Skip to content

Conversation

@CSE-Shaco
Copy link
Contributor

@CSE-Shaco CSE-Shaco commented Dec 26, 2025

πŸ“Œ μ—°κ΄€λœ 이슈

ex) #이슈번호, #이슈번호

✨ μž‘μ—… λ‚΄μš©

이번 PRμ—μ„œ μž‘μ—…ν•œ λ‚΄μš©μ„ κ°„λž΅νžˆ μ„€λͺ…ν•΄μ£Όμ„Έμš”

πŸ’¬ 리뷰 μš”κ΅¬μ‚¬ν•­(선택)

Summary by CodeRabbit

New Features

  • 둜그인 ν…ŒμŠ€νŠΈ API μ—”λ“œν¬μΈνŠΈ μΆ”κ°€
  • ν…ŒμŠ€νŠΈ API에 λŒ€ν•œ 곡개 μ ‘κ·Ό κΆŒν•œ μ„€μ •

✏️ Tip: You can customize this high-level summary in your review settings.

CSE-Shaco and others added 2 commits December 19, 2025 14:32
feat(guestbook, luckydraw): λ°©λͺ…둝 및 λ°©λͺ…둝 연계 좔첨 κΈ°λŠ₯ μΆ”κ°€
@coderabbitai
Copy link

coderabbitai bot commented Dec 26, 2025

κ°œμš”

μƒˆλ‘œμš΄ ν…ŒμŠ€νŠΈ μ—”λ“œν¬μΈνŠΈλ₯Ό μΆ”κ°€ν•˜μ—¬ λ¦¬ν”„λ ˆμ‹œ 토큰 쿠킀와 Authorization ν—€λ”μ˜ 쑴재 μ—¬λΆ€λ₯Ό ν™•μΈν•˜λ©°, λ³΄μ•ˆ 섀정을 톡해 ν•΄λ‹Ή μ—”λ“œν¬μΈνŠΈλ₯Ό 인증 없이 μ ‘κ·Ό κ°€λŠ₯ν•˜λ„λ‘ κ΅¬μ„±ν–ˆμŠ΅λ‹ˆλ‹€.

λ³€κ²½ 사항

μ½”ν˜ΈνŠΈ / 파일 λ³€κ²½ μš”μ•½
Test μ—”λ“œν¬μΈνŠΈ μΆ”κ°€
src/main/java/inha/gdgoc/domain/test/controller/TestController.java
μƒˆλ‘œμš΄ REST 컨트둀러 클래슀 생성, /api/v1/test/login_test GET μ—”λ“œν¬μΈνŠΈ μΆ”κ°€, 선택적 refresh_token 쿠킀와 Authorization 헀더λ₯Ό μˆ˜λ½ν•˜μ—¬ 뢈린 값을 맡으둜 λ°˜ν™˜
λ³΄μ•ˆ μ„€μ • μ—…λ°μ΄νŠΈ
src/main/java/inha/gdgoc/global/security/SecurityConfig.java
인증 없이 μ ‘κ·Ό κ°€λŠ₯ν•œ μ—”λ“œν¬μΈνŠΈ λͺ©λ‘μ— /api/v1/test/** νŒ¨ν„΄ μΆ”κ°€

μ˜ˆμƒ μ½”λ“œ 리뷰 λ‚œμ΄λ„

🎯 2 (λ‹¨μˆœ) | ⏱️ ~10λΆ„

μΆ•μ‹œ μ‹œ

🐰 ν…ŒμŠ€νŠΈ μ—”λ“œν¬μΈνŠΈκ°€ ν”Όμ–΄λ‚¬λ„€μš”,
토큰과 헀더λ₯Ό 살짝 듀좰보고,
λ³΄μ•ˆμ€ μ—΄μ–΄μ£Όκ³ , 응닡은 κΉ”λ”ν•˜κ²Œ!
둜그인 확인, 이제 μ€€λΉ„ 끝! πŸ”βœ¨

Pre-merge checks and finishing touches

❌ Failed checks (2 warnings)
Check name Status Explanation Resolution
Title check ⚠️ Warning PR 제λͺ©μ€ 'ν…ŒμŠ€νŠΈ: Google 둜그인 ν…ŒμŠ€νŠΈ μΆ”κ°€'μ΄μ§€λ§Œ, μ‹€μ œ 변경사항은 Google 둜그인과 λ¬΄κ΄€ν•˜κ²Œ 일반적인 ν…ŒμŠ€νŠΈ μ—”λ“œν¬μΈνŠΈ(TestController)λ₯Ό μΆ”κ°€ν•˜κ³  λ³΄μ•ˆ 섀정을 μˆ˜μ •ν•œ κ²ƒμž…λ‹ˆλ‹€. PR 제λͺ©μ„ μ‹€μ œ 변경사항에 맞게 μˆ˜μ •ν•˜μ„Έμš”. 예: 'test: add login test endpoint' λ˜λŠ” 'test: add TestController with security config'
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. You can run @coderabbitai generate docstrings to improve docstring coverage.
βœ… Passed checks (1 passed)
Check name Status Explanation
Description Check βœ… Passed Check skipped - CodeRabbit’s high-level summary is enabled.
✨ Finishing touches
  • πŸ“ Generate docstrings
πŸ§ͺ Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❀️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copy link

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

πŸ“œ Review details

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between 303b53d and 188ba6a.

