Skip to content

Fix : 유효하지 않은 토큰 쿠키로 공개 경로가 500 나는 문제 수정 - #572

Merged
uykm merged 2 commits into
developfrom
fix/auth/#571-ignore-invalid-cookie-token
Oct 1, 2026
Merged

uykm merged 2 commits into
developfrom
fix/auth/#571-ignore-invalid-cookie-token

Conversation

@uykm

@uykm uykm commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Tasks

  • 쿠키에서 읽은 토큰이 유효하지 않으면 무시하고 비로그인 요청으로 처리
    • 인증이 필요한 경로는 기존 CustomAuthenticationEntryPoint가 401로 응답
  • Authorization 헤더 토큰이 유효하지 않으면 예외 대신 401 응답 (기존 500)
  • Swagger 경로(/swagger-ui/**, /v3/api-docs/**)는 토큰 필터를 거치지 않도록 제외
  • JwtAuthenticationFilterTest 추가

ETC

  • 토큰 쿠키가 Domain=depromeet.com이라 prod 쿠키가 dev에도 전송돼서, prod에서 로그인한 브라우저로 dev Swagger에 들어가면 500이 났어요.
  • 응답 코드(JWT-401-1, JWT-401-4)는 기존과 같아요.

Screenshot

Summary by CodeRabbit

  • 버그 수정
    • 잘못된 Authorization 헤더나 유효하지 않은 Bearer 토큰이 전달되면 구체적인 오류 코드와 함께 401 응답을 반환합니다.
    • 유효하지 않은 인증 쿠키만 있는 경우에는 요청이 차단되지 않고 비인증 상태로 계속 처리됩니다.
    • Swagger UI 및 API 문서 경로에서는 토큰 검증을 건너뛰어 요청을 진행합니다.

@uykm uykm added the 🐞 Bug label Oct 1, 2026
@uykm uykm self-assigned this Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 10b935a4-4882-49a1-8235-fb5f284b6442

📥 Commits

Reviewing files that changed from the base of the PR and between 36cf62f and 3a1098f.

📒 Files selected for processing (2)
  • application/src/main/kotlin/core/application/security/oauth/token/JwtAuthenticationFilter.kt
  • application/src/test/kotlin/core/application/security/oauth/token/JwtAuthenticationFilterTest.kt
 ___________________________________________________________
< This loop is doing cardio. Your users are doing timeouts. >
 -----------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcGtHShfT1PVH4iSiufgaz
@uykm
uykm merged commit 684aba4 into develop Oct 1, 2026
1 of 2 checks passed
@uykm
uykm deleted the fix/auth/#571-ignore-invalid-cookie-token branch October 1, 2026 01:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant