Skip to content

마이페이지 비밀번호 변경 API 구현 - #57

Merged
nariming merged 3 commits into
developfrom
feature/mypage-change-password
Aug 9, 2026
Merged

nariming merged 3 commits into
developfrom
feature/mypage-change-password

Conversation

@nariming

@nariming nariming commented Aug 9, 2026 •

Copy link
Copy Markdown
Member

📌 관련 이슈

  • #00

🔎 What is this PR?

로그인된 상태에서 현재 비밀번호를 확인하고 바로 새 비밀번호로 바꾸는 마이페이지 비밀번호 변경 API입니다.
기존 /auth/password/reset*은 이메일 인증코드 기반 재설정 플로우라, 이번에 추가한 플로우와는 성격이 달라 User 도메인 쪽에 별도로 구현했습니다.

✨ Changes

  • PATCH /users/password 엔드포인트 신규 추가 (JWT 인증 필요, @AuthenticationPrincipal로 userId 획득)
  • 요청 바디: { currentPassword, newPassword } — newPassword는 회원가입/비밀번호 재설정과 동일한 영문+숫자 8자 이상 정규식 적용
  • UserService.changePassword(): 현재 비밀번호 일치 여부 확인 후 User.changePassword()로 교체
  • 네이버 전용 계정(password=null)은 애초에 현재 비밀번호가 없으므로 SOCIAL_ACCOUNT_PASSWORD_CHANGE_NOT_ALLOWED(409)로 차단
  • 현재 비밀번호 불일치 시 INVALID_CURRENT_PASSWORD(401) 반환
  • SecurityConfig의 /users/** PATCH 인증 목록에 /users/password 명시 추가
  • UserServiceTest/UserControllerTest에 정상 변경·현재비밀번호 불일치·소셜계정 케이스 테스트 추가

📷 Result

UI 변경 없는 API 단위 작업이라 별도 스크린샷은 없습니다. Swagger에서 PATCH /users/password로 확인 가능합니다.

💬 To. Reviewer

✅ 체크 리스트

  • base 브랜치(develop 또는 main) 최신 상태 pull 및 충돌 확인 완료
  • Reviewers 설정
  • Assignees 설정
  • Labels 설정

Summary by CodeRabbit

  • New Features

    • Added authenticated password changes from the user account.
    • New passwords must be at least eight characters and include letters and digits.
    • Password changes verify the current password and securely store the new one.
  • Bug Fixes

    • Added clear handling for incorrect current passwords and unsupported social-account password changes.

@nariming nariming added ✨ feature 새로운 기능을 추가하는 작업 🐛 fix develop 브랜치에서 발생한 버그를 수정하는 작업 and removed 🐛 fix develop 브랜치에서 발생한 버그를 수정하는 작업 labels Aug 9, 2026
@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@nariming, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 52 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 84799232-32db-4e46-87b6-93fe1bbe5051

📥 Commits

Reviewing files that changed from the base of the PR and between 0aeaddd and 6e74a94.

📒 Files selected for processing (3)
  • src/main/java/com/daytodo/domain/user/dto/UserRequest.java
  • src/main/java/com/daytodo/domain/user/service/UserService.java
  • src/test/java/com/daytodo/domain/user/service/UserServiceTest.java
📝 Walkthrough

Walkthrough

Adds an authenticated PATCH /users/password endpoint. The request validates password fields, and the service rejects social accounts or invalid current passwords before encoding and saving the new password.

Changes

Password change

Layer / File(s) Summary
Password change contracts
src/main/java/com/daytodo/domain/user/dto/UserRequest.java, src/main/java/com/daytodo/domain/user/exception/code/UserErrorCode.java
Adds the validated ChangePassword request record and error codes for unsupported policies, invalid current passwords, and social accounts.
Password change service flow
src/main/java/com/daytodo/domain/user/service/UserService.java, src/test/java/com/daytodo/domain/user/service/UserServiceTest.java
Validates the account type and current password, encodes the new password, updates the user, and tests success and rejection cases.
Authenticated password endpoint
src/main/java/com/daytodo/domain/user/controller/UserController.java, src/main/java/com/daytodo/global/config/SecurityConfig.java, src/test/java/com/daytodo/domain/user/controller/UserControllerTest.java
Adds the authenticated PATCH /users/password route, delegates to the service, returns HTTP 204, and verifies the request flow.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

  • DayTodo/DayTodo_BE#34: Extends the same user controller, request, error-code, security, and test areas.

Suggested reviewers: kwonwnsduf

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: implementing the My Page password change API.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/mypage-change-password

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/main/java/com/daytodo/domain/user/service/UserService.java`:
- Around line 91-102: Update changePassword to load the user with
findActiveUserForUpdate(userId, UserStatus.ACTIVE) instead of getActiveUser
before validating the current password, ensuring the record is locked through
validation and password update. Preserve the existing login-type,
password-match, and changePassword behavior.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 40b01513-bd85-45a2-bbf0-f396393fcdb4

📥 Commits

Reviewing files that changed from the base of the PR and between a307dba and 0aeaddd.

📒 Files selected for processing (7)
  • src/main/java/com/daytodo/domain/user/controller/UserController.java
  • src/main/java/com/daytodo/domain/user/dto/UserRequest.java
  • src/main/java/com/daytodo/domain/user/exception/code/UserErrorCode.java
  • src/main/java/com/daytodo/domain/user/service/UserService.java
  • src/main/java/com/daytodo/global/config/SecurityConfig.java
  • src/test/java/com/daytodo/domain/user/controller/UserControllerTest.java
  • src/test/java/com/daytodo/domain/user/service/UserServiceTest.java

Comment thread src/main/java/com/daytodo/domain/user/service/UserService.java

@kwonwnsduf kwonwnsduf left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[changePassword()는 비밀번호만 교체하는데, 탈취된 리프레시 토큰을 가진 사용자는 비밀번호 변경 후에도 새 액세스 토큰을 발급받을 수 있어 계정 복구 효과가 없는것 같습니다. 성공 시 저장된 RefreshToken을 폐기하고, 발급된 비밀번호 재설정 코드도 함께 무효화하는 것이 안전할 거 같습니다. [ChangePassword 요청 DTO]/src/main/java/com/daytodo/domain/user/dto/UserRequest.java)는 길이 상한이 없습니다. 72바이트를 넘는 currentPassword는 matches()에서, newPassword는 encode()에서 IllegalArgumentException을 발생시킬 수 있습니다. 허용 문자와 UTF-8 바이트 길이를 제한해 400으로 처리하는 것도 괜찮을 것 같습니다.
최종구현까지 얼마남지 않아 참고만 해주시고 구현범위 클 경우 안 하는게 좋을 것 같습니다. 참고만해주세요! 수고하셨습니다!

@kwonwnsduf kwonwnsduf left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

수고하셨습니다!

@nariming
nariming merged commit b098abb into develop Aug 9, 2026
1 check passed
@nariming
nariming deleted the feature/mypage-change-password branch August 9, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

✨ feature 새로운 기능을 추가하는 작업

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants