Skip to content

[Feat/#111] AdMob 앱 인증을 위한 app-ads.txt 추가 - #112

Merged
yunmi-dev merged 1 commit into
developfrom
feat/#111-app-ads-txt
Apr 15, 2026
Merged

yunmi-dev merged 1 commit into
developfrom
feat/#111-app-ads-txt

Conversation

@yunmi-dev

@yunmi-dev yunmi-dev commented Apr 15, 2026 •

Copy link
Copy Markdown
Collaborator

📌 관련 이슈

✨ 변경 사항

  • AdMob 앱 인증을 위한 app-ads.txt 파일 추가
  • SecurityPath PUBLIC_URLS에 /app-ads.txt 추가

📚 리뷰어 참고 사항

  • 머지 후 배포하면 haebom.io.kr/app-ads.txt 접근 가능

✅ 체크리스트

  • 브랜치 전략(git flow)을 따랐나요?
  • 로컬에서 빌드 및 실행이 정상적으로 되나요?
  • 불필요한 주석이나 더미 코드는 제거했나요?
  • 컨벤션(커밋 메시지, 코드 스타일)을 지켰나요?
  • spotlessApply 실행했나요?

Summary by CodeRabbit

  • Chores
    • Added Google AdSense configuration support to enable ad verification across the platform.

@coderabbitai

coderabbitai Bot commented Apr 15, 2026 •

Copy link
Copy Markdown

Caution

Review failed

Failed to post review comments

📝 Walkthrough

Walkthrough

Added AdMob app authentication support by creating a new app-ads.txt static resource file and configuring its public URL path in security settings. The file contains AdSense publisher declaration for domain root access.

Changes

Cohort / File(s) Summary
AdMob Authentication Configuration
src/main/java/com/swyp/server/global/config/SecurityPath.java
Added "/app-ads.txt" to the PUBLIC_URLS list to allow public access to the app authentication file.
AdMob Publisher Declaration
src/main/resources/static/app-ads.txt
Created new static resource file containing AdSense publisher declaration with publisher ID, access type, and authorization token for AdMob app verification.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 A carrot-sized task, I declare with glee,
App-ads.txt now accessible for all to see,
Security paths aligned, authorization true,
AdMob's blessing flows, our app will breakthrough! 📱✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title directly describes the main change: adding app-ads.txt file for AdMob app authentication, which matches the PR's primary objective.
Linked Issues check ✅ Passed The PR fully implements both requirements from issue #111: created app-ads.txt file with correct AdMob credentials and added /app-ads.txt to SecurityPath PUBLIC_URLS.
Out of Scope Changes check ✅ Passed All changes are directly related to the linked issue #111 requirements; no out-of-scope modifications are present in the PR.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/#111-app-ads-txt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
src/main/resources/static/app-ads.txt (1)

1-1: LGTM! AdMob app-ads.txt declaration is correctly formatted.

The file content follows the IAB Tech Lab specification for app-ads.txt files, with the correct format: domain, publisher ID, relationship type (DIRECT), and Google's certification authority ID. This will enable proper AdMob app authentication once deployed.

Minor optional refinement: Add trailing newline

While not required by the spec, text files conventionally end with a newline character. Consider adding one:

-google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0
+google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0
+
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@src/main/resources/static/app-ads.txt` at line 1, Add a trailing newline to
the app-ads.txt file content (the line "google.com, pub-7290830541472397,
DIRECT, f08c47fec0942fa0") so the file ends with a newline character; simply
update the static resource write or file content to append a final newline when
saving this entry.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@src/main/java/com/swyp/server/global/config/SecurityPath.java`:
- Around line 17-18: Confirm whether the updated PUBLIC_URLS array in
SecurityPath (including "/app-ads.txt") is actually deployed and active, then
verify other runtime security layers: ensure the deployed build contains the
change, check JwtAuthenticationFilter.shouldNotFilter() and
SecurityConfig.authorizeHttpRequests() are the versions in production, and
inspect any additional filters (custom or platform-level web security) that may
still require auth for static files; also verify the deployed server serves
app-ads.txt with a correct Content-Type and file path so the security match and
static resource handler both allow unauthenticated access.

