-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathAuthController.java
More file actions
112 lines (91 loc) · 4.57 KB
/
Copy pathAuthController.java
File metadata and controls
112 lines (91 loc) · 4.57 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
package Gotcha.domain.auth.controller;
import Gotcha.common.api.SuccessRes;
import Gotcha.common.exception.CustomException;
import Gotcha.common.jwt.exception.JwtExceptionCode;
import Gotcha.common.mail.MailCodeService;
import Gotcha.common.util.CookieUtil;
import Gotcha.domain.auth.api.AuthApi;
import Gotcha.domain.auth.dto.EmailCodeVerifyReq;
import Gotcha.domain.auth.dto.EmailReq;
import Gotcha.domain.auth.dto.SignInReq;
import Gotcha.domain.auth.dto.SignUpReq;
import Gotcha.domain.auth.dto.TokenDto;
import Gotcha.domain.auth.service.AuthService;
import Gotcha.domain.user.service.UserService;
import jakarta.servlet.http.HttpServletResponse;
import jakarta.validation.Valid;
import lombok.RequiredArgsConstructor;
import org.springframework.http.HttpHeaders;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.CookieValue;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestHeader;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;
import java.util.HashMap;
import java.util.Map;
import static Gotcha.common.jwt.token.JwtProperties.ACCESS_HEADER_VALUE;
import static Gotcha.common.jwt.token.JwtProperties.REFRESH_COOKIE_VALUE;
@RestController
@RequiredArgsConstructor
@RequestMapping("/api/v1/auth")
public class AuthController implements AuthApi {
private final AuthService authService;
private final CookieUtil cookieUtil;
private final MailCodeService mailCodeService;
private final UserService userService;
@PostMapping("/sign-up")
public ResponseEntity<?> signUp(@Valid @RequestBody SignUpReq signUpReq) {
TokenDto tokenDto = authService.signUp(signUpReq);
return createTokenRes(tokenDto, tokenDto.autoSignIn());
}
@PostMapping("/sign-in")
public ResponseEntity<?> signIn(@Valid @RequestBody SignInReq signInReq) {
TokenDto tokenDto = authService.signIn(signInReq);
return createTokenRes(tokenDto, signInReq.autoSignIn());
}
@PostMapping("/guest/sign-in")
public ResponseEntity<?> guestSignIn(){
TokenDto tokenDto = authService.guestSignIn();
return createTokenRes(tokenDto, tokenDto.autoSignIn());
}
@PostMapping("/token-reissue")
public ResponseEntity<?> reIssueToken(@CookieValue(name = REFRESH_COOKIE_VALUE, required = false) String refreshToken) {
if (refreshToken == null) {
throw new CustomException(JwtExceptionCode.REFRESH_TOKEN_NOT_FOUND);
}
TokenDto tokenDto = authService.reissueAccessToken(refreshToken);
return createTokenRes(tokenDto, tokenDto.autoSignIn());
}
@PostMapping("/email/send")
public ResponseEntity<?> sendEmail(@Valid @RequestBody EmailReq emailReq) {
userService.checkEmail(emailReq.email());
mailCodeService.sendCodeToMail(emailReq.email());
return ResponseEntity.ok(SuccessRes.from("인증 코드가 발송되었습니다."));
}
@PostMapping("/email/verify")
public ResponseEntity<?> verifyEmail(@Valid @RequestBody EmailCodeVerifyReq emailCodeVerifyReq) {
mailCodeService.verifiedCode(emailCodeVerifyReq);
return ResponseEntity.ok(SuccessRes.from("이메일이 인증되었습니다."));
}
@GetMapping("/sign-out")
public ResponseEntity<?> signOut(@RequestHeader(value = ACCESS_HEADER_VALUE, required = false) String accessToken,
@CookieValue(name = REFRESH_COOKIE_VALUE, required = false) String refreshToken,
HttpServletResponse response) {
//Todo : Https 배포 후에는 accessToken, refreshToken null인지 검증과정 필요, 현재는 http라서 required = false 처리해둠
authService.signOut(accessToken, refreshToken, response);
return ResponseEntity.ok(SuccessRes.from("로그아웃 되었습니다."));
}
private ResponseEntity<?> createTokenRes(TokenDto tokenDto, boolean autoSignIn) {
Map<String, Object> responseData = new HashMap<>();
responseData.put("accessToken", tokenDto.accessToken());
responseData.put("expiredAt", tokenDto.accessTokenExpiredAt());
return ResponseEntity.ok()
.header(HttpHeaders.SET_COOKIE,
cookieUtil.createCookie(REFRESH_COOKIE_VALUE,
tokenDto.refreshToken(), autoSignIn).toString())
.body(responseData);
}
}