feat: 멤버십(무료/유료) 게이팅 — 백엔드
- member.plan(FREE/PREMIUM) 컬럼 추가 + SessionUser/MemberResponse 노출
- auth_session 백업에 plan 저장(세션 복원 시 유료 상태 유지)
- 관리자 회원 plan 변경 API (PUT /api/admin/members/{id}/plan)
- PremiumInterceptor 로 유료 전용 경로 차단(통계/예산/고정지출/태그/OCR/투자/카드알림/백업)
· 관리자는 플랜과 무관하게 허용, 무료 회원은 403 PREMIUM_REQUIRED
- WebConfigTest: 유료 경로 등록 회귀 가드 추가
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
93e06c9475
commit
6256d3e63d
@@ -2,6 +2,7 @@ package com.sb.web.common.config;
|
||||
|
||||
import com.sb.web.auth.web.AdminInterceptor;
|
||||
import com.sb.web.auth.web.AuthInterceptor;
|
||||
import com.sb.web.auth.web.PremiumInterceptor;
|
||||
import lombok.RequiredArgsConstructor;
|
||||
import org.springframework.context.annotation.Configuration;
|
||||
import org.springframework.web.servlet.config.annotation.InterceptorRegistry;
|
||||
@@ -18,6 +19,7 @@ public class WebConfig implements WebMvcConfigurer {
|
||||
|
||||
private final AuthInterceptor authInterceptor;
|
||||
private final AdminInterceptor adminInterceptor;
|
||||
private final PremiumInterceptor premiumInterceptor;
|
||||
|
||||
@Override
|
||||
public void addInterceptors(InterceptorRegistry registry) {
|
||||
@@ -29,5 +31,18 @@ public class WebConfig implements WebMvcConfigurer {
|
||||
// 인가: 관리자 전용 경로 (authInterceptor 다음에 실행되어 role 검사)
|
||||
registry.addInterceptor(adminInterceptor)
|
||||
.addPathPatterns("/api/admin/**");
|
||||
// 인가: 유료(PREMIUM) 전용 경로 (authInterceptor 다음에 실행되어 plan 검사)
|
||||
registry.addInterceptor(premiumInterceptor)
|
||||
.addPathPatterns(
|
||||
"/api/account/stats",
|
||||
"/api/account/category-stats",
|
||||
"/api/account/networth/trend",
|
||||
"/api/account/budgets", "/api/account/budgets/**",
|
||||
"/api/account/recurrings", "/api/account/recurrings/**",
|
||||
"/api/account/ocr", "/api/account/ocr/**",
|
||||
"/api/account/invest", "/api/account/invest/**",
|
||||
"/api/account/tags", "/api/account/tags/**",
|
||||
"/api/account/entries/notification",
|
||||
"/api/account/restore");
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user