---

Nitpick comments:
In `@src/main/resources/static/app-ads.txt`:
- Line 1: Add a trailing newline to the app-ads.txt file content (the line
"google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0") so the file ends
with a newline character; simply update the static resource write or file
content to append a final newline when saving this entry.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ea597768-6e24-4e5f-8212-a912c8cbdf5e

📥 Commits

Reviewing files that changed from the base of the PR and between c76f2de and b55b151.

📒 Files selected for processing (2)
  • src/main/java/com/swyp/server/global/config/SecurityPath.java
  • src/main/resources/static/app-ads.txt

Comment on lines +17 to +18
"/terms.html",
"/app-ads.txt");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify app-ads.txt is publicly accessible and has correct content-type

echo "Testing app-ads.txt endpoint after deployment..."

# Test URL accessibility and content-type
response=$(curl -s -o /dev/null -w "%{http_code}|%{content_type}" https://haebom.io.kr/app-ads.txt)
http_code=$(echo "$response" | cut -d'|' -f1)
content_type=$(echo "$response" | cut -d'|' -f2)

echo "HTTP Status: $http_code"
echo "Content-Type: $content_type"

# Fetch and display content
echo -e "\nFile content:"
curl -s https://haebom.io.kr/app-ads.txt

# Expected: HTTP 200, content-type should be text/plain, content should match the static file

Repository: swyp-4th-team7/server

Length of output: 240


🏁 Script executed:

cat -n src/main/java/com/swyp/server/global/config/SecurityPath.java

Repository: swyp-4th-team7/server

Length of output: 741


🏁 Script executed:

find . -name "app-ads.txt" -type f

Repository: swyp-4th-team7/server

Length of output: 104


🏁 Script executed:

fd -t f "app-ads.txt"

Repository: swyp-4th-team7/server

Length of output: 102


🏁 Script executed:

rg "PUBLIC_URLS" --type java

Repository: swyp-4th-team7/server

Length of output: 471


🏁 Script executed:

find . -name "*Filter*" -type f | head -20

Repository: swyp-4th-team7/server

Length of output: 139


🏁 Script executed:

find . -name "*SecurityConfig*" -type f

Repository: swyp-4th-team7/server

Length of output: 130


🏁 Script executed:

cat -n src/main/java/com/swyp/server/global/config/JwtAuthenticationFilter.java

Repository: swyp-4th-team7/server

Length of output: 3642


🏁 Script executed:

cat -n src/main/java/com/swyp/server/global/config/SecurityConfig.java

Repository: swyp-4th-team7/server

Length of output: 2546


⚠️ Code change is correct, but deployed endpoint still requires authentication — investigate deployment.

The addition of /app-ads.txt to PUBLIC_URLS (line 18) is properly configured and correctly referenced in both JwtAuthenticationFilter.shouldNotFilter() and SecurityConfig.authorizeHttpRequests(). However, testing the deployed endpoint shows it returns HTTP 401 Unauthorized with an authentication error, indicating the public access is not working in production despite the code configuration being sound.

This suggests the changes may not be deployed yet, or there is a deployment/configuration issue preventing the new PUBLIC_URLS entry from taking effect. Verify:

  1. Whether the latest code containing this change has been deployed
  2. If there are other security filters or configurations blocking static file access
  3. Whether the app-ads.txt file is being served with the correct content-type after deployment
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@src/main/java/com/swyp/server/global/config/SecurityPath.java` around lines
17 - 18, Confirm whether the updated PUBLIC_URLS array in SecurityPath
(including "/app-ads.txt") is actually deployed and active, then verify other
runtime security layers: ensure the deployed build contains the change, check
JwtAuthenticationFilter.shouldNotFilter() and
SecurityConfig.authorizeHttpRequests() are the versions in production, and
inspect any additional filters (custom or platform-level web security) that may
still require auth for static files; also verify the deployed server serves
app-ads.txt with a correct Content-Type and file path so the security match and
static resource handler both allow unauthenticated access.

@guzzang guzzang left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

고생하셨습니다!

@yunmi-dev
yunmi-dev merged commit 88ebd2c into develop Apr 15, 2026
2 checks passed
@yunmi-dev
yunmi-dev deleted the feat/#111-app-ads-txt branch April 15, 2026 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feat] AdMob 앱 인증을 위한 app-ads.txt 추가

2 participants