πŸ“’ Files selected for processing (2)
  • src/main/java/inha/gdgoc/domain/test/controller/TestController.java
  • src/main/java/inha/gdgoc/global/security/SecurityConfig.java
🧰 Additional context used
🧠 Learnings (2)
πŸ“š Learning: 2025-08-30T10:43:25.889Z
Learnt from: kaswhy
Repo: GDGoCINHA/24-2_GDGoC_Server PR: 207
File: src/main/java/inha/gdgoc/global/security/TokenAuthenticationFilter.java:31-39
Timestamp: 2025-08-30T10:43:25.889Z
Learning: The GDGoCINHA project has a consistent security architecture where public endpoints are handled in two layers: 1) SecurityConfig uses .permitAll() for paths like /api/v1/auth/**, /api/v1/game/**, /api/v1/apply/**, /api/v1/check/** and 2) TokenAuthenticationFilter excludes the same paths in shouldNotFilter(). This dual-layer approach is correct and intentional.

Applied to files:

  • src/main/java/inha/gdgoc/global/security/SecurityConfig.java
πŸ“š Learning: 2025-08-30T10:43:25.889Z
Learnt from: kaswhy
Repo: GDGoCINHA/24-2_GDGoC_Server PR: 207
File: src/main/java/inha/gdgoc/global/security/TokenAuthenticationFilter.java:31-39
Timestamp: 2025-08-30T10:43:25.889Z
Learning: In the GDGoCINHA project, the following API paths are intentionally designed as public endpoints that should not require authentication: /api/v1/auth/, /api/v1/test/, /api/v1/game/, /api/v1/apply/, /api/v1/check/. These paths are correctly excluded from the TokenAuthenticationFilter in shouldNotFilter() method.

Applied to files:

  • src/main/java/inha/gdgoc/global/security/SecurityConfig.java
🧬 Code graph analysis (1)
src/main/java/inha/gdgoc/global/security/SecurityConfig.java (1)
src/main/java/inha/gdgoc/global/config/openapi/OpenApiConfig.java (1)
  • Configuration (15-82)
πŸ”‡ Additional comments (1)
src/main/java/inha/gdgoc/global/security/SecurityConfig.java (1)

48-48: 이쀑 λ ˆμ΄μ–΄ λ³΄μ•ˆ μ•„ν‚€ν…μ²˜μ˜ 일관성이 이미 μœ μ§€λ˜κ³  μžˆμŠ΅λ‹ˆλ‹€.

/api/v1/test/** κ²½λ‘œλŠ” TokenAuthenticationFilter의 shouldNotFilter() λ©”μ„œλ“œμ— 이미 ν¬ν•¨λ˜μ–΄ μžˆμŠ΅λ‹ˆλ‹€ (line 43). SecurityConfig와 TokenAuthenticationFilter κ°„μ˜ 일관성이 μ˜¬λ°”λ₯΄κ²Œ μœ μ§€λ˜κ³  μžˆμœΌλ―€λ‘œ μΆ”κ°€ μ‘°μΉ˜λŠ” ν•„μš”ν•˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€.

Comment on lines +1 to +14
package inha.gdgoc.domain.test.controller;

import inha.gdgoc.global.dto.response.ApiResponse;
import java.util.Map;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.CookieValue;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestHeader;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
@RequestMapping("/api/v1/test")
public class TestController {
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

PR 제λͺ©κ³Ό κ΅¬ν˜„ λ‚΄μš©μ΄ λΆˆμΌμΉ˜ν•©λ‹ˆλ‹€.

PR 제λͺ©μ€ "test: add google login test"μ΄μ§€λ§Œ, 이 μ»¨νŠΈλ‘€λŸ¬λŠ” Google λ‘œκ·ΈμΈμ„ ν…ŒμŠ€νŠΈν•˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€. λ‹¨μˆœνžˆ 토큰과 ν—€λ”μ˜ 쑴재 μ—¬λΆ€λ§Œ ν™•μΈν•©λ‹ˆλ‹€.

