Repository navigation
[Feat] 카카오 OAuth2 로그인 및 JWT 인증/인가 구조 구현 - #10
Merged
Merged
Conversation
Closed
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
😌카카오 OAuth2 로그인을 기반으로 한 인증/인가 구조를 구현했습니다.
Refresh Token을 서버에서 관리하는 방식으로 구현한 이유
위 3가지는 서버에서 관리하지 않았을 때의 문제점들입니다. 따라서 보안상 위험도가 높은 Refresh Token은 서버(DB)에서 관리하여
토큰 무효화 및 재발급 제어가 가능하도록 구현했습니다.
흐름도
로그인 요청 -> CustomOAuth2UserService에서 카카오 사용자 정보를 조회
-> providerId를 기준으로 Member를 생성하거나 조회 -> 인증 성공 후 OAuth2LoginSuccessHandler에서 JWT Access Token을 발급
-> Refresh Token은 서버(DB)에 저장하여 만료 및 회전(rotation) 방식으로 관리
이후 모든 요청 -> JwtTokenFilter를 통해 Access Token을 검증 -> 유효한 토큰일 경우 SecurityContext에 인증 정보를 저장
-> Controller 단에서 인증된 사용자로 요청을 처리 -> Access Token 만료 시에는 Refresh Token을 이용해 재발급이 가능