Spring/JPA [17] 보안

totwo·2024년 9월 25일

Spring/JPA

목록 보기
17/17
post-thumbnail

DB 생성

basic table

  • table 만든 후 Set as Default Schema 설정

util
Previleges, Roles

  • 역할 판단시에서 Role이라는 접두사가 있어야 함. (권한에는 Role 접두사 필요없음)

인증 성공시
HttpSession => SecurityContextHolder으로 사용하기
Session안에서 인증된 객체를 Authentication로 관리함'

"/loginProc" request(요청) 시
.loginProcessingUrl("/loginProc")의 url을 가져와
UsernamePasswordAuthenticationFilter 실행됨
-> 로그인시 필터

UserDetailService(interface)를 implements한 (구현한) 서비스 클래스를 실행
-> 개발자의 업무
-> overide 필수
-> AccountService에서 implements 했고 추상 메서드 구현해줌

-> AccountService의 loadUserByUsername 실행

Account를 return 해주고 싶다?

  • 방법 : entity의 Account에서 UserDetails를 implements해주기 (추상메서드 구현 필수)
    -> entity에서 구현할 게 많이 생겨서 부적합하다.

return type이 UserDetails로 고정되어 있기 때문에

  • 방법 : Security가 제공해주는 User라는 class를 사용하자. UserDetails를 implements한 클래스임.



GrantedAuthority type로 넣어야 함

pass987

User의 email을 가져오려면 어떻게 해야 하나??
Session에 저장되어 있음.
authentication 안에 있는 값을 가리키는 단어 principal을 이용함.

profile
Hello, World!

0개의 댓글