Loading the catalog…
Loading the catalog…
13 · 접근 불가 페이지 만들기 💡 한 줄 요약 : 사용자의 권한으로 접근을 제어하고, 권한이 부족하면 접근 불가 응답·화면을 제공합니다. 권한 정보 구성 public enum UserRoleEnum { USER("ROLE_USER"), ADMIN("ROLE_ADMIN"); private final String authority; UserRoleEnum(String authority) { this.authority = authority; } public String getAuthority() { return authority; } } @Override public Collection<? extends GrantedAuthority> getAuthorities() { return List.of(new SimpleGrantedAuthority(user.getRole().getAuthority())); } 회원의 실제 역할에서 권한을 만듭니다. 모든 사용자를 고정된 관리자 권한으로 만드는 코드를 사용하지 않습니다. Role과 Authority 표현 확인하는 권한 hasRole("ADMIN") 기본 규칙에서 ROLE_ADMIN hasAuthority("ROLE_ADMIN") 정확히 ROLE_ADMIN @Secured("ROLE_ADMIN") 지정한 권한 문자열 모든 Authority가 반드시 ROLE_ 로 시작하는 것은 아닙니다. ROLE_ 는 역할 기반 표현에서 사용하는 기본 접두어 규칙입니다. @Secured 적용 @Configuration @EnableWebSecurity @EnableMethodSecurity(securedEnabled = true) public class WebSecurityConfig { // SecurityFilterChain 등의 설정 } @Secured("ROLE_ADMIN") @GetMapping("/api/products/secured") public String getProductsByAdmin( @AuthenticationPrincipal UserDetailsImpl userDetails) { return "redirect:/"; } @Secured 를 선언하는 것과 해당 메서드 보안을 활성화하는 설정을 함께 적용합니다. 접근 불가 화면 연결 http.exceptionHandling(exceptions -> exceptions .accessDeniedPage("/forbidden.html") ); 접근 불가 화면 자체가 다시 차단되지 않도록 정적 화면의 접근 정책도 확인합니다. 인증 실패와 인가 실패 상황 중심 문제 API 응답의 일반적인 표현 인증 정보 없음·잘못된 토큰 사용자 인증 실패 401 Unauthorized 인증되었지만 필요한 권한 없음 접근 권한 부족 403 Forbidden 브라우저 로그인 방식에서는 로그인 화면 이동 등으로 응답할 수도 있습니다. 화면 서비스의 이동 처리와 JSON API의 상태 코드 응답을 구분합니다. 복습 체크 일반 사용자와 관리자 권한을 동적으로 설정할 수 있습니다. @Secured 와 @EnableMethodSecurity 를 함께 적용할 수 있습니다. 401과 403이 나타내는 상황을 구분할 수 있습니다. 접근 불가 화면을 제공하되 실제 API 권한 검사도 적용합니다.
What RADAR observed and classified to build this opportunity. It is what the source published, not a verification that the offer is still active.
Spring 숙련 Chapter 1 - 접근 권한 제어. 13 · 접근 불가 페이지 만들기 💡 한 줄 요약 : 사용자의 권한으로 접근을 제어하고, 권한이 부족하면 접근 불가 응답·화면을 제공합니다. 권한 정보 구성 public enum UserRoleEnum { USER("ROLE_USER"), ADMIN("ROLE_ADMIN"); private final String authority; UserRoleEnum(String authority) { this.authority = authority; } public String getAuthority() { return authority; } } @Override public Collection getAuthorities() { return…