Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,8 @@ public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
.requestMatchers("/ws/**").permitAll()
.requestMatchers(HttpMethod.GET, "/api/chat/global/messages").permitAll()
.requestMatchers("/api/news/recommended/**").authenticated()
.requestMatchers("/api/admin", "/api/admin/**").authenticated()
.requestMatchers("/api/admin/accounts", "/api/admin/accounts/**").authenticated()
.requestMatchers("/api/admin", "/api/admin/**").permitAll()
.requestMatchers(HttpMethod.GET, "/api/news/**", "/api/market/**",
"/api/market-trends/overview",
"/api/stocks/**", "/api/ranking/**").permitAll()
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@
@RequiredArgsConstructor
public class AdminAuthorizationFilter extends OncePerRequestFilter {

private static final String ADMIN_PATH_PREFIX = "/api/admin";
private static final String ADMIN_ACCOUNTS_PATH_PREFIX = "/api/admin/accounts";

private final ObjectProvider<AdminAuthorizationService> adminAuthorizationServiceProvider;
private final ObjectMapper objectMapper;
Expand Down Expand Up @@ -65,7 +65,8 @@ protected void doFilterInternal(

private boolean isAdminPath(HttpServletRequest request) {
String path = request.getRequestURI();
return path.equals(ADMIN_PATH_PREFIX) || path.startsWith(ADMIN_PATH_PREFIX + "/");
return path.equals(ADMIN_ACCOUNTS_PATH_PREFIX)
|| path.startsWith(ADMIN_ACCOUNTS_PATH_PREFIX + "/");
}

private void writeError(HttpServletResponse response, ErrorCode errorCode) throws IOException {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ void tearDown() {
}

@Test
@DisplayName("admin 경로가 아니면 권한 검사를 건너뛴다")
@DisplayName("admin accounts 경로가 아니면 권한 검사를 건너뛴다")
void doFilterInternal_skips_non_admin_path() throws Exception {
MockHttpServletRequest request = new MockHttpServletRequest("GET", "/api/news");
MockHttpServletResponse response = new MockHttpServletResponse();
Expand All @@ -63,7 +63,20 @@ void doFilterInternal_skips_non_admin_path() throws Exception {
}

@Test
@DisplayName("admin 경로에서 인증 정보가 없으면 401을 반환한다")
@DisplayName("admin batch 경로는 권한 검사를 건너뛴다")
void doFilterInternal_skips_admin_batch_path() throws Exception {
MockHttpServletRequest request = new MockHttpServletRequest("POST", "/api/admin/batch/news");
MockHttpServletResponse response = new MockHttpServletResponse();
MockFilterChain filterChain = new MockFilterChain();

filter.doFilter(request, response, filterChain);

assertThat(response.getStatus()).isEqualTo(200);
verify(adminAuthorizationService, never()).requireAdmin(org.mockito.ArgumentMatchers.any());
}

@Test
@DisplayName("admin accounts 경로에서 인증 정보가 없으면 401을 반환한다")
void doFilterInternal_returns_unauthorized_when_anonymous() throws Exception {
MockHttpServletRequest request = new MockHttpServletRequest("POST", "/api/admin/accounts");
MockHttpServletResponse response = new MockHttpServletResponse();
Expand All @@ -75,7 +88,7 @@ void doFilterInternal_returns_unauthorized_when_anonymous() throws Exception {
}

@Test
@DisplayName("admin 경로에서 일반 유저면 403을 반환한다")
@DisplayName("admin accounts 경로에서 일반 유저면 403을 반환한다")
void doFilterInternal_returns_forbidden_when_not_admin() throws Exception {
UUID userId = UUID.randomUUID();
setAuthentication(userId);
Expand All @@ -94,7 +107,7 @@ void doFilterInternal_returns_forbidden_when_not_admin() throws Exception {
}

@Test
@DisplayName("admin 경로에서 비활성 유저면 401을 반환한다")
@DisplayName("admin accounts 경로에서 비활성 유저면 401을 반환한다")
void doFilterInternal_returns_unauthorized_when_user_not_active() throws Exception {
UUID userId = UUID.randomUUID();
setAuthentication(userId);
Expand All @@ -113,7 +126,7 @@ void doFilterInternal_returns_unauthorized_when_user_not_active() throws Excepti
}

@Test
@DisplayName("admin 경로에서 ADMIN 유저면 요청을 통과시킨다")
@DisplayName("admin accounts 경로에서 ADMIN 유저면 요청을 통과시킨다")
void doFilterInternal_allows_admin() throws Exception {
UUID userId = UUID.randomUUID();
setAuthentication(userId);
Expand Down
Loading