[Feat] 권한 모델 개편 - 콘텐츠 도메인(archive, curriculum, faq, review) 적용 - #211
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- archive, curriculum, faq, review admin 컨트롤러의 엔드포인트 18개에 @PreAuthorize 를 추가했다. - 주체 8종 × 엔드포인트 18개를 검사하는 ContentPermissionGridTest 를 추가했다.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: BOAZ-website/backend/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
💡 개요
콘텐츠 도메인 4개(archive, curriculum, faq, review)의 admin 엔드포인트에
CONTENT_WRITE인가를 적용했습니다.🪐 주요 변경 사항
Archive/Curriculum/Faq/ReviewAdminController@PreAuthorize("hasAuthority('CONTENT_WRITE')")추가*AdminControllerTest4개TestSecurityConfig→PermissionTestSecurityConfig, 인증 객체를AuthFixtures의(TEAM, 서비스운영팀)주체로 변경ContentPermissionGridTest(신규)✅ 상세 내용
18개 엔드포인트는 모두 CUD API입니다.
CONTENT_READ는 적용하지 않았습니다. 콘텐츠 조회는 공개 GET(permitAll)에서만 처리하므로 적용할 admin 엔드포인트가 없습니다.기존 테스트의 인증 객체는
ROLE_SUPER만 가지고 있었는데, 매트릭스상 SUPER(대표진)는 콘텐츠 CUD 권한이 없어서 주체를 서비스운영팀으로 바꿨습니다.@EnableMethodSecurity를 제거하고 격자 테스트를 실행하면 X 칸 108건이 실패하는 것을 확인했습니다. 전체 테스트 1204개가 통과했고 실패는 0개입니다.🔔 참고 사항
공개 컨트롤러 테스트 4개(
ArchiveControllerTest등)는TestSecurityConfig에 그대로 두었습니다.PermissionTestSecurityConfig에는 공개 경로permitAll목록이 없어서, 이 설정으로 바꾸면 공개 GET 요청이 모두 거부됩니다.