Repository navigation
[Feat/#111] AdMob 앱 인증을 위한 app-ads.txt 추가 - #112
Conversation
|
Caution Review failedFailed to post review comments 📝 WalkthroughWalkthroughAdded AdMob app authentication support by creating a new Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
src/main/resources/static/app-ads.txt (1)
1-1: LGTM! AdMob app-ads.txt declaration is correctly formatted.The file content follows the IAB Tech Lab specification for app-ads.txt files, with the correct format: domain, publisher ID, relationship type (DIRECT), and Google's certification authority ID. This will enable proper AdMob app authentication once deployed.
Minor optional refinement: Add trailing newline
While not required by the spec, text files conventionally end with a newline character. Consider adding one:
-google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0 +google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0 +🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@src/main/resources/static/app-ads.txt` at line 1, Add a trailing newline to the app-ads.txt file content (the line "google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0") so the file ends with a newline character; simply update the static resource write or file content to append a final newline when saving this entry.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@src/main/java/com/swyp/server/global/config/SecurityPath.java`:
- Around line 17-18: Confirm whether the updated PUBLIC_URLS array in
SecurityPath (including "/app-ads.txt") is actually deployed and active, then
verify other runtime security layers: ensure the deployed build contains the
change, check JwtAuthenticationFilter.shouldNotFilter() and
SecurityConfig.authorizeHttpRequests() are the versions in production, and
inspect any additional filters (custom or platform-level web security) that may
still require auth for static files; also verify the deployed server serves
app-ads.txt with a correct Content-Type and file path so the security match and
static resource handler both allow unauthenticated access.
---
Nitpick comments:
In `@src/main/resources/static/app-ads.txt`:
- Line 1: Add a trailing newline to the app-ads.txt file content (the line
"google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0") so the file ends
with a newline character; simply update the static resource write or file
content to append a final newline when saving this entry.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: ea597768-6e24-4e5f-8212-a912c8cbdf5e
📒 Files selected for processing (2)
src/main/java/com/swyp/server/global/config/SecurityPath.javasrc/main/resources/static/app-ads.txt
| "/terms.html", | ||
| "/app-ads.txt"); |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Verify app-ads.txt is publicly accessible and has correct content-type
echo "Testing app-ads.txt endpoint after deployment..."
# Test URL accessibility and content-type
response=$(curl -s -o /dev/null -w "%{http_code}|%{content_type}" https://haebom.io.kr/app-ads.txt)
http_code=$(echo "$response" | cut -d'|' -f1)
content_type=$(echo "$response" | cut -d'|' -f2)
echo "HTTP Status: $http_code"
echo "Content-Type: $content_type"
# Fetch and display content
echo -e "\nFile content:"
curl -s https://haebom.io.kr/app-ads.txt
# Expected: HTTP 200, content-type should be text/plain, content should match the static fileRepository: swyp-4th-team7/server
Length of output: 240
🏁 Script executed:
cat -n src/main/java/com/swyp/server/global/config/SecurityPath.javaRepository: swyp-4th-team7/server
Length of output: 741
🏁 Script executed:
find . -name "app-ads.txt" -type fRepository: swyp-4th-team7/server
Length of output: 104
🏁 Script executed:
fd -t f "app-ads.txt"Repository: swyp-4th-team7/server
Length of output: 102
🏁 Script executed:
rg "PUBLIC_URLS" --type javaRepository: swyp-4th-team7/server
Length of output: 471
🏁 Script executed:
find . -name "*Filter*" -type f | head -20Repository: swyp-4th-team7/server
Length of output: 139
🏁 Script executed:
find . -name "*SecurityConfig*" -type fRepository: swyp-4th-team7/server
Length of output: 130
🏁 Script executed:
cat -n src/main/java/com/swyp/server/global/config/JwtAuthenticationFilter.javaRepository: swyp-4th-team7/server
Length of output: 3642
🏁 Script executed:
cat -n src/main/java/com/swyp/server/global/config/SecurityConfig.javaRepository: swyp-4th-team7/server
Length of output: 2546
The addition of /app-ads.txt to PUBLIC_URLS (line 18) is properly configured and correctly referenced in both JwtAuthenticationFilter.shouldNotFilter() and SecurityConfig.authorizeHttpRequests(). However, testing the deployed endpoint shows it returns HTTP 401 Unauthorized with an authentication error, indicating the public access is not working in production despite the code configuration being sound.
This suggests the changes may not be deployed yet, or there is a deployment/configuration issue preventing the new PUBLIC_URLS entry from taking effect. Verify:
- Whether the latest code containing this change has been deployed
- If there are other security filters or configurations blocking static file access
- Whether the app-ads.txt file is being served with the correct content-type after deployment
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@src/main/java/com/swyp/server/global/config/SecurityPath.java` around lines
17 - 18, Confirm whether the updated PUBLIC_URLS array in SecurityPath
(including "/app-ads.txt") is actually deployed and active, then verify other
runtime security layers: ensure the deployed build contains the change, check
JwtAuthenticationFilter.shouldNotFilter() and
SecurityConfig.authorizeHttpRequests() are the versions in production, and
inspect any additional filters (custom or platform-level web security) that may
still require auth for static files; also verify the deployed server serves
app-ads.txt with a correct Content-Type and file path so the security match and
static resource handler both allow unauthenticated access.
📌 관련 이슈
✨ 변경 사항
📚 리뷰어 참고 사항
✅ 체크리스트
Summary by CodeRabbit