๐Ÿ’ Spring

๐Ÿ’ Spring/Spring Security

2. JWT๋ฅผ ์ดํ•ดํ•˜๊ธฐ ์ „ TCP์— ๋Œ€ํ•ด์„œ

์ด ํฌ์ŠคํŠธ๋Š” ๋ฐ์–ด ํ”„๋กœ๊ทธ๋ž˜๋ฐ๋‹˜์˜ ์œ ํŠœ๋ธŒ ๊ฐ•์˜๋ฅผ ๋“ฃ๊ณ  ๋‚˜์„œ ์ •๋ฆฌํ•œ ๊ธ€์ž…๋‹ˆ๋‹ค. OSI 7 ๊ณ„์ธต๊ณผ TCP์— ๋Œ€ํ•ด์„œ ๊ฐ„๋žตํ•˜๊ฒŒ ์ดํ•ดํ•ด๋ณด๋Š” ์‹œ๊ฐ„์„ ๊ฐ€์ ธ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. OSI 7 ๊ณ„์ธต ํ†ต์‹ ์—๋Š” OSI 7 ๊ณ„์ธต์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ๋‚ด๊ฐ€ ์–ด๋–ค ๊ฒŒ์ž„์—์„œ A ์Šคํ‚ฌ์„ ์“ด๋‹ค๊ณ  ํ–ˆ์„ ๋•Œ, ํ•ด๋‹น ๊ฒŒ์ž„ํšŒ์‚ฌ ์„œ๋ฒ„๊นŒ์ง€์˜ ์ „์†ก์„ ์˜ˆ๋กœ ๋“ค์–ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. Application: ํ•ด๋‹น ๊ฒŒ์ž„ ํ”„๋กœ๊ทธ๋žจ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. Presentation: ๋‚ด๊ฐ€ A ์Šคํ‚ฌ์„ ์“ด๋‹ค๋Š” ๋‚ด์šฉ์„ ์•”ํ˜ธํ™”ํ•ด์„œ ๋ณด๋ƒ…๋‹ˆ๋‹ค. (๋˜๋Š”, ์‚ฌ์ง„ ๊ฐ™์€ ๊ฒƒ๋“ค์„ ๋ณด๋‚ผ ๋•Œ ์••์ถ•์„ ํ•ด์„œ ๋ณด๋‚ด๊ธฐ๋„ ํ•ฉ๋‹ˆ๋‹ค.) Session: ์ธ์ฆ ์ฒดํฌ (๋‚ด๊ฐ€ ๋ณด๋‚ผ ์ˆ˜ ์žˆ๋Š”์ง€์— ๋Œ€ํ•œ ์ฒดํฌ : ์ƒ๋Œ€๋ฐฉ ์ปดํ“จํ„ฐ๊ฐ€ ์ผœ์ ธ์žˆ๋Š”์ง€, ๋‚ด๊ฐ€ ์ƒ๋Œ€๋ฐฉ ์ปดํ“จํ„ฐ์— ์ ‘๊ทผ์„ ํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ๋“ฑ) Transport: TCP/UDP ํ†ต์‹  ์—ฌ๋ถ€ ๊ฒฐ..

