Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 21 additions & 3 deletions build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -36,9 +36,14 @@ dependencies {
implementation group: 'org.springdoc', name: 'springdoc-openapi-starter-webmvc-ui', version: '2.1.0'
testImplementation group: 'org.springdoc', name: 'springdoc-openapi-starter-webmvc-api', version: '2.1.0'

implementation group: 'io.jsonwebtoken', name: 'jjwt-api', version: '0.11.5'
runtimeOnly group: 'io.jsonwebtoken', name: 'jjwt-impl', version: '0.11.5'
runtimeOnly group: 'io.jsonwebtoken', name: 'jjwt-jackson', version: '0.11.5'
//jwt
implementation group: 'io.jsonwebtoken', name: 'jjwt-api', version: '0.12.3'
runtimeOnly group: 'io.jsonwebtoken', name: 'jjwt-impl', version: '0.12.3'
runtimeOnly group: 'io.jsonwebtoken', name: 'jjwt-jackson', version: '0.12.3'

//jwk
implementation 'com.auth0:java-jwt:3.18.2'
implementation 'com.auth0:jwks-rsa:0.20.0'


// DB (MySQL)
Expand All @@ -54,13 +59,26 @@ dependencies {
implementation 'com.amazonaws:aws-java-sdk-s3'
implementation 'org.springframework.cloud:spring-cloud-starter-aws:2.2.6.RELEASE'

implementation 'org.projectlombok:lombok:1.18.28'


annotationProcessor 'org.projectlombok:lombok'
testImplementation 'org.springframework.boot:spring-boot-starter-test'
testImplementation 'org.springframework.security:spring-security-test'
testRuntimeOnly 'org.junit.platform:junit-platform-launcher'

implementation 'org.springframework.cloud:spring-cloud-starter-openfeign'
}

tasks.named('test') {
useJUnitPlatform()
}
ext {
set('springCloudVersion', "2023.0.4")
}

dependencyManagement {
imports {
mavenBom "org.springframework.cloud:spring-cloud-dependencies:2023.0.4"
}
}
2 changes: 2 additions & 0 deletions src/main/java/com/movelog/MoveLogApplication.java
Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,13 @@
import com.movelog.global.config.YamlPropertySourceFactory;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.cloud.openfeign.EnableFeignClients;
import org.springframework.context.annotation.PropertySource;
import org.springframework.data.jpa.repository.config.EnableJpaAuditing;

@SpringBootApplication
@EnableJpaAuditing
@EnableFeignClients
@PropertySource(value = { "classpath:oauth2/application-oauth2.yml" }, factory = YamlPropertySourceFactory.class)
@PropertySource(value = { "classpath:database/application-database.yml" }, factory = YamlPropertySourceFactory.class)
//@PropertySource(value = { "classpath:s3/application-s3.yml" }, factory = YamlPropertySourceFactory.class)
Expand Down
61 changes: 61 additions & 0 deletions src/main/java/com/movelog/domain/auth/application/AuthService.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
package com.movelog.domain.auth.application;

import com.movelog.domain.auth.dto.NicknameRes;
import com.movelog.domain.user.domain.User;
import com.movelog.domain.user.domain.repository.UserRepository;
import com.movelog.global.config.security.token.UserPrincipal;
import com.movelog.global.payload.Message;
import com.auth0.jwt.JWT;
import com.auth0.jwt.interfaces.DecodedJWT;
import jakarta.persistence.EntityNotFoundException;
import lombok.RequiredArgsConstructor;
import org.springframework.stereotype.Service;
import org.springframework.transaction.annotation.Transactional;

import java.util.Optional;

@Service
@RequiredArgsConstructor
@Transactional(readOnly = true)
public class AuthService {

private final UserRepository userRepository;

@Transactional
public User findOrCreateUser(String provider, String idToken) {

DecodedJWT decodedJWT = JWT.decode(idToken);
String providerId = decodedJWT.getSubject(); // ์‚ฌ์šฉ์ž ๊ณ ์œ  ID (sub)
String email = decodedJWT.getClaim("email").asString();
String username = decodedJWT.getClaim("nickname").asString();

Optional<User> optionalUser = userRepository.findByProviderAndProviderId(provider, providerId);

if (optionalUser.isPresent()) {
return optionalUser.get();
} else {
User newUser = new User("", username, email, "ROLE_USER", provider, providerId);
return userRepository.save(newUser);
}
}


@Transactional
public String findEmail(String providerId) {
User user = userRepository.findByProviderId(providerId)
.orElseThrow(EntityNotFoundException::new);
return user.getEmail();
}



@Transactional
public Message unlinkAccount(Long userId) {
User user = userRepository.findById(userId)
.orElseThrow(EntityNotFoundException::new);
userRepository.delete(user);
return Message.builder()
.message("ํšŒ์› ํƒˆํ‡ด์— ์„ฑ๊ณต ํ–ˆ์Šต๋‹ˆ๋‹ค.")
.build();
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
package com.movelog.domain.auth.application;

import com.movelog.domain.user.domain.User;
import com.movelog.domain.user.domain.repository.UserRepository;
import com.movelog.global.config.security.token.UserPrincipal;
import lombok.RequiredArgsConstructor;
import org.springframework.data.crossstore.ChangeSetPersister;
import org.springframework.security.core.userdetails.UserDetails;
import org.springframework.security.core.userdetails.UserDetailsService;
import org.springframework.security.core.userdetails.UsernameNotFoundException;
import org.springframework.stereotype.Service;