  • Google OAuth 둜그인 ν”Œλ‘œμš°λ₯Ό μ‹€μ œλ‘œ ν…ŒμŠ€νŠΈν•˜λ €λ©΄, Google 인증 μ„œλΉ„μŠ€μ™€μ˜ 톡합을 검증해야 ν•©λ‹ˆλ‹€
  • ν˜„μž¬ κ΅¬ν˜„μ€ 토큰 쑴재 μ—¬λΆ€λ§Œ ν™•μΈν•˜λŠ” 일반적인 인증 μƒνƒœ 체크 μ—”λ“œν¬μΈνŠΈμž…λ‹ˆλ‹€

PR 제λͺ©μ„ κ΅¬ν˜„μ— 맞게 μˆ˜μ •ν•˜κ±°λ‚˜, Google λ‘œκ·ΈμΈμ„ μ‹€μ œλ‘œ ν…ŒμŠ€νŠΈν•˜λŠ” λ‘œμ§μ„ μΆ”κ°€ν•˜λŠ” 것을 ꢌμž₯ν•©λ‹ˆλ‹€.

Comment on lines +16 to +30
@GetMapping("/login_test")
public ResponseEntity<ApiResponse<Map<String, Object>, Void>> loginTest(
@CookieValue(value = "refresh_token", required = false) String refreshToken,
@RequestHeader(value = "Authorization", required = false) String authorization
) {
boolean hasRefreshToken = refreshToken != null && !refreshToken.isBlank();
boolean hasAuthorization = authorization != null && !authorization.isBlank();

Map<String, Object> data = Map.of(
"has_refresh_token", hasRefreshToken,
"has_authorization", hasAuthorization
);

return ResponseEntity.ok(ApiResponse.ok("LOGIN_TEST_OK", data));
}
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

ν”„λ‘œλ•μ…˜ ν™˜κ²½μ—μ„œ ν…ŒμŠ€νŠΈ μ—”λ“œν¬μΈνŠΈ λ…ΈμΆœμ„ μ œν•œν•΄μ•Ό ν•©λ‹ˆλ‹€.

이 ν…ŒμŠ€νŠΈ μ—”λ“œν¬μΈνŠΈκ°€ λͺ¨λ“  ν™˜κ²½μ—μ„œ 곡개적으둜 μ ‘κ·Ό κ°€λŠ₯ν•˜λ„λ‘ μ„€μ •λ˜μ–΄ μžˆμŠ΅λ‹ˆλ‹€. ν”„λ‘œλ•μ…˜ ν™˜κ²½μ—μ„œ ν…ŒμŠ€νŠΈ μ—”λ“œν¬μΈνŠΈλ₯Ό λ…ΈμΆœν•˜λ©΄ λ³΄μ•ˆ μœ„ν—˜μ΄ λ°œμƒν•  수 μžˆμŠ΅λ‹ˆλ‹€.

λ‹€μŒ 쀑 ν•˜λ‚˜λ₯Ό μ μš©ν•˜λŠ” 것을 ꢌμž₯ν•©λ‹ˆλ‹€:

  • Spring Profile을 μ‚¬μš©ν•˜μ—¬ 개발/ν…ŒμŠ€νŠΈ ν™˜κ²½μ—μ„œλ§Œ ν™œμ„±ν™”
  • Feature flag둜 μ œμ–΄
  • λ³„λ„μ˜ ν…ŒμŠ€νŠΈ λͺ¨λ“ˆλ‘œ 뢄리
πŸ”Ž ν”„λ‘œν•„ 기반 ν™œμ„±ν™” μ œμ•ˆ
+import org.springframework.context.annotation.Profile;
+
+@Profile({"local", "dev", "test"})
 @RestController
 @RequestMapping("/api/v1/test")
 public class TestController {

λ˜λŠ” 쑰건뢀 빈 등둝을 μ‚¬μš©:

+import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty;
+
+@ConditionalOnProperty(name = "feature.test-endpoints.enabled", havingValue = "true")
 @RestController
 @RequestMapping("/api/v1/test")
 public class TestController {

Committable suggestion skipped: line range outside the PR's diff.

πŸ€– Prompt for AI Agents
In src/main/java/inha/gdgoc/domain/test/controller/TestController.java around
lines 16-30 the login_test endpoint is always exposed; restrict it so it is not
available in production by enabling it only for non-production profiles or via a
feature flag. Fix by annotating the controller (or its @Configuration) with a
profile/condition such as @Profile({"dev","test"}) or @Profile("!prod") or use a
conditional on a property (e.g.,
@ConditionalOnProperty(name="feature.test-endpoints.enabled",
havingValue="true", matchIfMissing=false)) and add the corresponding property to
dev/test configs (false or absent in production), then update docs and tests to
ensure the endpoint is only reachable in intended environments.

@CSE-Shaco CSE-Shaco merged commit 9987f97 into GDGoCINHA:develop Dec 26, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant