Repository navigation
[FIX] admin 필터 범위 변경 - #343
Conversation
📝 WalkthroughWalkthrough이 PR은 관리자 인증 필터의 적용 범위를 ChangesAdmin Authorization Scope Restriction
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
src/test/java/com/solv/wefin/global/config/security/AdminAuthorizationFilterTest.java (1)
65-142: ⚡ Quick win경계 경로 회귀 테스트를 추가해 주세요.
현재 스코프 변경의 핵심은 경로 경계 처리라서,
"/api/admin/accounts/123"은 권한 검사 수행,"/api/admin/accountsx"는 권한 검사 스킵 케이스를 각각 고정해두면 회귀 방지에 효과적입니다.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/test/java/com/solv/wefin/global/config/security/AdminAuthorizationFilterTest.java` around lines 65 - 142, Add two regression tests in AdminAuthorizationFilterTest to cover path-boundary behavior: (1) a test that sends a request to "/api/admin/accounts/123" (use MockHttpServletRequest and setAuthentication(UUID) to authenticate) and asserts the filter invokes adminAuthorizationService.requireAdmin(userId) and returns 200 (or passes the chain), and (2) a test that sends a request to "/api/admin/accountsx" and asserts the filter skips authorization (verify(adminAuthorizationService, never()).requireAdmin(...)) and returns 200; use the existing filter.doFilter(...), MockFilterChain, and verify/Mockito patterns to mirror the other tests so these boundary cases prevent regressions.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In
`@src/test/java/com/solv/wefin/global/config/security/AdminAuthorizationFilterTest.java`:
- Around line 65-142: Add two regression tests in AdminAuthorizationFilterTest
to cover path-boundary behavior: (1) a test that sends a request to
"/api/admin/accounts/123" (use MockHttpServletRequest and
setAuthentication(UUID) to authenticate) and asserts the filter invokes
adminAuthorizationService.requireAdmin(userId) and returns 200 (or passes the
chain), and (2) a test that sends a request to "/api/admin/accountsx" and
asserts the filter skips authorization (verify(adminAuthorizationService,
never()).requireAdmin(...)) and returns 200; use the existing
filter.doFilter(...), MockFilterChain, and verify/Mockito patterns to mirror the
other tests so these boundary cases prevent regressions.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: ebaa14ed-58c7-4ff2-88a6-00313c95f50c
📒 Files selected for processing (3)
src/main/java/com/solv/wefin/global/config/SecurityConfig.javasrc/main/java/com/solv/wefin/global/config/security/AdminAuthorizationFilter.javasrc/test/java/com/solv/wefin/global/config/security/AdminAuthorizationFilterTest.java
📌 PR 설명
관리자 권한 필터 적용 범위 수정
✅ 완료한 기능 명세
📸 스크린샷
💭 고민과 해결과정
🔗 관련 이슈
Closes #이슈번호
Summary by CodeRabbit
변경 사항
Bug Fixes
Tests