[Fix] CORS preflight 캐시 누락으로 불필요한 트래픽이 발생하는 문제 - #217
Conversation
- CorsConfiguration에 maxAge 1시간 지정 - CorsPreflightCacheTest 3건 추가 (캐시 헤더, 인증 없는 통과, 비허용 출처 차단)
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review. 📝 WalkthroughWalkthrough
ChangesCORS preflight 캐시
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This change caches CORS preflight policy responses for one hour to reduce unnecessary OPTIONS traffic without caching or altering application data responses. No actionable merge-blocking risk remains beyond normal checks and review. Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
📋 작업 내용
🎯 관련 이슈
📝 변경 사항
SecurityConfig:CorsConfiguration.setMaxAge(1시간)추가CorsPreflightCacheTest신규 (3건)maxAge를 지정하지 않으면 Spring이Access-Control-Max-Age헤더를 보내지 않고, 브라우저는 자체 기본값인 5초만 캐시합니다. 프론트가 30초 주기로 폴링 중이라 매 폴링마다 preflight가 새로 발생했습니다.캐시되는 것은 "이 origin이 이 URL에 이 헤더로 요청해도 되는가"라는 정책 답변이며 응답 데이터가 아닙니다. 본 요청은 매번 그대로 나가므로 거래일·마감 시각 등 시간에 민감한 도메인 데이터의 신선도에는 영향이 없습니다.
배포 후 promql로 검증 예정입니다.
📸 스크린샷 (선택사항)
📌 체크리스트
Summary by CodeRabbit