feat: 비밀번호 변경 기능 (PUT /api/auth/password)
현재 비번 검증 후 BCrypt 교체. 소셜 계정/동일 비번 거부. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
43d1b53d01
commit
eb6b9830ce
@@ -4,6 +4,7 @@ import com.sb.web.auth.domain.Member;
|
||||
import com.sb.web.auth.dto.LoginRequest;
|
||||
import com.sb.web.auth.dto.LoginResponse;
|
||||
import com.sb.web.auth.dto.MemberResponse;
|
||||
import com.sb.web.auth.dto.PasswordChangeRequest;
|
||||
import com.sb.web.auth.dto.SessionUser;
|
||||
import com.sb.web.auth.dto.SignupRequest;
|
||||
import com.sb.web.common.exception.ApiException;
|
||||
@@ -99,4 +100,26 @@ public class AuthService {
|
||||
redisTemplate.delete(SESSION_PREFIX + token);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 비밀번호 변경 (본인). 현재 비밀번호 검증 후 새 비밀번호로 교체.
|
||||
*/
|
||||
@Transactional
|
||||
public void changePassword(Long memberId, PasswordChangeRequest req) {
|
||||
Member member = memberMapper.findById(memberId);
|
||||
if (member == null) {
|
||||
throw new ApiException(HttpStatus.NOT_FOUND, "회원을 찾을 수 없습니다.");
|
||||
}
|
||||
if (!"LOCAL".equals(member.getProvider()) || member.getPassword() == null) {
|
||||
throw new ApiException(HttpStatus.BAD_REQUEST, "소셜 로그인 계정은 비밀번호를 변경할 수 없습니다.");
|
||||
}
|
||||
if (!passwordEncoder.matches(req.getCurrentPassword(), member.getPassword())) {
|
||||
throw new ApiException(HttpStatus.BAD_REQUEST, "현재 비밀번호가 올바르지 않습니다.");
|
||||
}
|
||||
if (passwordEncoder.matches(req.getNewPassword(), member.getPassword())) {
|
||||
throw new ApiException(HttpStatus.BAD_REQUEST, "새 비밀번호가 기존 비밀번호와 동일합니다.");
|
||||
}
|
||||
memberMapper.updatePassword(memberId, passwordEncoder.encode(req.getNewPassword()));
|
||||
log.info("[password] changed for {}", member.getLoginId());
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user