️ ~25 분 Possibly related PRs
제안 레이블
제안 리뷰어
시 🐰
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Fix all issues with AI agents
In `@README.md`:
- Around line 149-153: The README contains <img> tags missing alt attributes
(e.g., the two <img src="https://github.com/user-attachments/..."> instances
shown), causing accessibility issues; update each <img> element in README.md
(including the other instances between lines 192-221) to include meaningful alt
text that describes the image content (e.g., "screenshot of X", "architecture
diagram showing Y") so screen readers and static analysis no longer flag them.
- Line 470: Fix the markdown header typo in the README by removing the stray
"/>" from the header text "### 2) 좌석 동시성 제어 (HOLD → PAYING → CONFIRMED)/>" so it
becomes "### 2) 좌석 동시성 제어 (HOLD → PAYING → CONFIRMED)" (or otherwise properly
escape/format the arrow characters) to restore correct Markdown rendering.
8844b2b to
089fcb7
Compare
There was a problem hiding this comment.
♻️ Duplicate comments (1)
README.md (1)
149-152:⚠️ Potential issue | 🟡 Minor이미지 alt 속성 누락이 남아 있습니다.
Line 149, Line 152, Line 193, Line 196, Line 199, Line 202, Line 215, Line 218, Line 221의
<img>태그에alt가 없어 접근성/문서 품질 경고(MD045)가 계속 발생합니다.🔧 예시 수정안
- <img src="https://github.com/user-attachments/assets/e57143dc-6340-4c6a-9ca9-7af8b65c56c3" width="700"/> + <img src="https://github.com/user-attachments/assets/e57143dc-6340-4c6a-9ca9-7af8b65c56c3" width="700" alt="회원 기능 화면 모음"/> - <img src="https://github.com/user-attachments/assets/eb38c38e-5483-4eb4-8d68-fd7d9218f8fc" width="700"/> + <img src="https://github.com/user-attachments/assets/eb38c38e-5483-4eb4-8d68-fd7d9218f8fc" width="700" alt="관리자 기능 화면 모음"/> - <img src="https://github.com/user-attachments/assets/57ce3a42-ecc1-43d8-a3bc-a97c9b42ef74" width="320"/> + <img src="https://github.com/user-attachments/assets/57ce3a42-ecc1-43d8-a3bc-a97c9b42ef74" width="320" alt="ERD 항공편 테이블"/>Also applies to: 193-203, 215-221
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@README.md` around lines 149 - 152, Several <img> tags in README.md (e.g., the images with src values containing e57143dc-6340-4c6a-9ca9-7af8b65c56c3 and eb38c38e-5483-4eb4-8d68-fd7d9218f8fc, plus the other images around the same blocks) are missing alt attributes and trigger MD045; add an appropriate alt attribute to each <img> tag (use concise descriptive text for meaningful images or alt="" for purely decorative images) so every <img> in the affected sections (the groups around the shown src URLs and the other occurrences ~lines 193–203 and 215–221) includes an alt value.
🧹 Nitpick comments (1)
README.md (1)
176-176:alt="Image"/alt="image"는 의미가 너무 약합니다.접근성 품질을 위해 Line 176, Line 244, Line 247, Line 251의 alt 텍스트를 이미지 내용 중심으로 구체화하는 것을 권장합니다.
Also applies to: 244-247, 251-251
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@README.md` at line 176, The README contains <img> elements with generic alt attributes (alt="Image" / "image") which are not descriptive; update each <img> tag at the reported locations to replace the generic alt text with a concise, content-focused description of the image (e.g., describe the scene, purpose, or data shown) so that the alt attribute conveys the image meaning for assistive technologies; ensure you edit the alt attribute on the relevant <img> elements (use the existing <img ... src="..."> tags to locate them) and keep descriptions short, specific, and non-redundant with surrounding text.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Duplicate comments:
In `@README.md`:
- Around line 149-152: Several <img> tags in README.md (e.g., the images with
src values containing e57143dc-6340-4c6a-9ca9-7af8b65c56c3 and
eb38c38e-5483-4eb4-8d68-fd7d9218f8fc, plus the other images around the same
blocks) are missing alt attributes and trigger MD045; add an appropriate alt
attribute to each <img> tag (use concise descriptive text for meaningful images
or alt="" for purely decorative images) so every <img> in the affected sections
(the groups around the shown src URLs and the other occurrences ~lines 193–203
and 215–221) includes an alt value.
---
Nitpick comments:
In `@README.md`:
- Line 176: The README contains <img> elements with generic alt attributes
(alt="Image" / "image") which are not descriptive; update each <img> tag at the
reported locations to replace the generic alt text with a concise,
content-focused description of the image (e.g., describe the scene, purpose, or
data shown) so that the alt attribute conveys the image meaning for assistive
technologies; ensure you edit the alt attribute on the relevant <img> elements
(use the existing <img ... src="..."> tags to locate them) and keep descriptions
short, specific, and non-redundant with surrounding text.
📌 PR 설명
마이페이지 로그아웃 시 405 오류를 해결하고, 로그아웃, CSRF, 에러 처리를 보완하였습니다.
1. 오류 발생 원인
처음 발생하는 오류는 로그아웃 시 CSRF 검증 실패로 인한 403 오류였지만, 403 에러 페이지 포워딩 과정에서
/error가 POST를 처리하지 못해 405 오류가 발생되었습니다.2. 마이페이지에서만 로그아웃 CSRF 검증 실패가 발생한 이유
메인페이지와 달리 마이페이지는 회원용 API 호출(인증·토큰 갱신 등)로 인해 세션·쿠키 상태가 중간에 변경될 가능성이 높아 CSRF 토큰 정합성이 깨졌고, 이로 인해 마이페이지에서의 로그아웃 POST 요청에서만 403이 발생했습니다. 따라서 로그아웃 요청 시 CSRF 토큰 정합성을 보장하기 위해 form submit 방식 대신
csrfFetch함수를 사용하여 쿠키 기반 토큰을 헤더에 포함해 전송하도록 수정했습니다.✅ 완료한 기능 명세
로그아웃 시 세션 무효화 및 인증 정보 제거 (
invalidateHttpSession,clearAuthentication)로그아웃 요청 시
csrfFetch기반 CSRF 토큰 전송 처리/error엔드포인트가 GET/POST 모두 처리하도록 수정Origin/Referer 필터에서 localhost 스킴 변형 허용 로직 추가
로그아웃 CSRF 실패/성공 흐름 단위 테스트 추가 (
LogoutFlowTest)/error403 렌더링 테스트 추가 (ErrorControllerTest)💭 고민과 해결과정
처음에는 로그아웃 URL 매칭과 LogoutFilter이 원인이라고 생각했지만
CsrfFilter에서 차단이 발생하고 있었습니다.403이 발생했지만, 에러 포워딩으로 인해
/error로 POST가 전달되었고, 기존/error가 GET만 처리하여 405로 표시된 것이었습니다.이를 해결하기 위해
csrfFetch로 토큰을 명확히 전송하도록 수정/error를 모든 HTTP 메서드에서 처리하도록 변경하여 405 반환 오류 해결🔗 관련 이슈
Closes #262
Summary by CodeRabbit
New Features
Behavior
Tests
Documentation