๐Ÿ’ Spring/Spring Security

1. JWT๋ฅผ ์ดํ•ดํ•˜๊ธฐ ์ „์— Session์ด๋ž€ ๋ฌด์—‡์ธ๊ฐ€

์ด ํฌ์ŠคํŠธ๋Š” ๋ฐ์–ด ํ”„๋กœ๊ทธ๋ž˜๋ฐ๋‹˜์˜ ์œ ํŠœ๋ธŒ ๊ฐ•์˜๋ฅผ ๋“ฃ๊ณ  ๋‚˜์„œ ์ •๋ฆฌํ•œ ๊ธ€์ž…๋‹ˆ๋‹ค. ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์— ์ตœ์ดˆ ์ ‘๊ทผํ•œ ๊ฒฝ์šฐ ์š”์ฒญ ํ—ค๋”์— ์„ธ์…˜ ID๋ฅผ ๋“ค๊ณ  ์ ‘๊ทผํ•œ ๊ฒฝ์šฐ ๊ทธ๋Ÿผ ์ด ์„ธ์…˜๋งŒ ์žˆ์œผ๋ฉด ๊ณ„์† ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? ์•„๋‹ˆ๋‹ค. ์„ธ์…˜์ด ๋‚ ๋ผ๊ฐ€๋Š” ์‹œ์ ์ด ์žˆ๋‹ค. 1. ์„œ๋ฒ„์—์„œ ๊ฐ•์ œ๋กœ Session์„ ๋‚ ๋ฆฐ๋‹ค. 2. ์‚ฌ์šฉ์ž๊ฐ€ ๋ธŒ๋ผ์šฐ์ €๋ฅผ ์ข…๋ฃŒํ•  ๋•Œ 3. Session ๋งŒ๋ฃŒ ์‹œ๊ฐ„์ด ๋์„ ๋•Œ (๋ณดํ†ต 30๋ถ„์œผ๋กœ ๋‘”๋‹ค) ์„ธ์…˜ ๋กœ๊ทธ์ธ ์š”์ฒญ / ์ธ์ฆ ๋กœ์ง ์ฒ˜์Œ ๋กœ๊ทธ์ธ ์š”์ฒญ์„ ํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ID, PW๋ฅผ ํ™•์ธํ•˜์—ฌ ์‚ฌ์šฉ์ž๊ฐ€ ๋งž๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์„ธ์…˜ID๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž์—๊ฒŒ ์‘๋‹ต ํ—ค๋”์— ์„ธ์…˜ID๋ฅผ ๋‹ด์•„์„œ ์‘๋‹ตํ•ฉ๋‹ˆ๋‹ค. ์„ธ์…˜ID๋ฅผ ์›น ๋ธŒ๋ผ์šฐ์ €์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. ์ด์ œ ์„ธ์…˜ID๋ฅผ ํ—ค๋”์— ๋‹ด์•„์„œ ์š”์ฒญ์„ ํ•ฉ๋‹ˆ๋‹ค. ์„œ๋ฒ„์—์„œ๋Š” ์„ธ์…˜ID๊ฐ€ ์žˆ์œผ๋‹ˆ, ์„ธ์…˜ ์ €์žฅ์†Œ..

๐Ÿ’ Spring/Spring Security

security ๋กœ๊ทธ์ธ ์„ฑ๊ณต ํ›„ *.css , *.image ํŒŒ์ผ๋กœ ์ด๋™ํ•˜๋Š” ๊ฒฝ์šฐ

๋ฌธ์ œ : Security ๋กœ๊ทธ์ธ์— ์„ฑ๊ณต์„ ํ•˜๋ฉด ๋‚ด๊ฐ€ ์„ค์ •ํ•ด๋‘” url๋กœ redirect๊ฐ€ ๋˜์ง€ ์•Š๊ณ  .css ํŒŒ์ผ์ด๋‚˜ imageํŒŒ์ผ๋กœ ์ด๋™ํ•œ๋‹ค. ๋ฌธ์ œ์ : Security config์—์„œ js ๋˜๋Š” css ํด๋”๋ฅผ ํ—ˆ์šฉํ•ด์ฃผ์ง€ ์•Š์•˜๊ธฐ ๋•Œ๋ฌธ์— ๋ฌธ์ œ์˜ ์›๋ž˜ ์ฝ”๋“œ @Override protected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .anyRequest().authenticated() .and() .formLogin() .loginPage("/login") .permitAll() .defaultSuccessUrl("/") .and() .logout() .logoutSuccessUrl("/") .and() .cs..

๐Ÿ’ Spring

[intelliJ] Console log color ์ ์šฉ ์•ˆ๋  ๋•Œ

๋ฌธ์ œ intelliJ ์ฝ˜์†” ์ฐฝ์˜ color๊ฐ€ ์ ์šฉ์ด ์•ˆ๋  ๋•Œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ• ์ฝ˜์†” ์ฐฝ์— ์ƒ‰์ƒ์ด ๋น ์ ธ์„œ ๋ญ”๊ฐ€ ์•ˆ ์˜ˆ์˜๋‹ค.. ๊ฑฐ์Šฌ๋ฆฐ๋‹ค.. ํ•ด๊ฒฐ ๋ฐฉ๋ฒ• application.properties์— ์•„๋ž˜ ์ฝ”๋“œ๋ฅผ ์ถ”๊ฐ€ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค. spring.output.ansi.enabled=always ์ ์šฉ ํ›„ ์ฝ˜์†” ์ฐฝ ์ƒ‰์ƒ! ์•Œ๋ก๋‹ฌ๋ก ํ•ฉ๋‹ˆ๋‹ค REFERENCE https://www.logicbig.com/tutorials/spring-framework/spring-boot/color-logs.html Spring Boot - Enabling Color Coded Output Spring Boot - Enabling Color Coded Output [Last Updated: Sep 22, 2017] www.logicbig.com

