https://ekeprl.tistory.com/65 [Spring Security - JWT] (3) : JwtFilter이전 포스팅을 통해 JWT 토큰의 생성과 검증을 담당하는 JwtUtil을 작성했다.https://ekeprl.tistory.com/64 이번 포스팅은 매 요청마다 JWT 토큰을 검증하는 JwtFilter를 작성해보려 한다. 1.JwtFilter@Componentclassekeprl.tistory.com 이전 포스팅을 통해 JwtFilter 작성을 알아보았다.이번 포스팅은 로그인 / 회원가입 API 작성 및 Postman 테스트를 진행해보려 한다. 1. Controller@RestController@RequestMapping("/auth")class UserController( ..
이전 포스팅을 통해 JWT 토큰의 생성과 검증을 담당하는 JwtUtil을 작성했다.https://ekeprl.tistory.com/64 [Spring Security - JWT] (2) : JwtUtilhttps://ekeprl.tistory.com/63 [Spring Security - JWT] (1) : SecurityConfig 설정https://ekeprl.tistory.com/62 [Spring Security] 세션 기반 vs JWT 기반https://ekeprl.tistory.com/30 Spring Security (1)Spring boot : 3.1Spring Security6Kotlin Spring secuekeprl.tistory.com 이번 포스팅은 매 요청마다 JWT 토큰을 검증..
https://ekeprl.tistory.com/62 [Spring Security] 세션 기반 vs JWT 기반https://ekeprl.tistory.com/30 Spring Security (1)Spring boot : 3.1Spring Security6Kotlin Spring security의 방식에 대해선 다루지않고, 어떻게 작성했는지를 다루도록 하려한다. 1. Build.gradle.ktsdependencies { //spring-secutiry (ekeprl.tistory.com 이전 포스팅을 통해 세션기반 인증 vs JWT기반 인증을 비교했다. 이번 포스팅은 실전으로 들어가 JWT인증방식을 사용한 Spring Security 설정을 시작하려고 한다. 1. build.gradle.ktsdep..
애플리케이션에서 사용자의 권한을 구분하는 것은 중요한 보안 기능입니다. 특히, ADMIN과 USER와 같은 권한을 나누는 이유는, 각 사용자가 접근할 수 있는 리소스를 제한하려고 한다. 관리자는 모든 데이터에 접근할 수 있지만 일반 사용자는 제한된 기능만 사용해야 할 필요가 있습니다. 이때 Spring Security를 사용하여 사용자 인증 시 적절한 권한을 부여하고, 이를 세션에 저장하여 각 페이지에서 해당 권한에 맞는 행동을 제어할 수 있다. 세션에 권한을 저장하는 이유는 사용자가 로그인 후 매번 서버에 요청할 때마다 권한을 재확인할 필요 없이, 세션에 저장된 정보를 활용하여 빠르고 효율적으로 권한을 판단하고, 적절한 리소스만 접근하도록 하기 위함이다. 이번 글에서는 DB에서 저장된 권한 코드(aut..
3편은 Provider에서 인증 성공 / 실패 판단을하고 그 후 처리를 어떻게할지 Custom한Success , Failuer Handler에 대해 작성하려한다. 1) SuccessHandler2편에서 작성한 Provider을보면if(user?.userpw.equals(userpw)) { val authorities = listOf(SimpleGrantedAuthority("ROLE_USER")) return UsernamePasswordAuthenticationToken(userid,userpw,authorities)}해당 ID의 PW값과 입력한PW값을 비교해 일치하면 UsernamePasswordAuthenticationToken을 반환하고, 인증이 성공한것으로 간주되어 SuccessHan..
(1)편에 이어서 2편을 작성하려한다.2편은 AuthenticationProvider / Success,Failuer Handler를 다뤄보겠다. AuthenticationProvider : 실제 인증 처리 @Componentclass CustomAuthenticationProvider : AuthenticationProvider{ @Autowired private lateinit var mapper : CommonMapper override fun authenticate(authentication: Authentication?): Authentication { val userid = authentication?.principal.toString() val userp..
- Total
- Today
- Yesterday
- 명령줄이 너무 깁니다
- 게시판
- GitHub
- Column count doesn't match value count at row 1
- insert
- AI
- MariaDB
- dependencies
- gradle
- 백엔드
- Postman
- securityconfig
- springsecurity
- Powershell
- JAR매니패스트
- session저장
- kotlin
- null
- Git
- Spring Security
- 의존성
- ubuntu
- 특일정보
- spring ai
- dbeaver
- Insert오류
- jwt
- 서버호스트
- CRUD
- InetAddress
| 일 | 월 | 화 | 수 | 목 | 금 | 토 |
|---|---|---|---|---|---|---|
| 1 | ||||||
| 2 | 3 | 4 | 5 | 6 | 7 | 8 |
| 9 | 10 | 11 | 12 | 13 | 14 | 15 |
| 16 | 17 | 18 | 19 | 20 | 21 | 22 |
| 23 | 24 | 25 | 26 | 27 | 28 | 29 |
| 30 | 31 |