@Service
@RequiredArgsConstructor
public class CustomUserDetailsService implements UserDetailsService {

private final UserRepository userRepository;

//์ด๋ฉ”์ผ๋กœ ์ปค์Šคํ…€
@Override
public UserDetails loadUserByUsername(String email) throws UsernameNotFoundException {
User user = userRepository.findByEmail(email)
.orElseThrow(RuntimeException::new);

return UserPrincipal.createUser(user);
}
}
30 changes: 30 additions & 0 deletions src/main/java/com/movelog/domain/auth/dto/AuthRes.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
package com.movelog.domain.auth.dto;

import io.swagger.v3.oas.annotations.media.Schema;
import lombok.Builder;

@Builder
public record AuthRes(
@Schema(type = "string", example = "eyJhbGciOiJIUzUxMiJ9.eyJleHAiOjE2NTI3OTgxOTh9.6CoxHB_siOuz6PxsxHYQCgUT1_QbdyKTUwStQDutEd1-cIIARbQ0cyrnAmpIgi3IBoLRaqK7N1vXO42nYy4g5g", description = "access token ์„ ์ถœ๋ ฅํ•ฉ๋‹ˆ๋‹ค.")
String accessToken,

@Schema( type = "string", example ="Bearer", description="๊ถŒํ•œ(Authorization) ๊ฐ’ ํ•ด๋”์˜ ๋ช…์นญ์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.")
String tokenType,

@Schema( type = "Role", example = "USER", description = "Role์„ ์ถœ๋ ฅํ•ฉ๋‹ˆ๋‹ค.")
String role,

@Schema( type = "boolean", example = "false", description = "ํšŒ์›๊ฐ€์ž… ์™„๋ฃŒ ์—ฌ๋ถ€๋ฅผ ์ถœ๋ ฅํ•ฉ๋‹ˆ๋‹ค.")
boolean isRegistered
) {

@Builder
public AuthRes {
if (tokenType == null) {
tokenType = "Bearer";
}
if (role == null) {
role = "ROLE_USER";
}
}
}
39 changes: 39 additions & 0 deletions src/main/java/com/movelog/domain/auth/dto/CustomOAuth2User.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
package com.movelog.domain.auth.dto;

import org.springframework.security.core.GrantedAuthority;
import org.springframework.security.oauth2.core.user.OAuth2User;

import java.util.ArrayList;
import java.util.Collection;
import java.util.Map;

public record CustomOAuth2User(
UserDTO userDTO
) implements OAuth2User {
@Override
public Map<String, Object> getAttributes() {
return null;
}

@Override
public Collection<? extends GrantedAuthority> getAuthorities() {
Collection<GrantedAuthority> collection = new ArrayList<>();

collection.add(new GrantedAuthority() {
@Override
public String getAuthority() {
return userDTO.role();
}
});
return collection;
}

@Override
public String getName() {
return null;
}

public String getUsername() {
return userDTO.username();
}
}
11 changes: 11 additions & 0 deletions src/main/java/com/movelog/domain/auth/dto/IdTokenReq.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
package com.movelog.domain.auth.dto;

import lombok.Builder;
import lombok.Getter;

@Builder
public record IdTokenReq(
String idToken,
String provider
) {
}
11 changes: 11 additions & 0 deletions src/main/java/com/movelog/domain/auth/dto/NicknameRes.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
package com.movelog.domain.auth.dto;

import lombok.Builder;

@Builder
public record NicknameRes(
String nickname,
Long userid,
boolean isRegistered
) {
}
11 changes: 11 additions & 0 deletions src/main/java/com/movelog/domain/auth/dto/UserDTO.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
package com.movelog.domain.auth.dto;

import lombok.Builder;

@Builder
public record UserDTO(
String role,
String name,
String username
) {
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
package com.movelog.domain.auth.presentation;

import com.movelog.domain.auth.dto.AuthRes;
import com.movelog.domain.auth.dto.IdTokenReq;
import com.movelog.domain.auth.application.AuthService;
import com.movelog.domain.auth.dto.NicknameRes;
import com.movelog.domain.user.domain.User;
import com.movelog.domain.user.domain.repository.UserRepository;
import com.movelog.global.config.security.jwt.JWTUtil;
import com.movelog.global.config.security.oidc.OidcProviderFactory;
import com.movelog.global.config.security.oidc.Provider;
import com.movelog.global.config.security.token.CurrentUser;
import com.movelog.global.config.security.token.UserPrincipal;
import com.movelog.global.payload.ErrorResponse;
import com.movelog.global.payload.Message;
import io.swagger.v3.oas.annotations.Operation;
import io.swagger.v3.oas.annotations.Parameter;
import io.swagger.v3.oas.annotations.media.ArraySchema;
import io.swagger.v3.oas.annotations.media.Content;
import io.swagger.v3.oas.annotations.media.Schema;
import io.swagger.v3.oas.annotations.responses.ApiResponse;
import io.swagger.v3.oas.annotations.responses.ApiResponses;
import io.swagger.v3.oas.annotations.tags.Tag;
import jakarta.persistence.EntityNotFoundException;
import lombok.RequiredArgsConstructor;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.*;