๐Ÿ’ Spring/Spring Security

[Spring Security] ์Šคํ”„๋ง ์‹œํ๋ฆฌํ‹ฐ 403 Forbidden ์—๋Ÿฌ

๊ฐœ์š”ํ† ์ดํ”„๋กœ์ ํŠธ๋ฅผ ์ง„ํ–‰ํ•˜๋˜ ๋„์ค‘์— ์Šคํ”„๋ง ์‹œํ๋ฆฌํ‹ฐ๋ฅผ ์„ค์ •ํ•˜๊ณ  ๋‚˜์„œ, ๋กœ๊ทธ์ธ ์ธ์ฆ์„ ๋งˆ์ณค๋Š”๋ฐ๋„ 403 Forbidden ์—๋Ÿฌ๊ฐ€ ๊ณ„์†ํ•ด์„œ ๋ฐœ์ƒํ•˜์˜€์Šต๋‹ˆ๋‹ค. ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ์‹œ์ ์ด GET ์š”์ฒญ์€ ๋ฌด๋ฆฌ์—†์ด ์ž˜ ๋˜๋Š”๋ฐ, POST ์š”์ฒญ์œผ๋กœ ๋ณด๋‚ด๋ฉด ์ด์ƒํ•˜๊ฒŒ 403 ์—๋Ÿฌ๊ฐ€ ๋‚˜๋Š”๋ฐ ์ด์œ ๋ฅผ ๋ชจ๋ฅด๊ฒ ์Šต๋‹ˆ๋‹ค.SecurityConfig๋ฅผ ์‚ดํŽด๋ณด์ž์•„๋ž˜๋Š” ๊ธฐ์กด ์‹œํ๋ฆฌํ‹ฐ ์„ค์ • ์ฝ”๋“œ์ž…๋‹ˆ๋‹ค.@Overrideprotected void configure(HttpSecurity http) throws Exception { http .authorizeRequests() .antMatchers("/").authenticated() .antMa..

๐Ÿ’ Spring/Spring Security

[Spring Security] ์Šคํ”„๋ง ๋ถ€ํŠธ OAuth2-client๋ฅผ ์ด์šฉํ•œ ์†Œ์…œ(๊ตฌ๊ธ€, ๋„ค์ด๋ฒ„, ์นด์นด์˜ค) ๋กœ๊ทธ์ธ ํ•˜๊ธฐ

์ €๋ฒˆ ์‹œ๊ฐ„์—๋Š” ์ง์ ‘ ์ปจํŠธ๋กค๋Ÿฌ์—์„œ ์š”์ฒญ์„ ๊ตฌํ˜„ํ•˜์—ฌ์„œ OAuth2 ์ธ์ฆ์„ ์ฒ˜๋ฆฌํ•ด๋ดค์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ ์‹œ๊ฐ„์—๋Š” OAuth2-client ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์ด์šฉํ•ด์„œ, ์†Œ์…œ ๋กœ๊ทธ์ธ API๋ฅผ ๊ตฌํ˜„ํ•ด๋ณด๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ ํ™˜๊ฒฝ IntelliJ IDEA Spring Boot 2.4.4 Java 11 Spring JPA Maven 3.6.3 Maven ์˜์กด์„ฑ ์ถ”๊ฐ€ spring-boot-starter-oauth2-client๋ผ๋Š” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋Š” ๊ตฌ๊ธ€,ํŽ˜์ด์Šค๋ถ ๊ฐ™์€ ๋กœ๊ทธ์ธ์„ ํ†ตํ•œ ์ธ์ฆ๊ณผ ๊ถŒํ•œ ์ฒ˜๋ฆฌ๋ฅผ ์‰ฝ๊ฒŒ ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค€๋‹ค. org.springframework.boot spring-boot-starter-security org.springframework.boot spring-boot-starter-oauth2-client spring..

iseunghan
'๐Ÿ’ Spring' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (5 Page)