- 작성자 아바타: post/comment 조회 시 member JOIN(google_picture/profile_image),
목록·상세·댓글 응답에 노출
- 추천/비추천: post_vote/comment_vote 테이블 + 토글 API
(POST /board/posts|comments/{id}/vote), 게시글/댓글 응답에 up/down/myVote
- 추천자 목록: GET /board/posts/{id}/recommenders + PostDetail.recommenders
- 포인트: member.points + point_history. 글/댓글 작성 시 10P, 하루 3회 한도(합산).
PointService, GET /auth/points, MemberResponse.points 노출
- @MapperScan 에 point.mapper 추가, AuthController WebMvc 테스트 MockBean 보강
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
49 lines
2.4 KiB
Java
49 lines
2.4 KiB
Java
package com.sb.web.common.config;
|
|
|
|
import com.sb.web.auth.web.AdminInterceptor;
|
|
import com.sb.web.auth.web.AuthInterceptor;
|
|
import com.sb.web.auth.web.PremiumInterceptor;
|
|
import lombok.RequiredArgsConstructor;
|
|
import org.springframework.context.annotation.Configuration;
|
|
import org.springframework.web.servlet.config.annotation.InterceptorRegistry;
|
|
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;
|
|
|
|
/**
|
|
* 인증 인터셉터 등록.
|
|
* 보호가 필요한 엔드포인트에만 적용한다. (로그인/회원가입은 비보호)
|
|
* 보호 대상이 늘어나면 addPathPatterns 에 추가.
|
|
*/
|
|
@Configuration
|
|
@RequiredArgsConstructor
|
|
public class WebConfig implements WebMvcConfigurer {
|
|
|
|
private final AuthInterceptor authInterceptor;
|
|
private final AdminInterceptor adminInterceptor;
|
|
private final PremiumInterceptor premiumInterceptor;
|
|
|
|
@Override
|
|
public void addInterceptors(InterceptorRegistry registry) {
|
|
// 인증: 로그인 필요한 경로 (관리자 경로 포함 — SessionUser 세팅용으로 먼저 실행)
|
|
registry.addInterceptor(authInterceptor)
|
|
.addPathPatterns("/api/auth/me", "/api/auth/points", "/api/auth/logout", "/api/auth/password",
|
|
"/api/auth/verify-password", "/api/auth/profile", "/api/auth/profile-image",
|
|
"/api/board/**", "/api/admin/**", "/api/account/**");
|
|
// 인가: 관리자 전용 경로 (authInterceptor 다음에 실행되어 role 검사)
|
|
registry.addInterceptor(adminInterceptor)
|
|
.addPathPatterns("/api/admin/**");
|
|
// 인가: 유료(PREMIUM) 전용 경로 (authInterceptor 다음에 실행되어 plan 검사)
|
|
registry.addInterceptor(premiumInterceptor)
|
|
.addPathPatterns(
|
|
"/api/account/stats",
|
|
"/api/account/category-stats",
|
|
"/api/account/networth/trend",
|
|
"/api/account/budgets", "/api/account/budgets/**",
|
|
"/api/account/recurrings", "/api/account/recurrings/**",
|
|
"/api/account/ocr", "/api/account/ocr/**",
|
|
"/api/account/invest", "/api/account/invest/**",
|
|
"/api/account/tags", "/api/account/tags/**",
|
|
"/api/account/entries/notification",
|
|
"/api/account/restore");
|
|
}
|
|
}
|