- com.sb.web 패키지로 재구성: account / auth / board / user / admin / common - 가계부(account): 내역(필터), 계좌·순자산, 예산, 분류, 정기 거래, 투자 포트폴리오 (종목·매매 이력, 이동평균 평단·실현/평가손익) - MyBatis + MariaDB + Redis 세션, BCrypt - 스키마 자동 초기화(db/*.sql, 멱등), 사용자별 데이터 격리(member_id) - 문서: docs/BACKEND.md, .env.example Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
32 lines
1.3 KiB
Java
32 lines
1.3 KiB
Java
package com.sb.web.common.config;
|
|
|
|
import com.sb.web.auth.web.AdminInterceptor;
|
|
import com.sb.web.auth.web.AuthInterceptor;
|
|
import lombok.RequiredArgsConstructor;
|
|
import org.springframework.context.annotation.Configuration;
|
|
import org.springframework.web.servlet.config.annotation.InterceptorRegistry;
|
|
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;
|
|
|
|
/**
|
|
* 인증 인터셉터 등록.
|
|
* 보호가 필요한 엔드포인트에만 적용한다. (로그인/회원가입은 비보호)
|
|
* 보호 대상이 늘어나면 addPathPatterns 에 추가.
|
|
*/
|
|
@Configuration
|
|
@RequiredArgsConstructor
|
|
public class WebConfig implements WebMvcConfigurer {
|
|
|
|
private final AuthInterceptor authInterceptor;
|
|
private final AdminInterceptor adminInterceptor;
|
|
|
|
@Override
|
|
public void addInterceptors(InterceptorRegistry registry) {
|
|
// 인증: 로그인 필요한 경로 (관리자 경로 포함 — SessionUser 세팅용으로 먼저 실행)
|
|
registry.addInterceptor(authInterceptor)
|
|
.addPathPatterns("/api/auth/me", "/api/auth/logout", "/api/board/**", "/api/admin/**", "/api/account/**");
|
|
// 인가: 관리자 전용 경로 (authInterceptor 다음에 실행되어 role 검사)
|
|
registry.addInterceptor(adminInterceptor)
|
|
.addPathPatterns("/api/admin/**");
|
|
}
|
|
}
|