Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
package com.seeat.server.domain.auth.application.dto.response;

/**
* accessToken ์‘๋‹ต์ž…๋‹ˆ๋‹ค.
*
* @param accessToken accessToken
*/
public record TokenResponse(
String accessToken
) {
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
package com.seeat.server.domain.auth.presentation;

import com.seeat.server.domain.auth.application.dto.response.TokenResponse;
import com.seeat.server.domain.auth.presentation.swagger.AuthControllerSpec;
import com.seeat.server.domain.user.domain.entity.User;
import com.seeat.server.global.response.ApiResponse;
import com.seeat.server.global.response.CustomException;
import com.seeat.server.global.response.ErrorCode;
import com.seeat.server.global.util.JwtConstants;
import com.seeat.server.security.jwt.service.TokenService;
import jakarta.servlet.http.Cookie;
import jakarta.servlet.http.HttpServletRequest;
import lombok.RequiredArgsConstructor;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

import java.util.Optional;

@RestController
@RequiredArgsConstructor
@RequestMapping("/api/v1/auth")
public class AuthController implements AuthControllerSpec {

private final TokenService tokenService;

@GetMapping
public ApiResponse<TokenResponse> getAccessToken(HttpServletRequest request){

// ํด๋ผ์ด์–ธํŠธ ์ฟ ํ‚ค์—์„œ refreshToken ์ถ”์ถœ
String refreshToken = extractRefreshTokenFromCookies(request.getCookies());

// ์‚ฌ์šฉ์ž ์ •๋ณด ์กฐํšŒ
Optional<User> user = tokenService.getUserFromRefreshToken(refreshToken);
if (user.isEmpty()) {

return ApiResponse.fail(new CustomException(ErrorCode.NOT_USER, null));
}

// ์ƒˆ๋กœ์šด accessToken ์ƒ์„ฑ
String newAccessToken = tokenService.generateAccessToken(user.get());

// accessToken ์‘๋‹ต
return ApiResponse.ok(new TokenResponse(newAccessToken));
}

private String extractRefreshTokenFromCookies(Cookie[] cookies) {
// ์ฟ ํ‚ค์—์„œ refreshToken ์ถ”์ถœ
if (cookies == null) return null;

for (Cookie cookie : cookies) {
if (JwtConstants.REFRESH_TOKEN_COOKIE.equals(cookie.getName())) {
// ์ฟ ํ‚ค ๊ฐ’ ๋ฐ˜ํ™˜
return cookie.getValue();
}
}
// ์—†์œผ๋ฉด null
return null;
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
package com.seeat.server.domain.auth.presentation.swagger;

import com.seeat.server.domain.auth.application.dto.response.TokenResponse;
import com.seeat.server.global.response.ApiResponse;
import io.swagger.v3.oas.annotations.Operation;
import io.swagger.v3.oas.annotations.tags.Tag;
import jakarta.servlet.http.HttpServletRequest;
import org.springframework.web.bind.annotation.GetMapping;

@Tag(name = "ํ† ํฐ ์กฐํšŒ API", description = "ํ† ํฐ ์กฐํšŒํ•˜๋Š” API ์ž…๋‹ˆ๋‹ค.")
public interface AuthControllerSpec {
@Operation(summary = "AccessToken ์กฐํšŒ", description = "RefreshToken ๊ธฐ๋ฐ˜ AccessToken ์žฌ๋ฐœ๊ธ‰")
@GetMapping
ApiResponse<TokenResponse> getAccessToken(HttpServletRequest request);

}
13 changes: 13 additions & 0 deletions src/main/java/com/seeat/server/global/service/RedisService.java
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@

import java.time.Duration;
import java.util.Map;
import java.util.Set;

/**
* Redis์™€์˜ ์ƒํ˜ธ์ž‘์šฉ์„ ๋‹ด๋‹นํ•˜๋Š” ์„œ๋น„์Šค ํด๋ž˜์Šค
*
Expand Down Expand Up @@ -44,6 +46,17 @@ public <T> T getValues(String key, Class<T> clazz) {
return objectMapper.convertValue(value, clazz);
}

public boolean existsRefreshToken(String token) {
Set<String> keys = redisTemplate.keys(REFRESH_TOKEN_PREFIX + "*");
if (keys == null || keys.isEmpty()) return false;

ValueOperations<String, Object> values = redisTemplate.opsForValue();

return keys.stream()
.map(values::get)
.anyMatch(value -> token.equals(value));
}

public void deleteValues(String key) {
redisTemplate.delete(key);
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,8 @@ public CorsConfigurationSource corsConfigurationSource() {
configuration.addAllowedMethod("*");
configuration.setAllowCredentials(true);

configuration.addExposedHeader("Authorization");

UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
source.registerCorsConfiguration("/**", configuration);
return source;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,9 @@ public class RequestMatcherHolder {
new RequestInfo(DELETE, "/api/v1/search", null),
new RequestInfo(GET, "/api/v1/search/**", null),

// ํ† ํฐ ์กฐํšŒ ๊ด€๋ จ
new RequestInfo(GET, "/api/v1/auth", null),

// static resources
new RequestInfo(GET, "/docs/**", null),
new RequestInfo(GET, "/*.ico", null),
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,14 @@
import jakarta.servlet.http.HttpServletResponse;
import lombok.RequiredArgsConstructor;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.data.redis.core.RedisTemplate;
import org.springframework.http.HttpHeaders;
import org.springframework.security.core.Authentication;
import org.springframework.stereotype.Service;

import java.time.Duration;
import java.util.Arrays;
import java.util.Optional;

/**
* ํ† ํฐ ๋ฐœ๊ธ‰ ์„œ๋น„์Šค
Expand Down Expand Up @@ -80,4 +82,23 @@ public void generateDevTokensAndSetHeaders(Long userId, String username, UserRol

response.addCookie(refreshTokenCookie);
}

public Optional<User> getUserFromRefreshToken(String refreshToken) {
if (refreshToken == null || !redisService.existsRefreshToken(refreshToken)) {
return Optional.empty();
}

if (!jwtProvider.validateToken(refreshToken)) {
return Optional.empty();
}

Authentication authentication = jwtProvider.getAuthentication(refreshToken);
User user = (User) authentication.getPrincipal();

return Optional.ofNullable(user);
}

public String generateAccessToken(User user) {
return jwtProvider.generateAccessToken(user);
}
}
Loading