Skip to content

Conversation

@bmh7190
Copy link

@bmh7190 bmh7190 commented Dec 18, 2025

✅ 실습 체크리스트

  • 이론 학습을 완료하셨나요?
  • 미션 요구사항을 모두 이해하셨나요?
  • 실습을 수행하기 위한 공부를 완료하셨나요?
  • 실습 요구사항을 모두 완료하셨나요?

✅ 컨벤션 체크리스트

  • 디렉토리 구조 컨벤션을 잘 지켰나요?
  • pr 제목을 컨벤션에 맞게 작성하였나요?
  • pr에 해당되는 이슈를 연결하였나요?(중요)
  • 적절한 라벨을 설정하였나요?
  • 파트장에게 code review를 요청하기 위해 reviewer를 등록하였나요?
  • 닉네임/main 브랜치의 최신 상태를 반영하고 있는지 확인했나요?(매우 중요!)

📌 주안점

@bmh7190 bmh7190 requested a review from kfdsy0103 December 18, 2025 12:10
@bmh7190 bmh7190 self-assigned this Dec 18, 2025
@bmh7190 bmh7190 linked an issue Dec 18, 2025 that may be closed by this pull request
Copy link
Collaborator

@kfdsy0103 kfdsy0103 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

10주차 워크북 수행하시느라 수고 많으셨어요 미녁!
리뷰 확인 후 머지 부탁드립니다!

Comment on lines +42 to +47
@PostMapping("/login")
ApiResponse<MemberResDTO.LoginDTO> login(
@RequestBody @Valid MemberReqDTO.LoginDTO dto
) {
return ApiResponse.onSuccess(MemberSuccessCode.FOUND, memberQueryService.login(dto));
}
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

로그인/회원가입 같은 권한 관련 코드는 따로 Auth 패키지 파서 분리해줘도 좋아보여요!

Comment on lines +38 to +55
http
.authorizeHttpRequests(requests -> requests
.requestMatchers(allowUris).permitAll()
.requestMatchers("/admin/**").hasRole("ADMIN")
.anyRequest().authenticated()
)
// 폼로그인 비활성화
.formLogin(AbstractHttpConfigurer::disable)
// JwtAuthFilter를 UsernamePasswordAuthenticationFilter
.addFilterBefore(jwtAuthFilter(), UsernamePasswordAuthenticationFilter.class)
.csrf(AbstractHttpConfigurer::disable)
.logout(logout -> logout
.logoutUrl("/logout")
.logoutSuccessUrl("/login?logout")
.permitAll()
)
.exceptionHandling(exception -> exception.authenticationEntryPoint(authenticationEntryPoint()))

Copy link
Collaborator

@kfdsy0103 kfdsy0103 Dec 21, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

JWT를 사용하는 경우 session 비활성화를 명시해주는 것도 좋아보여요!

http
    .sessionManagement(session ->
        session.sessionCreationPolicy(SessionCreationPolicy.STATELESS)
    )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Chapter10_로그인 및 회원가입

2 participants