Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -14,5 +14,6 @@ public final class SecurityPath {
"/api-docs/**",
"/swagger-ui.html",
"/privacy.html",
"/terms.html");
"/terms.html",
"/app-ads.txt");
Comment on lines +17 to +18

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify app-ads.txt is publicly accessible and has correct content-type

echo "Testing app-ads.txt endpoint after deployment..."

# Test URL accessibility and content-type
response=$(curl -s -o /dev/null -w "%{http_code}|%{content_type}" https://haebom.io.kr/app-ads.txt)
http_code=$(echo "$response" | cut -d'|' -f1)
content_type=$(echo "$response" | cut -d'|' -f2)

echo "HTTP Status: $http_code"
echo "Content-Type: $content_type"

# Fetch and display content
echo -e "\nFile content:"
curl -s https://haebom.io.kr/app-ads.txt

# Expected: HTTP 200, content-type should be text/plain, content should match the static file

Repository: swyp-4th-team7/server

Length of output: 240


🏁 Script executed:

cat -n src/main/java/com/swyp/server/global/config/SecurityPath.java

Repository: swyp-4th-team7/server

Length of output: 741


🏁 Script executed:

find . -name "app-ads.txt" -type f

Repository: swyp-4th-team7/server

Length of output: 104


🏁 Script executed:

fd -t f "app-ads.txt"

Repository: swyp-4th-team7/server

Length of output: 102


🏁 Script executed:

rg "PUBLIC_URLS" --type java

Repository: swyp-4th-team7/server

Length of output: 471


🏁 Script executed:

find . -name "*Filter*" -type f | head -20

Repository: swyp-4th-team7/server

Length of output: 139


🏁 Script executed:

find . -name "*SecurityConfig*" -type f

Repository: swyp-4th-team7/server

Length of output: 130


🏁 Script executed:

cat -n src/main/java/com/swyp/server/global/config/JwtAuthenticationFilter.java

Repository: swyp-4th-team7/server

Length of output: 3642


🏁 Script executed:

cat -n src/main/java/com/swyp/server/global/config/SecurityConfig.java

Repository: swyp-4th-team7/server

Length of output: 2546


⚠️ Code change is correct, but deployed endpoint still requires authentication — investigate deployment.

The addition of /app-ads.txt to PUBLIC_URLS (line 18) is properly configured and correctly referenced in both JwtAuthenticationFilter.shouldNotFilter() and SecurityConfig.authorizeHttpRequests(). However, testing the deployed endpoint shows it returns HTTP 401 Unauthorized with an authentication error, indicating the public access is not working in production despite the code configuration being sound.

This suggests the changes may not be deployed yet, or there is a deployment/configuration issue preventing the new PUBLIC_URLS entry from taking effect. Verify:

  1. Whether the latest code containing this change has been deployed
  2. If there are other security filters or configurations blocking static file access
  3. Whether the app-ads.txt file is being served with the correct content-type after deployment
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@src/main/java/com/swyp/server/global/config/SecurityPath.java` around lines
17 - 18, Confirm whether the updated PUBLIC_URLS array in SecurityPath
(including "/app-ads.txt") is actually deployed and active, then verify other
runtime security layers: ensure the deployed build contains the change, check
JwtAuthenticationFilter.shouldNotFilter() and
SecurityConfig.authorizeHttpRequests() are the versions in production, and
inspect any additional filters (custom or platform-level web security) that may
still require auth for static files; also verify the deployed server serves
app-ads.txt with a correct Content-Type and file path so the security match and
static resource handler both allow unauthenticated access.

}
1 change: 1 addition & 0 deletions src/main/resources/static/app-ads.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
google.com, pub-7290830541472397, DIRECT, f08c47fec0942fa0