Repository navigation
fix: 프론트 연동 시 CORS 설정 추가로 preflight 차단(403) 해결 - #37
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthrough
ChangesCORS security integration
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
959d190 to
44e8e2b
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/main/java/com/daytodo/global/config/SecurityConfig.java`:
- Around line 92-97: Update the CORS configuration in SecurityConfig to use the
configured trusted frontend origins instead of List.of("*"), while retaining
only the methods and headers required by the application. Keep allowCredentials
enabled only if the configured authentication flow requires it, and remove or
update the conflicting Access-Control-Allow-Origin wildcard in nginx
configuration.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: da32de97-2fbb-41f3-8d4e-338a643aff3e
📒 Files selected for processing (1)
src/main/java/com/daytodo/global/config/SecurityConfig.java
| // allowCredentials(true)라 "*"는 못 쓰고 패턴을 사용 - 요청 Origin을 그대로 반사한다. | ||
| // TODO(팀 확인 필요): 배포 안정화되면 프론트 도메인만 명시적으로 화이트리스트할 것. | ||
| config.setAllowedOriginPatterns(List.of("*")); | ||
| config.setAllowedMethods(List.of("GET", "POST", "PUT", "PATCH", "DELETE", "OPTIONS")); | ||
| config.setAllowedHeaders(List.of("*")); | ||
| config.setAllowCredentials(true); |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
echo "CORS origins and configuration:"
fd --type f --hidden --exclude .git -0 \
| xargs -0 -r rg -n \
'setAllowedOrigin|setAllowedOriginPattern|allowed-origin|allowedOrigin|https?://' || true
echo "Authentication transport:"
fd --type f --hidden --exclude .git -0 \
| xargs -0 -r rg -n \
'Cookie|ResponseCookie|setCookie|Authorization|Bearer|localStorage|sessionStorage' || true
if rg -n --glob '*.java' \
'setAllowedOriginPatterns\(List\.of\("\*"\)\)' .; then
echo "Wildcard CORS origin remains." >&2
exit 1
fiRepository: DayTodo/DayTodo_BE
Length of output: 1935
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
echo "Security configuration:"
sed -n '1,140p' src/main/java/com/daytodo/global/config/SecurityConfig.java
echo "JWT filter:"
sed -n '1,180p' src/main/java/com/daytodo/global/security/JwtAuthenticationFilter.java
echo "Authentication and token transport references:"
rg -n -C 3 \
'JwtAuthenticationFilter|Authorization|Bearer|HttpOnly|SameSite|Cookie|ResponseCookie|Set-Cookie|accessToken|refreshToken|oauth2|login' \
src/main/java src/main/resources .platform || true
echo "Relevant configuration:"
sed -n '1,120p' src/main/resources/application.yml
sed -n '1,100p' .platform/ngnix.confRepository: DayTodo/DayTodo_BE
Length of output: 28259
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
python3 - <<'PY'
from pathlib import Path
import re
root = Path(".")
java = list(root.glob("src/main/java/**/*.java"))
text = "\n".join(p.read_text(errors="ignore") for p in java)
patterns = {
"cookie APIs": r"\b(?:Cookie|ResponseCookie|HttpCookie|Set-Cookie|addCookie)\b",
"authorization header": r"HttpHeaders\.AUTHORIZATION|Authorization",
"bearer parsing": r"Bearer\s*\+?|BEARER_PREFIX|startsWith\([^)]*Bearer",
"CORS wildcard": r"setAllowedOriginPatterns\s*\(\s*List\.of\(\s*\"\*\"\s*\)\s*\)",
}
for label, pattern in patterns.items():
matches = [(str(p), i + 1, line.strip())
for p in java
for i, line in enumerate(p.read_text(errors="ignore").splitlines())
if re.search(pattern, line, re.I)]
print(f"{label}: {len(matches)}")
for item in matches:
print(" ", item)
PYRepository: DayTodo/DayTodo_BE
Length of output: 1390
Restrict CORS to trusted frontend origins.
The application reads JWTs only from the Authorization header and does not use cookies, so this wildcard does not currently expose authenticated JWT responses by itself. Replace List.of("*") with configured frontend origins, and remove or update .platform/ngnix.conf because it also sets Access-Control-Allow-Origin: '*'. Keep credentials enabled only when required.
🧰 Tools
🪛 ast-grep (0.45.0)
[warning] 93-93: This 'CorsConfiguration' allows requests from any origin (""). A wildcard origin combined with credentials (or used at all on authenticated endpoints) lets any website read responses from this service. Configure an explicit allow-list instead, e.g. 'config.setAllowedOrigins(List.of("https://app.example.com"));', and avoid pairing wildcard origins with 'setAllowCredentials(true)'.
Context: config.setAllowedOriginPatterns(List.of(""))
Note: [CWE-942] Permissive Cross-domain Policy with Untrusted Domains.
(cors-allow-all-origins-config-java)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@src/main/java/com/daytodo/global/config/SecurityConfig.java` around lines 92
- 97, Update the CORS configuration in SecurityConfig to use the configured
trusted frontend origins instead of List.of("*"), while retaining only the
methods and headers required by the application. Keep allowCredentials enabled
only if the configured authentication flow requires it, and remove or update the
conflicting Access-Control-Allow-Origin wildcard in nginx configuration.
Source: Linters/SAST tools
SecurityConfig에 CORS 설정이 없어 브라우저의 preflight(OPTIONS) 응답에 Access-Control-Allow-Origin 헤더가 붙지 않아 프론트 연동 요청이 차단됨. .cors() 활성화 및 CorsConfigurationSource 빈 추가.
44e8e2b to
f65a025
Compare
📌 관련 이슈
🔎 What is this PR?
SecurityConfig에 CORS 설정이 없어 브라우저의 preflight(OPTIONS) 응답에 Access-Control-Allow-Origin 헤더가 붙지 않아 프론트 연동 요청이 차단되는 문제 해결
✨ Changes
.cors() 활성화 및 CorsConfigurationSource 빈 추가
📷 Result
💬 To. Reviewer
✅ 체크 리스트
Summary by CodeRabbit