@Tag(name = "Authorization", description = "Authorization API")
@RestController
@RequestMapping("/auth")
@RequiredArgsConstructor
public class AuthController {

private final OidcProviderFactory oidcProviderFactory;
private final JWTUtil jwtUtil;
private final UserRepository userRepository;


private final AuthService authService;


@Operation(summary = "์†Œ์…œ ๋กœ๊ทธ์ธ", description = "idToken๊ณผ provider(ex. kakao)๋กœ ์†Œ์…œ ๋กœ๊ทธ์ธ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.")
@ApiResponses(value = {
@ApiResponse(responseCode = "200", description = "๋กœ๊ทธ์ธ ์„ฑ๊ณต", content = {@Content(mediaType = "application/json", array = @ArraySchema(schema = @Schema(implementation = AuthRes.class)))}),
@ApiResponse(responseCode = "400", description = "๋กœ๊ทธ์ธ ์‹คํŒจ", content = {@Content(mediaType = "application/json", schema = @Schema(implementation = ErrorResponse.class))}),
})
@PostMapping("/login")
public ResponseEntity<AuthRes> login(@RequestBody IdTokenReq idTokenReq) {
System.out.println("idTokenReq = " + idTokenReq.idToken());
String providerId = oidcProviderFactory.getProviderId(
Provider.valueOf(idTokenReq.provider().toUpperCase()), idTokenReq.idToken());

if (providerId == null) {
return ResponseEntity.badRequest().build();
}

authService.findOrCreateUser(idTokenReq.provider(), idTokenReq.idToken());
String email = authService.findEmail(providerId);

String accessToken = jwtUtil.createJwt("access", providerId, "ROLE_USER", 3600000L, email);

User user = userRepository.findByProviderId(providerId)
.orElseThrow(EntityNotFoundException::new);


AuthRes authRes = AuthRes.builder()
.accessToken(accessToken)
.isRegistered(user.isRegistered())
.build();

return ResponseEntity.ok(authRes);
}


@Operation(summary = "ํšŒ์› ํƒˆํ‡ด", description = "ํ•ด๋‹น ์œ ์ €์˜ ๊ฐ€์ž…์„ ํƒˆํ‡ดํ•ฉ๋‹ˆ๋‹ค.")
@ApiResponses(value = {
@ApiResponse(responseCode = "200", description = "ํšŒ์› ํƒˆํ‡ด ์„ฑ๊ณต", content = {@Content(mediaType = "application/json", array = @ArraySchema(schema = @Schema(implementation = Message.class)))}),
@ApiResponse(responseCode = "400", description = "ํšŒ์› ํƒˆํ‡ด ์‹คํŒจ", content = {@Content(mediaType = "application/json", schema = @Schema(implementation = ErrorResponse.class))}),
})
@DeleteMapping()
public ResponseEntity<Message> unlinkSocialAccount(
@Parameter(description = "Accesstoken์„ ์ž…๋ ฅํ•ด์ฃผ์„ธ์š”.", required = true) @CurrentUser UserPrincipal userPrincipal
) {
return ResponseEntity.ok(authService.unlinkAccount(userPrincipal.getId()));
}
}
30 changes: 30 additions & 0 deletions src/main/java/com/movelog/domain/common/BaseEntity.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
package com.movelog.domain.common;

import jakarta.persistence.*;
import lombok.Getter;
import org.springframework.data.annotation.CreatedDate;
import org.springframework.data.annotation.LastModifiedDate;
import org.springframework.data.jpa.domain.support.AuditingEntityListener;

import java.time.LocalDateTime;

@Getter
@MappedSuperclass
@EntityListeners(AuditingEntityListener.class)
public class BaseEntity {
@CreatedDate
@Column(name = "created_at", updatable=false)
private LocalDateTime createdAt;

@LastModifiedDate
@Column(name = "updated_at")
private LocalDateTime updatedAt;

// @Enumerated(value = EnumType.STRING)
// @Column(name = "status")
// private Status status = Status.ACTIVE;
//
// public void updateStatus(Status status) {
// this.status = status;
// }
}
19 changes: 19 additions & 0 deletions src/main/java/com/movelog/domain/user/application/UserService.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
package com.movelog.domain.user.application;

import com.movelog.domain.user.domain.repository.UserRepository;
import com.movelog.global.payload.Message;
import jakarta.persistence.EntityNotFoundException;
import lombok.RequiredArgsConstructor;

import org.springframework.stereotype.Service;
import org.springframework.transaction.annotation.Transactional;
import org.springframework.web.multipart.MultipartFile;

@RequiredArgsConstructor
@Service
@Transactional(readOnly = true)
public class UserService {

private final UserRepository userRepository;

}
Loading