Skip to content

[Feat] 권한 모델 개편 - 콘텐츠 도메인(archive, curriculum, faq, review) 적용 - #211

Merged
seoyeon83 merged 2 commits into
devfrom
feat/#210-permission-content
Sep 27, 2026
Merged

seoyeon83 merged 2 commits into
devfrom
feat/#210-permission-content

Conversation

@wsxchoi

@wsxchoi wsxchoi commented Sep 25, 2026

Copy link
Copy Markdown

💡 개요

콘텐츠 도메인 4개(archive, curriculum, faq, review)의 admin 엔드포인트에 CONTENT_WRITE 인가를 적용했습니다.

🪐 주요 변경 사항

대상 변경
Archive/Curriculum/Faq/ReviewAdminController 엔드포인트 18개에 @PreAuthorize("hasAuthority('CONTENT_WRITE')") 추가
*AdminControllerTest 4개 TestSecurityConfig → PermissionTestSecurityConfig, 인증 객체를 AuthFixtures 의 (TEAM, 서비스운영팀) 주체로 변경
ContentPermissionGridTest (신규) 주체 8종 × 엔드포인트 18개 = 144건을 매트릭스 기대값과 비교

✅ 상세 내용

18개 엔드포인트는 모두 CUD API입니다. CONTENT_READ 는 적용하지 않았습니다. 콘텐츠 조회는 공개 GET(permitAll)에서만 처리하므로 적용할 admin 엔드포인트가 없습니다.

기존 테스트의 인증 객체는 ROLE_SUPER 만 가지고 있었는데, 매트릭스상 SUPER(대표진)는 콘텐츠 CUD 권한이 없어서 주체를 서비스운영팀으로 바꿨습니다.

@EnableMethodSecurity 를 제거하고 격자 테스트를 실행하면 X 칸 108건이 실패하는 것을 확인했습니다. 전체 테스트 1204개가 통과했고 실패는 0개입니다.

🔔 참고 사항

공개 컨트롤러 테스트 4개(ArchiveControllerTest 등)는 TestSecurityConfig 에 그대로 두었습니다. PermissionTestSecurityConfig 에는 공개 경로 permitAll 목록이 없어서, 이 설정으로 바꾸면 공개 GET 요청이 모두 거부됩니다.

wsxchoi and others added 2 commits September 25, 2026 13:06
- archive, curriculum, faq, review admin 컨트롤러의 엔드포인트 18개에 @PreAuthorize 를 추가했다.
- 주체 8종 × 엔드포인트 18개를 검사하는 ContentPermissionGridTest 를 추가했다.
@wsxchoi
wsxchoi requested a review from seoyeon83 September 25, 2026 13:01
@wsxchoi wsxchoi self-assigned this Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: BOAZ-website/backend/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 28ad7f21-46fa-4ffa-b69f-22921a750615

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seoyeon83 seoyeon83 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

잘 됐네요 고생하셨습니다`
LGTM 👍 👍

@seoyeon83
seoyeon83 merged commit 24e9408 into dev Sep 27, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feat] 권한 모델 개편 - 콘텐츠 도메인(archive, curriculum, faq, review) 적용

2 participants