feat: 회원가입 제한·봇차단(허니팟/레이트리밋)·카드 자동인식 보정

- 관리자 회원가입 허용 토글(app_setting), 공개 GET /auth/signup-enabled
- 회원가입 봇차단: 허니팟(website) + IP 레이트리밋(Redis, 1h 5회)
- 카드 알림: 현금 오선택 보정(카드 양방향 매칭+단일카드 자동), 광고 푸시 차단(승인신호 없는 광고성 표현 무시)
- @MapperScan 에 admin.mapper 추가
- account.sql: 매 기동 wallet MODIFY 제거(라이브 락 위험) — CREATE 정의에 255 반영됨

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
ByungCheol
2026-06-06 00:15:57 +09:00
co-authored by Claude Opus 4.8
parent fb94df8112
commit c05be0880c
13 changed files with 199 additions and 14 deletions
@@ -28,10 +28,27 @@ import org.springframework.web.bind.annotation.*;
public class AuthController {
private final AuthService authService;
private final com.sb.web.admin.service.AppSettingService appSettingService;
/** 회원가입 허용 여부 (비보호) — 프론트가 가입 진입 전에 차단 표시용 */
@GetMapping("/signup-enabled")
public java.util.Map<String, Boolean> signupEnabled() {
return java.util.Map.of("enabled", appSettingService.isSignupEnabled());
}
@PostMapping("/signup")
public ResponseEntity<MemberResponse> signup(@Valid @RequestBody SignupRequest req) {
return ResponseEntity.status(HttpStatus.CREATED).body(authService.signup(req));
public ResponseEntity<MemberResponse> signup(@Valid @RequestBody SignupRequest req,
HttpServletRequest request) {
return ResponseEntity.status(HttpStatus.CREATED).body(authService.signup(req, clientIp(request)));
}
/** 클라이언트 IP (nginx 프록시 뒤 → X-Forwarded-For 우선) */
private String clientIp(HttpServletRequest request) {
String xff = request.getHeader("X-Forwarded-For");
if (xff != null && !xff.isBlank()) {
return xff.split(",")[0].trim();
}
return request.getRemoteAddr();
}
@PostMapping("/login")