Repository navigation
마이페이지 비밀번호 변경 API 구현 - #57
Conversation
|
Warning Review limit reached
Next review available in: 52 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughAdds an authenticated ChangesPassword change
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/main/java/com/daytodo/domain/user/service/UserService.java`:
- Around line 91-102: Update changePassword to load the user with
findActiveUserForUpdate(userId, UserStatus.ACTIVE) instead of getActiveUser
before validating the current password, ensuring the record is locked through
validation and password update. Preserve the existing login-type,
password-match, and changePassword behavior.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 40b01513-bd85-45a2-bbf0-f396393fcdb4
📒 Files selected for processing (7)
src/main/java/com/daytodo/domain/user/controller/UserController.javasrc/main/java/com/daytodo/domain/user/dto/UserRequest.javasrc/main/java/com/daytodo/domain/user/exception/code/UserErrorCode.javasrc/main/java/com/daytodo/domain/user/service/UserService.javasrc/main/java/com/daytodo/global/config/SecurityConfig.javasrc/test/java/com/daytodo/domain/user/controller/UserControllerTest.javasrc/test/java/com/daytodo/domain/user/service/UserServiceTest.java
kwonwnsduf
left a comment
There was a problem hiding this comment.
[changePassword()는 비밀번호만 교체하는데, 탈취된 리프레시 토큰을 가진 사용자는 비밀번호 변경 후에도 새 액세스 토큰을 발급받을 수 있어 계정 복구 효과가 없는것 같습니다. 성공 시 저장된 RefreshToken을 폐기하고, 발급된 비밀번호 재설정 코드도 함께 무효화하는 것이 안전할 거 같습니다. [ChangePassword 요청 DTO]/src/main/java/com/daytodo/domain/user/dto/UserRequest.java)는 길이 상한이 없습니다. 72바이트를 넘는 currentPassword는 matches()에서, newPassword는 encode()에서 IllegalArgumentException을 발생시킬 수 있습니다. 허용 문자와 UTF-8 바이트 길이를 제한해 400으로 처리하는 것도 괜찮을 것 같습니다.
최종구현까지 얼마남지 않아 참고만 해주시고 구현범위 클 경우 안 하는게 좋을 것 같습니다. 참고만해주세요! 수고하셨습니다!
📌 관련 이슈
🔎 What is this PR?
로그인된 상태에서 현재 비밀번호를 확인하고 바로 새 비밀번호로 바꾸는 마이페이지 비밀번호 변경 API입니다.
기존
/auth/password/reset*은 이메일 인증코드 기반 재설정 플로우라, 이번에 추가한 플로우와는 성격이 달라 User 도메인 쪽에 별도로 구현했습니다.✨ Changes
PATCH /users/password엔드포인트 신규 추가 (JWT 인증 필요,@AuthenticationPrincipal로 userId 획득){ currentPassword, newPassword }— newPassword는 회원가입/비밀번호 재설정과 동일한 영문+숫자 8자 이상 정규식 적용UserService.changePassword(): 현재 비밀번호 일치 여부 확인 후User.changePassword()로 교체SOCIAL_ACCOUNT_PASSWORD_CHANGE_NOT_ALLOWED(409)로 차단INVALID_CURRENT_PASSWORD(401) 반환SecurityConfig의/users/**PATCH 인증 목록에/users/password명시 추가UserServiceTest/UserControllerTest에 정상 변경·현재비밀번호 불일치·소셜계정 케이스 테스트 추가📷 Result
UI 변경 없는 API 단위 작업이라 별도 스크린샷은 없습니다. Swagger에서
PATCH /users/password로 확인 가능합니다.💬 To. Reviewer
✅ 체크 리스트
Summary by CodeRabbit
New Features
Bug Fixes